Privacy Policy
Version 1.0 · Updated · Effective from
The Ukrainian version is the primary one.
In short
- The demo works without your consent. Without consent we store neither the text of your commands nor your voice.
- When you speak into the microphone, the audio is always sent to Google for speech recognition, even if you have not agreed to storage.
- We store text (the “text” checkbox) and audio (the “audio” checkbox) only with your explicit consent, to improve the Sho model. Audio can only be allowed together with text. If a command refines the one before (“and last week?”), with “text” consent we also store that earlier request.
- You can upload your own product catalogue to the demo (“Your own catalogue…”). Without the separate “catalogue” consent it lives only in the server’s memory for up to 24 hours and is never written to disk; with it we store the catalogue to improve Sho. This consent is independent of “text” and “audio”.
- Consent covers one visit. When you come back, the demo asks again, with the boxes unticked again. You can repeat your previous choice with one button, “Same as last time”.
- We use no cookies and no third-party analytics scripts, and we do not store your IP address, neither in the database nor in server logs. The site’s own analytics is pseudonymous: events without command text, with a random identifier that lives only in the page’s memory.
- If your browser sends a Global Privacy Control or Do Not Track signal, there is no analytics at all: not a single event is sent.
- The server is located in the EU (Warsaw, Poland).
- You can change your consent or delete everything you have sent under “My data”. If you withdraw consent, we delete what we have already stored based on it.
1. Who we are
The website shozee.io is a demo of the Shozee (Шозі) app and the Sho (Шо) language understanding model. On the site you can say or type a command, and Sho parses it and carries it out on fictional demo data.
Personal data controller: sole proprietor (FOP) Ivan Vasylovych Kurbatov, 10 Kustarnyi Lane, Poltava, Ukraine.
Contact for data questions: kurbatov.ivann@gmail.com.
We have not appointed a representative in the EU (Art. 27 GDPR). We consider that the exemption in Art. 27(2)(a) GDPR applies: we process no special categories of data (in particular, we do not use your voice to identify anyone), the amount of data is small, and we store it only with your consent, so the processing is unlikely to result in a risk to your rights and freedoms. If this changes, we will appoint a representative and name them here. For any data question, including from an EU country, write to us directly at the address above.
2. What data we process
We collect data by levels. Each next level requires your separate consent.
2.1 Without consent (level 0)
Pseudonymous usage events. Our own analytics runs on every page of the site: the home page, the documents (this policy, the terms of use) and the 404 page. Each page load gets a new random identifier that lives only in the memory of the open page. We do not write it to cookies, localStorage or sessionStorage, so a reload or moving to another page starts a new analytics session, unconnected to the previous one. Events are sent to our server in batches (every 10 seconds, and when you hide or leave the page). Each event has a name, the time on your device and only these fields:
| Event | What it contains |
|---|---|
| Page view | which page it is (one of the site’s pages, or “other”; an address with any other words in it is not kept), the language, the domain of the site you came from (the domain only, not the page address), the link’s UTM tags (utm_source, utm_medium, utm_campaign, short Latin codes only) |
| Call-to-action click | which button (sign up, App Store, Google Play, documentation), where on the page, and whether the link is live or still marked “Soon” |
| Demo on screen; demo loaded | that the demo came on screen; how many milliseconds it took to load |
| Microphone access | allowed, denied, or the browser cannot record |
| Command | how you entered it (typed, an example or voice), which action Sho recognised (or that there was no command), the kind of action, the confidence level, how long parsing and (for voice only) recognition took, whether the demo could carry it out. No command text |
| Action on a chat card | confirm, cancel, pick an option or open in the panel |
| “Correct/wrong” rating | the rating and an action name (the one Sho recognised, or the one that should have happened; none if you chose “Other”). No command text and no comment |
| Answer to the consent question | whether “text” and “audio” are allowed (yes/no) |
| Error | a code from a closed list, e.g. “the server did not answer in time”, “no microphone”, “heard nothing” |
| Theme change; language switch | light, dark or system theme; Ukrainian or English |
Every field is a value from a closed list, a number or a short code, so free text, such as the text of a command or your name, cannot get into an event: the server drops an event with any other field. Events contain no IP address, no browser data and no cookies. They are pseudonymous rather than anonymous: we do not know who you are, but the events of one page load are linked by the random identifier and, if you have started using the demo on that page, to the pseudonymous demo session too (see below). The reports we build from them contain totals only; a domain or UTM tag seen by fewer than 5 visitors is not named in a report.
