Privacy Policy
Last updated: 29 August 2026
Who controls your data
The data controller is SIMPLY EXPLAINED LTD (company number 17428320, 167-169 Great Portland Street, London, W1W 5PF), trading as Hello Polska. For data protection questions, contact us at contact@hellopolska.pl.
Our registration with the ICO register (Information Commissioner's Office, the UK's data protection authority) is in progress — the registration number will appear here once it has been issued.
Because Hello Polska is addressed to people living in Poland and across the EU, we apply not only UK law but also RODO (the EU-wide GDPR) to the relevant part of our data processing.
Core principle: data minimisation
Hello Polska is not a document archive. We collect and keep only the data needed to run a specific feature — and only for as long as that requires.
Free portal (articles, search)
Reading articles and using search require no personal data at all. At this stage we do not maintain user accounts.
The paid "Understand a Letter" feature
When you use this feature, we process:
- The photo or PDF of the document you upload — it goes into a secure, temporary, access-restricted file store (not reachable via any public web address).
- The content of the document is sent to Anthropic (the AI provider we use for the analysis). Under Anthropic's standard commercial terms, your data is not used to train their AI models and is not added to any shared knowledge base; on their side, Anthropic automatically deletes it within 30 days.
- The original photo or PDF is automatically deleted from our servers immediately after the analysis finishes (typically within minutes). As a backstop, an automatic cleanup also runs: if deletion doesn't happen right away for any reason (e.g. a technical fault), the file is still deleted within 1 hour at the latest. We never keep copies of your documents.
- We do keep the result of the analysis (the information extracted from the document — e.g. document type, required actions) — this lets you come back to your result and ask one follow-up question. This record contains no original photo/PDF and is automatically deleted 30 days after it's created.
- Payment details (card number etc.) never reach our servers — they are handled directly by Stripe, under the international payment security standard (PCI DSS).
Who we share data with
We use vetted providers who process data on our behalf, only to the extent the service actually requires:
- Stripe — payment processing,
- Anthropic — document content analysis (our AI technology provider),
- Vercel — site hosting and temporary file storage,
- Sanity — storage of the portal's articles (unrelated to your documents).
We do not sell or share your data with third parties for marketing purposes.
Security
All communication with the site is encrypted (HTTPS). Documents are stored in access-restricted, non-public storage. Access keys to our systems are kept securely and never published in the site's code.
Your rights
Because we process data belonging to residents of Poland/the EU, RODO (the EU-wide GDPR) applies, alongside UK GDPR (since the controller is a UK-registered company). You have the right to: access your data, correct it, have it deleted, restrict its processing, port it, and object to its processing. You can also lodge a complaint with the data protection authority where you live — UODO (Urząd Ochrony Danych Osobowych, Poland's data protection authority) — or the Information Commissioner's Office (ICO) in the UK, where the data controller is registered.
Changes to this policy
We may update this policy from time to time, e.g. when we add new features. The date at the top of this page always shows the last update.