Privacy Policy
Last updated: 24 July 2026.
Who we are
GDPRchat Community is a public community platform operated by FRITS AI ApS, CVR 45733785, Nyhavn 38, 1051 København K, Denmark — the company behind GDPRchat. FRITS AI ApS is the data controller for the processing described here. Contact: support@frits.ai. All data is processed and stored within the EU.
Your identity here
You sign in with your GDPRchat account. During sign-in, GDPRchat shares only an internal account identifier, your language preference, a yes/no flag that your email is verified, and — solely to pre-fill the name picker — a pseudonymous suggested handle. Never your real name, email address, or any chat content. The suggestion is not stored unless you choose to keep it. Your public identity here is solely the public name you choose. We never display your real identity, and we do not send your identity to any third party. Because a GDPRchat account requires you to be at least 16 years old, the same age floor applies here.
What is public
Everything you post — communities, posts, comments, votes shown as scores, your profile page — is public on the internet and may be indexed by search engines, attributed to your public name. Direct messages are not public; they are visible only to the two participants (and to us where required for abuse handling upon a report).
Data we store
Your public name, optional bio and country, language, community memberships, posts, comments, votes, saved and hidden posts, which threads you opened (to show "new comments since"), who you follow and block, notifications, community chat messages, direct messages, reports you file, uploaded images (re-encoded, with all camera metadata such as GPS location stripped on upload), and moderation records.
Cookies: we use only first-party cookies that the site needs to function — a session cookie (30 days), a language cookie and a theme cookie (both 1 year), and a few short-lived helpers for the sign-in flow and app display (minutes to hours). No advertising, no tracking cookies, no analytics identifiers, no third-party cookies — which is why there is no cookie banner: there is nothing to opt out of.
Your browser also keeps a few things locally that never reach our servers: your recent searches, your preferred comment order, and flags remembering which one-time hints you have already seen. Clearing your browser data removes them.
Community suggestions from your chats
GDPRchat can suggest a community when many people ask its AI about the same topic. To count that demand, the GDPRchat server sends the topic of a chat question here under an irreversible pseudonymous code — we never receive your account identity, and the question text itself is not kept: it is reduced on arrival to an anonymous topic counter. The pseudonymous code's link to a topic is kept for at most 30 days, and only if you explicitly choose to found a community is your question kept — for at most 24 hours — to start it. You can switch these suggestions off at any time in your GDPRchat settings ("community suggestions"), and questions the AI classifies as sensitive or personal are handled with extra restraint.
Translation and search
Posts, comments and community descriptions are machine-translated into readers' languages, and direct messages only when the reader explicitly presses "Translate". For this, and for semantic search, the text is processed by Mistral AI (France) acting as our processor under a data processing agreement — content only, never your identity or account identifier, and always within the EU. Translations are cached so each text is translated once. No other third party receives any data. We use no analytics, no advertising, and no tracking, and we make no automated decisions about you in the sense of Art. 22 GDPR.
Notifications to your GDPRchat app
When someone replies to you, messages you, or upvotes your content, we can deliver that notification through GDPRchat so it reaches you there. The notification carries the actor's public name and the relevant content snippet, addressed to your internal account identifier. This stays between GDPRchat Community and GDPRchat — both operated by FRITS AI ApS — and can be switched off in your notification settings.
Legal bases
We process your data to provide the service you signed up for (Art. 6(1)(b) GDPR — contract): your profile, contributions, messages and notifications. Moderation, abuse handling, rate limiting, the impersonation guard on freed names, and the anonymous demand counter rest on our legitimate interests (Art. 6(1)(f)) in keeping a public platform safe, lawful and useful; the counter is designed so it cannot single you out. Keeping your question to found a community happens only with your consent (Art. 6(1)(a)).
How long we keep data
Your content and profile: until you delete it or your account. Demand-counter codes: at most 30 days. A founding question: at most 24 hours. Moderation reports and the moderation log: 24 months, then deleted. Cached translations: as long as the translated content itself exists. Database backups rotate automatically and are kept for 14 days on EU servers (occasional encrypted cold-storage snapshots at most 90 days), so erased data also disappears from every backup within three months at the latest — from the regular rotation within about two weeks.
If you delete your GDPRchat account
Deletion propagates here automatically and permanently de-identifies you: the link to your account is severed, your public name is released from your contributions, and your account ceases to exist. Posts and comments remain in de-identified form, shown under a neutral "deleted user" label — this keeps the conversations everyone else took part in intact. Everything else is erased: the direct messages you sent (including any cached translations of them), your uploaded images, your votes, saved and hidden posts, reading timestamps, follows, blocks, community chat messages, notifications, and your name wherever it was echoed into other members' notifications. Posts and comments you had already deleted yourself have their content wiped as well. You can additionally delete individual posts and comments yourself at any time — doing so erases their text, images and translations immediately, leaving only a neutral placeholder in the thread. A public name that has been in use is never given to anyone else.
Your rights
You have the GDPR rights of access, rectification, erasure, restriction, portability and objection. Your GDPRchat data export (Settings → Privacy in GDPRchat) automatically includes everything GDPRchat Community holds about you. For anything else, contact support@frits.ai. You may lodge a complaint with the Danish Data Protection Agency (Datatilsynet, www.datatilsynet.dk) or your local supervisory authority.