Improvy OÜ logo
Improvy OÜ logo Improvy OÜ
  • About
  • Careers
    • Terms of Service
    • Refund Policy
  • Privacy
  • Contact

Privacy Policy

Improvy OÜ

Effective date: 29 June 2026

This policy explains how Improvy OÜ ("Improvy", "we", "us") handles personal data when you use improvy.io, Fullyst, Saylify, InoVPN, and related websites, apps, bots, and support channels (the "Services").

We do not sell personal data. We do not use third-party advertising trackers, and we do not allow vendors to use your data for their own advertising.

Who we are

  • Controller: Improvy OÜ, Harju maakond, Tallinn, Kesklinna linnaosa, Tornimäe tn 5, 10145, Estonia
  • Registry code: 16377480
  • Privacy contact: [email protected]

What we collect

The exact data depends on which Service you use and what you choose to send us.

Data you provide

  • Account and contact details: name, email address, usernames, billing identifiers, profile details, and support messages.
  • User content: messages, files, audio, transcripts, summaries, moderation rules, VPN configuration requests, and other content you submit or ask a Service to process.
  • Payment and subscription details: payment status, plan, invoices, transaction references, and refund or dispute information. Card details are handled by payment providers, not stored by Improvy.

Data collected automatically

  • Technical and security data: IP address, timestamps, browser or device information, request URLs, error data, and logs needed to keep the Services secure and reliable.
  • Product usage data: feature events, service status, moderation actions, transcript processing status, VPN capacity and abuse-prevention signals, and aggregate analytics.
  • Platform data: identifiers and metadata received through platforms you connect to the Services, such as Telegram account IDs, usernames, group or channel IDs, message IDs, or bot interaction data.

Product-specific notes

  • Improvy websites: we process contact form details, Cloudflare Turnstile challenge results, and basic request logs so we can answer messages and prevent spam.
  • Fullyst: we process Telegram chat data, moderation settings, flagged content, voice messages, transcripts, analytics, and admin actions to provide moderation, transcription, and community health features.
  • Saylify: we process audio, transcripts, summaries, topics, action items, account data, and app telemetry to provide transcription, summarization, search, and support features.
  • InoVPN: we process contact or Telegram details, WireGuard public keys, configuration details, and limited operational data needed to issue access, maintain service availability, prevent abuse, and protect the network. We do not use VPN activity data for ads or profiling.

Sensitive data

We do not ask for special-category data such as health information, political opinions, religious beliefs, or biometric data. If you include sensitive information in content you submit, we process it only as needed to provide the feature you requested. Please avoid sending sensitive information unless it is necessary.

Why we process data and legal bases

For people in the European Economic Area and other GDPR-covered locations, we rely on these legal bases:

  • Provide the Services: create accounts, deliver product features, process user content, manage subscriptions, and provide support. Legal basis: contract, GDPR Art. 6(1)(b).
  • Security, reliability, and abuse prevention: protect accounts, detect spam or fraud, troubleshoot errors, keep logs, and maintain infrastructure. Legal basis: legitimate interests, Art. 6(1)(f); legal obligation where required, Art. 6(1)(c).
  • Communication: send transactional messages, security notices, service updates, and replies to your requests. Legal basis: contract, Art. 6(1)(b); legitimate interests, Art. 6(1)(f).
  • Analytics and improvement: understand aggregate usage, product reliability, and feature performance using privacy-respecting analytics. Legal basis: legitimate interests, Art. 6(1)(f), unless consent is legally required.
  • Compliance and enforcement: meet tax, accounting, consumer, regulatory, and legal duties; enforce our terms; and respond to lawful requests. Legal basis: legal obligation, Art. 6(1)(c); legitimate interests, Art. 6(1)(f).
  • Optional programs or marketing: newsletters, beta programs, testimonials, or other optional communications. Legal basis: consent, Art. 6(1)(a), which you can withdraw at any time.

We do not make automated decisions that produce legal or similarly significant effects about you. AI-assisted features may generate transcripts, summaries, labels, moderation suggestions, or other outputs, but important decisions should be reviewed by a person where the context requires it.

