Privacy Policy

Translation disclaimer: This English translation is provided for convenience only. The Polish-language version, available at fider.in/polityka-prywatnosci, remains the legally binding text until this translation has been reviewed and approved by qualified legal counsel. In case of any discrepancy between the Polish and English versions, the Polish version prevails.

§ 1. Data Controller

The Data Controller for personal data of fider.in users is:

JWeb Jonasz Walasik

ul. Ignacego Daszyńskiego 11 lok. 43, 95-070 Aleksandrów Łódzki, Poland

NIP: 7282650504 | REGON: 528537910

E-mail: helpdesk@fider.in
Last updated: August 21, 2026

For any matters relating to the processing of personal data, please contact: helpdesk@fider.in. The Data Controller has not appointed a Data Protection Officer (DPO). All data protection inquiries should be directed to the Data Controller at the address above.

§ 2. Definitions

In this Privacy Policy:

  • GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data.
  • Personal data – any information relating to an identified or identifiable natural person.
  • User – a natural person using the Service.
  • Service – the platform available at fider.in.
  • External AI Providers – third-party providers of AI model services to which the Service transmits the User’s content at the User’s request for the purpose of generating, editing, or animating content.
  • EEA – European Economic Area.

§ 3. Scope and Purposes of Processing

3.1. Registration Data and User Account

Purpose: performance of a contract (Art. 6(1)(b) GDPR).

Scope: full name or company name, email address, login credentials (password stored in hashed form).

Retention period: for the duration of the contract (active Account) and for 12 months following Account deletion (legal basis: legitimate interest of the Data Controller – pursuit and defense of claims, which are subject to a limitation period of up to 3 years), after which the data is permanently deleted.

3.2. Billing and Payment Data

Purpose: processing payments, issuing invoices, fulfilling tax and accounting obligations.

Scope: invoice identification data (full name / company name, address, tax identification number), transaction information (amount, date, subscription number).

Legal basis: Art. 6(1)(b) (performance of a contract) and Art. 6(1)(c) GDPR (legal obligation – tax regulations).

Retention period: 5 years from the end of the tax year in which the invoice was issued (obligation under tax regulations).

Important: payment card data is not stored by the Data Controller. Payment processing is handled entirely by a third-party payment operator – Stripe, Inc. – in accordance with its own privacy policy (stripe.com/privacy). The Data Controller receives only transaction and billing information (not card data).

3.3. Multimedia Content (Media Library)

Purpose: providing the Service – storing and making the User’s content available, enabling content creation and publishing.

Scope: photos, graphics, and video files uploaded by the User.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

Retention period: for the duration of the active Account and for 30 days following Account deletion, after which content is permanently and irreversibly deleted from the Data Controller’s servers.

Note: Content uploaded by the User may be transmitted to External AI Providers only at the User’s explicit request, for the purpose of performing AI operations (animation, editing, generation). See § 5 for details.

3.4. Technical Data and Logs

Purpose: ensuring the security and proper functioning of the Service, error diagnostics.

Scope: IP address, browser data, timestamps, activity logs.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest of the Data Controller – system security).

Retention period: up to 12 months.

3.4a. Data used to prevent abuse

Purpose: detecting and investigating abuse, in particular the creation of multiple Accounts by the same person in order to obtain benefits from the referral program, discounts or promotions, as well as handling related complaints.

Scope: the IP address recorded at the moment of Account registration.

Legal basis: Art. 6(1)(f) GDPR (the Controller’s legitimate interest – protection against abuse and assessment of the merits of complaints).

Retention period: for as long as the Account exists; the data is deleted together with the Account.

Access: the Controller only. This data is not shared with affiliates, other Users or any third parties.

3.5. Communications (Complaints, Support)

Purpose: handling complaints and support requests, responding to inquiries.

Scope: email address, content of correspondence.

Legal basis: Art. 6(1)(b) GDPR (complaints – performance of a contract) and Art. 6(1)(f) GDPR (general inquiries – legitimate interest of the Data Controller).

Retention period: for the duration of the subscription and 1 year after its termination.

3.6. Social Media Platform Authentication Tokens (OAuth)

Purpose: enabling the publication of content on Social Media Platforms on behalf of the User.

