Privacy Policy

Last updated: 10 May 2026

NAIARA AI — Virtual Assistant Application powered by Artificial Intelligence — Version 3.0

This Privacy Policy explains how NAIARA AI, S.L. (hereinafter, "NAIARA AI") processes the personal data of users of the NAIARA AI application. It applies together with the Terms of Use v3.0. This version supersedes and renders version 2.2 without effect.

1. Data controller and handling of rights

Controller: NAIARA AI, S.L. (tax ID B70751045), C/ Historiador Joan Mari Cardona 6, Esc. 2, Fl. 0, Door D, 07800 Eivissa (Illes Balears), Spain. Handling of rights and GDPR enquiries: info@naiara.com (subject: "Privacy – [Your right]"). Data Protection Officer (DPO): NAIARA AI is not currently required to appoint a DPO (Art. 37 GDPR), as the circumstances of Art. 37.1 do not apply (public authority, large-scale monitoring, large-scale special categories). The appointment will be reassessed when the volume of processing increases significantly. Complaints: Spanish Data Protection Agency (www.aepd.es), C/ Jorge Juan 6, 28001 Madrid.

2. Data we process

a) Account data Email and/or phone number, user ID, authentication data (Google, Apple), date of birth (verification of legal age 18+), IP address. Processing necessary for the performance of the contract.

b) User content (conversations) Text, transcribed voice, images and shared documents. Conversations are shared with Google (Gemini API) in order to generate responses. Your account data is NOT shared with Google. Do not provide sensitive confidential information (bank details, passwords, social security numbers) to the assistants.

Context caching of the system prompt (NEW in v3.0). To optimise cost and latency, each assistant's system prompt (a description of the assistant's personality and knowledge, approximately 10,000 tokens) is cached on Google AI Studio infrastructure through the Cached Content API. User content is NEVER cached. Only the assistant's own system prompt, which is editorial content belonging to NAIARA AI and not personal data of the user.

Conversation history compression (NEW in v3.0). To manage long conversations, when a conversation exceeds 20 turns, the earliest turns are processed by the Gemini Flash-Lite model to generate a condensed summary (approximately 450 tokens) that replaces the individual messages in the context sent to the API. This summary is stored with the conversation and respects the data minimisation principle of Art. 5.1.c GDPR. The user may request access to their summaries or their erasure at any time.

b.bis) Special categories of data (Art. 9 GDPR) NAIARA AI does not intentionally collect data covered by Art. 9 GDPR (health data, sexual orientation, political opinions, religion, genetic data, identifying biometric data, etc.). If you voluntarily provide this type of data when interacting with the assistants (especially in categories such as health, wellbeing, personal advice, intensive sport, dermatology, etc.), processing will be based on your explicit consent (Art. 9.2.a GDPR), inferred from the voluntary act of sharing it in the conversation.

NAIARA AI applies automatic filters to detect this type of data in conversations. When detected, the system may: (a) warn you before continuing; (b) recommend consulting a healthcare professional; (c) limit the storage of the sensitive information identified; (d) in some sensitive cases (diabetic foot, declared cardiac conditions, high-risk pregnancy, etc.), refer the user's query to a qualified human professional and refrain from generating a specific recommendation.

You may withdraw this consent at any time in Settings → Privacy, which will cause the erasure of previously shared sensitive data.

c) Voice data

The Application allows voice input. Voice data is processed for real-time transcription. NAIARA AI does not store voice recordings permanently, unless you expressly consent.

d) Transaction and affiliate click data (EXPANDED in v3.0)

When you buy through affiliate links, NAIARA AI records an anonymous click identifier (click_id) that is transmitted to the affiliate network (Amazon Associates, Awin, Tradedoubler, Tradeinn) as a SubID, clickRef or epi parameter as applicable. This allows the commission to be correlated later when the network confirms it via webhook, without transmitting identifiable user data to the network. NAIARA AI may receive information about the transaction (amount, category, confirmation) in order to improve recommendations, calculate commissions and allocate bonus tokens. NAIARA AI does NOT have access to your payment data, which is handled by the provider or the app store.

