1. Data controller
The controller is Javier Darío Fresnadillo, CUIT 20-28096900-2, with address at Francisco Carabelli 895, Trenque Lauquen, Province of Buenos Aires, Argentina, owner of Comprender AI and the ARQUIGÉNESIS ecosystem.
Privacy: privacidad@comprenderai.com.
General contact: contacto@comprenderai.com.
2. Scope
This Policy applies to comprenderai.com, the Comprender AI application, accounts, organisms, conversations, files, reports, payments, requests, communications, and integrated services that refer to it.
3. Data we may process
3.1 Registration and account
- first and last name;
- email address;
- internal identifiers;
- protected credentials or authentication identifiers;
- country, language, or other optional information;
- date, time, and legal versions accepted.
3.2 Platform use
- messages and conversations;
- organism names and content;
- Memory, Memories, Principles, syntheses, tensions, functions, diagnostics, relationships, and proposals;
- files or data provided;
- decisions to accept, edit, or reject;
- account type, subscription, Usage Capacity, and technical consumption required to operate the service;
- synchronized information, temporary local states, and operational events.
3.3 Technical and security data
- IP address and approximate derived location;
- device, browser, operating system, and technical logs;
- access dates, events, errors, and security activity;
- session and authentication identifiers.
3.4 Payments and subscriptions
- account or subscription type;
- status, date, amount, and currency;
- customer, subscription, and transaction identifiers;
- country and necessary tax information.
Full card details or other payment credentials are normally processed by the payment provider rather than Comprender AI.
3.5 Requests and communications
- email and contact details;
- type of request or complaint;
- comments;
- reference number, status, dates, and resolution;
- minimum evidence needed to verify identity;
- preferences and delivery records.
4. Sensitive data and third-party data
Comprender AI does not request sensitive data as a general condition of use. Because conversations are open-ended, users may enter such information voluntarily. We recommend not including specially protected information or third-party personal, confidential, or professional-secret data unless necessary, authorized, or otherwise supported by a sufficient legal basis.
5. Purposes
We process data to create and administer accounts; provide requested functions; generate AI responses; build and maintain organisms, Memory, Memories, Principles, and continuity; administer account type, Capacity, payments, and subscriptions; measure technical consumption required to operate, protect, and sustain the service; answer questions, complaints, and legal requests; send legal, transactional, and operational communications; prevent fraud, abuse, and incidents; correct errors, measure performance, and improve the service; comply with obligations and defend rights.
Commercial communications are sent in accordance with consent or another permitted basis and include opt-out mechanisms.
6. Legal bases
Depending on the case, processing is based on informed consent, performance of the service, compliance with legal obligations, security, fraud prevention, defense of rights, or other permitted legal bases.
7. Artificial intelligence
Messages and necessary context may be sent to model providers to generate responses. The system may select, summarize, structure, or distill part of a conversation to preserve continuity.
Compy is the automated conversational presence of Comprender AI. When Compy is described as “remembering”, “knowing”, or “accompanying”, this refers to technical continuity rather than personal knowledge or human intervention.
Comprender AI does not make legally or administratively binding decisions solely through automated processing. Results must be evaluated by the user.
Private content is not used for third-party advertising. Use for general training of proprietary models is not presumed authorized merely by using the service.
8. Memory, retention and deletion
| Category | General criterion |
|---|---|
| Account and profile | While active and afterwards for the period required for closure and applicable obligations |
| Conversations | May be deleted after 12 months of inactivity |
| Memory, Memories and Principles | While the account or organism exists, unless deletion is requested or legal retention is required |
| Inactive free account | May be deleted after 24 months without activity, with the planned prior notices |
| Deletion initiated from the account | May be scheduled with a 7-day safety period and possibility of revocation |
| Payments and receipts | For applicable tax, accounting, contractual, or anti-fraud periods |
| Requests and legal evidence | For the period needed to respond, demonstrate compliance, and defend rights |
| Security logs | For a period proportionate to risk and purpose |
| Communication events | For the period needed for traceability, security, and compliance; then deleted or anonymized when no longer necessary |
Deleting a conversation does not necessarily delete Memory. Cancelling a subscription also does not automatically delete the account or data.
