Effective from: 21 August 2026
Struxy is a personal AI and life-administration service designed to help you capture, organise, remember and act on information that matters to you.
This Privacy Policy explains how personal data is handled when you visit struxy.app, request or purchase beta access, create or use a Struxy workspace, communicate with us, or use related Struxy services.
1. Who is responsible for your data?
Struxy is operated by Kushagra Mittal, sole trader operating Struxy, of Dublin, Ireland (“Struxy”, “we”, “us”, “our”).
For data-protection purposes, we are generally the controller of personal data processed in connection with the Struxy service.
Privacy questions and data-rights requests: privacy@struxy.app
General support: support@struxy.app
If you are in the European Economic Area, you may also have the right to complain to your local data-protection authority. Where Ireland is our lead supervisory jurisdiction, the relevant authority is the Irish Data Protection Commission.
2. What data we process
2.1 Account and identity data
We may process your name or display name, email address, account identifiers, email verification and one-time-code status, account creation and sign-in timestamps, terms-acceptance version and timestamp, and beta entitlement or access status.
We use email-based authentication. We do not ask you to create a Struxy password where passwordless authentication is enabled.
2.2 User Content
“User Content” means information you intentionally provide to Struxy or create through the service.
This may include:
- text or voice captures and the transcription or text derived from them;
- tasks, reminders and follow-ups;
- information about people, projects, places, plans and commitments;
- notes, source snippets and conversation context;
- relationships between items in your Struxy workspace;
- corrections, approvals, dismissals and other feedback you give to Struxy;
- information you choose to provide when asking Struxy a question.
Struxy is designed around personal context. User Content may therefore contain information about you or other people.
You should only provide information that you are entitled to provide and should avoid entering highly sensitive information unless you are comfortable with it being processed as described in this Policy.
2.3 AI-derived and organisational data
To organise User Content, Struxy may create or store evidence/source mappings, proposed structured items, suggested links, confidence/provenance metadata, model outputs used to create reviewable proposals, and error/retry/inference metadata.
AI-generated proposals may be incorrect. Struxy is designed to distinguish source material, inferred information and user-approved information where the product supports that distinction.
2.4 Device and local-storage data
Depending on the platform and feature, Struxy may store information locally on your device, including local application databases, preferences, authentication/session state, secure tokens, temporary checkout state and consent preferences.
Some Struxy features may operate locally while others rely on cloud processing or synchronisation. The product interface should indicate material differences where relevant.
2.5 Technical, security and diagnostic data
When you access Struxy, our infrastructure may process IP address, browser, operating system and device type, application version, request timestamps, network/server logs, security and abuse-detection information, and crash/failure/performance information.
We use this information to operate, secure, troubleshoot and protect the service.
2.6 Analytics data
If you give consent to non-essential analytics, we may use PostHog to understand how Struxy is used.
Analytics data may include anonymous or pseudonymous analytics identifiers, page views and navigation events, feature exposure and interaction events, device/platform information, approximate geographic or timezone information supplied by the analytics service, referral/campaign attribution, and product performance/conversion events.
We do not intentionally send the text of your personal captures, payment-card details, or your Struxy password to PostHog.
Analytics is optional. You may refuse or withdraw analytics consent without losing access to the core service.
2.7 Acquisition and beta-access data
When you request or purchase beta access, we may process first name, email address, landing page, referring page/domain, campaign parameters such as UTM values, advertising click identifiers if present in the incoming link, time of first interaction, and checkout-attempt/entitlement status.
We use this information to understand where genuine interest in Struxy comes from, administer beta access and prevent checkout abuse.
Where non-essential device storage is used for attribution or analytics, we request consent as required. Attribution information supplied as part of a beta-access form may also be recorded when you submit that form.
2.8 Payment and transaction data
Payments for Founding Beta access are currently handled by Dodo Payments, which acts as Merchant of Record and legal reseller for the transaction.
Dodo Payments may collect payment-card, billing, tax, fraud-prevention and other transaction information directly from you under its own terms and privacy policy.
