Privacy Policy

How we collect, use, and protect your data

Privacy Policy Overview

This privacy policy is structured to provide comprehensive information about how we handle your data. Below are the main sections covered:

1. Company/Owner Information

Essential contact information for Ögren Digital including company address, email, phone number, and general contact details for privacy-related inquiries.

2. Privacy Notice for Swiss Residents

Specific privacy notice for Swiss residents covering FADP compliance, data protection principles, your rights under Swiss law, international data transfers, and information about our Swiss data protection representative.

3. General Privacy Policy Highlights

Overview of our data processing practices including audio processing and text processing, local data storage, third-party services, user account management and more.

4. Contact Information for Representatives

Contact details for our Swiss representative (for FADP matters) and GDPR representative (for EU data protection matters), including addresses, phone numbers, and email contacts for data protection inquiries.

Company/Owner Information

Company Name:
Ögren Digital
Product Brand Name:
WritingAnt
Address:
Loretostrasse 1
6300 Zug
Switzerland
Phone:
+41 (0) 77 267 65 62
For questions about this privacy policy, please contact us using the information above.

Privacy Notice for Swiss Residents

This Notice outlines how Ögren Digital processes personal data of Swiss residents in compliance with the Swiss Federal Act on Data Protection (FADP) and the Swiss Data Protection Ordinance (DPO).

Data Protection Principles Under FADP

FADP is underpinned by six important principles that Ögren Digital adheres to. These principles require that personal data must: Be processed lawfully; Be processed in good faith and proportionately; Be collected for a specific purpose that the data subject can recognise; and may only be further processed in a manner that is compatible with this purpose; Be destroyed or anonymised as soon as they are no longer required for the purpose of processing; Be accurate and kept up to date; If processed with consent as a lawful base, the consent is given voluntarily for one or more specific instances of processing based on appropriate information.

Legal Basis for Processing

Ögren Digital relies on the following legal bases for processing: Your consent, Performance of a contract with you, Compliance with a legal obligation, Protection of your vital interests, Our legitimate interests, provided they do not override your fundamental rights and freedoms, Public interest or exercise of official authority.

Your Rights Under FADP

As a Swiss resident, you have the following rights regarding your personal data:
Right of access to personal data
(including right to receive the following information: Identity and contact details of the data controller, the personal data processed, purpose of processing, retention period or criteria, source of data (if not collected from the data subject), information about automated individual decisions and their logic, recipients of personal data)
Right to data portability
(including the right to request from us to deliver your personal data to another controller in a conventional electronic format if: your data is being processed in an automated way and if your data is being processed with your consent or in direct connection with performance of a contract between Ögren Digital and you.
Right to personal data deletion or destruction
Right to personal data rectification
(including the right to demand correction of inaccurate personal data and the right to request that disputed data be marked as such)
Right to personal data processing prohibition
Right to personal data non-disclosure
Right to be informed of measures taken
(including the right to request that measures related to deletion, rectification, prohibition of processing, or non-disclosure of your data be published or communicated to third parties)
To exercise these rights, please contact us at info@oegren-digital.ch. We will respond to your request within 30 days.

International Data Transfers

Ögren Digital may transfer personal data outside Switzerland to countries whose law does not ensure an adequate level of data protection, provided that data protection is ensured by other mechanisms, in particular on the basis of standard data protection clauses or other suitable guarantees. In exceptional cases, we may export personal data to countries without adequate or suitable data protection if the specific data protection requirements are met, for example, the express consent of the data subjects or a direct connection with the conclusion or processing of a contract.
We will gladly provide data subjects with information about any guarantees or provide a copy of any guarantees upon request.

