Privacy Policy
Last updated: 2 September 2026
This Privacy Policy explains how ProdigyAI Solutions SRL (“we”, “us”) collects and uses personal data when you use the Tai Chi Service — the Tai Chi mobile applications for iOS and Android, the website at easytaichi.app, and the Tai Chi web application. We are the data controller for this processing.
Controller: ProdigyAI Solutions SRL, str. Transilvaniei A9, Aiud 515200, Alba, Romania, CUI 47791661 — hello@easytaichi.app
1. What we collect
What we collect depends on the platform you use and the features you choose. Not every category below applies to every user.
Information you give us
- Email address — if you sign in with Apple or Google, enter your email to sign in with a code, provide it during web checkout, or join a waiting list. If you sign in with Apple or Google, we receive the email address (and, where you allow it, the name) associated with that account.
- Onboarding answers — the questions we ask to build your practice plan, such as age or year of birth, gender, height, weight, target weight, goals, activity level, walking habits, how you manage stairs and squats, neck and arm mobility, energy between meals, sleep, water intake, diet, motivation, what gets in the way of exercising, an event you may be preparing for, and how you heard about us. Some of these answers concern your physical condition. We use them only to personalise your plan and provide the Service.
- Support communications — messages you send us, and feedback you give when cancelling.
Information created by using the Service
- Identifiers — on iOS, an identifier generated for the app on your device; on Android, the device's Android ID; on the web, a random identifier generated in your browser. These let us keep your progress and subscription without requiring an account. Push notification tokens if you enable notifications.
- Practice and progress data — sessions started and completed, minutes practised per day, your current day in a programme, streaks and badges, and the practice plans generated for you.
- Subscription and purchase data — subscription status and history, product and price, transaction, order and subscription identifiers from Apple, Google, or our payment provider, and purchase tokens used to verify a purchase, and, for purchases on our website, a record of your confirmation that you want immediate access (see our Refund Policy). Payment information is processed by the applicable payment provider or app store. We generally do not receive or store your full payment card details.
- Device and technical data — device model, operating system version, app version, language, region, time zone, screen size, accessibility settings, and, on the web, browser type. We also receive your IP address when your device or browser connects to our servers; we use it to operate and secure the Service, to derive your approximate region, and for advertising measurement as described below.
- Usage analytics — events such as screens viewed, onboarding steps completed, paywall views, and workouts started or finished.
- Diagnostics — crash reports, performance data, and application logs that help us find and fix problems.
- Session replay (iOS) — the iOS app may capture a simplified visual representation of app screens and how you move through them, using PostHog, to improve usability. This is switched off for users whose region we detect as the EU/EEA, the United Kingdom, or California.
Advertising and attribution data
We advertise on Apple Search Ads, Meta (Facebook and Instagram), TikTok, and Google, and we measure whether those ads lead to installs and subscriptions. For this we may process:
- an attribution token provided by Apple Search Ads, which tells us the campaign and keyword that led to an install;
- your advertising identifier — on iOS only if you allow tracking when the app asks, and on Android where the ad SDKs can access it;
- app events (such as install, onboarding completed, and purchase) sent through the Meta and TikTok SDKs and, on the server side, to Meta's Conversions API together with your IP address, device information, a hashed form of your email address, and a hashed form of your user identifier;
- technical signals — IP address, browser or device type, screen size, locale, and time zone — recorded when you click one of our ads and when the app first connects, which we may match to each other for a short period to attribute the install;
- on iOS, your email address may be used by Google's on-device conversion measurement to attribute an install to a Google ad; Google hashes it on your device.
2. Why we use it and on what legal basis
- Providing the Service — creating your plan, saving your progress, delivering content, notifications you have enabled. Basis: performance of our contract with you.
- Accounts and subscriptions — linking your subscription to your device or email, verifying purchases with Apple, Google, or our payment provider, managing renewals and cancellations, and processing refunds. Basis: performance of a contract; legal obligations for tax and accounting records.
- Customer support — answering your messages and refund requests. Basis: contract; legitimate interest in resolving problems.
- Security and abuse prevention — detecting fraud, verifying that requests come from a genuine app, protecting our systems. Basis: legitimate interest.
- Analytics and product improvement — understanding how the Service is used so we can improve it, and testing changes such as pricing or onboarding flows. Basis: legitimate interest; consent where applicable law requires it.
- Advertising measurement — attributing installs and purchases to our advertising and reporting results to the advertising platforms we use. Basis: consent where the law or your device requires it (for example, iOS tracking permission); otherwise legitimate interest.