Struxy does not need to receive your full payment-card number. We may receive or store purchaser email, checkout/payment identifiers, customer identifier, amount/currency, payment/refund/entitlement status, and limited transaction metadata needed to provide or revoke access.
2.9 Communications, support and feedback
If you contact us, join a feedback community, participate in research, or send us feedback, we may process your contact information and the content of those communications.
If you choose to join a third-party community such as Slack, that provider will also process information under its own terms and privacy practices.
2.10 Marketing preferences
If you separately opt in to Struxy marketing, we may store your name, email, consent status, date/source/wording version of the consent you gave, and unsubscribe or objection status.
We do not treat a beta-access request that did not result in a purchase as permission to send promotional email.
Transactional messages about an access request, payment, authentication, security issue or account are not the same as marketing messages.
3. Why we process your data and our lawful bases
Where the GDPR applies, we rely on one or more of the following lawful bases.
Contract and steps before entering a contract
We process data when necessary to create and operate your account, provide Struxy features you request, process and organise User Content, provide cloud synchronisation and AI-assisted functionality, administer beta access and entitlements, and provide customer support related to the service.
Legitimate interests
We may process data where necessary for legitimate interests such as keeping Struxy secure, preventing fraud/abuse, diagnosing failures, maintaining reliable service infrastructure, understanding aggregated product reliability, and establishing/exercising/defending legal claims.
We do not rely on legitimate interests where your rights and interests override ours.
Consent
We rely on consent where required, including for non-essential cookies/local storage or similar tracking technologies, optional analytics, promotional email where affirmative consent is required, and other optional processing for which we specifically ask for consent.
You may withdraw consent at any time. Withdrawal does not affect processing already carried out lawfully before withdrawal.
Legal obligations
We may process information where necessary to comply with applicable laws, lawful regulatory requests, accounting requirements, fraud-prevention obligations, court orders or other legal duties.
4. Sensitive information
Struxy is a general personal-productivity and context service. It is not currently intended to be a system for storing regulated medical records, legal files, financial-account credentials, government identity documents or other highly sensitive records.
Because users may write naturally about their lives, User Content could nevertheless reveal sensitive information.
During the public beta, you should not intentionally submit special-category or highly sensitive personal data unless Struxy has expressly introduced a feature designed to handle that category of data and provided any additional notice or consent mechanism required by law.
Do not submit passwords or authentication secrets, full payment-card data, private cryptographic keys, government identity-document images, information you are legally prohibited from disclosing, or another person’s highly sensitive information without an appropriate basis for doing so.
5. How AI processing works
Struxy uses AI to interpret and organise some User Content.
For relevant AI features, Struxy may send the capture or query you submitted, a limited amount of relevant Struxy context, and system instructions necessary to perform the task to our AI inference provider.
Our current primary inference provider is TensorX Ltd, an Irish AI-inference provider. TensorX states that prompts and completions are processed using zero-data-retention infrastructure, are not stored as inference content, and are not used to train models.
Struxy may store its own copy of your original User Content and may store resulting proposals, structured outputs and audit information in order to provide the Service. TensorX’s zero-retention policy does not mean Struxy itself deletes information you asked Struxy to remember.
See our AI Transparency Notice and Third-Party Services page for more detail.
6. Who receives personal data?
Depending on the feature, recipients may include:
- Supabase — authentication, database, backend and edge-function infrastructure;
- TensorX Ltd — AI inference;
- PostHog — optional product analytics where you consent;
- Cloudflare — hosting, delivery, network security and related infrastructure where deployed;
- Dodo Payments — Merchant of Record, reseller and payment/transaction provider;
- professional advisers, insurers, auditors or authorities where reasonably necessary and lawful.
A more detailed and updateable list is available on our Third-Party Services page.
We do not sell your personal data. We do not use the contents of your personal Struxy workspace for third-party advertising.
7. International data transfers
We aim to use European infrastructure for core personal-data processing where practical. Our Supabase project and current TensorX inference arrangement use European infrastructure, and our PostHog integration is configured to use PostHog’s EU service endpoint.
