Privacy
Version 2026-08-14-v5
Controller
The controller is Peter Valášik, business address Obrancov mieru 2005/10, 953 01 Zlaté Moravce, company ID 50058045, tax ID 1121257951, email drakderos@gmail.com, telephone +421 948 616 012. Data-subject requests may be sent by email, post or through the contact page.
Anonymous watching
Watching needs no account and uses no advertising or tracking cookies. The live viewer count does not build a persistent viewer profile.
Public contribution and AI
We process the exact prompt, AI interpretation, chosen name, preview, category, price and result for pre-contract steps and contract performance. The prompt is sent to an AI provider and the prompt, chosen name, result and Chronicle entry are public.
Account, payment and contract evidence
If you sign in we process account identifiers, email and display name. Stripe handles card data; we store references, amount, currency, state and time. An immutable order and legal snapshot records consent and contract evidence.
Withdrawal and complaints
The form stores name, surname, email, order reference, request type, optional reason and receipt time. These fields are private, are not sent to AI, and are used to handle and acknowledge the request.
Security
Short-lived salted one-way pseudonymous counters protect the service. Raw card numbers are never stored. A legal request is stored before anti-spam controls and cannot be disabled by a global quota.
Recipients
Recipients include hosting/database, Stripe, AI and transactional-email providers, using appropriate safeguards for transfers outside the EEA.
Retention
Public contributions remain during service operation, but prompt and creator name are anonymised or hidden after valid withdrawal or another justified request. Contract, payment, accounting and legal-submission records follow statutory periods.
Your rights
Subject to legal conditions, you have rights of access, rectification, erasure, restriction, objection and portability, and may complain to the Slovak data-protection authority.
Content reports
The report form for illegal or rights-infringing content stores the content reference, category, explanation, reporter email, optional name or organisation, the good-faith confirmation and the receipt time. These fields are private and are never sent to the AI provider. They are used to assess and handle the report, to contact the reporter and to demonstrate compliance, and are kept while the report is handled and for the applicable statutory and limitation periods.
Lawful bases by purpose
Pre-contract processing of a prompt, creation of a preview, the order, account processing needed for a chosen feature and performance of the order rely on Article 6(1)(b) GDPR. Accounting, tax, consumer-protection and other mandatory records rely on Article 6(1)(c). Service security, abuse prevention, protection of legal claims and proportionate follow-up assessment of reported content rely on Article 6(1)(f); our legitimate interests are secure operation, protection of users and property, defence of legal claims and integrity of the public world. Consent is used only where it is specifically requested as a separate legal basis; contract and legal-obligation processing do not depend on consent.
Required and optional data
No account is required merely to watch. A prompt and the data necessary to create, verify and perform an order and payment are required to place an order; without them the order cannot be concluded or performed. For an account, an email or account identifier is necessary to sign in and to use verified-account functions. Fields marked optional in forms are voluntary; information needed to identify a request or order must be provided or we may be unable to handle it.
Data sources
Most data come directly from you. Payment status and references come from Stripe, sign-in/session identifiers come from our account/authentication system, and necessary technical or security data arise when your device communicates with the service. Card details are collected and processed directly by Stripe; we do not receive or store the full card number.
AI and automated processing
AI interprets the prompt and creates the title, description, category and visual proposal; automated rules also screen prompts and results for safety and permitted content. The resulting offer and price are shown before you freely decide whether to confirm the order. Automated screening may refuse a contribution before publication, but you can request human review. Reports concerning already published content and appeals are not decided solely by automated means.
Cookies and device storage
We intentionally use no advertising or analytics cookies and do not perform behavioural advertising profiling. The service, authentication, security mechanisms and payment flow may use strictly necessary cookies or local storage required for functionality you request; Stripe may use its own strictly necessary technologies in the payment environment. If optional analytics, advertising or other non-essential technologies requiring consent are introduced later, they will not run before valid consent and rejecting them will be as easy as accepting them.
Transfers outside the EEA and safeguards
We prefer EEA processing where a provider offers it. Where a provider processes data in a third country, we use an available GDPR transfer mechanism: a European Commission adequacy decision, including the EU-US Data Privacy Framework for an eligible recipient, or Standard Contractual Clauses and supplementary safeguards where required. You may request information about the applicable mechanism or a copy of relevant safeguards through our contact; commercial or security-sensitive details may be appropriately redacted.
Retention periods and criteria
A public contribution is retained while the service operates unless it is validly withdrawn, anonymised, removed or restricted for a legal reason. An account is retained until deletion or termination, while separate contract, payment and statutory records may remain for applicable accounting, tax and limitation periods. Order, payment and consent evidence is kept for periods required by law and as necessary to establish or defend legal claims. Complaints, withdrawals and content reports are kept while handled and then for applicable statutory or limitation periods. Short-lived security counters and technical records are kept only as long as reasonably necessary for security and diagnostics.
Supervisory authority
If you believe personal-data processing infringes the GDPR, you may lodge a complaint with a competent supervisory authority, in particular the Office for Personal Data Protection of the Slovak Republic, Galvaniho Business Centrum II, Galvaniho 7/B, 821 04 Bratislava, Slovakia. This does not limit your right to approach another competent GDPR supervisory authority.