BadMars — Privacy Policy
We wrote this to be read, not survived. It explains what BadMars collects, why, what we do with it, and the rights you have. The short version: we store your material only in the EU, we never use it to train AI models, and the moat we keep is made of anonymous patterns, not your plans.
1. Who we are
BadMars is operated by Nivobit Digital SRL (Romania, EU), the data controller for the processing described here. Company identification is on the Legal Notice.
- Privacy / data-request contact: [email protected]
- Supervisory authority (Romania): Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral Gheorghe Magheru 28-30, Sector 1, 010336 București; +40 318 059 211; [email protected].
We have assessed our current processing against the GDPR Article 37 criteria and do not currently consider the appointment of a Data Protection Officer mandatory, because our core activities do not require large-scale regular and systematic monitoring of individuals or large-scale processing of Article 9 or Article 10 data. We reassess this if our scale, product use cases or processing change (for example, material user-volume growth, a feature that deliberately supports Article 9 data, systematic scoring of people, or telemetry/profiling becoming a core product function). We are established in Romania, so no EU Article 27 representative is required. The contact above is your route for anything data-related.
2. The two roles
For individuals analysing their own material (Flyby, Landing, Colony), we are the controller throughout — for your account, your billing relationship, your Missions, and our telemetry.
For business customers (Fleet, and Enterprise/API), features that permit a customer to submit personal data on behalf of another person (its clients or staff) are available only under the data-processing terms applicable to that feature — under which we act as a processor for that Customer Content while remaining an independent controller for account, billing, and operational telemetry. Until those terms are in force, do not submit that data. Where a Data Processing Agreement governs an account, it prevails for that Customer Content.
3. What we collect
Five buckets:
- Account data — email, name, a hashed (never plaintext) password, and, if you use “Sign in with Google,” the account identifier, email, and name Google returns. Source for that last one is Google (GDPR Art. 14(2)(f)).
- Payloads — the business-plan text and material you submit for analysis.
- Outputs — the Mission Reports, Scores, Verdicts, Findings, and Debrief replies generated for you.
- Operational telemetry — limits, spend, session and funnel events, IP address, device class, and security signals (see §7 for how long we keep it).
- Pattern records — anonymous, coded classifications derived from analyses (see §4).
The consumer Service is not designed for personal data about other people or special-category data (health, racial/ethnic origin, political/religious/ philosophical beliefs, trade-union membership, genetic or biometric identification data, sex-life/orientation, criminal-offence data, government identification numbers, payment-card data, and similar). You must not submit it. Payloads are free text; we neither intend to nor have a legal basis to process special-category data. Submitting prohibited data does not instruct or authorise us to analyse it and does not create a legal basis for processing it as part of the requested analysis. We implement proportionate preflight controls to intercept obvious prohibited material; where such material is detected, we stop the requested analysis and isolate or delete the affected material as promptly as reasonably possible (a positive hit does not create a reusable pattern record). Because Payloads are free text, we do not promise perfect detection. We do not intentionally route detected prohibited material into report-generating inference, use it to profile a person or infer sensitive characteristics, or create pattern records from it, and we do not process payload content for any purpose beyond generating your report. Any processing or retention required by applicable law is carried out only where an applicable legal basis and, where required, an Article 9 condition exists — detecting and deleting prohibited data is not itself an Article 9 exception. You warrant you have the right to submit what you submit (the Terms of Service set the prohibited-data rule).
We never collect or store your payment card details. Purchases go through Paddle (see §5 and §9).
4. Patterns, not plans
This is the part most companies bury. We keep it in the open, because it is what makes BadMars durable and private at the same time:
- We derive candidate classification records from analyses. A candidate record may remain personal data while a person, customer or source record can reasonably be singled out, linked or inferred, so we treat candidate records as personal data until they pass our documented anonymisation process. Only records that have demonstrably passed that process are retained as anonymous pattern records outside the GDPR. We do not retain document content in that anonymous dataset.
- Conversations (Debrief) are classified for product-improvement signals; the classification verdict is stored, the conversation text is not.
- “Frog” evidence text is user-authored, excluded from aggregate use by default, and deletable on request.
- Account deletion removes the account, the payloads, the reports and the Debrief. Only pattern records that have already passed the anonymisation process remain — they are no longer personal data (see §7 for why, and why that is lawful).
- Operational telemetry (limits, spend, sessions) is retained for the periods in §7 and is deletable with your account.
