NAIARA AI — Virtual Assistant App with Artificial Intelligence — Version 3.0
This Privacy Policy explains how NAIARA AI, S.L. (hereinafter, “NAIARA AI”) processes the personal data
of users of the NAIARA AI app. It applies in conjunction with the Terms of Use v3.0. This version
supersedes and renders version 2.2 null and void.
1. Data Controller and Handling of Data Subject Rights
Data Controller: NAIARA AI, S.L. (Tax ID No. B70751045), 6 Historiador Joan Mari Cardona St., Building 2, Floor 0, Door D,
07800 Ibiza (Balearic Islands), Spain.
For inquiries regarding GDPR rights and requests: info@naiara.com (subject line: “Privacy – [Your right]”).
Data Protection Officer (DPO): NAIARA AI is not currently required to appoint a DPO (Art. 37
GDPR) as the circumstances of Art. 37.1 (public authority, large-scale monitoring,
special categories on a large scale) do not apply. The appointment will be reassessed when the volume of processing increases
significantly.
Complaints: Spanish Data Protection Agency (www.aepd.es), C/ Jorge Juan 6, 28001 Madrid.
2. Data we process
a) Account information:
email address and/or phone number, user ID, authentication credentials (Google, Apple), date of birth (
verification of age 18+), IP address. Processing is necessary for the performance of a contract.
b) User content (conversations)
Text, transcribed voice, images, and shared documents. Conversations are shared with Google
(Gemini API) to generate responses. Your account information is NOT shared with Google. Do not provide
sensitive confidential information (bank details, passwords, Social Security numbers) to the
assistants.
System prompt caching (NEW v3.0). To optimize costs and latency, the system prompt
for each assistant (description of the assistant’s personality and knowledge, approximately 10,000
tokens) is cached in the Google AI Studio infrastructure using the Cached Content API. User content is NEVER cached. Only the assistant’s own system prompt—which is editorial content from NAIARA AI (
) and not the user’s personal data—is cached.
Conversation History Compression (NEW v3.0). To manage lengthy conversations, when
a conversation exceeds 20 turns, the earliest turns are processed by the Gemini
Flash-Lite model to generate a condensed summary (approximately 450 tokens) that replaces the individual messages
in the context sent to the API. This summary is stored in association with the conversation and complies
with the principle of data minimization under Article 5.1.c of the GDPR. The user may request access to their summaries or their
deletion at any time.
b.bis) Special categories of data (Art. 9 GDPR)
NAIARA AI does not intentionally collect data covered by Art. 9 GDPR (health data, sexual orientation, political opinions
, religion, genetic data, biometric identifiers, etc.). If you voluntarily provide this type of data
when interacting with the assistants (especially in categories such as health, wellness, personal advice, intensive sports, dermatology, etc.), the processing will be based on your explicit consent (Art. 9.2.a GDPR), inferred from the voluntary act of sharing it in the conversation.
NAIARA AI uses automatic filters to detect this type of data in conversations. When such data is detected
, the system may: (a) warn you before proceeding; (b) recommend consulting a healthcare professional
; (c) limit the storage of the identified sensitive information; (d) in certain sensitive cases (diabetic foot, known heart conditions, high-risk pregnancy, etc.), refer the user to a qualified human professional and refrain from generating specific recommendations.
You can revoke this consent at any time in Settings ® Privacy, which will result in the deletion of any sensitive data previously shared.
c) Voice data
The app supports voice input. Voice data is processed for real-time transcription. NAIARA AI does not permanently store voice recordings, unless express consent is given.
d) Affiliate transaction and click data (AMPLIADO v3.0)
When you make a purchase through affiliate links, NAIARA AI records an anonymous click identifier (click_id) that is transmitted to the affiliate network (Amazon Associates, Awin, Tradedoubler, Tradeinn) as the SubID, clickRef, or epi parameter, as applicable. This allows for subsequent correlation with the commission when the network confirms it via webhook, without transmitting any identifiable user data to the network. NAIARA AI may receive information about the transaction (amount, category, confirmation) to improve recommendations, calculate commissions, and assign bonus tokens. NAIARA AI does NOT have access to your payment data, which is managed by the provider or the app store.