You can rate an answer “correct/wrong” without “text” consent too: the rating is then kept only as such a pseudonymous event. With “text” consent we also keep it together with the command (section 2.2).
Global Privacy Control and Do Not Track. If your browser sends a Global Privacy Control or Do Not Track signal, analytics does not start on the page at all: no identifier, no events. The rating buttons then appear only with “text” consent, since without it a rating would have nowhere to go. The demo works as usual.
Demo session record. When you start using the demo (the first command or the microphone), we create a pseudonymous session with a random identifier. Analytics never creates sessions itself: if you only read the pages, there is no session record, only events with the page load’s random identifier. The demo session’s token is kept in sessionStorage (section 8) only for the demo to work; analytics only reads it, to link the events of the same page to the session. The session record contains:
- the interface language;
- the domain of the site you came from, and the link’s UTM tags;
- a generalised browser type and device type;
- the time it was created.
Voice limit counters. So that the demo stays within its daily speech recognition limits, we count how many seconds of audio were sent for recognition: per pseudonymous session per day (such a counter is kept for 1–2 days) and for the whole site per day (not linked to any session). Counters per IP address hash exist only in the server’s memory.
Processing without storage.
- The command text reaches our server, Sho parses it, and without “text” consent we do not store it. Server logs contain neither command text nor IP addresses.
- Together with the command we send the demo context: fictional client and product names, so that Sho and speech recognition can recognise them. The rest of the demo state stays in your browser.
- If you upload your own product catalogue (“Your own catalogue…”), it comes to our server together with the demo shop’s fictional suppliers. Without “catalogue” consent we keep it only in the server’s memory, so that Sho can parse your commands on it: it is forgotten after 24 hours without use (or sooner, when the server restarts) and never written to disk. Commands refer to it only by its identifier, a hash of its content. The server logs hold only the number of products and variants.
- To protect against abuse and to enforce request limits, we compute a keyed hash of your IP address with a key that changes daily. The hash exists only in the server’s memory, and we do not store the IP address itself.
- We send your voice to Google for recognition (see section 3).
2.2 With “text” consent (level 1)
- the command text and how it was entered;
- the speech recognition result: the final text, the interim versions received during the recording, the name of the recognition service, the latency and why the recording ended;
- the demo context: fictional client and product names at the time of the command;
- the full output of the Sho model, the model’s name and version, and processing times;
- if a command refines the one before (for example “and last week?” after “show this week’s orders”), that earlier request too: as the demo sent it to Sho with the command (what the request was and which of the demo’s records it named) and when it ran;
- your “correct/wrong” rating, and the correct action and a comment (up to 300 characters) if you provide them.
The “text” checkbox is off by default. Without it, a “correct/wrong” rating under Shozik’s answer stays only a pseudonymous event (section 2.1), and no comment can be added to it.
Consent covers one visit (demo session). When you come back, the demo asks for consent again before the first command or recording, and the boxes are always unticked: we never tick them for you. If the consent text has not changed, the demo reminds you what you allowed last time and offers a “Same as last time” button: pressing it gives the same consent for this visit. You can instead tick the boxes yourself or continue without them, and then we store nothing. If the consent text has changed, the demo asks you to decide afresh, with no reminder and no such button.
2.3 With “audio” consent (level 2)
The audio recording of the command in WAV format (16 kHz, mono, up to 15 seconds per recording), linked to the text record of that command.
“Audio” consent can only be given together with “text” consent: without the text and Sho’s result, a recording is not usable for training. If you untick “text”, “audio” is unticked too, and what we stored is deleted (section 7). The “audio” checkbox is off by default.
2.4 With “catalogue” consent
A separate box, “My product catalogue, to improve Sho”, in the “Your own catalogue” window and under “My data”. It is independent of the “text” and “audio” consents and off by default. With it we store:
- the products you uploaded: names, variants, other names, brand and unit, and prices and stock if you gave them;
- the demo shop’s fictional suppliers the catalogue ran with, and whether it has stock;
- how you uploaded it (a pasted list, a CSV file or the form) and the shop type, if you chose one;
- the version of the consent text and the time.