- No customer documents are used to train AI models — not by us, and not by our model providers (see §5).
5. AI processing and sub-processors
BadMars is an AI system. To analyse your payload, we send it to third-party large-language-model providers (currently Anthropic, with OpenAI as a failover and for text embeddings) for inference, on our instruction. Our residency posture is three plain, separately true claims:
Stored only in the EU. Never used for training. Processed under no-training terms with minimal, short retention.
- Storage is EU-only — your documents, reports, account, and backups live only in the EU (Hetzner, Germany).
- Inference is transit, not residence — under the business/API terms and account settings we currently use, our model providers do not use BadMars API inputs or outputs to train their general models, and we do not opt in to voluntary data sharing for model training. Provider-side retention and state can vary by provider, feature, endpoint and contracted control; provider copies or logs may be retained for limited operational, abuse-monitoring, safety or legal purposes, and some API features maintain application state for their documented period. We do not publish a provider-wide or service-wide retention period unless we have verified that period for every endpoint to which the statement applies; the current verified per-provider details are maintained in our Sub-processor List and transfer register. No EU inference region is currently available for our providers.
- We describe a workflow as zero-data-retention only where that control is contractually available to our account and verified for every endpoint it uses, including inference, failover, embeddings and any stateful or file-based features. We do not make a product-wide zero-retention claim.
- If and when we secure EU-region inference end-to-end, we will say so here — never before it is true.
The full, versioned list of the third parties we use, what each does, where it sits, and the transfer safeguard, is on the Sub-processor List. For what BadMars is as an AI system, see the Disclosure (our Article 50 transparency page).
6. Legal bases
We rely on the following bases under GDPR Article 6:
| What we do | Legal basis |
|---|---|
| Create and run your account; sign-in | Contract — Art. 6(1)(b) |
| Analyse your payload and deliver the report / Debrief | Contract — Art. 6(1)(b) |
| Keep billing/entitlement and tax records | Contract — Art. 6(1)(b) and legal obligation — Art. 6(1)© |
| Security, anti-abuse, bot protection (IP, Turnstile), stability | Legitimate interests — Art. 6(1)(f) |
| First-party operational telemetry and the anonymous Dataset | Legitimate interests — Art. 6(1)(f) |
| Transactional email (verification, resets, receipts) | Contract — Art. 6(1)(b) |
| Google Analytics 4, and any marketing/advertising pixels | Consent — Art. 6(1)(a), given via the cookie banner |
| Any future marketing email | Consent — Art. 6(1)(a) |
Where we rely on legitimate interests, our interest is running a secure, reliable service and improving it without processing your plans as content; the balancing analysis is recorded internally. Where we rely on consent — analytics and marketing cookies (see the Cookie Policy) — you give it through the cookie banner and can withdraw it at any time (Art. 7(3)) via the “Cookie settings” link, without affecting processing already carried out.
Automated decisions: the report is advisory analysis presented to you. It does not produce a legal or similarly significant effect on you within the meaning of GDPR Article 22, and we do not make solely-automated decisions of that kind about you. This is an enforceable product boundary, not only a description: the Terms of Service prohibit using the Service as the sole or determinative basis for consequential decisions about a person (credit, employment, housing, insurance, healthcare and similar), and no BadMars API or Enterprise feature may be marketed, configured or documented as the sole or determinative gate for such decisions about a natural person without a separate DPIA / Article 22 review and approved architecture.
7. Retention
- Payloads and reports — kept while the Program lives; deleted when you delete your account.
- Operational telemetry — two bands:
- Security (wall events, IP-level logs, injection tags, refund/chargeback flags, guarantee marks): 13 months.
- Product (session/funnel events, spend accrual, device class): 13 months at user/session/pseudonymous level; any longer product analysis is kept only as genuinely anonymized aggregates (see §4). Both are deleted with your account, with one exception: a minimized pseudonymous anti-fraud marker associated with a prior guarantee refund may be retained for up to 13 months after account deletion, solely to prevent delete-and-re-signup or aliasing from resetting the one-time guarantee. It is access-restricted, one-way-normalized, and auto-deleted at the end of that period. That is fraud-prevention legitimate interest.
- Anonymized pattern records — retained indefinitely only to the extent they genuinely no longer constitute personal data (irreversibly de-identified, no stable account/source identifier, no small-cell uniqueness); they are not attributable to you (see §4).
