pod.builders
TermsPrivacyFAQ

Privacy Policy

MB "AI Konsultacijos", Lithuania · Last updated: June 11, 2026

This policy explains what data MB "AI Konsultacijos" ("pod.builders", "we") collects when you use pod.builders, why, and what your rights are. We are the data controller for your account data, and we are based in Lithuania, in the European Union.

1. What we collect

In plain words: Your email and name, the stores and designs you build, basic usage data, and - once you sell - your buyers' shipping details so orders can be fulfilled. Your card number goes to Stripe, never to us.

  • Account data: email address, optional display name, sign-in events.
  • Store and content data: the niches, prompts, designs, listings, prices, and settings created in your stores, and your Etsy shop connection (the OAuth access and refresh tokens Etsy issues when you connect your shop, stored server-side and used only to act on your behalf). You never give us a print-provider API token - production and shipping run through print-provider accounts that we own and manage.
  • Billing data: your subscription status and invoices. Card details are collected and stored by Stripe, not by us.
  • Usage and technical data: logs, IP address, approximate location, device and browser information, used for security, rate limiting, and debugging.
  • Order data:when your products sell, we receive order details from Printify/Etsy, including your buyer's name and shipping address, so fulfillment can be tracked in your dashboard.

2. How we use your data

In plain words: To run Bob, charge your subscription, keep bots out, support you, and improve the product. We do not sell your data and we do not run third-party ads.

  • providing the service - building, running, and publishing your stores;
  • processing subscription payments via Stripe;
  • sending magic sign-in links, store alerts, and service notices via email;
  • security: abuse prevention, rate limiting, captcha (Cloudflare Turnstile), fraud prevention;
  • support, when you contact us;
  • understanding usage and improving the product, including error tracking (Sentry) and aggregate analytics.

Legal bases under GDPR: performance of our contract with you, our legitimate interests (security, product improvement), and legal obligations (tax and accounting records).

3. AI processing

In plain words: Bob's brain runs on third-party AI models. Your prompts, niches, and designs are sent to them to do the work. Per our provider agreements, that data is not used to train their models. Keep personal data out of prompts.

Bob generates research, designs, and listing text using third-party AI model providers (currently Google's Gemini models via API). The content needed for each step - your niche input, prompts, product context, and designs - is transmitted to these providers for processing. Under the API terms we use, this data is not used to train the providers' models.

Please do not include personal data (yours or anyone else's) in niche descriptions, prompts, or feedback to Bob - it is not needed for anything Bob does.

Automated processing notice: Bob makes automated product decisions inside your store (what to design, how to price). These decisions concern your store content, are always reviewable and reversible by you, and have no legal or similarly significant effect on you.

4. Your buyers' data

In plain words: For your Etsy buyers, YOU are the controller - we process their order data on your behalf so fulfillment works. Their questions go to you.

When your products sell, we process limited data about your buyers (name, shipping address, order contents) on your behalf, as a processor, solely for showing and tracking orders and supporting fulfillment. You, the merchant, are the data controller for your buyers; their privacy questions and rights requests should go to you (and to Etsy, under whose terms the sale happened). We process buyer data only as needed to provide the service and never for marketing.

5. Who we share data with

In plain words: Only the processors that make the product work - hosting, payments, AI, email, fulfillment - plus lawyers and authorities when legally required. No data sales, no ad networks.

We share personal data only with:

  • Service providers that run the product: Vercel (hosting), Supabase (database, authentication, storage), Stripe (payments), Google (AI models), Printify (fulfillment), Resend (email delivery), Sentry (error tracking), Cloudflare (bot protection). Each is bound by data-protection obligations.
  • Legal recipients where required: to comply with law or valid requests, enforce our terms, or protect rights, safety, and property.
  • A successor in a merger, acquisition, or asset sale, in which case this policy continues to apply.

We do not sell personal data and we do not share it with advertising networks.

6. International transfers

In plain words: Some of our providers are in the US. Transfers are covered by EU-approved safeguards.

Some service providers process data outside the EEA (notably in the United States). Where they do, transfers rely on the European Commission's adequacy decisions (including the EU-US Data Privacy Framework where the provider is certified) or Standard Contractual Clauses.

7. Retention

In plain words: We keep data while you have an account, then delete or anonymize it - except what tax law makes us keep.

We keep your data while your account exists. If you delete your account or ask us to, we delete or anonymize personal data within a reasonable period, except data we must retain for legal reasons (for example invoices for accounting law) or need to resolve disputes and prevent abuse. Aggregated, non-identifying usage data may be retained.

8. Security

In plain words: Encryption in transit, scoped access, and webhooks that verify signatures. No system is perfect; we act fast when something is wrong.

We use appropriate technical and organizational measures: encrypted connections, access controls, signature-verified payment webhooks, rate limiting, and isolation between users' data. If a breach affecting your data ever occurs, we will notify you and the supervisory authority as required by GDPR.

9. Your rights

In plain words: Access, correct, export, delete, restrict, object - email us and we will do it. EU residents can also complain to a data-protection authority.

Under GDPR (and similar laws elsewhere) you can request access to, correction of, export of, or deletion of your personal data, restrict or object to certain processing, and withdraw consent where processing is based on consent. Email bob@pod.builders from your account email and we will respond within 30 days.

EU/EEA residents may lodge a complaint with their local supervisory authority or with Lithuania's State Data Protection Inspectorate (VDAI). California and other US-state residents: we do not sell or share personal data as defined by those laws; contact us to exercise any applicable rights.

10. Cookies

In plain words: Only what the product needs to work: sign-in session and security. No third-party advertising cookies.

We use strictly necessary cookies and local storage for authentication sessions and security (including Cloudflare Turnstile's bot checks). We do not use third-party advertising cookies. If we ever add optional analytics cookies, we will ask for consent first.

11. Changes and contact

In plain words: If this policy changes materially, we tell you. Questions go to bob@pod.builders.

We will post updates to this policy here and notify you of material changes. Contact: MB "AI Konsultacijos", Lithuania, bob@pod.builders. See also our Terms of Service.

Questions? Email bob@pod.builders - a human answers.
TermsPrivacyFAQbob@pod.builders

The term "Etsy" is a trademark of Etsy, Inc. This application uses the Etsy API but is not endorsed or certified by Etsy, Inc.