Third-Party Services and Data Transfers

Service ProvidedContactSub processorsSafeguards in place
Text enhancement & generation, general cloud infrastructureMicrosoft Azure Switzerland /EU, OpenAI Ireland LtdSCCs/Data Privacy Framework
Account signup & authenticationWorkOS Inc. (US), backup Microsoft Azure Switzerland /EUDPA/SCCs, DPF/SCCs
Billing & invoicesMicrosoft 365 EU and US, Bexio AG (CH), UBS E-banking, Stripe Inc. (US)SCCs/DPF; Switzerland adequacy
Usage analytics/quota managementMicrosoft Azure Switzerland and EUSCCs/Data Privacy Framework
Support ticketsMicrosoft 365 EU and US, Microsoft Azure Switzerland /EUSCCs/Data Privacy Framework
Consent trace CookiesUsercentrics Denmark/EU, Microsoft Azure Switzerland/EUSCCs/Data Privacy Framework
Consent trace DocumentsIubenda Italy, Microsoft Azure Switzerland/EUSCCs/Data Privacy Framework

Your Right to Object to a Transfer

You have the right to object to the transfer of your personal data to these third parties. To exercise this right, please contact us at info@oegren-digital.ch. Please note that objecting to certain data transfers may affect our ability to provide certain services to you.

Swiss Representative

Under Article 14 of the FADP, we have appointed a Swiss Representative to act as our data protection agent. Our nominated Swiss Representative is:
Company:
ALTRION Sagl
Phone:
Tel +41 78 229 72 57
Address:
Via Luigi Lavizzari 8
6850 Mendrisio
Switzerland

Legal Protection

Data subjects have the right to enforce their data protection claims through legal channels or to lodge a complaint with a competent data protection supervisory authority. The data protection supervisory authority for private data controllers and federal bodies in Switzerland is the Federal Data Protection and Information Commissioner (FDPIC). In the case of projects financed by cantons or municipalities in Switzerland, the cantonal data protection commissioners are responsible in some cases.

Highlighted user responsibility related to data during usage of our services

Our services allow users to input and process speech and or text content as part of the main functionality of this speech-to-text software, including through third-party AI providers (find more details in the main privacy policy at the link below). We recommend that users avoid using personal or sensitive information when recording audio for speech-to-text, text enhancements, and audio prompts for creative writing, or when using text as input for text enhancements. Users are responsible for the content they choose to submit and should ensure that they have the legal right to process such information.

Local Audio Processing and Data Handling

Audio Stays Local:
Your audio recordings never leave your device. All audio data from your microphone is processed locally on your computer and is never transmitted to our servers, third-party services, or any cloud infrastructure.
Initial Speech-to-Text Processing:
The first step of converting your speech to text happens entirely on your computer using local speech recognition technology. This initial transcript is created without any data leaving your device.
Transcript Enhancement:
Only the text transcript (not the audio) resulting from the local speech-to-text conversion is sent to our cloud services for further enhancement and improvement. This text-only data is then processed through our AI services to create well-written, formatted text.
Applies to All Speech Features:
This local audio processing approach applies to all speech-to-text features in our application, including:

Standard speech-to-text conversion
Speech-to-text creative writing features
Voice command keyword detection and recognition
All other voice-activated functionality
Privacy Benefits:
This architecture ensures maximum privacy for your spoken content. Your voice, pronunciation patterns, and audio characteristics remain completely private and secure on your device, while still allowing us to provide advanced AI-powered text enhancement services.

Local Event Data Communication

Socket.io Communication:
Our application uses a random available Socket.io port communication to handle real-time data exchange between different components of the application on your local computer.
Application Architecture:
The application consists of both Python backend components and Electron/JavaScript frontend components that need to communicate with each other. This local Socket.ioconnection enables seamless coordination between these different parts of the software.
Encrypted Communication:
All data transmitted through these Socket.io events are encrypted so only the logged-in user in the operating system should be able to have access. Further limiting is set to only allow a client application to connect from the local computer, and limitation is set to one client application.

Highlighted AI Third-Party Services for Data Processing including international data transfers

We use third-party services from Microsoft Azure (this is where the AI models originally created by OpenAI are hosted as well via Azure AI Foundry) and OpenAI Ireland Ltd to process data as part of providing our services including AI services, especially for and text improvement features. This processing may involve international data transfers outside of Switzerland, the European Union (EU), the European Economic Area (EEA), and the United Kingdom.