Some providers may operate globally or use companies outside the EEA.
Where the GDPR applies and personal data is transferred outside the EEA to a country without an applicable adequacy decision, we require an appropriate transfer mechanism where required, such as the European Commission’s Standard Contractual Clauses, together with supplementary safeguards where appropriate.
Provider locations and roles may change as Struxy develops. Material changes will be reflected in this Policy or our Third-Party Services page.
8. How long we keep data
Our current intended retention approach is:
- Account data: while your account is active and for a limited period afterwards where needed for account closure, security or legal obligations.
- User Content: while your account is active, unless you delete the content sooner. Following a verified account-deletion request, we aim to remove User Content from primary systems within 30 days.
- Backups: deleted information may remain in encrypted or access-restricted backups for up to 90 days before normal backup expiry, unless longer retention is legally required.
- Incomplete beta/waitlist records: normally no longer than 12 months after your last meaningful interaction unless you become a user, ask us to retain the request, or another lawful reason applies.
- Payment, refund and entitlement records: up to 6 years where reasonably required for accounting, fraud, dispute, contractual or legal purposes.
- Security and operational logs: ordinarily up to 12 months, and often substantially less, unless needed to investigate a security incident or legal claim.
- Analytics data: 12 months when analytics is enabled and you have consented.
- Marketing consent/objection records: for as long as reasonably necessary to honour and demonstrate your preference, including after you unsubscribe.
We may anonymise information so it can no longer reasonably be linked to you. Properly anonymised information may be retained for product, security or statistical purposes.
9. Security
We use technical and organisational measures intended to protect personal data, including encrypted network transport, access controls, server-side secrets management, owner-scoped data controls where applicable, separation of payment-card handling from the Struxy application, secure token storage, restricted administrative access, and logging/audit mechanisms for sensitive backend operations.
No internet or software service can guarantee absolute security.
If you believe your Struxy account or data may have been compromised, contact security@struxy.app or support@struxy.app.
10. Your rights
Depending on where you live, you may have rights over your personal data.
Where the GDPR applies, these may include the right to access your personal data, correct inaccurate data, request deletion, restrict processing, receive certain data in a portable format, object to certain processing, object at any time to direct marketing, withdraw consent where processing is based on consent, and complain to a data-protection authority.
Some rights are subject to legal conditions and exceptions.
To exercise a right, email privacy@struxy.app. We may need to verify your identity before fulfilling a request.
11. Account deletion and data export
You may request deletion of your Struxy account and associated User Content by contacting privacy@struxy.app or through any in-product deletion control we make available.
We may retain limited information where required for fraud prevention, payment/refund disputes, tax/accounting records, security incidents, enforcement of legal rights, or compliance with law.
Where technically supported, we intend to provide export tools for user-controlled Struxy data. Export functionality may be limited during beta.
12. Children
Struxy’s public beta is intended for adults aged 18 or over.
Do not create a Struxy account if you are under 18.
If we learn that an under-18 user has created an account, we may suspend or delete the account and associated data, subject to applicable law.
13. Automated decisions
Struxy uses AI and automated systems to organise information, rank context and make suggestions.
Struxy’s beta is not intended to make legal or similarly significant decisions about you without human involvement.
AI-generated proposals may affect how information is displayed or suggested inside your workspace, but you remain able to review, reject or correct relevant proposals where the product provides those controls.
14. Changes to this Policy
We may update this Policy as Struxy changes.
If a change materially affects how we process personal data, we will take reasonable steps to bring the change to your attention, such as through the app, website or email.
15. Contact
Privacy: privacy@struxy.app
Support: support@struxy.app
Security: security@struxy.app
Legal operator:
Kushagra Mittal
Dublin, Ireland
Revision history
Every substantive update to this document is listed here, newest first. The current version is dated 21 August 2026.
- 21 August 2026Current versionFirst published version for the Founding Beta.
- Set out the controller details, contact addresses and Irish supervisory authority.
- Described the categories of personal context processed and the legal bases for each.
- Documented retention periods, sub-processors and your data-subject rights.