e) Automatically processed data
Device information, IP address, carrier, timestamp and session duration, essential cookies, in-app events, selected language, locale.
f) Preference and personalization data
User-specified preferences (style, budget, favorite brands, size, tech ecosystem, skill level, etc.). These can be viewed and deleted under "Privacy."
g) Advertising data
IP address, advertising ID, interactions with ads. We may share encrypted email addresses with advertising partners. We will obtain your prior consent. Premium users enjoy an ad-free experience.
h) Facial data
If you upload images containing faces, NAIARA AI will NOT use them for identification, authentication, or facial recognition. They are processed solely to generate the requested response. No separate databases are maintained. They are not sold to third parties.
i) Supporting data
If you contact info@naiara.com, we will use the information you voluntarily provide to respond to your inquiry.
j) Subscription and free trial eligibility information (NEW v3.0)
To manage Premium subscriptions and free trial periods and prevent abuse, NAIARA AI processes the
the following information:
– Subscription status (free / trial / trial_cancelling / premium / premium_cancelling / expired_reminder) and Apple/Google transaction identifiers (originalTransactionId, purchaseToken).
– A hashed identifier for the Apple ID or Google Play account (account_hash), generated using a one-way cryptographic hash function. NAIARA AI does NOT know the user’s Apple/Google account; it only stores the hash to detect whether the same user is attempting to obtain multiple free trials by creating new accounts in the app.
– Key dates in the subscription lifecycle: trial start date, expected trial end date (day 8), next renewal date, cancellation date (if applicable), and the most recent webhook event received.
– Count of previous trials (trial_count: 0 or 1) and date of last activity to assess re-eligibility after 90 days of inactivity.
– Primary agent ID (primary_agent_id) — the agent the user interacted with most frequently during their Premium or trial period; this is calculated automatically to determine which agent remains accessible in Recall Mode.
– Subscription event log (audit log): Each state transition (trial_started, trial_converted, cancelled, etc.) is logged with a timestamp, the event source (Apple webhook, Google webhook, manual action), and, in some cases, the original webhook payload for auditing and troubleshooting purposes.
k) Token usage data and operational metrics (NEW v3.0)
To manage the token system described in the Terms of Use (Sections 9.4 through 9.6), NAIARA AI processes:
– Cumulative cost for the month (cumulative_cost_usd_cents): an internal counter tracking the cost of AI processing generated by user interactions, expressed in U.S. cents. This value allows you to calculate the percentage of the monthly allocation that has been used.
– Agent usage histogram: the number of messages exchanged with each agent, used to determine the primary_agent_id applicable to Recall Mode and for aggregated operational analysis.
– Top-up purchases (Empujoncito and Complete Pack): date, pack type, Apple/Google transaction ID. This information is used to enforce the rule limiting purchases to one Empujoncito per monthly cycle and for operational analysis.
– Bonus tokens awarded: date of award, amount of the commission that generated the bonus, referring affiliate network. This allows you to calculate whether the monthly bonus cap (+50,000 tokens) has been met and to reverse tokens if the commission is subsequently canceled.
– Threshold events: records of when the user crossed the 80%, 95%, and 100% thresholds of the cap, and which option they selected in the end-of-assignment dialog (Nudge, Full Pack, Wait). Data used for product improvement.
3. Purposes and legal basis of the processing
3.1. Registration and management of personal accounts. Legal basis: Art. 6.1.b GDPR (performance of a contract).
Retention period: until cancellation + 5-year statute of limitations.
3.2. Provision of the service (interacting with attendees, managing purchases, ensuring proper operation). Legal basis: Article
.b of the GDPR.
3.3. Improving the Application using pseudonymized/anonymized data. Legal basis: Art. 6.1.f GDPR (
). Impact assessment conducted.
3.4. Contextual analysis of conversations to display recommendations, content, or context-
. Legal basis: Art. 6.1.f GDPR.
3.5. Commercial intermediation and personalized recommendations. Legal basis: Art. 6.1.a and 6.1.b of the GDPR.
3.6. Marketing and commercial communications. Legal basis: Art. 6.1.a GDPR (granular consent).
Separate subcategories with their own checkboxes: NAIARA email newsletter, push notifications about new features, promotional communications from affiliate partners, market research, and invitations to the beta
, product improvement (surveys, NPS). You may opt out of one without affecting the others.
