Skip to content
Philologica
DiagnosisReportHow it worksPricingFAQ
Log in Start free

Privacy Policy

1) Data Controller

Controller: LATIN FLASH – LDA
VAT/NIF: PT 518 260 151
Address: Rua das Mercês, 41, 9000-224 São Pedro, Funchal – Madeira Island, Portugal
Email: [email protected]
Website: philologica.com

2) Scope and applicable law (EU & Portugal)

This Privacy Policy explains how we process personal data when you use Philologica (the “Platform”). We apply the EU General Data Protection Regulation (GDPR) and the Portuguese data protection framework, including Law No. 58/2019 (GDPR implementation), as well as the rules on privacy in electronic communications (including Law No. 41/2004, as amended) for cookies and similar technologies.

3) What is Philologica?

Philologica is a web application aimed primarily at university students, researchers, writers, and teachers for text and document analysis and editorial assistance (including AI features).

4) Personal data we process

  • Account data: name (optional), email, password hash (if email login), role/tier, authentication tokens, and profile settings.
  • Content data: text, PDFs/DOCX/TXT you submit, prompts/queries, generated outputs, and project metadata you create within the Platform.
  • Usage & technical data: IP address, device/browser info (user-agent), timestamps, error logs, security logs, and token usage counters.
  • Payment data: subscription status, Stripe customer/subscription identifiers, purchase history, and billing metadata (we do not store full card details).
  • Support data: messages you send to support and related correspondence.
  • Local storage: language/theme preferences and (where enabled) cached project state in your browser (LocalStorage).
Important: Please do not upload trade secrets or highly confidential information. Avoid special-category data (e.g., health, political opinions) unless strictly necessary and lawful.

5) Purposes and legal bases

  • Provide and operate the service (create accounts, run analyses, store projects) – contract (GDPR Art. 6(1)(b)).
  • Security, fraud prevention, and abuse protection (rate limiting, logging, incident response) – legitimate interests (Art. 6(1)(f)).
  • Customer support – contract and/or legitimate interests.
  • Payments and subscriptions (billing, reconciliation, accounting) – contract and legal obligation (Art. 6(1)(c)).
  • Product improvement (debugging, performance monitoring) – legitimate interests. Where consent is required (e.g., non-essential cookies), we rely on consent (Art. 6(1)(a)).
  • Legal claims and compliance – legal obligation and/or legitimate interests.

6) Artificial Intelligence (Google Gemini)

To provide AI features, your submitted content (or relevant excerpts) may be transmitted to and processed by Google (Gemini API). Google acts as a processor/subprocessor under contractual safeguards. AI results are indicative and require human review; do not rely on them for legal, medical, or other high-stakes decisions.

7) Payments (Stripe)

Payments are processed by Stripe. We receive confirmation of payment, plan tier, and technical identifiers. We do not store full card numbers; payment data is handled by Stripe under its security standards.

8) Cookies and similar technologies

We use strictly necessary cookies and similar storage technologies to keep you logged in, secure the Platform, and remember preferences. For details, see our Cookie Policy.

9) Recipients and subprocessors

We share personal data only as needed to operate the Platform, including with service providers acting as processors/subprocessors, such as:

  • Hosting and infrastructure providers (e.g., Vercel, Google Cloud Run).
  • AI provider (Google / Gemini).
  • Payments provider (Stripe).
  • Fonts/CDN providers (e.g., Google Fonts) when loaded.

We may update providers over time; where required, we will update this Policy accordingly.

10) International data transfers

Some providers may process data outside the European Economic Area (EEA) (for example in the United States). Where this occurs, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (SCCs) and/or adequacy decisions, plus additional technical and organizational measures where appropriate.

11) Retention and deletion

  • Account & project content: stored while your account is active. You may request deletion of your account and associated content.
  • Local browser storage: you can clear cached project history and preferences using your browser settings and/or the Platform’s “Clear History” feature (if available).
  • Security logs: kept for a limited period necessary for security and diagnostics (typically months).
  • Billing and accounting records: retained for the period required by applicable law (often up to 10 years for tax/accounting documentation in Portugal).

12) Security

We implement appropriate technical and organizational measures to protect personal data, including access controls, least-privilege practices, encrypted transport (HTTPS), and monitoring. No method of transmission or storage is 100% secure; please keep your credentials safe and use strong passwords.

13) Your rights (GDPR)

Depending on your situation, you may have the right to: access, rectification, erasure, restriction, portability, and objection; and to withdraw consent at any time (without affecting prior processing). You also have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects (we do not aim to make such decisions via AI outputs).

To exercise your rights, contact [email protected]. We may need to verify your identity before fulfilling a request.

14) Complaints

You can lodge a complaint with your local data protection authority. In Portugal, the supervisory authority is the CNPD (Comissão Nacional de Proteção de Dados). You may also complain to the authority in your habitual residence or workplace in the EU.

15) Changes

We may update this Policy to reflect legal, technical, or business changes. We will publish the updated version on philologica.com and update the “Last updated” date.

16) Contact

Questions about privacy? Email us at [email protected].

Cloudflare and audience measurement

The website uses Cloudflare for security, delivery and Cloudflare Web Analytics. This audience measurement is cookieless, does not create cross-site profiles and processes limited technical data such as page, referrer, device type and approximate location.

Philologica

Traceable AI-assisted editorial review.

Product

DiagnosisReportHow it worksPricingFAQ

Legal

PrivacyTermsCookiesCookie preferences

Contact

[email protected]Documentation

PHILOLOGICA / ACADEMIC SYSTEMS / 2026

Human review remains essential.