The catalogue is linked to the demo session, and the commands you give on it with “text” consent are linked to the catalogue. A catalogue must contain products only: the demo’s clients stay fictional, so do not put personal data into it (see the Terms of Use). Other visitors cannot see your catalogue.
The purpose of “catalogue” consent is to improve Sho for different shops: so that the model better understands names of products, variants and units that the demo shops do not have. We use a stored catalogue for no other purpose, do not publish it and pass it to no one. If, while checking the data before training (section 4), we notice personal data in a catalogue, we will not use that catalogue and will delete it.
2.5 Consent and deletion records
- Consent history. Each time you give or withdraw consent, we add a record: the kind of consent (text, audio or catalogue), whether it was given or withdrawn, the version of the consent text, the language and the time. Records are never overwritten, so we can prove exactly what you agreed to.
- Deletion log. When you delete your data or withdraw consent, we record only the session identifier, the reason (deletion, or withdrawal of “text”, “audio” or “catalogue” consent), how many records of each kind were deleted and the time, without their content.
2.6 What we do not do
- We do not use cookies, tracking pixels or third-party analytics scripts.
- We do not store your IP address, neither in the database nor in server logs.
- We do not write anything to your browser for analytics, and we send no events at all if your browser asks not to be tracked (Global Privacy Control, Do Not Track).
- We do not ask for your name, e-mail or phone number to use the demo.
- We do not use your voice to identify who you are: we create no voiceprints and do not turn on speaker separation at Google. Your voice is needed only to get the text of the command, and recordings kept with “audio” consent only to help Sho understand speech better.
3. Voice and Google
When you press the microphone, your browser asks for permission to use it. The audio goes in real time to our server and from there to Google Cloud Speech-to-Text (the Chirp 3 model, EU region) to recognise Ukrainian and Russian speech.
This always happens when you use the microphone, even without “audio” or “text” consent. Consent only determines whether we keep the recording and the text on our side. If you do not want your voice sent to Google, type your commands instead.
Google acts as our processor: it processes the audio on our behalf and on our instructions, under the Cloud Data Processing Addendum.
The audio is streamed to Google in the EU multi-region (eu), and we have not turned on the Speech-to-Text data logging programme, under which Google could use audio to improve its services. According to Google’s documentation, the audio of streaming requests is processed in memory and not stored; Google only temporarily logs request metadata (such as the time and size of the request) to run the service and combat abuse, and uses the content for nothing but providing the service. Google returns the recognised text to us, and we keep it only with “text” consent.
4. Why we process data and on what legal basis
We follow the Law of Ukraine “On Personal Data Protection” and, for visitors from the EU, also the EU General Data Protection Regulation (GDPR), which applies to us under Art. 3(2) GDPR.
| Purpose | Data | Legal basis |
|---|---|---|
| Running the demo: recognise and parse a command, show the result | Command text, audio for Google, session | Legitimate interest in showing how the product works (Art. 6(1)(f) GDPR) |
| Security and abuse protection: limits, protecting the model | IP hash in memory, session | Legitimate interest (Art. 6(1)(f) GDPR) |
| Pseudonymous analytics: how the site and the demo are used | Events, session record | Legitimate interest (Art. 6(1)(f) GDPR) |
| Improving and training the Sho model | Text, the earlier requests a command refines, results, ratings (level 1); audio (level 2) | Your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time |
| Improving Sho for different shops | Your product catalogue, shop type, how it was uploaded | Your “catalogue” consent (Art. 6(1)(a) GDPR). You can withdraw it at any time |
| Proving that consent was given or withdrawn, and data deleted | Consent history, deletion log | Obligation to demonstrate consent (Art. 7(1) GDPR) and legitimate interest |
Under Art. 11 of the Law of Ukraine “On Personal Data Protection”, the legal bases are:
- running the demo, security and abuse protection, proof of consent and deletion: the need to protect the controller’s legitimate interests, except where your fundamental rights and freedoms prevail (Art. 11(1)(6));
- improving and training Sho (text and audio) and your product catalogue: your consent (Art. 11(1)(1)), which you can withdraw at any time;
- pseudonymous analytics: we cannot tell from the events who you are, so we consider that they are not personal data under the Law; if they were considered such, the basis is the controller’s legitimate interests (Art. 11(1)(6)).