Scope: OAuth access tokens issued by Social Media Platform operators (Facebook, Instagram, TikTok, YouTube, LinkedIn, Google Business). The Data Controller does not store the User’s passwords for Platform accounts.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract – provision of the publishing feature).

Retention period: for the duration of the active integration and for 30 days following disconnection or Account deletion, after which tokens are permanently deleted.

3.7. Children’s Data

The Service is intended solely for persons aged 18 and over. The Data Controller does not knowingly collect personal data from children under the age of 13. If the Data Controller becomes aware that an Account has been created by a person under the age of 13, the Account and all associated data will be deleted immediately. Parents or legal guardians who believe that their child has submitted personal data to the Service may contact helpdesk@fider.in to request deletion of such data.

§ 4. Recipients of Data

Users’ personal data may be transferred to the following categories of recipients:

  • Payment operator – Stripe, Inc. (USA) – payment processing, invoice issuance. Data transfers to the USA are made on the basis of Standard Contractual Clauses (SCCs) approved by the European Commission or on the basis of an adequacy decision.
  • IT infrastructure providers – entities providing hosting, servers, database systems, and CDN, with whom the Data Controller has concluded data processing agreements.
  • External AI Providers – providers of artificial intelligence services – entities providing visual and textual content generation, editing, and animation services, to which the Service transmits the User’s content exclusively at the User’s request for the purpose of performing the requested AI operations. Data transfers to entities outside the EEA are made on the basis of Standard Contractual Clauses (SCCs) or other mechanisms in accordance with Art. 46 GDPR.
  • Reel rendering tool providers – technical entities involved in the process of generating animated reels.
  • Social Media Platform integration providers – entities providing connectivity between the Service and external platforms (Facebook, Instagram, TikTok, YouTube, LinkedIn, Google Business).
  • Analytics providers – Google Ireland Ltd. (Google Analytics) and Microsoft Ireland Operations Ltd. (Microsoft Clarity – anonymized session recordings and heatmaps used to improve the usability of the Service) – activated only after the User consents to statistics cookies. Transfers outside the EEA are based on Standard Contractual Clauses (SCC) or an adequacy decision.
  • Marketing tool providers – Meta Platforms Ireland Ltd. (Meta Pixel and Conversions API – ad performance measurement) – activated only after the User consents to marketing cookies.
  • E-mail service provider – Sendinblue SAS (Brevo, France) – delivery of transactional e-mails and account notifications.
  • Referral program partners (affiliates) – individuals and entities who referred the Service to a given User – only to the extent necessary to verify and settle the commission due to them, and only in relation to their own referrals. The scope of the disclosed data is described in § 7a. Affiliates are contractually obliged to keep the data they receive confidential and to use it solely for the purpose of settling the cooperation.
  • Public authorities – only where applicable law obliges the Data Controller to disclose data.

The Data Controller does not sell Users’ personal data to third parties for marketing purposes or within the meaning of the CCPA/CPRA (California Consumer Privacy Act / California Privacy Rights Act). The current list of entities processing data on behalf of the Data Controller is available on request at helpdesk@fider.in. The Data Controller enters into data processing agreements with entities processing personal data on its behalf in accordance with Art. 28 GDPR, ensuring an adequate level of protection.

§ 5. Transmission of Content to External AI Providers

1. Fider acts as a technical intermediary (orchestrator) in the process of AI-based content processing. The Service uses external AI systems within the meaning of Regulation (EU) 2024/1689 (the EU AI Act). AI-generated content constitutes suggestions that require human review – detailed liability rules are set out in the Terms of Service.

2. The User’s content (photos, videos) is transmitted to External AI Providers exclusively:

  • at the User’s explicit request (by using the AI features in the Service),
  • for the purpose of performing operations requested by the User (animation, image editing, visual content generation).

3. The Data Controller does not process the content of materials on its own servers. The only technical operation performed locally after receiving the finished file from the External AI Provider’s API is cropping (adjusting aspect ratio to template requirements) – this does not alter the visual content of the material.

4. External AI Providers process transmitted content in accordance with their own terms of service and privacy policies. By using the AI features in the Service, the User accepts that their content will be transmitted to external AI systems. Information about the specific AI providers currently used by the Service is available on request at helpdesk@fider.in.

