Privacy Policy
Last updated: March 11, 2026
AI Migrator (“we,” “us,” “our”) is operated by AI Blew My Mind / SC INNOVALISTA SRL. This Privacy Policy explains how we collect, use, and protect your information when you use our service at ai-migrator.aiblewmymind.com.
This policy applies to all users worldwide, including users in the European Economic Area (EEA), United Kingdom (UK), and other jurisdictions with data protection laws.
1. Data Controller
The data controller responsible for your personal data is:
SC INNOVALISTA SRL
Bucharest, Romania
Email: daria@aiblewmymind.com
2. What Data We Collect
Account Information
When you create an account, we collect your email address and a hashed password. We use Supabase Auth for authentication. We do not store passwords in plain text.
Conversation Data You Upload
When you use the migrator, you upload conversation export files (JSON, text, markdown) or paste text. This data is processed in your browser and on our server only during extraction. Here is exactly what happens:
- Files are parsed client-side in your browser to detect their type and extract conversations.
- Conversation text is sent to our API, which forwards it to the Google Gemini API for fact extraction.
- The extracted facts (your AI profile) are returned to your browser.
- We do not permanently store your uploaded files or raw conversation text. They are held in server memory only during processing and discarded immediately after.
- Your generated AI profile (the extracted facts) is stored in our database so you can access it from your account.
Payment Information
Payments are processed by Stripe. We do not store your credit card number, CVV, or full card details. Stripe provides us with a payment confirmation, transaction ID, and your email for order fulfillment. See Stripe’s Privacy Policy.
Analytics
We use Google Analytics and Vercel Analytics to understand how people use the site (page views, traffic sources). These tools may set cookies. No personal conversation data is sent to analytics services.
3. Legal Basis for Processing (GDPR)
If you are in the EEA or UK, we process your personal data under the following legal bases:
- Consent (Art. 6(1)(a) GDPR): When you upload conversation data for extraction and when you opt in to our newsletter. You can withdraw consent at any time.
- Contract (Art. 6(1)(b) GDPR): To provide the AI profile extraction service you purchased, process payments, and manage your account.
- Legitimate interest (Art. 6(1)(f) GDPR): To improve the service based on aggregated, anonymized usage data, and to prevent fraud and abuse.
4. How We Use Your Data
- To provide the AI profile extraction service
- To process payments and deliver purchased features
- To send transactional emails (password reset, payment confirmation)
- To send the newsletter (only if you opted in — you can unsubscribe anytime)
- To improve the service based on aggregated, anonymized usage patterns
We do not sell, rent, or share your personal data or conversation content with third parties for marketing or advertising purposes.
5. Third-Party Services & Data Processors
We use the following third-party services (data processors) to operate AI Migrator:
- Supabase — Authentication and database. Data is hosted in the EU. See Supabase Privacy Policy.
- Google Gemini API — AI extraction processing. Conversation snippets are sent to Google’s servers for analysis. Google states that data sent through the paid Gemini API is not used to train their models. See Gemini API Terms.
- Stripe — Payment processing (PCI DSS Level 1 certified). See Stripe Privacy Policy.
- Vercel — Hosting and deployment. See Vercel Privacy Policy.
- Google Analytics — Website analytics (anonymized). See Google Privacy Policy.
6. International Data Transfers
Some of our processors (Google, Stripe, Vercel) may process data in the United States. These transfers are protected by:
- The EU-U.S. Data Privacy Framework (where applicable)
- Standard Contractual Clauses (SCCs) approved by the European Commission
- The processor’s own GDPR compliance mechanisms
Our primary database (Supabase) is hosted in the EU.
7. Data Retention
- Uploaded files and raw conversations: Not stored. Processed in server memory and discarded immediately.
- Extracted profiles: Stored in your account until you delete them or your account.
- Account data: Retained until you request deletion.
- Payment records: Retained for 7 years for tax and legal compliance.
- Analytics data: Anonymized and aggregated; individual sessions expire per provider policy.
8. Your Rights
Depending on your location, you have the following rights regarding your personal data. Under the GDPR, EEA and UK residents have all of these rights:
- Right of access — request a copy of all personal data we hold about you
- Right to rectification — correct inaccurate data
- Right to erasure (“right to be forgotten”) — request deletion of your account and all associated data
- Right to data portability — download your AI profile in a machine-readable format at any time
- Right to restrict processing — limit how we use your data
- Right to object — object to processing based on legitimate interests
- Right to withdraw consent — withdraw your consent at any time without affecting prior processing
- Right to lodge a complaint — file a complaint with your local data protection authority (e.g., ANSPDCP in Romania)
To exercise any of these rights, email us at daria@aiblewmymind.com. We will respond within 30 days (or the timeframe required by applicable law).
9. Cookies
We use the following types of cookies:
- Essential cookies: Required for authentication (session tokens) and core functionality. These cannot be disabled without breaking the service.
- Analytics cookies: Google Analytics and Vercel Analytics use cookies to understand site usage. These are optional — you can disable them in your browser settings without affecting the service.
We do not use advertising or tracking cookies. We do not participate in cross-site tracking.
10. Security
We implement appropriate technical and organizational measures to protect your data, including:
- HTTPS/TLS encryption for all data in transit
- Hashed passwords (never stored in plain text)
- Row-level security (RLS) on our database — users can only access their own data
- Service role keys stored securely in environment variables, never exposed to the client
However, no system is 100% secure. Please do not upload highly sensitive documents (medical records, financial statements, legal documents) that you would not want processed by a third-party AI.
11. Children
AI Migrator is not intended for children under 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately and we will delete it.
12. Changes to This Policy
We may update this policy from time to time. We will notify users of significant changes via email or a notice on the site. The “Last updated” date at the top reflects the most recent revision. Continued use of the service after changes constitutes acceptance of the updated policy.
13. Contact & Data Protection Inquiries
For any questions about this Privacy Policy, your data, or to exercise your rights, contact us at: daria@aiblewmymind.com
SC INNOVALISTA SRL
Bucharest, Romania
If you are in the EU and believe we have not adequately addressed your data protection concerns, you have the right to lodge a complaint with the Romanian data protection authority (ANSPDCP) or the supervisory authority in your EU member state.