Privacy Policy
resolvenengine — publication draft, prepared 13 September 2026 Effective date: [PUBLISH-01: insert actual publication date]
Owner review required: resolve the publication markers and the provider/retention schedule before publishing. This notice describes the reviewed extension architecture; it does not certify the live deployment.
1. Who is responsible
The operator of resolvenengine is Szegi Roland Attila E.V., a Hungarian sole proprietor, registered at 5000 Szolnok, Városmajor út 59/B, B épület, 2. emelet 24., Hungary. Sole proprietor registration number: 61835722. Tax number: 91754804-1-36. Contact: hello@dropsite.hu, +36 30 798 2618.
We are the controller for website administration, account management, subscription access, support and security. When a business customer instructs us to process personal data in its connected services or conversations, we act as its processor to the extent described in our Business Data Processing Agreement. The customer remains responsible for its instructions and the legal basis for that processing. Providers may have their own controller responsibilities; using our service does not make every provider our processor for every purpose.
2. What the service does
resolvenengine is an AI browser assistant delivered through a Chrome extension and supporting server services. You can ask it to work with a web page or an authorised connector. Google sign-in identifies your resolvenengine account; it does not itself authorise reading your Gmail, Drive or Calendar. Connecting a service is a separate permission step.
The reviewed release supports Gmail, Google Drive, Google Calendar and ClickUp. Availability and permissions may vary by version. Your selected AI service processes the content needed for your requests. Under the BYOK plan, you configure and pay for your own AI API access.
3. Personal data we process
| Category | Examples and source |
|---|---|
| Account | Google account identifier, verified email, internal account identifier, session and sign-in records, from Google and your use of the app |
| Subscription | Account/customer references, plan, subscription status, billing period, payment-event identifiers and transaction information made available by Polar |
| Connected services | Authorised account/workspace identifiers, email, connector settings, permissions and access/refresh credentials, from you and the connected provider |
| Tasks and conversations | Prompts, responses, conversation titles, timestamps, generated document text, attachment metadata, task progress and tool arguments/results included in saved conversations |
| Content used for a task | Selected or retrieved email text, files, calendar events, tasks, page content, URLs, and screenshots where used; these may contain other people's personal data |
| Local extension data | Session information, settings, AI API configuration/key, local conversations, attachment files and context documents stored in your browser |
| Support and security | Messages you send us, necessary troubleshooting information, access/security events and technical data such as IP address processed by hosting/security services |
| Website storage | Necessary security cookies and any additional storage identified in the Cookie Policy |
We do not need your Google or ClickUp password. Signing in takes place with the provider. Do not deliberately include passwords, payment-card details or unnecessary sensitive personal data in prompts or attachments. Browser pages and connected content can nevertheless contain sensitive information; review the material and permissions you make available.
Some information is necessary: without account identification we cannot provide an account; without the relevant connector permission we cannot perform its API operations; without subscription entitlement we cannot provide paid access. Optional support attachments and optional consent-based features are not required to create an account.
4. Purposes and legal bases
| Purpose | GDPR basis when we act as controller |
|---|---|
| Create and operate your account, provide requested tasks and save your conversations | Article 6(1)(b), performing our contract with you or taking steps you request before it |
| Manage subscription entitlement and customer support | Article 6(1)(b); Article 6(1)(c) for specific applicable legal duties |
| Prevent abuse, protect sessions and investigate service failures | Article 6(1)(f), our legitimate interests in a secure and reliable service, subject to a documented balancing assessment |
| Keep records required by tax or other applicable law | Article 6(1)(c), limited to the records and period the relevant law requires |
| Establish, exercise or defend legal claims | Article 6(1)(f), limited to necessary claim-related records |
| Optional non-essential tracking or marketing, if introduced | Prior consent under Article 6(1)(a) and applicable electronic-communications law; no such deployment is established by this draft |
For business content processed on customer instructions, the customer determines the applicable legal basis; our DPA governs our processing. A contract with a subscriber is not automatically a legal basis for every use of third-party email senders' data. Where we determine a purpose for such data, we must establish an appropriate basis and meet applicable transparency requirements. [PUBLISH-02: complete the third-party-data assessment and any required Article 14 arrangements before launch.]
OAuth permission is technical authorisation. It is not a blanket GDPR consent for unrelated processing. Article 6 alone is not sufficient for intentional processing of special-category data: an Article 9 condition is also needed. Do not use the product for regulated or special-category workflows until the applicable conditions and safeguards have been agreed.
5. AI processing and human access
To answer or perform a task, relevant instructions and content are sent to the AI API endpoint you configure. This can include retrieved email/file text, page content, screenshots and conversation context. It does not mean that all of your connected account is automatically copied to an AI provider. The actual scope depends on the task and the tools used.
The reviewed configuration supports an Anthropic API endpoint and may support compatible custom endpoints. Provider identity, processing location, retention and training rules must be checked for the endpoint and contract actually selected. BYOK does not automatically mean zero retention or that no international transfer occurs. [PUBLISH-03: publish the supported-provider schedule, applicable terms and transfer safeguards; restrict unsupported endpoints where necessary.]
