Giminds - AI Experts That Work Together to Complete Your Tasks

    Privacy Policy

    Last Updated: 12 December 2025

    This Privacy Policy ("Policy") explains how Giminds, a product operated by Orchestrator Lda. ("Company," "we," "us," or "our") collects, uses, stores, shares and protects personal data when you ("User", "you" or "your") access, download or use our application, website and related services (collectively, the "Service"). By using the Service, you acknowledge that you have read and understood this Policy.

    We are committed to protecting your privacy and complying with applicable data protection laws, including the General Data Protection Regulation (EU Regulation 2016/679, "GDPR"), the UK Data Protection Act 2018 and UK GDPR, the California Consumer Privacy Act and California Privacy Rights Act (collectively "US Privacy Laws"), and any other data protection laws that may apply to you. This Policy also provides transparency regarding our data processing practices related to the use of artificial intelligence ("AI") and machine learning as described in our Terms and Conditions.

    1. Identity and Contact of the Data Controller

    1.1. For Users in the European Economic Area (EEA), United Kingdom (UK) and Switzerland

    Data Controller: Giminds, headquartered in Portugal. This entity determines the purposes and means of processing personal data collected through the Service for users located in the EEA/UK/Switzerland.

    Data Protection Officer (DPO): If required by law, we have appointed a DPO whom you may contact regarding any questions or requests related to this Policy:

    • Email: [email protected]
    • Postal address: Orchestrator Lda., Av. D. João II, 98 A, 1990-100 Lisbon, Portugal

    1.2. For Users Outside the EEA/UK/Switzerland (including the United States)

    Data Controller: Giminds, headquartered in Portugal. This entity determines the purposes and means of processing personal data for users located outside Europe.

    2. Principles of Data Processing

    We adhere to the following data protection principles:

    • Lawfulness, Fairness and Transparency: We process personal data lawfully, fairly and in a transparent manner.
    • Purpose Limitation: We collect personal data for specified, explicit and legitimate purposes and do not further process the data in a manner incompatible with those purposes.
    • Data Minimization: We limit collection to personal data that is adequate, relevant and necessary for the purposes for which it is processed.
    • Accuracy: We take reasonable steps to ensure that personal data is accurate and kept up to date.
    • Storage Limitation: We keep personal data in a form that permits identification for no longer than necessary for the purposes for which the data is processed, unless otherwise required by law.
    • Integrity and Confidentiality: We process personal data in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing, accidental loss, destruction or damage.
    • Accountability: We are responsible for demonstrating compliance with these principles.

    3. Types of Personal Data We Collect

    We collect different types of personal data depending on how you interact with the Service:

    3.1. Account and Registration Data

    • Account information: Name, email address, username, password, phone number, date of birth (for age verification) and country of residence.
    • Third‑party authentication data: If you choose to sign up via third‑party services (e.g., Google, Apple, Facebook), we receive the basic profile information authorized by those services. When you sign in with Google, we access only your email address and display name to create your account. We do not access your contacts, Google Drive, calendar, photos, or any other Google service data.
    • Billing information: Billing address, contact name, subscription or payment plan details, and partial payment card data (complete card details are processed by our payment processors).

    3.2. User Content (Input and Output)

    • Input: Data and content voluntarily submitted by you, including prompts, questions, commands, text, code, files, images, videos, or other materials. Some of this input may contain personal or sensitive data.
    • Output: Content generated by our AI in response to your input. Output may include personal data if your input contained such data or if the AI uses publicly available data to generate responses.
    • Special Categories of Data: When using health or fitness features, you may provide information about your diet, weight, height, physical symptoms, medical history or other health‑related data. We treat such data as sensitive and rely on explicit consent where required by law (Article 9 GDPR).

    3.3. Usage and Technical Data

    • Log data: Internet Protocol (IP) address, browser type and version, device type, operating system, pages visited, date/time of visits, interactions with the Service, error logs and other diagnostic data.
    • Cookies and similar technologies: See Section 12 below for details on our use of cookies, pixels and similar tracking technologies.
    • Approximate location: Derived from your IP address to ensure security, comply with geographic legal obligations or localize content and services.

    3.4. Third‑Party Data

    • Integration data: When you integrate or use third‑party applications or APIs with our Service (for example, connecting a payment provider or external AI model), we may receive data from these third parties as authorized by you or necessary to provide the Service.
    • Payment processing data: We receive transaction confirmation and anonymized payment information from our payment processors, such as transaction IDs, payment card brand and last four digits, and the result of fraud checks.

    3.5. Aggregated and Anonymized Data

    We aggregate and/or anonymize personal data to create statistical or aggregated information that does not identify you. We may use such information for research, analytics, security, improving our models and services, or other legitimate purposes.

    4. Purposes and Legal Bases for Processing

    We process personal data for the purposes described below. Where GDPR applies, we also indicate the legal basis for the processing.

    4.1. Provision and Operation of the Service

    Purposes: Creating and managing your account; providing and customizing the Service; enabling interactions with our AI; processing requests, subscriptions and credits; delivering notifications, updates and administrative messages; personalizing user experiences.