e) Data processed automatically

Device information, IP, carrier, timestamp and duration of sessions, essential cookies, in-app events, selected language, locale.

f) Preference and personalisation data

Preferences declared by the user (style, budget, favourite brands, size, technology ecosystem, skill level, etc.). Viewable and deletable from "Privacy".

g) Advertising data

IP, advertising ID, interactions with ads. We may share an encrypted email with advertising partners. Your prior consent will be obtained. Premium users enjoy an ad-free experience.

h) Facial data

If you upload images containing faces, NAIARA AI will NOT use them for identification, authentication or facial recognition. They are only processed to generate the requested response. No separate databases are maintained. They are not sold to third parties.

i) Support data

If you contact info@naiara.com, we will process the data you voluntarily provide in order to respond.

j) Subscription and free trial eligibility data (NEW in v3.0)

To manage the Premium subscription, the free trial period and to prevent abuse, NAIARA AI processes the following data:

– Subscription status (free / trial / trial_cancelling / premium / premium_cancelling / expired_recuerdo) and Apple/Google transaction identifiers (originalTransactionId, purchaseToken).

– Hashed identifier of the Apple ID or Google Play account (account_hash), generated using a one-way cryptographic hash function. NAIARA AI does NOT know the user's Apple/Google account; it only keeps the hash in order to detect whether the same user is attempting to obtain multiple free trials by creating new accounts in the application.

– Relevant subscription lifecycle dates: trial start, expected end of trial (day 8), next renewal, cancellation date if applicable, last webhook event received.

– Previous trial counter (trial_count: 0 or 1) and last activity date, in order to assess re-eligibility after 90 days of inactivity.

– Primary assistant identifier (primary_agent_id) — the assistant the user used most during their Premium or trial period, calculated automatically to determine which assistant retains access in Memory Mode.

– Subscription event log (audit log): each status transition (trial_started, trial_converted, cancelled, etc.) is recorded with a timestamp, the source of the event (Apple webhook, Google webhook, manual action) and, in some cases, the original webhook payload for auditing and incident resolution purposes.

k) Token consumption data and operational metrics (NEW in v3.0)

To manage the token system described in the Terms of Use (Sec. 9.4 to 9.6), NAIARA AI processes:

– Cumulative monthly cost (cumulative_cost_usd_cents): an internal counter of the AI processing cost generated by the user's interactions, expressed in US dollar cents. This value makes it possible to calculate the percentage of the monthly allowance consumed.

– Usage histogram by assistant: the number of messages exchanged with each assistant, in order to determine the primary_agent_id applicable to Memory Mode and for aggregated operational analysis.

– Top-up purchases (Empujoncito and Full Pack): date, pack type, Apple/Google transaction identifier. Used to apply the rule of a maximum of one Empujoncito per monthly cycle and for operational analysis.

– Bonus tokens granted: date granted, the amount of the commission that gave rise to the bonus, originating affiliate network. Allows the monthly bonus cap (+50,000 tokens) to be enforced and tokens to be reversed if the commission is subsequently cancelled.

– Threshold events: records of when the user crossed the 80%, 95% and 100% thresholds of the cap, and which option they chose in the end-of-allowance dialogue (Empujoncito, Full Pack, Wait). Data used for product improvement.

3. Purposes and legal basis for processing

3.1. Registration and management of a personal account. Legal basis: Art. 6.1.b GDPR (performance of a contract).

Retention: until cancellation + 5 years limitation period.

3.2. Provision of the service (interacting with assistants, managing purchases, ensuring the service works). Legal basis: Art. 6.1.b GDPR.

3.3. Improving the Application with pseudonymised/anonymised data. Legal basis: Art. 6.1.f GDPR (legitimate interest).

An impact assessment has been carried out.

3.4. Contextual analysis of conversations in order to show recommendations, content or contextual advertising.

Legal basis: Art. 6.1.f GDPR.

