Privacy Policy
Last updated: November 12, 2025
WatSupAI is based in the Netherlands. This policy complies with GDPR and Dutch privacy laws.
1. Data Controller
Company: AllBlazing BV — c/o WatSup AI
Address: Buitenwatersloot 81, 2613 TB Delft, The Netherlands
Chamber of Commerce (KvK): 83648941
VAT Number: NL862946670B01
For privacy inquiries, contact us at Contact.
2. Legal Basis for Processing (GDPR Article 6)
We process your data based on:
- Consent: For cookies and analytics (you can withdraw at any time)
- Contract: For Pro subscription services (necessary to provide the service)
- Legitimate interest: For abuse prevention and service security
3. What Data We Collect
Free Tier
We store zero free-tier data. No user data stored. Quota tracking is done via localStorage (client-side only). We don't know who you are, and that's how we like it.
Pro Tier
Email address (from Stripe, not stored separately) and Stripe Customer ID for Pro status verification. That's it. We don't need anything else.
Cookies
We use cookies for analytics (GA4) and forms (Netlify). You can accept or decline cookies via the cookie banner. No cookies = no analytics. Your choice.
4. How We Use Data
We use your data only for:
- Pro status verification (Pro tier only)
- Payment processing (handled by Stripe)
- Analytics (only if you accept cookies)
We don't share your data with anyone except Stripe for payment processing. No marketing emails. No spam. No selling your info to third parties. Simple.
5. Data Storage
Free Tier
Zero server storage. All quota tracking is client-side (localStorage). When you close your browser, we don't remember you. That's privacy.
Pro Tier
Email and payment data handled by Stripe (GDPR-compliant). We don't store payment information. Stripe handles all that securely.
Images
Pro images are ephemeral, deleted <5 seconds after processing. We don't store your supplement images. They're gone before you can blink.
Data Location
All data is stored within the EU (Netherlands). We comply with GDPR and Dutch privacy laws (AVG).
6. Data Sharing
We don't share your data with anyone except Stripe for payment processing. No third-party data sharing. No analytics companies (unless you accept cookies). No sketchy stuff.
7. Your Rights (GDPR/AVG)
Under GDPR and Dutch privacy law (AVG), you have the right to:
- Access: Request a copy of your data (Pro users can request their data)
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your data (Pro users can cancel subscription)
- Portability: Request data export in a machine-readable format
- Objection: Object to processing of your data
- Restriction: Request restriction of processing
- Withdraw consent: Opt out of cookies (cookie banner on first visit)
To exercise these rights, contact us at Contact. We'll respond within 30 days as required by GDPR.
8. Data Retention
We retain data only as long as necessary:
- Free tier: No data retained (localStorage only, client-side)
- Pro tier: Data retained while subscription is active. Deleted upon cancellation.
- Images: Deleted <5 seconds after processing
- Cookies: As per your consent preference (stored in localStorage)
9. Security & Data Breaches
We use industry-standard security measures to protect your data. All data transmission is encrypted (HTTPS). Payment data is handled by Stripe (PCI DSS compliant). We don't store sensitive data on our servers.
In the unlikely event of a data breach that affects your personal data, we will notify you and the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours as required by GDPR.
10. Cookies & Tracking
We use cookies for:
- Analytics (GA4): To understand how users interact with our service (only if you accept cookies)
- Forms (Netlify): To process contact form submissions
You can accept or decline cookies via the cookie banner. No cookies = no analytics. Your choice. See our cookie banner for more details.
11. Third-Party Services
We use the following third-party services:
- Stripe: Payment processing (GDPR-compliant, EU-based)
- Google Analytics (GA4): Analytics (only if you accept cookies)
- Netlify: Hosting and forms (GDPR-compliant)
All third-party services are GDPR-compliant and have data processing agreements in place.
13. Children's Privacy
WatSupAI is 18+ only. We don't knowingly collect data from anyone under 18. If you're under 18, please don't use our service.
14. Changes to This Policy
We may update this privacy policy from time to time. We'll notify you of any changes by updating the "Last updated" date at the top of this page. Continued use of our service after changes constitutes acceptance.
15. Contact & Complaints
Data Protection Contact: For privacy questions or to exercise your rights, contact us at Contact.
Complaints: If you're not satisfied with our response, you have the right to file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.
EU Online Dispute Resolution: For consumer disputes, you can use the EU Online Dispute Resolution platform at ec.europa.eu/consumers/odr.
Entertainment & education only. Not medical advice. AI vibes ≠ lab results. Consult a doctor. Get blood work. 18+ only.
← Back to home