Any such data transfers are carried out in compliance with applicable data protection laws, including the Swiss Federal Act on Data Protection (nFADP) and the General Data Protection Regulation (GDPR). In particular, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and, where applicable, the UK International Data Transfer Addendum (IDTA).

Appropriate safeguards are used to protect your personal data during international transfers and maintain documentation of these safeguards in accordance with Article 30(2) of the GDPR.

Microsoft is certified under the EU-U.S. Data Privacy Framework, the Swiss-U.S. Data Privacy Framework, and the UK Extension to the EU-U.S. Data Privacy Framework. These certifications ensure an adequate level of data protection for international transfers.
Data Storage and Retention by Third-Party Services:
When processing your requests through Microsoft Azure and OpenAI Ireland Ltd, these services may store request data and logs for up to 30 days. This data can include:

User ID and authentication information
Text input and transcripts
Text enhancement and generation results
HTTPS request metadata (including IP address, user agent, timestamps, request headers)
Language settings used for processing

This temporary storage is necessary for service operation, error handling, and system stability and quality assurance. After the retention period, this data is automatically deleted.

Highlighted User Accounts Data

We use the third-party WorkOS Inc. (US) to provide authentication and user account management. When you create or use a user account, we collect and process limited personal data needed for authentication, account management, fraud prevention, and service security.
Account data we collect:
Full name
Email address
IP address
Browser user agent


WorkOS Data Processing Addendum
Backups in Microsoft Azure (EU / Switzerland)

Highlighted Online Storage and Processing of Usage Data

Usage Data Collection:
We want to highlight that we especially store and process the usage data listed below, related to our speech-to-text and, text generation, and text enhancement features to manage your subscription limit usage and providing our services as well as analysis of whether the usage limits in the subscription plans are viable for future business, and other analytical evaluations for assessing our business model. We store this data for two years to evaluate usage changes over time. We want to avoid setting prices that are too high or too low based on these usage-driven costs. Our goal is to have a simple and clear way to communicate pricing quotas to the end user which we can achieve by analyzing the data from this two-year period.
Highlighted Types of Usage Data Collected:
Email address
Number of requests made for speech-to-text, text generation, and text enhancement features
Time and date of each request
Language used for processing
Amount of requests and number of tokens consumed by third-party AI language models
Information about which AI model was used for processing
Application version
Operating system (Windows or Mac)
User interface used (simplified window view or variant for inserting text into any application)
Text result quality requested
Result character size
Request timing for the underlying AI service
Situation profile (e.g., general, customer support, corporate communication, sales)
Application startup events, including how far you progress through the startup flow, to confirm that the program launches and initializes correctly
Whether the operating-system permissions the application asks for during setup (microphone, and on macOS accessibility and input monitoring) were granted, reported during the startup dialog and once setup completes, so we can detect installations that fail because a required permission is missing
A randomly generated, pseudonymous launch identifier. Before you sign in, application startup and AI-model download progress events are reported with this identifier only — it is generated anew for each launch, kept solely in the program's memory, never written to your disk, and never linked to your name, email address, or user account. Because a fresh identifier is used every time, two launches cannot be connected to each other, and these events are only sent until the application has started up completely for the first time
Which steps of the built-in learning guides (the Key Functionality Guide and Guide Level 2) you have completed, so we can see which features new users discover and improve the guides
Whether you currently have an active subscription
How you heard about WritingAnt (for example: from a friend, an online search, social media, or other)
The country you selected for pricing and whether you are purchasing as a private person or as a company
Startup and Onboarding Telemetry — Purpose, Legal Basis, and Retention:
The application startup, onboarding-progress, and installation-identifier events listed above are collected so that we can confirm that installations and application launches complete successfully, diagnose startup problems across different devices and operating-system versions, and understand whether the first-run experience is intuitive so we can improve it. Where the GDPR applies, we process this data on the basis of our legitimate interest in ensuring that our software installs and runs reliably and that new users can get started without problems (Art. 6(1)(f) GDPR); under the Swiss FADP we process it in accordance with the principles of lawfulness, proportionality, and purpose limitation. You have the right to object to this processing at any time (Art. 21 GDPR) using the contact details provided in this policy. Like the other usage data in this section, these events are retained for a maximum of two years and are then deleted or irreversibly anonymised.
The pre-login launch identifier is anonymous in practice: it is a random value generated fresh for every launch, held only in the program's memory and never stored on your device, so neither we nor anyone else can connect two launches or trace the events back to you. The events reported with it are limited to startup milestones, the platform (Windows or macOS), the application version, and the interface language you selected, and they stop permanently once the application has completed one successful startup. We do not join or correlate these events with your user account or any other account data on our servers — not even after you sign in.

