← Back

Privacy policy

Effective date: 19 September 2026

This policy explains what data TIB processes, why and on what legal basis. It describes only what the system actually does today.

1. Who is the controller

Data controller: Mihai Morariu · Empresario individual · NIF X9002058L · Calle Padre José Aguirre, 5, 26500 Calahorra, La Rioja, España.

You can write to us about any privacy matter at the address below.

2. What data we process

  • Account data: name, email, password stored encrypted by the authentication provider, language and preferences.
  • Professional details you provide: phone, country, company, role.
  • Data you enter about your clients and contacts: name, company, role, notes, opportunities, tasks and meetings.
  • Email, if you connect an IMAP or Outlook mailbox or use blind-copy capture: senders, recipients, subjects and message content related to your opportunities.
  • Voice notes, meeting recordings and their transcripts, when you choose to record.
  • Documents and transcripts you upload or import.
  • Email open tracking: switched off. TIB does not insert tracking pixels and does not record opens, user agents or any value derived from the IP address.
  • Technical usage data needed to run and secure the service.

3. Purposes and legal bases

  • Providing the service, maintaining your account and generating summaries and recommendations: performance of the contract.
  • Invoicing and accounting or tax obligations: legal obligation.
  • Security, fraud prevention and incident handling: legitimate interest.
  • Support, setup help and asking for feedback during the trial, including use of your business phone: legitimate interest in the B2B relationship.
  • Product news and commercial messages by email, phone or WhatsApp: separate, revocable consent that is not a condition for signing up.

4. Third-party data you enter

When you record contacts, emails or recordings of other people, you decide what data you enter and why: for that data you act as controller and TIB processes it on your behalf, on your instructions.

If you need a written data processing agreement, write to us and we will provide one.

5. Recordings and transcripts

Recordings are created only when you start them. They are transcribed and summarised automatically for your own commercial use. Checking whether your country requires you to inform or ask participants is your responsibility.

Before any recording starts, TIB shows a notice reminding you to inform participants and obtain their permission where the law requires it. That notice is information for you: it is not in itself the participants' consent, and we cannot guarantee it is sufficient in every country.

6. Who we share data with

We work with the following providers, each with the minimum access required:

  • Lovable Cloud (Supabase): hosting, database and authentication.
  • Lovable AI gateway, using Google Gemini models: summaries, recommendations, audio transcription.
  • SendGrid: sending and receiving service email.
  • Microsoft (Outlook/Graph) and the IMAP server you configure: only if you connect your mailbox.
  • Paddle: merchant of record and payment processing.

7. International transfers

Providers that may process data outside the European Economic Area: Google (AI models via the Lovable gateway), Microsoft (only if you connect Outlook), SendGrid (Twilio) and Paddle. Lovable Cloud (Supabase) hosts the database and file storage in the European Union.

These providers publish standard contractual clauses in their own data processing terms. We are collecting and filing that documentation per provider; until it is complete we do not claim the safeguards have been verified by us, and we do not state exact storage locations.

8. How long we keep data

We keep your data while your account is active and you keep it in the app. There is no automatic time-based deletion today: the end of a trial or subscription does not erase your information, and we do not announce retention periods the system does not yet enforce.

Planned retention criteria per category, to be applied once scheduled deletion is implemented: account and workspace data, while the account is active and up to 12 months after closure; accounts, contacts, opportunities, notes and tasks, for as long as you keep them; imported email, 24 months; audio recordings, 12 months, keeping the transcript and summary for as long as you keep the meeting; uploaded documents, for as long as you keep them; technical and security logs, 12 months; invoicing and tax data, the applicable statutory periods (up to 6 years in Spain).

When you request deletion, we delete your data except what we must keep for legal, accounting or claim-handling reasons.

9. Security

Each user and workspace can access only their own data through row-level security policies in the database. IMAP mail credentials are stored encrypted. Passwords are handled by the authentication provider, never in clear text.

10. Cookies and browser storage

TIB uses no third-party analytics or advertising tools. We use a technical cookie to remember interface state and browser local storage for your language, session and filters. Without this data the app cannot work.

11. Your rights

You can access, correct, delete, restrict, object to and port your data, and withdraw consent at any time, by writing to our contact address.

If you believe we have not handled your request properly, you can complain to the Spanish Data Protection Agency or to the supervisory authority in your country of residence.

12. Changes to this policy

We will publish any new version with its effective date and notify you if the change is material.

Privacy and data rights: info@theinvisiblebridge.app