3.5. Commercial intermediation and personalised recommendations. Legal basis: Art. 6.1.a and 6.1.b GDPR.

3.6. Marketing and commercial communications. Legal basis: Art. 6.1.a GDPR (granular consent).

Separate subcategories each with their own checkbox: NAIARA newsletter by email, push notifications about new features, promotional communications from affiliate partners, market research and beta invitations, product improvement (surveys, NPS). You can object to one without affecting the rest.

3.7. Management of competitions and promotions. Legal basis: Art. 6.1.a GDPR.

3.8. Legal compliance, protection of rights, fraud prevention. Legal basis: Art. 6.1.c and 6.1.f GDPR.

3.9. Processing of special categories (Art. 9.2.a GDPR): explicit consent inferred from the voluntary act of sharing, see Sec. 2.b.bis.

Revocable at any time.

3.10. Management of the free trial period and anti-fraud (NEW in v3.0).

Processing of the data described in Sec. 2.j in order to: determine the user's initial eligibility (verifying that they are a new subscriber), apply the re-eligibility rules after 90 days of inactivity, detect attempts to abuse the trial period through hashing of Apple/Google account identifiers, and manage subscription status transitions based on Apple and Google webhooks. Legal basis: Art. 6.1.b GDPR (performance of the subscription contract) and Art. 6.1.f GDPR (legitimate interest in fraud prevention).

3.11. Management of the token system and top-ups (NEW in v3.0).

Processing of the data described in Sec. 2.k in order to: calculate the percentage of the monthly allowance consumed, determine Empujoncito eligibility (automatic rule: cap ≥ 95% AND days to reset ≤ 7 AND Empujoncitos already used = 0), calculate and grant bonus tokens when an affiliate commission is confirmed, and determine the primary_agent_id applicable to Memory Mode. Legal basis: Art. 6.1.b GDPR.

3.12. Internal economic control dashboard (NEW in v3.0).

NAIARA AI maintains an internal administrative dashboard, accessible only by authorised staff through SSO with the naiara_admin role, showing aggregated and pseudonymised metrics on service consumption, margin health, Empujoncito effectiveness, trial period conversion rates and other operational indicators. The dashboard data is updated hourly by a batch process that aggregates information from the operational tables. The dashboard is not accessible to end users and is not shared with third parties. All access is recorded in an audit log. Legal basis: Art. 6.1.f GDPR (legitimate interest in the operational and economic management of the company, without interference with the user's fundamental rights, as the data is aggregated or pseudonymised).

Acceptance is always revocable, without retroactive effect. To revoke: info@naiara.com (subject: "Privacy – Revocation").

4. Retention of conversations and data monetisation

4.1. NAIARA AI retains conversations for: (a) provision and improvement of the service; (b) training and optimisation; (c) generation of anonymised data for analysis and monetisation. Legal basis for (c): Art. 6.1.a GDPR (separate explicit consent).

4.2. Before any sharing or sale of data, NAIARA AI applies rigorous anonymisation in accordance with AEPD Guidance and EDPB Opinion 05/2014: removal of direct and indirect identifiers, k-anonymity, l-diversity, differential privacy and periodic assessment of re-identification risk.

4.3. NAIARA AI may share or sell anonymised and aggregated data for market analysis, trends, statistical reports and research. Because this is genuinely anonymised data, it falls outside the scope of the GDPR.

4.4. Consent for monetisation is specific, informed, freely given and unambiguous, through active opt-in (no pre-ticked boxes). Revocable in Settings → Privacy without affecting the basic service.

4.5. Anonymised data may be shared with: market research firms, advertising agencies, consultancies, academic institutions. Identifiable data is NEVER shared for monetisation.

4.6. NAIARA AI has carried out and keeps up to date a Data Protection Impact Assessment (Art. 35 GDPR). A summary is available on request at info@naiara.com.

5. Who we share your data with

Your data may be processed by third-party processors (Art. 28 GDPR):

• Google LLC / Google Ireland Limited (Gemini API): provider of the AI model. Processes conversation content in order to generate responses and, through the Cached Content API, caches NAIARA AI's editorial system prompts (not user content). Privacy: https://policies.google.com/privacy. Terms: https://ai.google.dev/gemini-api/terms.

