Privacy Policy
Last updated: 7.9.2026 • Effective from: 1.9.2026
This Policy explains what we do with personal data when you use QuizyPeasy. It is written to meet Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679.
1. Controller
The controller is OMNI solutions s. r. o., Školská 992/7, 931 01 Šamorín, Slovak Republic, company registration number (IČO) 57 431 027, registered in the Commercial Register maintained by the District Court Trnava.
Write to support@quizypeasy.com about anything in this Policy.
We have not appointed a data protection officer, because we do not meet the conditions in Article 37 GDPR. Requests go to the address above and are handled by us directly.
2. What we process
Account data. Your name, email address, profile image, and either a hashed password or the identifiers of the Google, Microsoft or Apple account you sign in with. Passwords are stored only as salted hashes; we never hold the password itself.
Your content. The documents and images you upload, the topics you type, the tests generated from them, the tests you create or edit yourself, and your answers. Uploaded documents may themselves contain personal data — see section 5, which matters.
Learning and usage data. Your results, per-question statistics, mastery levels across repeated attempts, how long you spend on a test, and the volume of AI generation attributable to your account.
Billing data. Your subscription status, billing details, invoices, and the customer and subscription identifiers assigned by Stripe. Card details are handled by Stripe alone; we do not receive or store them.
Communication data. Support messages and the resulting ticket history, and the notifications we have sent you.
Sharing data. Who shared what with whom, when a share was accepted, and access records for public share links.
Technical data. IP address, browser and device type, log records, and cookies as described in the Cookie Policy.
3. Why we process it, and on what basis
| Purpose | Legal basis | Retention |
|---|---|---|
| Creating and running your account | Art. 6(1)(b) — performance of the contract | while the account exists, then 30 days for export |
| Generating tests, running them, storing results and statistics | Art. 6(1)(b) | while the account exists |
| Sharing features, including public links | Art. 6(1)(b) | while the share exists; access logs 12 months |
| Sending service messages — changes, outages, renewal reminders | Art. 6(1)(b) | while the account exists |
| Payments, invoicing and accounting records | Art. 6(1)(b) and Art. 6(1)(c) — legal obligation | 10 years for accounting records |
| Support tickets | Art. 6(1)(b) | 3 years from closure of the ticket |
| Security, abuse prevention, quota enforcement | Art. 6(1)(f) — our legitimate interest in protecting the Service and its users | logs 12 months |
| Handling complaints and legal claims | Art. 6(1)(c) and Art. 6(1)(f) | until the applicable limitation period expires |
| Improving the Service and the quality of generated content | Art. 6(1)(f) — our legitimate interest | 12 months, then aggregated or deleted |
| Newsletter, if you sign up | Art. 6(1)(a) — consent | until you withdraw consent |
| Browser push notifications, if you allow them | Art. 6(1)(a) — consent | until you withdraw permission |
Where we rely on legitimate interest, we have carried out a balancing assessment and concluded that our interest does not override your rights and freedoms. We will send you that assessment on request.
Deletion is not always immediate: content can persist in encrypted backups for a short period after you delete it, and we remove it from those in the ordinary backup cycle.
4. Artificial intelligence
Generation of tests and test result insights uses large language models operated by Google (Gemini). When you generate a test, we send them the source material or topic you provided, together with the generation parameters — nothing more. We do not send your name, email address, account identifier or payment data.
That is pseudonymisation within the meaning of Article 4(5) GDPR, not anonymisation: we can still connect a request back to you through our own records.
This matters for you. Pseudonymisation only protects what is not inside the content itself. If your uploaded document contains names, case numbers, medical details or anything else identifying, that goes to the AI provider along with the rest of the file. Please remove or replace identifying details before uploading, and use generic labels — "the client", "the patient", "witness X". If the material belongs to someone else's professional file, this is not a formality.
Under our contracts, the AI providers do not use this content to train their models, and neither do we.
Generated content is produced automatically and can be wrong. Scoring within the Service is arithmetic, and grading of short answers is done by you. None of it produces a decision with legal or similarly significant effect for you, so Article 22 GDPR does not apply.
5. Personal data of other people in what you upload
If you upload a document containing personal data about someone else, we process that data in order to give you the service you asked for, and we do not inspect the substance of your files. You are responsible for having a proper basis to upload it, and for the fact that those people generally do not know the file is here. Where we are the controller of that data, we cannot practicably inform them individually, and we rely on Article 14(5) GDPR; this Policy serves as the public information about that processing.