- Troubleshooting and diagnostics. Basis: legitimate interest.
- Legal compliance — meeting tax, accounting, and consumer-law obligations and responding to lawful requests. Basis: legal obligation.
Where we rely on legitimate interests, we have assessed that they are not overridden by your interests or rights; you can object at any time (see section 7). Where we rely on consent, you can withdraw it at any time without affecting processing that took place before withdrawal.
3. Who we share it with
We do not sell your personal data. We share it with providers who process it for us, only for the purposes above, and with the app stores and advertising platforms where you or the law require it:
- App stores and payment — Apple (App Store purchases, subscription verification, and refund requests), Google (Google Play purchases), and Stripe (payments on our website).
- Hosting and infrastructure — Hetzner Online GmbH (servers), MongoDB Atlas (database), and DigitalOcean (storage of exercise videos and images — this does not contain your personal data).
- Email delivery — Resend, which sends the sign-in codes we email you.
- Analytics and diagnostics — Google Firebase (analytics, crash reporting on Android, push notification delivery on Android, and Remote Config) and PostHog (iOS analytics and session replay).
- Advertising platforms — Apple Search Ads, Meta, TikTok, and Google, as described in section 1. These platforms act as independent controllers for the data they receive; their own privacy policies apply.
We may also disclose personal data where required by law, to protect our rights, or as part of a business transfer, in which case this policy will continue to apply.
4. Refund requests
If you ask Apple or Google for a refund, they may ask us how the purchase was used. We may share how long your account has existed, how much time you have spent practising, whether purchased content was delivered, and amounts paid or previously refunded — as recorded, only with the store handling your request, and only in response to a request you made.
5. International transfers
We are based in Romania, and some of the providers listed above process data in the United States or other countries outside the European Economic Area. Where we transfer personal data outside the EEA, we rely on a lawful transfer mechanism such as an adequacy decision (including the EU-U.S. Data Privacy Framework, where the recipient is certified) or the European Commission's Standard Contractual Clauses.
6. How long we keep it
We keep personal data for as long as needed for the purposes above and then delete or anonymise it. In practice:
- account, profile, and progress data — while you use the Service, and until you ask us to delete it;
- subscription and transaction records — as long as required for tax, accounting, and dispute purposes;
- sign-in codes — until used or expired;
- advertising attribution signals — for the short window needed to attribute an install, then only in the resulting attribution record;
- diagnostic logs and analytics — for the period our providers retain them, after which they are deleted or aggregated.
You can ask us to delete your data at any time (section 7).
7. Your rights
Under the GDPR and, depending on where you live, other laws, you have the right to: access the personal data we hold about you; have it corrected; have it deleted; restrict or object to our processing; receive the data you gave us in a portable format; withdraw consent where processing is based on consent; and lodge a complaint with a supervisory authority. In Romania that is the National Supervisory Authority for Personal Data Processing (ANSPDCP, dataprotection.ro); you may also complain to the authority where you live.
To exercise any of these rights, email hello@easytaichi.app. Because many users are identified only by a device or browser identifier, we may ask you for information that lets us find your record, such as the email you used or your app user identifier from the settings screen. We respond within the time allowed by law, normally one month.
You can also control some data directly: turn off iOS tracking or Android ad personalisation in your device settings; disable notifications in your device settings; and clear the web app's stored onboarding answers by clearing your browser's site data for easytaichi.app.
8. Security
We use technical and organisational measures appropriate to the risk, including encrypted connections, access controls, and hashing of sensitive values before they are sent to advertising platforms. No system is completely secure, and we cannot guarantee that unauthorised access will never occur, but we work to prevent it and to respond appropriately if it does.
9. Cookies and similar technologies
The easytaichi.app website uses Google Firebase Analytics, which may set identifiers in your browser to measure page views and clicks. It only loads after you accept analytics in the banner shown on your first visit; you can change your choice by clearing the site's cookies. The web app stores your onboarding progress and identifier in your browser's local storage so you can continue where you left off; this is not sent to anyone other than us. The mobile apps use SDK-level identifiers rather than cookies, as described in section 1.
10. Children
The Service is not directed to children under 16, and subscriptions may only be purchased by adults. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Changes to this policy
We may update this policy as the Service or the law changes. For material changes we will give notice in the App, by email, or on this page before they take effect. The date at the top shows when it was last updated.
12. Contact
ProdigyAI Solutions SRL
str. Transilvaniei A9, Aiud 515200, Alba, Romania
CUI 47791661
hello@easytaichi.app