5. Transfers of content outside the EEA (to providers located outside the European Economic Area, including AI model providers based in the USA) are made on the basis of Standard Contractual Clauses (SCCs) approved by the European Commission or other mechanisms ensuring an adequate level of data protection in accordance with Art. 46 GDPR. Users may obtain information about the specific transfer mechanisms applied by contacting helpdesk@fider.in.

6. By uploading content to the Service and using the AI features, the User represents that they hold all necessary rights and consents with respect to such content, including the right for it to be processed by External AI Providers. The User further represents that such content does not contain the likeness or personal data of children under the age of 13 without the consent of their parents or legal guardians.

§ 6. User Rights

Under the GDPR, Users have the following rights:

  • Right of access – the right to obtain information about what personal data the Data Controller processes.
  • Right to rectification – the right to request correction of inaccurate or completion of incomplete data.
  • Right to erasure – the right to request deletion of data (“right to be forgotten”), subject to exceptions under the GDPR (e.g., the obligation to retain data for tax purposes).
  • Right to restriction of processing – the right to request restriction of processing in certain circumstances.
  • Right to data portability – the right to receive data in a structured, commonly used format.
  • Right to object – the right to object to the processing of data on the basis of the Data Controller’s legitimate interest.
  • Right to withdraw consent – where processing is based on consent, the User may withdraw it at any time without affecting the lawfulness of processing prior to withdrawal.

Requests regarding the above rights should be submitted to: helpdesk@fider.in.

The Data Controller responds to requests within 30 days. For complex requests, this period may be extended by a further 60 days – the User will be informed of any such extension.

The User has the right to lodge a complaint with the supervisory authority – the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland.

§ 7. Cookies and Tracking Technologies

1. The Service uses cookies and similar technologies (including localStorage) in the following categories:

  • Necessary – ensuring the proper operation of the Service: User login and session, security, remembering the selected language, handling payments via Stripe. Basis: technical necessity / legitimate interest. No consent required.
  • Preferences – remembering display settings selected by the User. Activated only after consent is given; withholding consent in this category does not restrict access to any function of the Service.
  • Statistics – Google Analytics (Google) and Microsoft Clarity (Microsoft; anonymized session recordings and heatmaps used to improve the usability of the Service). Activated only after consent is given.
  • Marketing – Meta Pixel (ad performance measurement) and the referral program cookie fider_aff together with an auxiliary localStorage entry (remembering the referral code after clicking a referral link; stored for up to 90 days). Activated only after consent is given.

2. The User grants consent to preference, statistics and marketing cookies via the banner displayed on the first visit. The decision itself is stored in the cookies fider_preferences_consent, fider_statistics_consent and fider_marketing_consent, retained for 365 days. Consent can be changed or withdrawn at any time using the “Manage consent” button visible in the corner of the page. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

3. The User may also manage cookies through browser settings. Disabling necessary cookies may prevent the use of the Service.

§ 7a. Referral Program (Affiliation)

1. The Service operates a referral program in which partners (affiliates) share referral links and codes, and the Controller measures the effectiveness of referrals and settles accounts with affiliates.

2. The following data is processed within the program:

  • the referral code entered or pre-filled at registration – stored on the User’s account (assignment of the account to an affiliate),
  • the fider_aff cookie and an auxiliary localStorage entry – remembering the referral code after clicking a referral link, stored for up to 90 days, saved only after the User consents to marketing cookies (without consent, attribution relies solely on the URL parameter and the referral code field in the registration form, which does not require storing data on the device),
  • settlement events – the fact of registering via a referral, the fact and amount of the first payment and subscription renewals (amount, currency, plan), linked to the User’s account,
  • aggregated referral link click counters – without the IP address in permanent storage; only an irreversible technical hash is used for short-term duplicate detection.

3. Purposes and legal bases: measuring the effectiveness of the referral program and settlements with affiliates – Art. 6(1)(b) and (f) GDPR; cookies and localStorage – the User’s prior consent (Art. 5(3) of the ePrivacy Directive).

4. Assignment to an affiliate follows the last-click rule and is fixed on the account at the moment of registration. Until the first payment, the User may change the assignment by entering a discount code linked to another affiliate at checkout; after the first payment the assignment no longer changes.

5. Providing a referral code is voluntary and does not affect the terms of use of the Service or its price (except for a discount resulting from a discount code used).