If you learn that you have uploaded something you should not have, delete it in the application. Contact us if you need help removing it from a share you no longer control.
6. Who receives the data
We use the following processors, each under a data processing agreement meeting Article 28 GDPR:
| Processor | What it does | Location |
|---|---|---|
| Supabase | database, file storage, authentication, real-time collaboration | EU region |
| Vercel | application hosting, edge network, aggregated usage and performance metrics | EU / USA |
| Google (Gemini) | AI generation of tests and test result insights | EU / USA |
| Google, Microsoft, Apple | sign-in, where you choose that option | EU / USA |
| Stripe | payment processing and subscription billing | EU / USA |
| Resend | transactional email and receipt of inbound support email | USA |
An up-to-date list is maintained at [●]. We announce changes there before a new processor starts work.
We also disclose data to public authorities where the law requires it, and to our professional advisers where necessary for a specific matter.
Where you sign in with Google, Microsoft or Apple, that provider acts as an independent controller for your use of its own sign-in service, under its own privacy notice.
7. Transfers outside the EEA
Some of the processors above operate in the United States. Those transfers rest on the Standard Contractual Clauses adopted by the European Commission and, where the recipient is certified under the EU–US Data Privacy Framework, on the Commission's adequacy decision of 10 July 2023. We assess the circumstances of each transfer and apply additional measures, principally encryption in transit and minimisation of what is sent.
You can ask us for a copy of the safeguards that apply to a particular processor at support@quizypeasy.com.
8. Users under 18
QuizyPeasy may be used by people aged 13 to 17 only where a parent or legal guardian has agreed to the Terms of Use and is the account holder. In that case the parent or guardian exercises the rights in section 10 on the young person's behalf.
We do not knowingly process data of children under 13. If you believe a child under 13 has an account, write to us and we will delete it.
For accounts belonging to users under 18, public sharing is switched off unless the account holder enables it, and we do not use their data for any marketing purpose.
9. Security
We protect the Service by technical and organisational measures appropriate to the risk, under Article 32 GDPR. They include:
-
encryption in transit throughout (HTTPS/TLS);
-
storage of passwords as salted hashes only;
-
row-level security at database level, so that each account can reach only its own data;
-
access to production data limited to a small number of people bound by confidentiality;
-
separation of file storage from application logic, and signed, expiring URLs for file access;
-
logging of administrative actions;
-
regular security updates and monitoring.
If a personal data breach occurs, we notify the competent supervisory authority within 72 hours of becoming aware of it where the breach is likely to result in a risk to your rights, and we notify you without undue delay where it is likely to result in a high risk.
10. Your rights
You have the right to obtain confirmation of whether we process your data and a copy of it (Art. 15), to have inaccurate data corrected and incomplete data completed (Art. 16), to have data erased (Art. 17), to have processing restricted (Art. 18), to receive your data in a structured, commonly used, machine-readable format and to have it transmitted to another controller (Art. 20), and to object to processing based on our legitimate interest on grounds relating to your particular situation (Art. 21). Where processing rests on consent, you can withdraw it at any time, without affecting the lawfulness of what was done before.
The quickest route is in the application, under Settings → Privacy, where you can export everything we hold about you in a single file and delete your account permanently. Otherwise write to support@quizypeasy.com. We answer within one month, and tell you if we need to extend that by up to two further months because the request is complex.
If you think we are handling your data unlawfully, you can lodge a complaint with a supervisory authority — either the authority in the Member State where you live or work, or ours, the Office for Personal Data Protection of the Slovak Republic, Bratislava, www.dataprotection.gov.sk.
11. Is providing data mandatory?
Providing your name, date of birth (age), email address and password is a requirement for entering into the contract: without them we cannot create an account or provide the Service. Everything else is voluntary — the newsletter, push notifications, and any optional profile information — and refusing has no consequence for your use of the Service.
12. Cookies
Cookies and similar technologies are described in the separate Cookie Policy, together with how to give, refuse and withdraw consent.
13. Changes to this Policy
We update this Policy as the Service changes. We tell you about material changes by email and in the application at least 15 days before they take effect. The current version is always available at https://www.quizypeasy.com/privacy.