3.7. Management of contests and promotions. Legal basis: Art. 6.1.a GDPR.
3.8. Legal compliance, protection of rights, and fraud prevention. Legal basis: Articles 6(1)(c) and 6(1)(f) of the GDPR (
).
3.9. Processing of special categories of data (Art. 9.2.a GDPR): explicit consent inferred from the voluntary act of sharing
; see Sec. 2.b.bis. May be withdrawn at any time.
3.10. Management of the free trial period and anti-fraud measures (NEW v3.0). Processing of the data
described in Sec. 2.j to: determine the user’s initial eligibility (verification that they are a new
subscriber), apply re-eligibility rules after 90 days of inactivity, detect attempts to abuse the
trial period by hashing Apple/Google account identifiers, and manage subscription status transitions based on Apple and Google webhooks. Legal basis: Art. 6.1.b GDPR (performance
of the subscription contract) and Art. 6.1.f GDPR (legitimate interest in fraud prevention).
3.11. Management of the token and recharge system (NEW v3.0). Processing of the data described in Sec.
2.k to: calculate the percentage of monthly allocation consumed, determine eligibility for the "
" and "Empujoncito" (automatic rule: cap ³ 95% AND days until reset £ 7 AND "empujoncitos" already consumed = 0),
calculate and grant bonus tokens when an affiliate commission is confirmed, determine the "
" and "primary_agent_id" applicable to Reminder Mode. Legal basis: Art. 6.1.b GDPR.
3.12. Internal Financial Control Dashboard (NEW v3.0). NAIARA AI maintains an internal administrative dashboard, accessible only to authorized personnel via SSO with the naiara_admin role, which displays aggregated and pseudonymized metrics on service usage, margin health, the effectiveness of the "Empujoncito," conversion rates during the trial period, and other operational indicators. The dashboard data is updated hourly via a batch process that aggregates information from the operational tables. The dashboard is not accessible to end users nor is it shared with third parties. All access
is recorded in an audit log. Legal basis: Art. 6.1.f GDPR (legitimate interest in the company’s operational and economic management
, without infringing on the user’s fundamental rights as the data is aggregated or pseudonymized
).
This consent is revocable at any time, with no retroactive effect. To revoke your consent: info@naiara.com
(subject line: “Privacy – Revocation”).
4. Retention of conversations and monetization of data
4.1. NAIARA AI retains conversations for the following purposes: (a) to provide and improve the service; (b) for training and
optimization; (c) generation of anonymized data for analysis and monetization. Legal basis for (c): Art. 6.1(a) of the GDPR (separate explicit consent).
4.2. Before sharing or selling any data, NAIARA AI implements rigorous anonymization in accordance with the AEPD Guidelines and EDPB Opinion 05/2014: removal of direct and indirect identifiers,
k-anonymity, l-diversity, differential privacy, and periodic assessment of the risk of re-identification.
4.3. NAIARA AI may share or sell anonymized and aggregated data for market analysis,
trends, statistical reports, and research. Since this data is genuinely anonymized, it falls
outside the scope of the GDPR.
4.4. Consent for monetization is specific, informed, freely given, and unambiguous, provided through active opt-in
(without pre-selection). It can be revoked in Settings ® Privacy without affecting the basic service.
4.5. Anonymized data may be shared with: market research firms, advertising agencies,
consulting firms, and academic institutions. Identifiable data is NEVER shared for commercial purposes.
4.6. NAIARA AI has conducted and maintains an up-to-date Data Protection Impact Assessment (Art. 35 GDPR). A summary is available at
or upon request to info@naiara.com.
5. Who we share your data with
Your data may be processed by third-party processors (Art. 28 of the GDPR):
• Google LLC / Google Ireland Limited (Gemini API): AI model provider. It processes conversation content
to generate responses and, using the Cached Content API, caches
NAIARA AI’s editorial system prompts (not user content). Privacy:
https://policies.google.com/privacy. Terms: https://ai.google.dev/gemini-api/terms.
• Google LLC (Gemini Flash-Lite): processes the history of lengthy conversations (more than 20 turns)
to generate condensed summaries, in accordance with the principle of data minimization under Article 5(1)(c) of the GDPR.
