Last updated: February 2026
1. Introduction & Data Controller
BDK Invest sp. z o.o. ("we", "us", or "our") operates ScrollMind, an AI-focused microlearning platform. This Privacy Policy explains how we collect, use, and protect your personal information when you use our service.
Data Controller:
BDK Invest sp. z o.o.
ul. Sybirakow 16, Bialystok, Poland
Contact: biuro.bdkinvest@gmail.com
2. Information We Collect
2.1 Account Information
- Email address and password when you create an account
- Name and profile information from Google when you sign in with Google
- Display name (if you choose to set one)
2.2 Learning Data
- Course progress and last-seen post position
- Bookmarked posts and threads
- Quiz and poll responses
- Course completion records
2.3 AI Tutor Chat Data
- Messages you send to the AI tutor
- AI-generated responses
- Chat metadata such as message count and discussed topics
2.4 Payment Information
- Purchase records (course purchased, amount, currency, timestamp)
- Stripe session and customer identifiers
- Full payment card details are handled directly by Stripe and never stored on our servers
2.5 Waitlist Data
- Email address submitted via waitlist or signup forms
- Submission source and timestamp
2.6 Analytics & Usage Data
- Page views, button clicks, and feature interactions
- Device information, browser type, and IP address (collected automatically by Google Analytics)
- Course engagement events (post impressions, quiz completions, tutor usage)
2.7 Automatically Collected Data
- Scroll position within courses (stored locally on your device and in our database)
- Authentication session tokens
3. How We Use Your Information
We use your information to:
- Provide and operate the ScrollMind platform, including course delivery and progress tracking
- Generate AI tutor responses to your questions using Google Gemini
- Process course purchases via Stripe
- Remember your bookmarks, preferences, and scroll position
- Send service updates and product announcements
- Analyze usage patterns to improve our content and user experience
- Prevent abuse and enforce rate limits
- Comply with legal obligations (e.g., tax record-keeping for purchases)
4. Cookies & Tracking Technologies
- Essential cookies: Used for authentication and session management via Firebase Authentication. Required for the service to function.
- Analytics cookies: Google Analytics 4 (GA4) / Firebase Analytics cookies are used to understand how users interact with the platform. These cookies collect anonymized usage data including page views, interaction events, and device information.
- Local storage: Used to persist your scroll position within courses for a seamless reading experience.
We do not use third-party advertising cookies or sell data to advertisers. You can control cookies through your browser settings, but disabling essential cookies may prevent you from using the service.
5. Third-Party Services
We share data with the following third-party services to operate ScrollMind:
Google Firebase
We use Google Firebase for authentication, database storage, serverless backend functions, web hosting, and analytics. Your account information, learning data, and usage events are processed through Firebase. See Google's Privacy Policy.
Google Gemini AI
The AI tutor feature is powered by Google's Gemini model. When you use the AI tutor, your chat messages and surrounding course content are sent to Google's servers for processing. See Google's Generative AI Terms.
Stripe
We use Stripe to process course purchases. When you make a payment, your payment details (card number, billing address) are handled directly by Stripe. We receive only transaction confirmation data (amount, currency, timestamp). See Stripe's Privacy Policy.
Email Marketing
Waitlist and signup email addresses may be used to send product announcements via an external email marketing service. You can unsubscribe from marketing emails at any time using the unsubscribe link in each email.
6. Data Storage & Security
Your data is stored securely using Google Firebase / Google Cloud infrastructure, which provides enterprise-grade security including encryption at rest and in transit. Access to your personal data is restricted by security rules that ensure only you can read and modify your own data. API keys and secrets are managed through Firebase Secret Manager and are never exposed to client applications. We do not sell your personal information to third parties.
7. Legal Basis for Processing (GDPR)
We process your personal data on the following legal grounds:
- Contract performance (Art. 6(1)(b)): Account management, learning progress tracking, course purchases, AI tutor functionality
- Legitimate interest (Art. 6(1)(f)): Analytics to improve the platform, abuse prevention and rate limiting, service-related communications
- Consent (Art. 6(1)(a)): Marketing communications, analytics cookies
- Legal obligation (Art. 6(1)(c)): Tax and financial record-keeping for purchases
8. Your Rights (GDPR)
If you are located in the European Union, you have the following rights:
- Right to Access (Art. 15): Request a copy of your personal data
- Right to Rectification (Art. 16): Request correction of inaccurate data
- Right to Erasure (Art. 17): Request deletion of your account and all associated data
- Right to Restrict Processing (Art. 18): Request restriction of processing in certain circumstances
- Right to Data Portability (Art. 20): Request your data in a machine-readable format
- Right to Object (Art. 21): Object to processing based on legitimate interest, including analytics
- Right to Withdraw Consent (Art. 7(3)): Withdraw consent at any time where processing is based on consent (e.g., marketing emails)
To exercise any of these rights, use the account deletion feature in Settings or contact us at biuro.bdkinvest@gmail.com.
You also have the right to lodge a complaint with the Polish supervisory authority: Urzad Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.
9. International Data Transfers
Your data may be transferred to and processed in countries outside the European Economic Area, primarily the United States, where Google and Stripe maintain servers. These transfers are protected by EU Standard Contractual Clauses (SCCs) and the data processing agreements maintained by Google and Stripe.
10. AI Tutor & Automated Processing
Our AI tutor feature uses Google's Gemini model to generate educational responses:
- Your chat messages are sent to Google's servers for processing
- Surrounding course content (neighboring posts and concept context) is included to provide relevant answers
- Conversation history within a thread is stored and used for contextual responses
- Usage is limited to 100 messages per day per user
- AI responses are generated automatically and may contain inaccuracies
No automated decision-making or profiling is used that produces legal or similarly significant effects on you.
11. Data Retention
- Account and learning data: Retained as long as your account is active. Permanently deleted within 30 days of account deletion.
- AI tutor messages: Deleted when you delete your account.
- Purchase records: Retained for up to 7 years after the transaction for tax and legal compliance purposes, even after account deletion.
- Waitlist emails: Retained until the waitlist campaign ends or you request removal.
- Analytics data: Retained per Google Analytics default retention settings (user-level data expires after 14 months; aggregated data may be retained indefinitely).
12. Children's Privacy
ScrollMind is not directed at children under 16. We do not knowingly collect personal data from children. If we learn that we have collected data from a child under 16, we will delete it promptly. If you believe a child has provided us with personal data, please contact us.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through an in-app notice, and will update the "Last updated" date at the top of this page.
14. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us:
BDK Invest sp. z o.o.
ul. Sybirakow 16, Bialystok, Poland
Email: biuro.bdkinvest@gmail.com