Local Data Storage: User session auth data and optional personal data for voice command actions

Keyword-Trigger Features:
When you use the optional keyword-trigger features in the installed desktop application that start with "private" (e.g., "private address" or "private first name"), you must first save this private data in the App Settings. This data is subject to the local processing and encryption measures described below.
Local-Only Storage:
We store this kind of data strictly on your device and never transmit or retain it on our servers. All keyword-trigger data remains exclusively on your local machine.
Encryption at Rest:
Your settings and personal data are encrypted at rest using a industry-standard encryption algorithm (AES with HMAC authentication) to ensure that this data can only be accessed and decrypted on your specific device. The encryption key is derived locally, and never transmitted or stored on our servers.
Memory Processing:
Data is decrypted in memory and then inserted into the input field where you placed your cursor/caret at the time of use.
User Control:
You retain full control over your data—you can delete or clear the local cache at any time via the App Settings.
Encrypted Credential Storage:
Your user credentials are stored in encrypted form on your computer to enable easier login in the future. This encrypted storage uses industry-standard encryption algorithms (AES with HMAC authentication) to ensure that only your device can access and decrypt these credentials. The encryption keys are derived locally and never transmitted to our servers, maintaining the security and privacy of your authentication information.
Where data is stored on your device:
Settings and the encrypted cache are kept under the OS “user data” folder. Typical paths:

Windows: %LOCALAPPDATA%\OegrenDigital\SpeechToWellWrittenTextAssistant
macOS: ~/Library/Application Support/SpeechToWellWrittenTextAssistant
Folders Created on Your Computer:
The desktop application and its helper processes (the launcher, the overlay user interface, and the local speech-recognition subprocesses) create the folders and entries listed below on your computer. Data described as encrypted is encrypted at rest using an AES-based algorithm; the encryption key is stored in the operating system's secure key store (macOS Keychain or Windows Credential Manager, entry name "WritingAnt") and never leaves your device.
Main data folder:
macOS: ~/Library/Application Support/SpeechToWellWrittenTextAssistant
Windows: %LOCALAPPDATA%\OegrenDigital\SpeechToWellWrittenTextAssistant

This folder contains:
Encrypted files: settings.json (application settings), credentials.json (login session), history.json (dictation history and results), magic_snippets.json (personal snippets), custom_app_launchers.json (custom voice commands), custom_writing_styles (one file per custom writing style), writing_styles_setup.json, feature_settings_v2.json and feature_settings_v3.json (feature preferences)
audio_recordings — optionally saved audio recordings, stored encrypted (*.enc.wav); the subfolder audio_recordings/exported holds temporarily decrypted exports and is emptied automatically at the next application start
ai_models — downloaded AI transcription models (not encrypted; may be deleted at any time to free disk space, the application offers to download the models again when needed)
CrashLogs — crash and diagnostic reports (not encrypted; they contain technical information, not your recorded audio or dictated text)
logs — application log files (not encrypted)
launcher_status.json (application startup progress) and tokens.json (non-sensitive login metadata) — not encrypted
development — a subfolder with the same structure that is only used by development builds of the application
Additional folders and entries:
On macOS:
~/Library/Application Support/writing-ant and ~/Library/Application Support/writing-ant-overlay — framework caches of the application windows (Chromium/Electron caches, local storage, cookies); no user documents are stored here
~/Library/Logs/WritingAnt Overlay — log folder of the overlay user interface (normally empty)
~/Library/Preferences/com.writingant.app.plist and ~/Library/Preferences/com.oegren-digital.writing-ant-frontend.plist — small preference files (window and overlay position)
macOS Keychain — an entry named "WritingAnt" holding the local encryption key