• Apple Inc. (App Store Server Notifications v2) (NEW v3.0): Notifies NAIARA AI about the subscription lifecycle (trial start, cancellations, renewals, expirations, refunds). Apple
acts as the payment processor and as the authoritative source for subscription status.
• Google LLC (Real-Time Developer Notifications) (NEW v3.0): Apple's equivalent in the Android ecosystem (
). Notifies NAIARA AI of subscription events.
• Amazon Web Services: cloud infrastructure, with servers located within the EEA whenever possible.
• BlazeByte: a development team based in India, operating under a data processing agreement (Article 28 of the General Data Protection Regulation (
)) with Standard Contractual Clauses for international data transfers.
• Apple Inc. and Google LLC: payment processing, subscriptions, refunds, and free trials.
• Affiliate networks (Amazon Associates, Awin, Tradedoubler, Tradeinn): These networks receive an anonymous click identifier (click_id) from
that allows them to link the purchase to NAIARA AI when the commission is confirmed, without
receiving any personally identifiable information from the user. The network may collect user data through its own cookies and policies, over which NAIARA AI has no control.
For transfers outside the EEA (the U.S. for Google Gemini, Apple, and infrastructure; India for BlazeByte):
Standard Contractual Clauses (Art. 46 GDPR) and, where applicable, the EU-U.S. Privacy Shield.
We may also disclose information to comply with legal obligations or requests from authorities, or in the event of a merger, acquisition, or sale of assets (with prior notice).
6. Rights of data subjects
As the data subject, you have the following rights under the GDPR:
• Access (Art. 15 GDPR): obtain confirmation of which data is being processed and a copy of said data.
• Rectification (Art. 16 GDPR): correct inaccurate or incomplete data.
• Erasure (Art. 17 GDPR, “right to be forgotten”): delete your data when it is no longer necessary or
you withdraw your consent. Deletion includes data in Recall Mode.
• Restriction (Art. 18 GDPR): restrict processing under certain circumstances.
• Portability (Art. 20 GDPR): receive your data in a structured, commonly used, and machine-readable format
(JSON), and transmit it to another controller. Includes data from Regulation (EU) 2023/2854 (Data Act) where
applies.
• Objection (Art. 21 GDPR): object to processing based on legitimate interest, including the internal dashboard
(Sec. 3.12) and the analyses in Sec. 3.4.
• Automated decisions (Art. 22 GDPR): not to be subject to fully automated decisions with
significant legal effects without consent. See Sec. 11.
• Withdraw consent (Art. 7.3 GDPR): at any time, without affecting the lawfulness of prior processing
.
• Complaint to a supervisory authority: AEPD (www.aepd.es) or the authority in your Member State.
To exercise your rights: info@naiara.com (subject: “Privacy – [Your right]”). Please provide your name, contact email (
), the right you wish to exercise, and the data regarding which you are making the request.
7. Duration of treatment and storage — Table by category
| Data category | Retention period | Legal Basis |
|---|---|---|
| Account information (email, phone number, ID, date of birth) | Until cancellation + 5 years | Civil statute of limitations (Art. 1964 CC) |
| Conversations with attendees | 24 months by default, configurable | Principal + legitimate interest |
| Condensed medical records (Flash-Lite) | Involved in the conversation; same deadline | Art. 5.1.c Minimization |
| Transaction data (affiliate purchases) | 6 years | Accounting Law (Art. 30 of the Civil Code) |
| Subscription and trial information (Sec. 2.j) | Until cancellation + 5 years | Contract performance + statute of limitations |
| anti-fraud account hash for the trial | 24 months after last use | Legitimate interest (Art. 6.1.f) |
| Token consumption data (Section 2.k) | 24 months (detailed data); indefinite (aggregated) | Principal + legitimate interest |
| Status Mode Memory | Indefinite while the account is active | Performance of the contract; subject to Art. 17 |
| Internal dashboard logs (audit) | 13 rolling months | Legitimate interest (audit) |
| Advertising data and advertising ID | Until consent is withdrawn | Consent, Art. 6.1.a |
| Marketing data (newsletter, push notifications) | Until consent is withdrawn | Consent, Art. 6.1.a |
| Voice data (transcripts) | They are not stored permanently | Art. 5.1.c Minimization |
| Facial data | Processed only, not stored | Section 5.1.c |
| Special categories (health, etc.) Art. 9 | 12 months or until revoked | Explicit consent |
| Technical and security logs | 12 months | Legitimate interest |
| System Backups | 30-day rolling period | Service continuity |
| info@naiara.com | 3 years since the ticket was closed | Contractual Compliance |
8. Security
Technical and organizational measures (Art. 32 GDPR): encryption in transit (TLS 1.3) and at rest (AES-256),
role-based access controls (RBAC), periodic audits, incident response plans. Access to the
internal dashboard is restricted via SSO with a specific role and an audit log for each access. In the event of a data breach (
): notification to the AEPD within 72 hours (Art. 33) and communication to the user without delay when it involves a high risk (Art. 34). No measure on the Internet is impregnable.
