Privacy Policy

This Privacy Policy explains how Sunan AI collects, uses, and protects your personal data.

Take Control of Your Privacy

Beyond reading this policy, you can actively manage your data. Export, delete, or adjust your privacy settings anytime.

View Your Privacy Controls

1. Information We Collect

We collect: (a) Information you provide: email, name, password, chat messages, quiz answers; (b) Automatically collected: IP address, browser user agent, cookies, device information; (c) Usage data: pages visited, features used, timestamps. IP addresses and user agents are collected for security, fraud prevention, and service improvement purposes. They are retained for 90 days unless required longer for security investigations.

2. How We Use Information

To provide and improve services (quizzes, AI answers), personalize experience, secure accounts, and comply with law.

3. Sharing

We do not sell personal data. We may share with service providers under contract (e.g., hosting/analytics) and as required by law.

4. Security

We use reasonable technical and organizational measures to protect data; no method is 100% secure.

5. Your Rights

Depending on your jurisdiction, you may request access, correction, deletion, or restriction of your data. Contact us to exercise rights.

6. Cookies

We use cookies for essential functionality and analytics. You can control cookies in your browser settings.

7. International Transfers

Data may be processed in regions outside your country; we take steps to protect it appropriately.

8. Changes

We may update this Policy; we’ll revise the date and, when required, notify you of significant changes.

9. Contact

For privacy questions or requests, contact: privacy@sunanai.com

10. Data Controller

Sunan AI is the data controller. Contact: privacy@sunanai.com.

11. Legal bases

We process personal data on: (a) contract necessity (to provide the service), (b) legitimate interests (to secure, prevent abuse, and improve), (c) consent (analytics cookies), and (d) legal obligations where applicable.

12. Data retention

We keep account data while your account is active, then delete or anonymize within a reasonable period. Security logs are kept up to 12 months. Analytics data follows Google Analytics retention (up to 25 months).

13. Recipients and processors

We share data with: OpenAI (for AI responses, DPA in place), Google Analytics (with your consent, for usage statistics), SMTP email provider (for account emails). We do not sell your data to third parties. IP addresses may be shared with security services in case of suspected fraud or abuse.

14. Your right to complain

If you are in the EU/EEA, you may lodge a complaint with your local authority. In France: CNIL — www.cnil.fr.