On Windows:
%APPDATA%\writing-ant and %APPDATA%\writing-ant-overlay — framework caches of the application windows (Chromium/Electron caches, local storage, cookies); no user documents are stored here
%LOCALAPPDATA%\Oden — state of the native overlay user interface (overlay position and dismissed update notifications)
Windows Credential Manager — an entry named "WritingAnt" holding the local encryption key
Registry value HKCU\Software\WritingAnt\InstalledFrom — written only by Microsoft Store installations and removed when the application is uninstalled
On both operating systems the application additionally uses the system's temporary folder for an instance lock file (writing_ant_main.lock) and for short-lived audio buffers during transcription; these temporary files are removed automatically.
Deleting these folders (or uninstalling the application) removes all locally stored data. If the ai_models folder is deleted, the AI models are simply downloaded again on demand.

Keyboard Shortcuts, Mouse Buttons, and Input Monitoring

Optional Keyboard Shortcuts:
If you enable keyboard shortcuts in Settings (for example, to start or stop recordings for writing sessions — including double-press shortcuts, combination shortcuts such as a modifier key plus a letter or punctuation key, and, on Mac, the Globe (fn) key), the application observes keyboard events system-wide, even while you are using other applications. This observation is not limited to the designated shortcut combinations: while any keyboard shortcut is enabled, the application sees which keys are pressed, because combination shortcuts can only be detected that way, and because the application must recognize ordinary commands (for example copy-and-paste shortcuts) so that they never falsely trigger a writing session. Every keyboard event is evaluated in the moment against your configured shortcuts and then discarded: keystrokes are never logged, stored, or transmitted, and the application never reconstructs the text you type. Key presses that match an enabled shortcut are consumed by the application; all other keystrokes pass through to your applications unchanged. While no keyboard shortcut is enabled, this monitoring does not run at all.
Optional Mouse-Button Triggers:
You can optionally assign spare mouse buttons (such as the side or wheel buttons) as triggers for writing sessions. While a mouse-button trigger is assigned, the application listens for presses of the middle and additional (side) mouse buttons, even while you are using other applications. On macOS, ordinary left and right clicks and pointer movement are excluded at the operating-system level and never reach the application; on Windows, the system-provided hook technically routes all mouse events past the application, but anything other than a middle- or side-button press is passed on immediately without being examined. Presses of a button you have assigned are handled by the application instead of being passed to other programs, so that button can no longer trigger its original function while the application is running; presses of spare buttons you have not assigned are received but ignored and passed through unchanged. The application does not record or transmit your mouse activity; button presses are used in the moment, solely to start or stop the action you assigned. While no mouse-button trigger is assigned, this monitoring does not run at all.
Mac Users - Additional Permission Required:
On macOS, the system requires you to grant additional permission in System Settings (Accessibility, or Input Monitoring) to allow the application to detect these triggers. The application will guide you to enable the permission when you first set up a keyboard or mouse-button trigger.
Alternatives to Keyboard and Mouse Triggers:
You can use the application without enabling keyboard shortcuts or mouse-button triggers. Alternative control methods include using voice commands or starting and stopping writing sessions by clicking buttons in the application window.

Application Aware Preset Switching

What it detects:
If you turn on the optional Application Aware feature and configure mappings, the application reads the name of the currently active application and, only for the browser rules you create, the web address of the active browser tab. On Windows this is done via standard Windows APIs and Windows' built-in accessibility interface (UI Automation); on macOS via Apple's system interfaces. This is used solely to apply the language and writing-style preset you chose for that app or website. Page contents and password fields are never read.
Processed locally, never transmitted:
This detection happens entirely on your device. Application names and browser tab addresses are used in the moment to switch your preset and are never stored beyond your own settings, and never transmitted to our servers or any third party.
Optional and off by default:
Application Aware is turned off by default and must be explicitly enabled in Settings, where you configure every mapping yourself. While the feature is off, the application never checks which application or website is active — no such detection runs on your computer at all.