Proposed binding product commitment: we do not sell connected Google user data, use it for advertising, or use it to develop, improve or train generalised AI/ML models. Our use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements, and applicable Google Workspace API policies. [PUBLISH-04: confirm downstream AI arrangements and technical enforcement before adopting this commitment publicly.]
Authorised personnel may access data only where necessary for a permitted support, security, maintenance or legal purpose, with appropriate access controls. Google-derived data is subject to additional restrictions on human access under Google's policies. This is not an end-to-end encrypted service in which the operator is technically unable to access all content.
6. Storage and connector credentials
The reviewed backend encrypts stored connector credentials and synchronised conversation payloads using server-managed encryption keys. HTTPS protects transport. This is encryption at rest and in transit, not a promise of end-to-end encryption.
Drive, Calendar and ClickUp credentials are used by the backend proxy. In the reviewed Gmail implementation, a short-lived Gmail access token is returned to the extension for Gmail API requests; the refresh token remains on the backend. Local browser storage also holds app session information and AI configuration. Protect access to your device and Chrome profile.
Saved conversations can include retrieved personal data in tool results and generated text, not just the messages you typed. Original attachment binaries and local context files are not necessarily included in cloud synchronisation. Synchronisation availability depends on the extension and network; a twice-daily check while the panel is open is not a guarantee of continuous background backup.
7. Recipients and international transfers
Data is disclosed only as needed to hosting/database/security providers, connected API providers, the AI provider used for the task, subscription provider Polar, authorised support personnel, and authorities or advisers where legally necessary. Our Service Provider Schedule explains each role and the outstanding deployment details.
Polar handles the sale and payment checkout as Merchant of Record/authorised reseller. It processes purchase, payment, fraud-prevention and tax information under its own applicable terms and privacy notice. We receive information needed to associate payment status with your account. Our application is not intended to collect or store full payment-card details.
Providers and their personnel may process information outside the EEA. Where the GDPR requires safeguards, the applicable transfer must be covered by a valid adequacy decision or appropriate safeguards such as the European Commission's Standard Contractual Clauses, together with any necessary supplementary measures. We do not claim that every provider is covered by the same mechanism. [PUBLISH-05: complete the actual countries, entities and mechanism for each provider.] Contact us for information about applicable safeguards and a copy where available, subject to necessary redactions.
8. Retention
We retain account, conversation and connection information for the purposes described here, subject to your deletion/disconnection instructions, applicable legal duties and necessary legal claims. Disconnecting a service removes its locally held connection credential on the backend, but does not automatically delete content already saved in a conversation. Signing out ends the current app session; it does not delete your account, conversations or every provider grant.
Some records have technical validity periods: app sessions currently expire after 30 days; OAuth states after 10 minutes; certain hand-off records after 2 minutes. These are validity limits, not proof that a physical database cleanup job has run. Conversation retention, deletion completion, infrastructure logs and backup expiry require the deployment-specific schedule below.
[PUBLISH-06: adopt and implement the final retention schedule from the internal register, including deletion completion, log and backup periods. Do not publish unimplemented deadlines.] Statutory records and narrowly scoped evidence needed for legal claims may be retained separately when deletion of ordinary account data is appropriate.
9. Your choices and rights
You can choose which services to connect and which available operations to allow. You can disconnect a connector, revoke the app's grant in the provider's account settings, sign out, and request deletion. These actions have different effects, as explained in our Data Deletion and Rights page.
Depending on the applicable conditions, you may request access and a copy, rectification, erasure, restriction, portability of qualifying data, and object to processing based on legitimate interests. You can withdraw consent at any time for processing based on consent without affecting earlier lawful processing. Contact hello@dropsite.hu. We normally respond within one month; if a lawful extension is necessary, we will explain it within that first month. We use proportionate identity checks and do not routinely require an identity document.
You may complain to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), 1055 Budapest, Falk Miksa utca 9–11., Hungary, postal address 1363 Budapest, Pf. 9., email ugyfelszolgalat@naih.hu, website naih.hu, telephone +36 1 391 1400. You may also complain to the competent authority where you habitually reside, work, or where the alleged infringement occurred, and seek a judicial remedy.
10. Children and automated decisions
The service is intended for adults aged 18 or over. We do not knowingly offer accounts to children. Contact us if you believe a child has supplied data.
AI generates answers and proposes or performs requested operations. The service is not intended to make solely automated decisions producing legal or similarly significant effects about individuals. Do not use it for such decisions without a separate lawful design and appropriate safeguards. AI output can be inaccurate; review consequential actions and results.
11. Changes and contact
We will identify the effective date of changes and notify users of material changes through an appropriate service or email notice. A new purpose or consent requirement will not be introduced merely by silently changing this page. Questions: hello@dropsite.hu.