Privacy Policy
Last updated: 22 July 2026
1. Data controller
- Anastasia Zhukova
- c/ de la Safor, 12/95, 46015 Valencia, España
- stasya.spain@gmail.com
- +34 642 16 06 64
This policy applies to the azhukova.com website and to the personal account.
2. What data we process
- account data: email address, name, password in hashed form;
- questionnaire and profile: sex, age, height, weight, goals, lifestyle, eating habits;
- health data: allergies and intolerances, chronic conditions, medication, well-being;
- measurements and progress;
- food diary and plans;
- conversations with the AI assistant;
- subscription status and payment history;
- technical data: session cookie, IP address, security logs.
Health data is a special category of personal data under Article 9 GDPR. We process it only with your explicit consent, which you give when filling in the questionnaire and may withdraw at any time.
Card details are processed and stored by Stripe; we never see them.
3. Purposes and legal bases
- providing the service and the personal account — performance of a contract, Article 6(1)(b) GDPR;
- personal calculations and recommendations based on health data — explicit consent, Article 9(2)(a) GDPR;
- email newsletters — consent; you can unsubscribe in one click in every message;
- security and prevention of abuse — legitimate interest, Article 6(1)(f) GDPR;
- accounting and tax duties — legal obligation.
4. Artificial intelligence
For personal recommendations, selected questionnaire data and your messages are transferred to the artificial intelligence provider (OpenAI) to the extent necessary to produce an answer.
Answers are generated automatically. The service does not take decisions that significantly affect you without your involvement.
5. Who we share data with
We engage the following processors:
- Stripe — payments;
- OpenAI — artificial intelligence features;
- Hetzner — hosting, EU;
- Resend — email delivery.
Data processing agreements are in place with all processors. Transfers outside the EEA are safeguarded by the EU standard contractual clauses (SCC). Data is not sold.
6. Retention periods
Data is kept while the account is active. After the account is deleted the data is erased; backups are kept for up to 14 days.
Payment records are kept for the periods required by tax law.
7. Your rights
Under the GDPR you have the right to:
- access your data;
- rectification of data;
- erasure of data;
- restriction of processing;
- data portability;
- object to processing;
- withdraw consent at any time — withdrawal does not affect the lawfulness of processing carried out before it was received.
Send requests to stasya.spain@gmail.com; we will reply within one month.
You also have the right to lodge a complaint with the Spanish supervisory authority — Agencia Española de Protección de Datos, AEPD (www.aepd.es).
8. Account deletion
The account is deleted upon request sent to stasya.spain@gmail.com from the email address of the account.
Self-service deletion will appear in the personal account in due course.
9. Cookies
We use only strictly necessary cookies: the login session and the locale preference.
There are no advertising or third-party analytics cookies. Should any appear, this policy will be updated and consent will be requested.
10. Security
We apply the following protective measures:
- encryption in transit (TLS);
- password hashing;
- access segregation;
- logging of administrative actions;
- backups.
11. Children
The service is intended for persons aged 18 and over. We do not knowingly process children’s data.
12. Updates to this policy
The current version of the policy is always on this page; the date of the last update is stated in the document header.
We will notify you of material changes.