Clipboard-Based Text Processing

Selected Text Capture via Clipboard:
When you use the correct voice command, keyboard shortcut, or another trigger you have configured (such as an assigned mouse button or, on Mac, the Globe (fn) key), the Software will take the text you have selected in an application and automatically copy it to the operating system clipboard. The Software then reads this text from the clipboard and sends it to our cloud services for further processing, such as text enhancement or rewriting.
Similarity to Recording-Based Processing:
This feature works similarly to making a recording to capture text as a basis for further editing. The difference is that instead of recording speech, you select existing text. The same cloud processing, third-party AI services, and data handling practices described elsewhere in this Privacy Policy apply to this clipboard-based text processing.
Automatic Pasting of Processed Result:
After processing, the system will automatically paste the result through your operating system. If the text is still selected in a third-party application, it will be replaced with the processed result. The processed text passes through the operating system clipboard during this operation.
Clipboard Restoration (Processed Locally):
By default, immediately before the Software inserts text for you (for example a dictation result or a processed text), it briefly reads the content currently on your operating system clipboard — which may include text, formatting, or an image you copied earlier — solely in order to put that content back on the clipboard shortly after the insertion. This snapshot is held only temporarily in the application's memory on your device; it is never written to disk, never used for any other purpose, and never transmitted to our servers or to any third party. It is discarded as soon as the restoration has been performed or abandoned. Restoration works on a best-effort basis and may not succeed for every content type (for example, copied files cannot be restored). If you prefer that the most recently inserted result stays on the clipboard so you can paste it again elsewhere, you can turn restoration off in the application settings; in that case the clipboard is not read before insertions.
User Control:
This clipboard-based text processing only occurs when you actively trigger it via the designated voice command, keyboard shortcut, or another trigger you have configured (such as an assigned mouse button). Apart from the insertion-time restoration snapshot described above — which likewise happens only as part of an action you triggered — the Software does not monitor or access your clipboard at any other time.

Local Storage of Audio Recordings and Results

Temporary Audio Storage During Processing:
Transcription is the process of converting speech audio to text out of that speech, which happens locally on the user's computer. In some situations the transcription takes place fully in memory and sometimes a temporary file is stored, depending on which AI model framework is used and if storing a temporary audio file is necessary or not. Audio recordings are stored unencrypted temporary during transcription and are automatically removed by default after the transcription has succeded. You can also choose to store the recordings on disk for longer if you want, as described below.
Optional Local Storage:
You have the option to save the results of text enhancements, speech-to-text conversions / text generation / text enhancements (offline and online requests), and audio recordings locally on your computer. This is an optional feature that you can choose to enable or disable.
Storage Security:
All locally stored files, including audio recordings and processing results, are encrypted using industry-standard encryption algorithm (AES with HMAC authentication) to ensure that this data can only be accessed and decrypted on your specific device. The encryption key is derived locally, and never transmitted or stored on our servers.
User-Controlled Duration:
The duration of local storage is entirely under your control and can be configured in the application settings. You can choose how long to keep files locally and delete them at any time.

Data Storage and Retention for Bookkeeping Purposes

Swiss Legal Requirements:
As a company based in Switzerland, we are required by Swiss law to maintain certain business records for bookkeeping and tax purposes. We store the following data for compliance with these legal obligations:
Data Types Retained for Bookkeeping:
Email address
Subscription tier purchases
Name and billing address information
Potentially VAT ID
Payment method data (payment processor references)
Retention Period:
This bookkeeping data is retained for 10 years from the end of the fiscal year in which the transaction occurred, as required by Swiss commercial and tax law.
Legal Basis:
This data retention is based on our legal obligations under Swiss law, including the Swiss Code of Obligations (CO) and Swiss tax regulations. This constitutes a legitimate interest that overrides individual data deletion requests for this specific category of data during the retention period. We store and potentially share bookkeeping data and invoices with authorities in order to comply with applicable Swiss and EU legal requirements related to financial record-keeping, audit, registrations, and statutory obligations.
Data Security:
All bookkeeping data is stored securely with appropriate technical and organizational measures to prevent unauthorized access, modification, or disclosure. Access is restricted to authorized personnel who require this information for legitimate business purposes.