- Accounting and supporting records — retained for the period required by Romanian law, generally five years calculated from 1 July of the year following the financial year in which they were prepared, subject to any longer requirement, legal hold, or category-specific rule.
8. Your rights
You have the full set under GDPR: access, rectification, erasure, restriction, portability, and objection, plus withdrawal of consent where we rely on it.
We built the mechanics to be honest:
- You can delete your account yourself, any time, from Settings → Data rights. Deletion is immediate and irreversible: it removes the account, Payloads, Outputs and Debrief, subject to the limited legal-retention exceptions described in §7. Only pattern records that have already passed our documented anonymisation test are outside the erasure scope. You can also email [email protected]; we act on valid erasure requests without undue delay and within the periods required by GDPR Article 12.
- To exercise any other right, email [email protected]. We respond within one month (GDPR Art. 12), extendable where the law allows for complex requests.
- You can lodge a complaint with ANSPDCP (§1) or your local supervisory authority at any time.
Providing your data is necessary to use the service — without an account and a payload, there is no report.
9. International transfers
Some of our model providers and infrastructure vendors are outside the EEA (see the Sub-processor List). We use the transfer mechanism that applies to the actual recipient and transfer. Where an applicable European Commission adequacy decision covers the recipient and the data — including the EU–US Data Privacy Framework for a US recipient whose certification is valid and covers the relevant processing — we may rely on that adequacy decision. Where no adequacy decision applies, we use an appropriate GDPR Article 46 safeguard, including the Commission’s 2021 Standard Contractual Clauses where those clauses are legally available, with supplementary measures where required. We do not use the 2021 SCCs as the transfer instrument where a recipient’s relevant processing is itself directly subject to the GDPR (Article 3) and those clauses are therefore not the appropriate instrument; direct GDPR applicability does not by itself eliminate Chapter V, so we identify and use another applicable Chapter V basis where one is required. A copy of the safeguards is available on request.
10. Security
Our infrastructure is in the EU. Data is encrypted in transit and at rest. No payment card data ever touches BadMars — Paddle handles it. Access to production systems is limited to the founder-operator. Payloads are parsed in isolation. We do not run certification theatre; we run the controls that matter.
11. Regional rights
We offer the rights below to everyone, but some regions add specifics.
EEA / UK residents
The GDPR rights in §8 apply. UK users are covered by the UK GDPR and the Data Protection Act 2018; your supervisory authority is the Information Commissioner’s Office (ICO), ico.org.uk. UK transfers to non-adequate countries are covered by the SCCs as supplemented by the UK International Data Transfer Addendum (or the IDTA).
California residents (CCPA / CPRA)
We honour these rights voluntarily. Based on our most recent documented assessment we currently believe we are below the statutory thresholds that would make us a CCPA “business,” and we reassess this periodically; regardless, we extend the protections below.
- Categories we collect map to §3: identifiers (email, name, account IDs), internet/network activity (telemetry, IP), user content (payloads, reports), and commercial information (entitlements; payment handled by Paddle). We do not collect sensitive personal information for the purpose of inferring characteristics.
- Sources, purposes, and recipients are as described in §3, §5, §6 and the sub-processor list.
- We do not sell your personal information. Today we do not “share” it for cross-context behavioural advertising either — our analytics (GA4) runs with Google’s advertising features and Google Signals off, so it is not used for cross-context behavioural advertising. If and when we enable advertising pixels (for example Meta or TikTok), that activity counts as “sharing” under the CCPA — at that point we provide a “Do Not Sell or Share My Personal Information” control, honour opt-out signals (including the Global Privacy Control), and update this section. You can refuse marketing cookies in the cookie banner at any time.
- No significant automated decisions. We do not use automated decision-making or profiling that produces legal or similarly significant effects about you (see §6).
- Your rights: know/access, delete, correct, opt out of sale/share, limit use of sensitive information, and non-discrimination for exercising them. Contact [email protected], or use the cookie banner for cookie opt-outs.
Other jurisdictions
Rights may vary by where you live (for example Brazil’s LGPD, Canada’s PIPEDA, and other US state laws). Our GDPR-grade baseline meets or exceeds most of them, and the rights in §8 are available to you; contact us to exercise them.
12. Children, changes, contact
- 18+. BadMars is not for anyone under 18. We do not knowingly process children’s data.
- Changes. We update this policy as the service and the law change; the date at the top moves and, for material changes, we give notice.
- Contact. [email protected] for anything in this policy.