Controller and scope
Wedalio is a daily planner, private journal, modular event workspace and public community. The operator is Gastro ponuda j.d.o.o., Ulica Ivana Matetića Ronjgova 22, Zagreb, Croatia; OIB 02605114426. Support and privacy contact: [email protected]. VAT status, registration details and provider contracts require confirmation before commercial launch. This draft covers the website and Android app.
Information and purposes
Account name, e-mail and authentication records support login and account administration. Private notes, journals, calendars, workouts, education records, wardrobe photos, family albums and studio files are processed to provide the features you request. Public profiles, blogs, offers and events are shared only when you deliberately publish them. Private guest links are bearer links: anyone you forward one to may access the shared information.
Legal bases
Account and requested workspace services rely on performance of a contract. Optional visitor/app usage analytics rely on consent. Fraud prevention, essential security logging and handling support requests may rely on legitimate interests, subject to an assessment. Tax and other mandatory record keeping rely on legal obligations where applicable. Do not put health diagnoses, identification documents or other highly sensitive information into support messages.
Analytics and storage
Optional first-party analytics are disabled until you opt in. We record only approved page categories, coarse device classes, interface language and web/Android source, using a random session identifier. We do not record journal text, chat text, photos, guest lists, exact URLs with private identifiers, search text or precise location for analytics. Raw consented analytics are removed after 90 days. Consent receipts are retained for 12 months. Resolved and closed support cases are removed 12 months after their last update; open requests remain until resolved. Security audit history has a 90-day schedule. Essential session cookies expire after seven days. Server/CDN infrastructure logs have separate retention that the operator must verify.
Service providers and international transfers
Hosting, Cloudflare, Google sign-in, OpenAI and, when enabled, payment providers process limited information for their functions. AI translation, wardrobe analysis and support involve sending the specific content you submit to OpenAI. Support AI receives only your explicit question and relevant published help articles; analytics AI receives aggregates. OpenAI requests use store:false, which is not a promise of zero provider retention. Processor agreements, hosting locations and applicable transfer safeguards must be documented by the operator before commercial launch.
Your choices and rights
You can change cookie/analytics choices at any time, keep your profile private, control optional translations and export your workspace in Settings. Request access, correction, erasure, restriction, portability or objection through the Privacy & account page or support. We verify identity before disclosing or deleting account data. EU requests are normally addressed within one month, with a permitted extension explained if needed. You may complain to your competent data protection authority, including AZOP in Croatia where applicable.
US residents
We do not sell personal information or share it for cross-context behavioural advertising. We respect Global Privacy Control by disabling optional analytics. If a state privacy law applies to our business and your request, we support its applicable access, correction, deletion, portability and opt-out rights without discrimination. Coverage and deadlines must be assessed against the operator’s activity, thresholds and location; this notice does not claim universal CCPA coverage.
Children and family content
The Family module is for parents/guardians managing their own private books. Child photos uploaded by adults are not used in visitor analytics or automatically submitted to support AI. Free pupil access is not evidence of parental consent. The child-directed offering, account age threshold and verified guardian process require a separate review before onboarding younger children.
Retention, deletion and changes
Workspace records remain until deletion is requested and fulfilled or another documented retention rule applies. Support handles deletion of the account and associated content after identity verification. Shared content, lawful billing records and provider copies may require an explained separate process. Server backups have a 35-day retention schedule; deleted live records may persist there until expiry. Provider deletion procedures and off-server recovery must be completed by the operator before commercial launch. Material changes will be communicated before taking effect.