9. Minimum age — 18 years old — and verification
NAIARA AI is exclusively for users 18 years of age or older. Verification upon registration: declaration of date of birth
+ confirmation checkbox + acceptance checkbox. The system blocks registrations where the declared age is under 18.
Additional measures: monitoring for anomalous patterns, persistent mark following prior blocking, and human-
review in suspicious cases. If a minor is detected, the account and associated data will be immediately deleted (Art. 17 GDPR). Report use by a minor: info@naiara.com.
10. Cookies
The App uses cookies that are strictly necessary for its operation. For non-essential cookies
(analytics, advertising), prior consent is required in accordance with the LSSI-CE, ePrivacy, and the AEPD 2023 Guidelines.
Layered cookie banner with “Accept All,” “Reject All,” and “Customize” options at the same visual level
, without pre-selection. Categories: strictly necessary (always active), preferences (opt-in), analytics (opt-in), advertising (opt-in), third parties (granular opt-in). Configurable from “Privacy.”
11. Automated decisions and profiling
In accordance with Article 22 of the GDPR, NAIARA AI uses various automated algorithmic processing methods:
• Personalized recommendations: assistants use AI to provide recommendations based on
preferences, history, and profile.
• Eligibility for the free trial period (NEW v3.0): automatic determination based on the
Apple/Google account status and the account_hash to determine whether the user is eligible for an initial free trial
or for re-eligibility after 90 days of inactivity.
• Calculation of the token cap and eligibility for the Empujoncito (NEW v3.0): automatic calculation of the
percentage of monthly allocation consumed; automatic determination of eligibility for the
Empujoncito based on the rule described in the Terms.
• Automatic awarding of bonus tokens (NEW v3.0): when an affiliate network
confirms a commission via webhook, NAIARA AI automatically awards the corresponding tokens
following the rule of 500 tokens/€1, with a cap of +50,000/month.
• Selection of the primary_agent_id for Reminder Mode (NEW v3.0): upon subscription expiration, the
system automatically selects the agent with the highest number of interactions during the
Premium period to maintain access in Reminder Mode.
You have the right to: meaningful information about the logic applied, express your point of view, challenge the
decision, and request human intervention. None of the automated decisions described have significant legal effects on the user within the meaning of Art. 22.1 GDPR (they do not affect employment contracts,
credit granting, etc.). In case of disagreement, write to info@naiara.com (subject: “Privacy – Review of automated decision”) and a team member will review your case.
12. Changes to this policy
NAIARA AI may modify this Policy by publishing an updated version. For substantial changes (such as monetization, new categories of processing, or new processors such as Apple ASSN or Google RTDN),
, we will request renewed consent with 30 calendar days' advance notice.
Simplified summary
Your privacy matters. We collect data to manage your account, provide the service, improve the assistants, and
show you relevant recommendations. We manage your subscription and free trial in collaboration with
Apple/Google and implement appropriate anti-fraud measures. We comply with the GDPR, LOPDGDD, AI Act, DSA,
Data Act, and other applicable regulations. You can access, correct, delete, or export your data at any
time. Only contracted providers see your data. Personally identifiable information is never sold.
Contact: info@naiara.com (subject line “Privacy” for GDPR-related matters).
NAIARA AI, S.L. — Ibiza, Balearic Islands, Spain — Privacy Policy Version 3.0 — May 10, 2026
— Replaces and supersedes Version 2.2.