For training Sho, we export into the dataset only records that have valid consent at the time of export. The controller then labels the records manually himself.
- Every new export excludes records whose consent has been withdrawn and data you have deleted. If you used “Delete everything I sent”, that visit’s records are never exported.
- With “catalogue” consent an export also contains your catalogue, and the commands given on it refer to it. Before training, catalogues pass an automatic filter (length, language, repeats, stop words) and a manual spot check.
- An export contains the command text, the recognised text, Sho’s result, the earlier request a command refines, your rating and comment, and, with “audio” consent, the voice recording. It contains no IP address, no browser or device details and no session identifier; the commands of one visit are marked with a pseudonym that holds only within that one export.
- Exported files are kept only on the controller’s workstation, never on the public server: the data comes from the server over an encrypted connection (SSH) and is not stored on the server. We keep only the latest exports: older ones are deleted once a new one is made.
- Data already used for training cannot be removed from an existing model, and we do not retrain such models after consent is withdrawn. However, the data is excluded from future training.
The Sho model is trained by the controller himself (section 1), on his own workstation, from these exports; Sho is his own project. We pass your data to no one for training or labelling: neither to cloud services nor to other people. Should this ever change, we will first update this policy and name here to whom and where we pass the data.
5. Where data is stored and who has access
- Server. All data we store is kept on a virtual server in the EU (Warsaw, Poland). The server is provided by the Ukrainian hosting provider Mirohost (Internet Invest LLC, ТОВ «ІНТЕРНЕТ ІНВЕСТ», Kyiv, company code 32493292) under its public contract. Mirohost only provides the server; we entrust it with no other processing of the data.
- Backups. For now the data is kept only on this server in Warsaw: we do not yet make backups of our own outside it. Mirohost’s cloud platform, as the provider describes it, makes automatic encrypted backups of servers in its own storage; the provider does not publish how often, where exactly or for how long, and we are clarifying this with it. We will add nightly backups of the database and the audio outside the main server, in the EU, deleting copies older than 30 days, and will update this policy then.
- Google receives audio for recognition as our processor, in the EU region (section 3).
- The training dataset is kept only on the controller’s workstation (section 4).
We do not sell data or pass it to advertisers.
The data is stored in the EU, but the controller and the hosting provider are Ukrainian entities, and there is no European Commission adequacy decision for Ukraine. You give the data to us directly, and the GDPR applies to us directly (Art. 3(2) GDPR): we meet its requirements just as a controller in the EU would. The data is kept on the server in Poland. From Ukraine, only we access it, over an encrypted connection: to administer the server and to export the training dataset to the controller’s workstation (only records with your consent, section 4). Under the Law of Ukraine “On Personal Data Protection”, keeping the data in Poland is a transfer to a state of the European Economic Area, which ensures adequate protection (Art. 29).
The site uses no third-party bot protection services.
6. How long we keep data
| Data | Retention |
|---|---|
| Command text (with the earlier requests they refine), results, ratings, audio | Until you withdraw consent, but no longer than 24 months |
| Your catalogue, with “catalogue” consent | Until you withdraw consent, but no longer than 24 months |
| Your catalogue, without consent | Only in the server’s memory, up to 24 hours without use |
| Pseudonymous usage events | 13 months |
| Session records and consent history | 13 months, but no less than the related text and audio are kept |
| IP address hash | Only in memory; the key changes daily |
| Session’s seconds-of-voice counter | 1–2 days |
| Site’s seconds-of-voice counter | 13 months |
| Deletion log (counts only) | 13 months |
| Our backups outside the server (once added, section 5) | Up to 30 days |
| Exported training dataset | Until the next export |
An automated job deletes expired data every day. Deletion, whether on your request, after you withdraw consent or by expiry, also reaches our backups within 30 days.