• Google LLC (Gemini Flash-Lite): processes the history of long conversations (more than 20 turns) to generate condensed summaries, applying the data minimisation principle of Art. 5.1.c GDPR.

• Apple Inc. (App Store Server Notifications v2) (NEW in v3.0): notifies NAIARA AI about the subscription lifecycle (trial start, cancellations, renewals, expiries, refunds). Apple acts as processor for payments and as the authoritative source of subscription status.

• Google LLC (Real-Time Developer Notifications) (NEW in v3.0): the Android equivalent of Apple's service. Notifies NAIARA AI about subscription events.

• Amazon Web Services: cloud infrastructure, servers within the EEA wherever possible.

• BlazeByte: subcontracted development team in India, under a data processing agreement (Art. 28 GDPR) with Standard Contractual Clauses for international transfers.

• Apple Inc. and Google LLC: management of payments, subscriptions, refunds and the free trial.

• Affiliate networks (Amazon Associates, Awin, Tradedoubler, Tradeinn): receive an anonymous click identifier (click_id) that allows the purchase to be correlated with NAIARA AI when the commission is confirmed, without receiving identifiable personal data about the user. The network may collect user data through its own cookies and policies, over which NAIARA AI has no control.

For transfers outside the EEA (USA for Google Gemini, Apple and infrastructure; India for BlazeByte): Standard Contractual Clauses (Art. 46 GDPR) and, where applicable, the EU-US DPF.

We may also disclose data in order to comply with legal obligations or requests from authorities, or in the event of a merger, acquisition or sale of assets (with prior notice).

6. Data subject rights

As the data subject, you have the following rights under the GDPR:

• Access (Art. 15 GDPR): obtain confirmation of what data is processed and a copy of it. • Rectification (Art. 16 GDPR): correct inaccurate or incomplete data. • Erasure (Art. 17 GDPR, "right to be forgotten"): delete your data when it is no longer necessary or you withdraw consent. Erasure includes data held in Memory Mode. • Restriction (Art. 18 GDPR): restrict processing in certain circumstances. • Portability (Art. 20 GDPR): receive your data in a structured, commonly used, machine-readable format (JSON) and transmit it to another controller. Includes data under Regulation (EU) 2023/2854 (Data Act) where applicable. • Objection (Art. 21 GDPR): object to processing based on legitimate interest, including the internal dashboard (Sec. 3.12) and the analyses in Sec. 3.4. • Automated decisions (Art. 22 GDPR): not to be subject to decisions based solely on automated processing with significant legal effects, without consent. See Sec. 11. • Withdraw consent (Art. 7.3 GDPR): at any time, without affecting the lawfulness of prior processing. • Complaint to a supervisory authority: AEPD (www.aepd.es) or the authority in your Member State.

To exercise your rights: info@naiara.com (subject: "Privacy – [Your right]"). State your name, contact email, the right you wish to exercise and the data concerned.

7. Duration of processing and retention — table by category

Data category Retention period Legal basis

Account data (email, phone, ID, date of birth) Until cancellation + 5 years Civil limitation period (Art. 1964 CC)

Conversations with assistants 24 months by default, configurable Service + legitimate interest

Compressed history summaries (Flash-Lite) Linked to the conversation; same period Art. 5.1.c minimisation

Transaction data (affiliate purchases) 6 years Accounting law (Art. 30 Commercial Code)

Subscription and trial data (Sec. 2.j) Until cancellation + 5 years Performance of contract + limitation period

Anti-fraud trial account_hash 24 months after last use Legitimate interest (Art. 6.1.f)

Token consumption data (Sec. 2.k) 24 months (detailed data); indefinite (aggregated) Service + legitimate interest

Memory Mode status Indefinite while the account is active Performance of contract; subject to Art. 17

Internal dashboard logs (audit) 13 months rolling Legitimate interest (auditing)

Advertising data and advertising ID Until consent is withdrawn Consent Art. 6.1.a

Marketing data (newsletter, push) Until consent is withdrawn Consent Art. 6.1.a

Voice data (transcriptions) Not stored permanently Art. 5.1.c minimisation

Facial data Only processed, not stored Art. 5.1.c

Special categories (health, etc.) Art. 9 12 months or until revoked Explicit consent

