selfunderstand

Privacy Policy

Effective May 23, 2026

This Privacy Policy explains how IamLadi s.r.o. (“selfunderstand,” “we,” “us”) collects, uses, discloses, retains, and protects personal data when you use the selfunderstand website and application (the “Service”). It applies in addition to our Terms of Service and the data-processing consent you grant before starting the assessment.

1. Data Controller

The controller of your personal data is IamLadi s.r.o., IČO 09877169, č.p. 332, 739 45 Fryčovice, Czech Republic, registered at Krajský soud v Ostravě, C 84636, contactable at ladi@iamladi.com. For purposes of the EU General Data Protection Regulation (“GDPR”) and the UK GDPR, we are the controller for personal data processed in connection with the Service. We have not appointed a data protection officer; you may direct privacy inquiries to the contact address above.

2. Categories of Personal Data We Collect

  • Account identifiers. Your email address and any name or avatar attribute returned by Google Sign-In via Clerk.
  • Assessment content. Your free-text responses, conversation transcripts with the AI interviewer and assistant, derived scores across our 37 facets, goals you create, notes, and consents recorded with a content-hash and timestamp.
  • Operational telemetry. Minimal request logs (timestamp, route, status, model used, token counts) generated by Convex and OpenRouter to operate the Service. We do not embed third-party web analytics or advertising SDKs.
  • Communications. The contents of any email you send to ladi@iamladi.com and our reply.

We do not knowingly collect special categories of personal data (such as racial or ethnic origin, political opinions, religious beliefs, health, sex life, or sexual orientation). If you choose to disclose such data in free-text responses you do so voluntarily; please avoid doing so unless necessary, as the Service is not designed to process special-category data.

3. Sources

We collect data (a) directly from you when you sign in, grant consent, and converse with the Service; (b) automatically when you use the Service (operational telemetry); and (c) from Google via Clerk for the limited purpose of authenticating you. We do not buy personal data and do not enrich your profile from data brokers.

4. Purposes and Legal Bases

PurposeLegal Basis (GDPR)
Provide the assessment and generate your reportPerformance of contract (Art. 6(1)(b))
Persist transcripts and scores for return visitsPerformance of contract (Art. 6(1)(b))
Process free-text assessment content via LLM providersExplicit consent (Art. 6(1)(a)) recorded at /consent
Cross-border transfer of personal data to the United StatesExplicit consent (Art. 6(1)(a)) and, where applicable, Standard Contractual Clauses / Data Privacy Framework
Secure the Service, prevent abuse, and debug errorsLegitimate interests (Art. 6(1)(f)) in maintaining a functional, secure product
Aggregate, de-identified analysis to improve scoring accuracyLegitimate interests (Art. 6(1)(f)); de-identified outputs cannot be re-associated to you
Respond to your inquiries and data-subject requestsLegal obligation (Art. 6(1)(c)) and legitimate interests
Comply with applicable law and respond to lawful requestsLegal obligation (Art. 6(1)(c))

Where processing is based on consent, you may withdraw it at any time by deleting your account from Settings → Data or by emailing ladi@iamladi.com. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

5. Sub-processors and Recipients

We share personal data with the following sub-processors:

Sub-processorPurposeLocation
Convex, Inc.Application database, server functions, file storageUnited States (US East)
Clerk, Inc.Authentication and identity managementUnited States
Google LLCGoogle Sign-In (OAuth identity provider)United States
OpenRouter, Inc.LLM routing gateway used to access the model providers belowUnited States
Anthropic, PBCClaude (Sonnet, Haiku) inference for the interviewer, scorer, and assistantUnited States
Google LLCGemini inference for the moderation/fast-path agent (separate from Google Sign-In above)United States
Cloudflare, Inc.Edge hosting, TLS, and DDoS protection for the web applicationGlobal edge network

We contractually require sub-processors to safeguard personal data and to process it only on our instructions. We do not sell or rent personal data, and we do not share it with advertisers. We may disclose personal data when required by law, to enforce our agreements, to protect rights, property, or safety, or in connection with a corporate transaction (in which case the acquirer will be bound by this Policy or one substantially similar).