Cookies, analytics, and similar technology

We use essential cookies, local storage, SDKs, or similar technology only where needed for security, sessions, preferences, forms, and service operation.

We run a self-hosted Plausible analytics instance at stats.ioy.one, controlled by Improvy OÜ, to measure aggregate website usage without advertising profiles. We also configure this website so the analytics script is not loaded when your browser sends Global Privacy Control or Do Not Track signals.

Some embedded or remote resources are loaded from providers such as Google Fonts, Font Awesome, Cloudflare Turnstile, Telegram, and payment or communication platforms when you use the related feature. These providers may receive technical data needed to deliver their services.

Who receives data

We share personal data only when needed for the purposes described in this policy:

  • Infrastructure and hosting providers: to host websites, apps, databases, storage, logs, and networks.
  • Security and anti-abuse providers: including Cloudflare Turnstile for form protection and related security checks.
  • Email and support providers: including Mailgun for sending or receiving support and transactional messages.
  • Product and platform integrations: such as Telegram, AI/transcription providers, payment processors, app stores, and other services you connect or choose to use.
  • Professional, legal, and compliance advisers: where needed for accounting, legal claims, audits, or regulatory duties.
  • Authorities or third parties when required: if we reasonably believe disclosure is required by law, necessary to protect people, or needed to protect our rights, security, or Services.

Where a provider acts as our processor, we require it to process data only on our instructions and under appropriate contractual protections. We do not share personal data with third parties for their independent advertising or profiling.

International transfers

We are based in Estonia. Some providers or connected platforms may process data outside the European Economic Area. Where required, we use appropriate safeguards such as EU Standard Contractual Clauses, adequacy decisions, and technical or organizational measures. We can provide more information about relevant transfer safeguards on request.

Retention

We keep personal data only for as long as needed for the purposes described above, unless a longer period is required by law or needed to resolve disputes, prevent abuse, or enforce agreements. Typical retention criteria include:

  • Account and subscription data: kept while your account or subscription is active, then deleted or anonymized after closure unless we must keep limited records.
  • User content: kept while needed to provide the feature or until you delete it, close the account, or request deletion, subject to backups and legal limits.
  • Support correspondence: kept long enough to handle the request, preserve context, and protect against repeated abuse.
  • Security and system logs: kept for limited periods appropriate to investigation, reliability, and security needs.
  • Accounting and legal records: kept for the periods required by tax, accounting, consumer, and company law.

When data is no longer needed, we delete it, anonymize it, or isolate it from routine use until deletion is possible.

Your rights

Subject to applicable law, you can ask us to:

  • Confirm whether we process your personal data and provide a copy.
  • Correct inaccurate or incomplete data.
  • Delete your data.
  • Restrict or object to certain processing, especially where we rely on legitimate interests.
  • Provide data you gave us in a portable, machine-readable format.
  • Withdraw consent where processing is based on consent.

To use your rights, email [email protected]. We usually respond within one month. If a request is complex or numerous, we may extend the response period where the law allows and will explain why. We may ask for limited information to verify your identity when necessary.

You can also complain to your local data protection authority or the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon): aki.ee/en.

Security

We use appropriate technical and organizational measures, including encryption in transit, access controls, role-based permissions, monitoring, backups, and limited logging. No service can be perfectly secure, but we work to prevent incidents and respond responsibly if they occur.

Children

Our Services are not directed to children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided personal data to us, contact [email protected] and we will take appropriate steps to delete it.

Changes to this policy

We may update this policy when our Services, providers, or legal obligations change. If changes are material, we will notify you in a clear way, such as by posting an update on the website or sending an in-product or email notice where appropriate.

Contact

Questions or requests about privacy?

Improvy OÜ — Harju maakond, Tallinn, Kesklinna linnaosa, Tornimäe tn 5, 10145, Estonia (registry code 16377480)

[email protected]

  • Fullyst
  • InoVPN
  • Saylify