    Legal bases: Performance of a contract with you (Article 6(1)(b) GDPR) and our legitimate interest in operating a secure and efficient service (Article 6(1)(f) GDPR).

    4.2. Communication and Support

    Purposes: Responding to user inquiries and support requests; sending service‑related information, such as password resets, security alerts and policy updates; providing customer assistance and technical support.

    Legal bases: Performance of a contract; legitimate interest in maintaining user relations; consent for marketing communications where required (Article 6(1)(a) GDPR).

    4.3. AI Training and Service Improvement

    Purposes: Using input, output and usage data to train, refine and improve our AI models, algorithms and other technologies; researching and developing new features and services; analyzing usage patterns and performance metrics.

    Legal bases: Legitimate interest in improving and developing AI technologies (Article 6(1)(f) GDPR); explicit consent for processing sensitive data and for including your content in model training, if required.

    You may have the option to opt out of using your data (input/output) for model training through your privacy settings. If you opt out, certain AI features may become limited or unavailable.

    4.4. Legal Compliance and Protection

    Purposes: Complying with legal and regulatory obligations; responding to subpoenas, court orders or other legal requests; detecting, preventing and addressing fraud, security breaches, spam, abuse and illegal or unauthorized activities; protecting our rights, property and safety, as well as those of our users and third parties.

    Legal bases: Compliance with a legal obligation (Article 6(1)(c) GDPR); legitimate interest in safeguarding our operations (Article 6(1)(f) GDPR).

    4.5. Payment Processing

    Purposes: Processing subscription fees and credit purchases; billing and invoicing; validating payment methods; conducting antifraud checks; complying with tax and accounting requirements.

    Legal bases: Performance of a contract; compliance with legal obligations; legitimate interest in preventing fraud.

    4.6. Marketing and Promotions

    Purposes: Sending promotional emails, newsletters, offers and other marketing communications. Tracking the effectiveness of marketing campaigns; personalizing marketing messages.

    Legal bases: Your consent where required under applicable law (Article 6(1)(a) GDPR) and our legitimate interest in promoting our services. You can opt out of marketing communications at any time through your account settings or the unsubscribe link included in marketing emails.

    5. Data Sharing and Disclosure

    We may share personal data in the following circumstances:

    5.1. Service Providers and Subprocessors

    We engage third‑party companies and individuals to perform services that support the operation of our platform, such as cloud hosting, data storage, analytics, customer support, email delivery, identity verification, payment processing, and IT services. These vendors are contractually obligated to maintain confidentiality and implement appropriate security measures.

    We use third-party service providers for infrastructure and communications, including:

    • Cloudflare, Inc. (content delivery network, security and performance services)
    • Resend, Inc. (transactional email delivery)

    Some infrastructure providers may process limited technical data (such as IP addresses and request metadata) for security, performance and abuse-prevention purposes.

    5.2. Payment Processors

    We partner with payment processors (e.g., Stripe) to handle transactions. We do not store your full payment card details. Our processors collect and use payment information to process your payments and comply with their legal obligations.

    Our primary payment processor is Stripe, Inc.. Payment data is handled directly by Stripe in accordance with their own privacy policy and security standards.

    5.3. Third‑Party AI Services and Integrations

    To provide AI-generated content (text, images, video), we share user inputs — including text prompts and uploaded images — with third-party AI service providers:

    • Google LLC (Gemini API)
    • OpenAI, Inc. (GPT and DALL-E APIs)
    • Black Forest Labs (FLUX API)

    These providers process data according to their own terms and privacy policies and may retain data as described in those policies.

    Depending on the context, these providers may act as independent data controllers for certain processing activities outside our direct control, including security, abuse prevention and legal compliance.

    Data may be processed outside the European Economic Area (EEA) under appropriate safeguards.

    5.4. Affiliates and Corporate Group

    We may share your data with parent companies, subsidiaries, joint ventures or other companies under common control, provided they comply with this Policy.

    5.5. Legal and Regulatory Authorities

    We may disclose personal data if required by law, regulation, court order or valid legal process, or in response to a lawful request by public authorities, including law enforcement and national security agencies. We may also disclose personal data if we believe disclosure is necessary to protect the rights, property or safety of the Company, our users or others.

    5.6. Business Transfers

    In the event of a corporate transaction such as a merger, acquisition, bankruptcy, dissolution, asset sale or transfer of all or part of our business, your data may be transferred to the relevant third party as part of the transaction. We will ensure that any such transfer is subject to appropriate safeguards and that the recipient continues to honour the commitments in this Policy.