6. The affiliate uses a partner panel showing only their own referrals. The scope of data disclosed to the affiliate about a referred person covers: the e-mail address in a shortened and masked form, stripped of both the user name and the domain name (only the first letter of each and the domain ending remain, e.g. “j***@e***.com”), the Account creation date, the name of the purchased plan, the number and dates of paid billing periods, and the payment amounts forming the basis for calculating the commission. The affiliate does not receive: the full e-mail address, first and last name or company name, billing data, IP address, content created in the Service, or contact details. The panel does not allow the affiliate to contact the referred person.

7. The basis for disclosing the data referred to in paragraph 6 is Art. 6(1)(f) GDPR – the legitimate interest of the Controller and the affiliate in enabling verification of the correctness of the calculated commission and in preventing abuse. The affiliate is contractually obliged to keep this data confidential and to use it solely for the purpose of settling the cooperation. The User has the right to object to this processing on the terms described in § 6; if the objection is upheld, the User’s data ceases to be presented in the partner panel.

8. Deleting the User’s Account permanently removes identifying data, including ceasing to present that Account in the partner panel. Settlement events are anonymized (stripped of any link to the person) and retained solely for accounting and settlement purposes for the period required by accounting regulations (up to 5 years); after anonymization they no longer constitute personal data.

9. The User may at any time request information on whether and with which code their Account was referred, as well as what data is presented to the affiliate in that connection, by contacting the Controller.

§ 8. Data Security

1. The Data Controller applies technical and organizational measures to protect personal data appropriate to the risk, including:

  • encryption of data transmission (HTTPS/TLS protocol),
  • passwords stored in hashed form (hashing),
  • access controls for systems processing personal data,
  • regular data backups.

2. Payment card data is not stored by the Data Controller – payment processing is handled entirely by Stripe, Inc.

3. In the event of a personal data breach that may result in a risk to the rights and freedoms of natural persons, the Data Controller will notify the President of the UODO within 72 hours and, where the risk is high, will also notify affected Users.

§ 9. Social Media Platform Integrations

1. Using integrations with Social Media Platforms (Facebook, Instagram, TikTok, YouTube, LinkedIn, Google Business) requires logging in to those platforms outside the Service and granting the relevant permissions.

2. The Data Controller does not store the User’s passwords for Social Media Platform accounts.

3. Data transmitted to Social Media Platforms (content published via the Service) is subject to the privacy policies of those platforms. The Data Controller is not responsible for the manner in which Social Media Platform operators process such data.

4. Users may disconnect a Social Media Platform integration at any time in the Service Settings.

§ 10. Changes to This Privacy Policy

1. The Data Controller reserves the right to amend this Privacy Policy.

2. Users will be notified of any material changes by email at least 14 days in advance.

3. The current version of this Privacy Policy is always available at fider.in/en/privacy.

4. The date of the last update is indicated at the top of this document.

§ 11. Rights of US Users

1. This section applies primarily to residents of the state of California (USA) using the Service within the meaning of the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA). Similar rights may also apply to residents of other US states with their own privacy laws (including Virginia, Colorado, Connecticut, and Texas).

2. California residents have the right to:

  • obtain information about the categories and specific personal data collected by the Data Controller,
  • request deletion of personal data, subject to exceptions provided by law,
  • request correction of inaccurate personal data,
  • opt out of the sale or sharing of personal data with third parties (the Data Controller does not sell users’ personal data).

3. The Data Controller does not sell Users’ personal data within the meaning of the CCPA/CPRA. Data transmitted to External AI Providers and to the payment operator (Stripe) constitutes the provision of services necessary for the operation of the Service, not a sale of data.

4. Requests regarding rights under the CCPA/CPRA should be submitted to: helpdesk@fider.in, with the subject line “CCPA Request”. The Data Controller will respond within 45 days, with the possibility of a further 45-day extension in justified cases.

5. The Data Controller does not discriminate against Users who exercise their rights under the CCPA/CPRA.

§ 12. Final Provisions

1. This Privacy Policy enters into force on March 20, 2026.

2. Matters not covered by this Privacy Policy are governed by the GDPR and applicable Polish law.

3. The binding language for the interpretation of this Privacy Policy is Polish.