7. Your rights and how to exercise them
“My data”
In the “My data” section (below the demo and at the bottom of the page) you can:
- change your consent for the current visit: turn “text”, “audio” and “catalogue” on or off;
- see how much is stored from this visit and from earlier visits that the erase keys in this browser still reach, and separately how many pseudonymous usage events are linked to this visit;
- press “Delete everything I sent”: this deletes the data of this visit and of earlier visits.
The consent of an earlier visit cannot be changed, but its data can be deleted.
Withdrawing consent deletes what we have already stored:
- if you untick “text”, we delete this visit’s command texts with the earlier requests they refine, Sho’s output, ratings and audio recordings with their files;
- if you untick only “audio”, we delete the audio recordings with their files;
- if you untick “catalogue”, we delete this visit’s stored catalogues; commands given on them stay (with “text” consent), without the link to the catalogue.
In every case we add a record that consent was withdrawn. Usage events remain until the end of their retention period.
“Delete everything I sent” erases the command texts, the audio recordings with their files, the ratings, the catalogues and the events of every session this browser can reach: the current visit’s and those of earlier visits whose erase keys it keeps. A session’s events are those linked to it and all other events of the same page loads, including those sent before you started using the demo. Events of other page loads (before a reload, on other pages of the site or without the demo) are not linked to you, so we cannot find them: they stay pseudonymous until the end of the period in section 6 (13 months). The browser then removes shozee-data as well. For each session we add records withdrawing every consent. Each session record remains, but without the referrer, UTM tags, browser type and device type. Together with the consent history, it is kept until the end of the period in section 6 as proof that consent was withdrawn.
Erase key
Each time you give “text” or “catalogue” consent (including when you turn only “audio” on or off), your browser receives a new random erase key and stores it in localStorage together with the session identifier, and the session’s previous key stops working. The server stores only the key’s hash. With the key you can see and delete your data even months later, from the same browser, long after the session has ended. The key is valid as long as the session record exists on the server: at least 13 months, until it is deleted by expiry (section 6), including after you have deleted your data.
We do not know who you are, so we can find your data only by the session identifier or the erase key. If you clear the site’s data in your browser or switch to another browser or device, we will not be able to link you to your records.
Other rights
You have the right to:
- know what data about you we process, and get a copy of it;
- correct inaccurate data;
- have data deleted or its processing restricted;
- object to processing based on legitimate interest;
- receive the data you provided with consent in a machine-readable format;
- withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before it.
To exercise these rights, write to kurbatov.ivann@gmail.com. We will reply within the time limits set by law.
Complaints
If you believe we are violating your rights, you can complain to the Ukrainian Parliament Commissioner for Human Rights or to the data protection supervisory authority in the EU country where you live or work, or where the violation took place.
8. What we store in your browser
We do not use cookies. In your browser we store only what is needed for actions you chose yourself. We write nothing to your browser for analytics: its session identifier lives only in the memory of the open page.
| Storage | What | When |
|---|---|---|
localStorage |
The selected colour theme | If you changed the theme |
sessionStorage |
Signed demo session token (valid 30 minutes) | Once you start using the demo; needed for the demo to work; cleared when the tab closes |
localStorage |
Session identifiers and erase keys of this and earlier visits, the consent text version and your last choice of boxes (shozee-data) |
Only after “text” or “catalogue” consent. A visit’s entry goes when you withdraw both for it; everything goes after “Delete everything I sent” |
You can clear this data in your browser settings. Delete your data via “My data” first, because without the key we cannot find it.
9. Children
The demo is not intended for people under 16. If you are younger, please do not consent to storing text, audio or a catalogue. We do not ask for or check anyone’s age.
10. Changes to this policy
The policy has a version and an update date at the top of the page. Consent texts are versioned too (currently consent-v3: consent-v2 added “catalogue” to “text” and “audio”, and in consent-v3 “text” also covers the earlier request a command refines; under a consent given to an older text we do not store that request). If we materially change what we collect with consent, the consent text gets a new version and the demo asks for your consent again.
11. Contact
Sole proprietor (FOP) Ivan Vasylovych Kurbatov, 10 Kustarnyi Lane, Poltava, Ukraine, kurbatov.ivann@gmail.com.
See also the Terms of Use.