    6. International Data Transfers

    We operate globally and may transfer your personal data to and process it in countries outside your country of residence, including to countries that may not provide the same level of data protection as your jurisdiction. When we transfer personal data outside the EEA/UK/Switzerland, we ensure that adequate safeguards are in place, such as:

    • Adequacy decisions: Countries recognized by the European Commission or the UK Information Commissioner's Office as providing an adequate level of protection.
    • Standard Contractual Clauses (SCCs): We use SCCs approved by the European Commission or adopted by the UK authorities to protect personal data transferred from the EEA/UK to third countries.
    • Binding Corporate Rules (BCRs): Intra‑group transfer agreements that provide an adequate level of protection where applicable.
    • User consent: In limited situations, we may rely on your explicit consent for specific transfers.

    7. Data Retention

    We retain personal data for as long as necessary to fulfill the purposes described in this Policy or as required by law. Retention periods vary depending on the nature of the data:

    • Account data: Retained while your account remains active and for a reasonable period thereafter to comply with legal obligations and prevent fraud.
    • Input and output: Input and output may be stored temporarily to provide the Service and improve the AI, and then aggregated or anonymized. If you opt out of model training, we minimize retention of your content accordingly.
    • Payment data: Retained for the duration required by applicable tax, accounting and financial regulations.
    • Usage and technical data: Retained for analytics, security and development purposes for a period consistent with our cookies and analytics policies.

    When there is no longer a legitimate business need to process your personal data, we will either delete or anonymize it, or if this is not possible (e.g., because the data has been stored in backup archives), we will securely store your data and isolate it from further processing until deletion becomes possible.

    8. Your Rights and Choices

    Depending on your location and applicable law, you have certain rights regarding your personal data.

    8.1. Rights under GDPR (EEA/UK/Switzerland)

    • Right of access: Obtain confirmation as to whether we process your personal data and, if so, request a copy of that data.
    • Right to rectification: Request correction of inaccurate or incomplete personal data.
    • Right to erasure (right to be forgotten): Request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, or when processing is unlawful or you have withdrawn consent.
    • Right to restriction of processing: Request that we limit our use of your personal data.
    • Right to data portability: Receive your personal data in a structured, commonly used and machine‑readable format and transmit it to another controller.
    • Right to object: Object to processing of your personal data for direct marketing purposes or based on our legitimate interests.
    • Rights related to automated decision‑making: You may have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects.
    • Right to lodge a complaint: You may lodge a complaint with your national data protection authority if you believe that we have violated data protection laws.

    8.2. Rights under US Privacy Laws (California, Virginia, Colorado, Connecticut, etc.)

    • Right to know: Request information about our data collection, use, disclosure and sale practices.
    • Right to access: Request a copy of specific personal data we have collected about you.
    • Right to delete: Request deletion of personal data we have collected, subject to certain exceptions.
    • Right to correct: Request correction of inaccurate personal data.
    • Right to opt out of sale or sharing: You may direct us not to sell or share your personal data for targeted advertising purposes. We do not sell personal data for monetary consideration.
    • Right to non‑discrimination: We will not discriminate against you for exercising your privacy rights.

    8.3. How to Exercise Your Rights

    To exercise any of the above rights, please contact us using the details provided in Section 14 below. We may require verification of your identity before processing your request. We will respond within the timeframes required by law (generally within 30 days under GDPR and 45 days under US privacy laws). If you have authorized an agent to submit requests on your behalf, we may require proof of authorization.

    9. Security Measures

    We implement technical, administrative and physical safeguards designed to protect personal data from unauthorized access, disclosure, alteration or destruction. These measures include encryption in transit and at rest, access controls, regular security testing and employee training. However, no system is completely secure. While we strive to protect your data, we cannot guarantee absolute security and encourage you to take your own precautions.

    10. Children's Privacy

    The Service is not intended for children under thirteen (13) years of age, or below the minimum age required by applicable law in your jurisdiction. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without parental consent, we will take steps to delete the information as soon as possible. If you believe that a child has provided us with personal data, please contact us immediately.

    11. Third‑Party Links and Services

    The Service may contain links to third‑party websites, applications or services that are not operated by us. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third‑party services before providing your personal data.

    12. Cookies and Tracking Technologies

    We use cookies, pixels, device identifiers and similar technologies to collect information about your interactions with the Service. These technologies help us operate and improve the Service, remember your preferences, authenticate users, analyze traffic, and personalize content and advertising. For a detailed explanation of how we use these technologies and how you can manage your preferences, please see our Cookie Policy [if applicable, link here].

    13. Updates to This Policy

    We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational, legal or regulatory reasons. When we make material changes, we will notify you through the Service or by other appropriate means, such as email. We encourage you to review this Policy periodically for the latest information on our privacy practices.

    14. Contact Us

    If you have any questions, concerns or requests regarding this Privacy Policy or our data processing practices, please contact us at:

    • Email: [email protected]
    • Postal Address: Orchestrator Lda., Av. D. João II, 98 A, 1990-100 Lisbon, Portugal

    For users in the EEA/UK/Switzerland, you also have the right to lodge a complaint with your local supervisory authority if you believe that we have not handled your personal data in accordance with applicable law.

    Wir verwenden Cookies, um Ihre Benutzererfahrung zu verbessern. Für einen vollständigen Überblick über alle verwendeten Cookies siehe unsere .