Loading
Legal
What Polaisar collects, why it is allowed to hold it, who processes it, and how you get it back or have it deleted.
Last updated 4 September 2026
Polaisar is a guided meditation and self-reflection app. It is run by Arkadiusz Sobol, a sole trader based in the United Kingdom, trading as Polaisar. Arkadiusz Sobol is the data controller for the personal data described in this policy. In this policy we and us mean the same. You can reach us at any time at polaisar@proton.me.
Polaisar is operated from the United Kingdom, so this policy follows the UK General Data Protection Regulation and the Data Protection Act 2018. If you use Polaisar from the European Union, the equivalent EU GDPR rights apply to you in the same way.
We keep the amount of data as small as the app allows. There is no advertising, no tracking across other websites, and no selling of anything to anyone.
For your account, your journal and your progress the lawful basis is performance of a contract. Without this data the app cannot do the thing you signed up for.
For security records and fault diagnosis the lawful basis is our legitimate interest in keeping the service working and protected against abuse.
If we ever send optional emails beyond the ones needed to run your account, we will ask for your consent first and you will be able to withdraw it in one click.
We use a small number of providers, and each of them acts only on our instructions.
Every table in the database has row level security switched on. In plain terms the database itself refuses to return a row unless the request comes from the account that owns it, so one user cannot read another user journal even if something in the application were to go wrong.
Passwords are stored only as a hash, which means we cannot read them and cannot tell you what your password is. Traffic between your device and our servers is encrypted.
Your account data and your journal stay for as long as your account exists. When you ask us to delete your account, the account and everything attached to it are removed from the live database, and any residual copy inside routine provider backups falls away within thirty days.
Technical security records are kept for a short period only, normally no longer than ninety days.
Under UK GDPR you have the rights listed below. Write to polaisar@proton.me and we will act within one month, which is the statutory deadline.
Polaisar sets only the cookies needed to keep you signed in. They are strictly necessary, so no consent banner is required for them. There are no advertising or analytics cookies. If that ever changes we will ask you first.
Polaisar is not intended for children under sixteen. If you believe a child has created an account, write to us and we will remove it.
If we change anything meaningful we will update the date at the top of this page and, where the change affects how your data is used, tell you by email before it takes effect.