Legal
Privacy Policy
Last updated July 18, 2026
This Privacy Policy explains how Pacti collects, uses, and protects your personal data when you use the Website (pacti.ai) and the App (app.pacti.ai). We follow the EU General Data Protection Regulation (GDPR) and applicable local law.
Your journal entries and answers are personal to you. We treat them with care and only use them to provide and improve the Services, as described below.
1. General provisions and definitions
“Personal data” means any information relating to an identified or identifiable person. “Processing” means any operation performed on personal data. “Controller” means the entity that decides why and how personal data is processed.
Terms defined in our Terms of Use have the same meaning here.
2. Applicability
This policy applies to personal data we process about visitors to the Website and users of the App. It does not apply to third-party websites or services we link to, which have their own privacy policies.
3. Controller, its obligations and scope
The controller of your personal data is Outsi sp. z o.o., ul. Kartuska 2, 83-334 Miechucino, Poland (KRS 0000935494, NIP 5892069190, REGON 520550442).
We have not appointed a Data Protection Officer. For any privacy question or to exercise your rights, contact us at privacy@onsoul.ai.
4. Data categories and sources
We collect data you give us and data generated as you use the Services:
- Account data — such as your email address and sign-in details.
- Content you create — your journal entries, quiz/survey answers, mood check-ins, and challenge progress.
- Usage and device data — such as pages viewed, actions in the App, approximate location derived from IP, browser and device type, collected through analytics.
- Payment data — subscription status and billing metadata. Card payments are processed by Stripe; we do not store full card numbers.
- Communications — messages you send us, for example to support@pacti.ai.
Please avoid entering sensitive information you do not wish to record (for example detailed health data). Pacti is a general well-being companion, not a medical service.
5. Purpose and legal basis
We process personal data on the following legal bases:
- To provide the Services and your account (performance of a contract, Art. 6(1)(b) GDPR).
- For product analytics and to improve the Services (your consent, Art. 6(1)(a), and/or our legitimate interests, Art. 6(1)(f)).
- For marketing and advertising, including measurement (your consent, Art. 6(1)(a)).
- To comply with legal obligations, such as accounting and tax (Art. 6(1)(c)).
- To keep the Services secure and prevent abuse (our legitimate interests, Art. 6(1)(f)).
Where processing is based on consent, you can withdraw it at any time without affecting processing already carried out.
6. Social media presence and other communication
We may maintain profiles on social platforms and run advertising campaigns. When you interact with our ads or profiles, the relevant platform also processes your data as a controller under its own policy. We may send you service messages and, with your consent, marketing emails you can unsubscribe from at any time.
7. Your rights
Under the GDPR you have the right to:
- access your personal data and receive a copy;
- rectify inaccurate data;
- erase your data (“right to be forgotten”);
- restrict or object to processing;
- data portability;
- withdraw consent at any time;
- lodge a complaint with a supervisory authority (in Poland, the President of the Personal Data Protection Office, UODO).
To exercise any of these rights, contact privacy@onsoul.ai. You can also delete your account from within the App.
8. Data security
We use appropriate technical and organizational measures to protect your data, including encryption in transit, access controls, and hosting with reputable providers. No method of transmission or storage is completely secure, but we work to protect your information and to respond promptly to any incident.
9. Recipients of personal data
We share data only as needed to run the Services, with processors acting on our instructions. The categories of recipients are:
- hosting and database providers — application, website, and data storage;
- payment processors — subscription and billing;
- product analytics providers — usage measurement and improvement;
- advertising and measurement partners — where you have consented;
- email providers — transactional and, with your consent, marketing email.
Some providers may process data outside the European Economic Area. Where they do, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses. We do not sell your personal data.
10. Retention period
We keep your personal data for as long as your account is active and as needed to provide the Services. After you delete your account, we remove or anonymize your data within a reasonable period, except where we must keep certain records to meet legal obligations (for example billing records).
11. Cookies
We use cookies and similar technologies for essential functionality, analytics, and — with your consent — marketing. For details and how to manage your choices, see our Cookie Policy.