Technical and security logs 12 months Legitimate interest

System backups 30 days rolling Service continuity

Support data (info@naiara.com) 3 years from ticket closure Contractual compliance

8. Security

Technical and organisational measures (Art. 32 GDPR): encryption in transit (TLS 1.3) and at rest (AES-256), role-based access controls (RBAC), periodic audits, incident response plans. Access to the internal dashboard is restricted through SSO with a specific role and an audit log of every access. In the event of a breach: notification to the AEPD within 72 hours (Art. 33) and communication to the user without undue delay where it entails a high risk (Art. 34). No measure on the Internet is impregnable.

9. Minimum age — 18 years — and verification

NAIARA AI is exclusively for people over 18. Verification on registration: declaration with date of birth + confirmation checkbox + acceptance checkbox. The system blocks registrations with a declared age below 18.

Additional measures: monitoring of anomalous patterns, a persistent marker after a previous block, human review in suspicious cases. If a minor is detected, their account and associated data are deleted immediately (Art. 17 GDPR). To report use by a minor: info@naiara.com.

10. Cookies

The Application uses cookies that are strictly necessary for it to work. For non-essential cookies (analytics, advertising), prior consent is requested in accordance with the LSSI-CE, ePrivacy and the AEPD 2023 Guidelines. A layered cookie banner with "Accept all", "Reject all" and "Customise" options at the same visual level, with no pre-ticked boxes. Categories: strictly necessary (always on), preferences (opt-in), analytics (opt-in), advertising (opt-in), third parties (granular opt-in). Configurable from "Privacy".

11. Automated decisions and profiling

In accordance with Art. 22 GDPR, NAIARA AI uses several automated algorithmic processes: • Personalised recommendations: the assistants use AI to make recommendations based on preferences, history and profile. • Free trial eligibility (NEW in v3.0): automatic determination, based on Apple/Google account status and the account_hash, of whether the user is eligible for an initial free trial or for re-eligibility after 90 days of inactivity. • Token cap calculation and Empujoncito eligibility (NEW in v3.0): automatic calculation of the percentage of the monthly allowance consumed; automatic determination of Empujoncito eligibility according to the rule described in the Terms. • Automatic granting of bonus tokens (NEW in v3.0): when an affiliate network confirms a commission via webhook, NAIARA AI automatically grants the corresponding tokens following the 500 tokens/EUR 1 rule, with a cap of +50,000/month. • Selection of the primary_agent_id for Memory Mode (NEW in v3.0): when the subscription expires, the system automatically selects the assistant with the highest number of interactions during the Premium period in order to retain access in Memory Mode.

You have the right to: meaningful information about the logic applied, to express your point of view, to contest the decision, and to request human intervention. None of the automated decisions described produces significant legal effects on the user within the meaning of Art. 22.1 GDPR (they do not affect employment contracting, credit granting, etc.). In the event of disagreement, write to info@naiara.com (subject "Privacy – Automated decision review") and a member of the team will review your case.

12. Changes to this policy

NAIARA AI may modify this Policy by publishing the updated version. For substantial changes (monetisation, new processing categories, new processors such as Apple ASSN or Google RTDN), renewed consent will be requested with 30 calendar days' notice.

This Privacy Policy is offered in Spanish and English. In the event of any discrepancy, the Spanish version prevails, unless the user's local law mandatorily provides otherwise.

Plain-language summary Your privacy matters. We collect data to manage your account, provide the service, improve the assistants and show you relevant recommendations. We manage your subscription and free trial together with Apple/Google and apply proportionate anti-fraud measures. We comply with the GDPR, LOPDGDD, AI Act, DSA, Data Act and other applicable legislation. You can access, correct, delete or export your data at any time. Only providers under contract see your data. Identifiable personal data is never sold. Contact: info@naiara.com (subject "Privacy" for GDPR matters).

NAIARA AI, S.L. — Eivissa, Illes Balears, Spain — Privacy Policy Version 3.0 — 10 May 2026 — Supersedes and renders version 2.2 without effect.