User Account Data Retention

Account Deletion Process:
When you delete your user account, we retain your account data for up to 30 days after deletion. This grace period allows you to recover your account if the deletion was accidental or if you change your mind.
Subscription Cancellation:
If you cancel your subscription, your account will remain active until the end of your current subscription period. After the subscription period expires, your account will be automatically deleted according to the standard 30-day retention period described above.
Data Recovery:
During the 30-day retention period, you can contact us to recover your account and associated data. After this period expires, your account data will be permanently deleted and cannot be recovered.
Exception for Legal Requirements:
Please note that certain data may be retained longer if required by law, such as the bookkeeping data described in the previous section, which is subject to separate legal retention requirements.

Email & Support Communication Retention

Retention Periods:
We retain customer support-related email communications (error reports, information inquiries, troubleshooting, and non-contractual sales discussions) for up to 3 years after the conclusion of the support interaction. This period allows us to provide ongoing customer service, reference past issues, and ensure quality assurance.
Emails that contain or reference invoices, contracts, billing, or other financial or legal documentation are retained for up to 10 years, in order to comply with applicable Swiss and EU legal requirements related to financial record-keeping, audit, and statutory obligations.
At the end of the respective retention periods, we permanently delete or irreversibly anonymize the emails, unless a longer retention is required by law, or unless you request otherwise and it is legally permissible.

Consent & Agreement Records Retention

Cookie and consent banner acceptance:
We store records of your consent—including timestamp, method, version of consent options, and your browser/session identifier—for up to 12 months. After that, we will request renewal to ensure continued valid and informed consent.
Acceptance of policies and EULA/T&C documents:
When you accept our Privacy Policy, End User License Agreement, Terms of Service, or similar legal documents during signup, we keep a record of the version accepted and date of acceptance for as long as your account remains active, and for an additional 3 months following account deletion related to last day of canceled subscription period. This ensures we can reference these agreements in case of disputes or audit.
At the end of these periods, we delete or irreversibly anonymise records unless continued retention is required by law.

Children's Data Protection

Our services are not directed at children and we do not knowingly collect, use or process personal data from children. If we become aware that we have inadvertently collected personal data from a child without appropriate consent, we will take steps to delete such data as soon as possible. If you are a parent or a guardian and believe that your child has provided us with their personal information without your consent, please contact us at patric@oegren-digital.ch so that we can take appropriate action.

Main Privacy Policy

Below is our main privacy policy
Our Privacy Policy is managed through Iubenda to help ensure compliance with privacy regulations.
Last Updated: 24th August 2026

Swiss Representative

For Swiss Data Protection Matters
Under Article 14 of the FADP, we have appointed a Swiss Representative to act as our data protection agent.
Company Name:
ALTRION Sagl
Phone:
+41 78 229 72 57
Address:
Via Luigi Lavizzari 8
6850 Mendrisio
Switzerland

EU GDPR Representative

For EU Data Protection Matters
If you are located in the European Union and have questions, concerns, or requests regarding your personal data or our data protection practices, you can contact our designated EU GDPR Representative:
Company Name:
Instant EU GDPR Representative Ltd
Representative Name:
Adam Brogden
EU Dublin Address:
INSTANT EU GDPR REPRESENTATIVE LIMITED
Office 2
12A Lower Main Street, Lucan Co.
Dublin K78 X5P8
Ireland
Data Protection Request Portal:
https://oegrendigital.gdprlocal.com/eu
You can submit data protection requests, complaints, or other GDPR-related inquiries through our online portal or by contacting the representative directly.
Our EU representative can assist with Subject Access Requests, Right to Erasure, Data Breach reports, complaints, and other data protection matters under GDPR Article 27.