Privacy Policy
Last updated: 24 March 2026
1. Data Controller
MyFutures ("we", "us", "our") is the data controller responsible for your personal data. We are committed to protecting your privacy in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
2. Data We Collect
We may collect and process the following personal data:
- Account data: name, email address, and password (hashed).
- Profile data: responses to explorations, scores, insights, and companion conversations.
- Usage data: pages visited, features used, and session information.
- Technical data: IP address, browser type, device information, and cookies.
3. How We Use Your Data
We use your personal data to:
- Provide, maintain, and improve the Service.
- Personalise your experience and the AI companion's responses.
- Generate scores, insights, and profile information from your explorations.
- Communicate with you about your account and the Service.
- Ensure security and prevent fraud.
4. Legal Basis for Processing (Article 6 GDPR)
We process your personal data on the following legal bases:
- Consent (Art. 6(1)(a)): for non-essential cookies and optional communications.
- Contract (Art. 6(1)(b)): to provide the Service you have signed up for.
- Legitimate interests (Art. 6(1)(f)): for security, fraud prevention, and service improvement.
- Legal obligation (Art. 6(1)(c)): to comply with applicable laws.
5. Third Parties and Data Sharing
We do not sell your personal data. We may share data with trusted service providers who assist us in operating the Service (e.g., hosting, analytics), subject to appropriate data processing agreements.
We may also disclose data if required by law or to protect our rights and safety.
6. International Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA). Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.
7. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. When you delete your account, we will delete or anonymise your personal data within 30 days, unless retention is required by law.
8. Your Rights (Data Subject Rights)
Under the GDPR, you have the following rights:
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: request correction of inaccurate or incomplete data.
- Right to erasure: request deletion of your personal data ("right to be forgotten").
- Right to restriction: request that we limit how we process your data.
- Right to data portability: receive your data in a structured, machine-readable format.
- Right to object: object to processing based on legitimate interests.
- Right to withdraw consent: withdraw consent at any time where processing is based on consent.
- Right to lodge a complaint: file a complaint with your local supervisory authority.
To exercise any of these rights, please contact us at hello@myfutures.ai.
9. Children
The Service is not intended for children under 16 years of age. We do not knowingly collect personal data from children under 16. If we learn that we have collected data from a child under 16, we will take steps to delete it promptly.
10. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. However, no method of transmission over the Internet is 100% secure.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy and revising the "Last updated" date. Your continued use of the Service constitutes acceptance of the revised policy.
12. Data Protection Contact
For any questions or concerns about this Privacy Policy or our data practices, please contact our Data Protection Officer at hello@myfutures.ai.