A formal erasure request will be assessed under Argentine Law 25,326. Some data may be retained in blocked or restricted form because of legal obligations, pending transactions, fraud prevention, or defense of rights. Backups may retain information for a limited additional period until secure rotation.
9. Providers and recipients
| Provider or category | Main function | Possible data |
|---|---|---|
| Vercel | Hosting and execution | technical data, requests, and processed content |
| Supabase | Authentication, database, and storage | account, organisms, conversations, memory, and events |
| AI providers contracted through API | Generation and processing | messages, instructions, and necessary context |
| Brevo | Transactional and operational email | email, name, content, and delivery events |
| Lemon Squeezy | International subscriptions and payments | commercial identity, subscription, payment, and necessary tax data |
| Mercado Pago | Payments for Argentina | transaction and subscription data |
| Cloudflare | Domain, DNS, security, and web delivery | IP, technical data, and security logs |
| Necessary technologies and internal technical metrics | Operation and performance | identifiers and events according to configuration |
We may also disclose information to authorities, advisers, or third parties when legally required or necessary to protect rights.
10. International transfers
Some providers operate outside Argentina. Data may be stored or processed in other countries through contracts, configurations, and safeguards intended to provide adequate protection. The primary region of some services may be configured in São Paulo, Brazil, without excluding technical processing or support in other jurisdictions disclosed by providers.
11. Security and confidentiality
We apply reasonable measures such as access controls, authentication, per-user permissions, encryption in transit, secret management, security logging, and incident review. No system is completely infallible.
12. Communications and preferences
We distinguish legal or transactional, operational and security, organism-continuity, and commercial communications. Opting out of commercial messages does not block confirmations, security, payments, account changes, or legally necessary messages.
13. Cookies and local storage
The website and application may use technologies necessary to maintain sessions, remember preferences, protect forms, prevent abuse, and temporarily preserve technical state.
Analytics, personalization, or advertising cookies that may be added in the future must be identified and activated in accordance with applicable rules.
Comprender AI combines account-linked storage with local states. Deleting browser data may remove sessions or information that has not yet been synchronized, but does not necessarily mean deleting the account or remote data.
14. Data-subject rights
Data subjects may request information, access, correction, updating, erasure where applicable, confidentiality or blocking, withdrawal of applicable consent, and opt-out from commercial communications.
Requests may be sent to privacidad@comprenderai.com or through public forms. We may reasonably verify identity using only necessary information and without revealing whether an email belongs to an account when doing so would affect security.
As a general rule, Argentine Law 25,326 provides ten calendar days to respond to access requests and five business days for correction, updating, or erasure, without prejudice to legal exceptions.
15. Cancellation, account deletion and erasure
- Service cancellation: stops renewals or cancels a service.
- Account deletion: initiates closure of the account and associated data.
- Personal-data erasure: exercise of a legal right subject to verification and retention exceptions.
Cancelling a subscription does not automatically delete all data.
16. Minors
Direct subscription is not intended for people under 18. Pedagogical functions must operate with clear information, data minimization, adult supervision, and appropriate controls.
17. Changes to this Policy
We may update this Policy because of legal, technical, functional, or provider changes. We will publish the new version and effective date. If processing changes substantially, we will communicate it and request renewed consent when required.
18. Contact and supervisory authority
Controller: Javier Darío Fresnadillo — CUIT 20-28096900-2.
Address: Francisco Carabelli 895, Trenque Lauquen, Province of Buenos Aires, Argentina.
Privacy: privacidad@comprenderai.com.
General contact: contacto@comprenderai.com.
Supervisory authority in Argentina: Agencia de Acceso a la Información Pública (AAIP) — argentina.gob.ar/aaip.