Privacy Policy

Last updated: November 12, 2025

WatSupAI is based in the Netherlands. This policy complies with GDPR and Dutch privacy laws.

1. Data Controller

Company: AllBlazing BV — c/o WatSup AI

Address: Buitenwatersloot 81, 2613 TB Delft, The Netherlands

Chamber of Commerce (KvK): 83648941

VAT Number: NL862946670B01

For privacy inquiries, contact us at Contact.

2. Legal Basis for Processing (GDPR Article 6)

We process your data based on:

  • Consent: For cookies and analytics (you can withdraw at any time)
  • Contract: For Pro subscription services (necessary to provide the service)
  • Legitimate interest: For abuse prevention and service security

3. What Data We Collect

Free Tier

We store zero free-tier data. No user data stored. Quota tracking is done via localStorage (client-side only). We don't know who you are, and that's how we like it.

Pro Tier

Email address (from Stripe, not stored separately) and Stripe Customer ID for Pro status verification. That's it. We don't need anything else.

Cookies

We use cookies for analytics (GA4) and forms (Netlify). You can accept or decline cookies via the cookie banner. No cookies = no analytics. Your choice.

4. How We Use Data

We use your data only for:

  • Pro status verification (Pro tier only)
  • Payment processing (handled by Stripe)
  • Analytics (only if you accept cookies)

We don't share your data with anyone except Stripe for payment processing. No marketing emails. No spam. No selling your info to third parties. Simple.

5. Data Storage

Free Tier

Zero server storage. All quota tracking is client-side (localStorage). When you close your browser, we don't remember you. That's privacy.

Pro Tier

Email and payment data handled by Stripe (GDPR-compliant). We don't store payment information. Stripe handles all that securely.

Images

Pro images are ephemeral, deleted <5 seconds after processing. We don't store your supplement images. They're gone before you can blink.

Data Location

All data is stored within the EU (Netherlands). We comply with GDPR and Dutch privacy laws (AVG).

6. Data Sharing

We don't share your data with anyone except Stripe for payment processing. No third-party data sharing. No analytics companies (unless you accept cookies). No sketchy stuff.

7. Your Rights (GDPR/AVG)

Under GDPR and Dutch privacy law (AVG), you have the right to:

  • Access: Request a copy of your data (Pro users can request their data)
  • Rectification: Correct inaccurate data
  • Erasure: Request deletion of your data (Pro users can cancel subscription)
  • Portability: Request data export in a machine-readable format
  • Objection: Object to processing of your data
  • Restriction: Request restriction of processing
  • Withdraw consent: Opt out of cookies (cookie banner on first visit)

To exercise these rights, contact us at Contact. We'll respond within 30 days as required by GDPR.

8. Data Retention

We retain data only as long as necessary:

  • Free tier: No data retained (localStorage only, client-side)
  • Pro tier: Data retained while subscription is active. Deleted upon cancellation.
  • Images: Deleted <5 seconds after processing
  • Cookies: As per your consent preference (stored in localStorage)

9. Security & Data Breaches

We use industry-standard security measures to protect your data. All data transmission is encrypted (HTTPS). Payment data is handled by Stripe (PCI DSS compliant). We don't store sensitive data on our servers.

In the unlikely event of a data breach that affects your personal data, we will notify you and the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours as required by GDPR.

10. Cookies & Tracking

We use cookies for:

  • Analytics (GA4): To understand how users interact with our service (only if you accept cookies)
  • Forms (Netlify): To process contact form submissions

You can accept or decline cookies via the cookie banner. No cookies = no analytics. Your choice. See our cookie banner for more details.

11. Third-Party Services

We use the following third-party services:

  • Stripe: Payment processing (GDPR-compliant, EU-based)
  • Google Analytics (GA4): Analytics (only if you accept cookies)
  • Netlify: Hosting and forms (GDPR-compliant)

All third-party services are GDPR-compliant and have data processing agreements in place.

13. Children's Privacy

WatSupAI is 18+ only. We don't knowingly collect data from anyone under 18. If you're under 18, please don't use our service.

14. Changes to This Policy

We may update this privacy policy from time to time. We'll notify you of any changes by updating the "Last updated" date at the top of this page. Continued use of our service after changes constitutes acceptance.

15. Contact & Complaints

Data Protection Contact: For privacy questions or to exercise your rights, contact us at Contact.

Complaints: If you're not satisfied with our response, you have the right to file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.

EU Online Dispute Resolution: For consumer disputes, you can use the EU Online Dispute Resolution platform at ec.europa.eu/consumers/odr.

Entertainment & education only. Not medical advice. AI vibes ≠ lab results. Consult a doctor. Get blood work. 18+ only.

← Back to home