6. International Data Transfers

Your personal data is processed and stored in the United States. If you access the Service from the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction with data-export restrictions, this constitutes a cross-border transfer. We rely on (a) your explicit consent recorded at /consent, (b) the EU-US Data Privacy Framework where the relevant sub-processor is certified, and (c) Standard Contractual Clauses approved by the European Commission where applicable. You may obtain a copy of the transfer mechanism applicable to a given sub-processor by emailing ladi@iamladi.com.

7. Retention

We retain your account data for as long as your account is active. You may delete your account and associated data at any time from Settings → Data or by emailing ladi@iamladi.com. A deletion request removes your account, transcripts, scores, goals, and usage history within 24 hours via an automated cascade. Backups managed by our sub-processors may retain residual copies for the period stated in their published policies; we do not separately back up personal data outside those systems. Aggregated, de-identified statistics that cannot be re-associated to you may be retained for the purpose of improving the Service.

8. Security

We use industry-standard administrative, technical, and physical safeguards to protect personal data, including encryption in transit (TLS 1.2+) and at rest, least-privilege access controls, audit logging, dependency scanning, secret-leak detection, and regular review of sub-processor security postures. No system is perfectly secure; you use the Service at your own risk and should choose a strong, unique credential for your Google account.

9. Your Rights

Subject to applicable law, you have the right to:

  • access the personal data we hold about you and obtain a copy;
  • have inaccurate or incomplete data corrected;
  • have your data erased (the “right to be forgotten”);
  • restrict or object to certain processing, including processing based on legitimate interests;
  • receive your data in a portable, machine-readable format;
  • withdraw consent at any time where processing is based on consent;
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (we do not make such decisions about you);
  • lodge a complaint with a supervisory authority — in the Czech Republic, the Úřad pro ochranu osobních údajů (uoou.cz); in your country of residence, your local DPA.

To exercise these rights, use the in-product controls at Settings → Data (export and account deletion) or email ladi@iamladi.com for any other request, including access, correction, restriction, objection, or withdrawal of consent. Settings → Consents is provided as a read-only history of the consents you have granted. We will respond within 30 days and may need to verify your identity before fulfilling certain requests.

10. California Residents (CCPA/CPRA)

If you are a California resident, you have the rights to know, delete, correct, and limit the use of sensitive personal information, and to opt out of the “sale” or “sharing” of personal information as those terms are defined under the CCPA. We do not sell personal information and do not share it for cross-context behavioral advertising. You may exercise these rights by emailing ladi@iamladi.com. We will not discriminate against you for exercising your rights.

11. Cookies and Local Storage

The Service uses only strictly necessary cookies and local-storage entries required for authentication (set by Clerk) and to maintain session state (set by Convex). We do not set advertising, analytics, or cross-site tracking cookies. Because all cookies are strictly necessary, no consent banner is presented; if we ever introduce non-essential cookies we will request your consent first.

12. Children

The Service is not directed to children under 16, and we do not knowingly collect personal data from them. If we learn that we have collected data from a child under 16, we will delete it. Parents and guardians who believe their child has provided us data should contact ladi@iamladi.com.

13. Automated Decision-Making and AI

The Service uses large language models to produce questions, scores, and reflections. These outputs are advisory and informational. We do not use them to make decisions that produce legal or similarly significant effects about you within the meaning of GDPR Article 22. We do not use the contents of your transcripts to train third-party foundation models, and our agreements with LLM providers prohibit them from doing so with your conversation content.

14. Changes to This Policy

We may update this Policy from time to time. If we make material changes, we will notify you by email and via an in-product notice at least 14 days before the changes take effect, and where required by law we will re-request consent. The “Effective” date at the top reflects the latest revision; prior versions are available on request.

15. Contact

Questions, requests, or complaints? Email ladi@iamladi.com.