Legal
Privacy Policy
Last updated: June 7, 2026
This Privacy Notice for Milan Horvath (doing business as KARSIS) ("we," "us," or "our") describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you:
- Visit our website at https://www.karsis.app or any website of ours that links to this Privacy Notice
- Use KARSIS — an upcoming AI-powered accountability app being developed by Milan Horvath. This Privacy Policy applies to the pre-launch waitlist at karsis.app — a free service that collects email addresses to notify subscribers when the app launches and to send pre-launch newsletter content.
- Engage with us in other related ways, including any marketing or events
Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at help@karsis.app.
Summary of Key Points
This summary provides key points from our Privacy Notice. You can find more details about any of these topics by reading the corresponding numbered section below.
What personal information do we process? Only your email address — voluntarily submitted via the waitlist form.
Do we process sensitive personal information? No.
Do we collect information from third parties? No.
How do we process your information? To deliver the pre-launch newsletter, respond to inquiries, send administrative messages (e.g. confirmation, unsubscribe), and notify you when KARSIS launches. We process your information only when we have a valid legal reason to do so.
With which third parties do we share information? Three service providers: Beehiiv (newsletter delivery), Cloudflare (DNS and email routing), and Vercel (website hosting). All bound by data processing agreements with Standard Contractual Clauses.
How do we keep your information safe? We rely on the SOC 2 / industry-standard security measures of our service providers (Beehiiv, Cloudflare, Vercel), HTTPS in transit, and encrypted environment variables. No system is 100% secure, but the technical footprint is intentionally minimal.
What are your rights? Depending on your location, you may have rights to access, correct, delete, or export your data, and to withdraw consent at any time. Easiest way: email help@karsis.app.
1. What information do we collect?
Personal information you disclose to us
In short: We collect personal information that you provide to us.
We collect personal information that you voluntarily provide to us when you express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.
Personal Information Provided by You. The personal information we collect is:
- email addresses
Sensitive Information. We do not process sensitive information.
All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.
2. How do we process your information?
In short: We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We process the personal information for the purposes listed below. We may also process your information for other purposes only with your prior explicit consent.
We process your personal information for a variety of reasons, depending on how you interact with our Services, including:
- To deliver and facilitate delivery of services to the user. We process your email to deliver the pre-launch newsletter and notify you when KARSIS launches.
- To respond to user inquiries / offer support to users. We process your information to respond to your inquiries and solve any potential issues you might have.
- To send administrative information to you. Subscription confirmation, welcome message, unsubscribe confirmation, and changes to terms or policies.
- To save or protect an individual’s vital interest. We may process your information when necessary to save or protect an individual’s vital interest, such as to prevent harm.
3. What legal bases do we rely on to process your information?
In short: We only process your personal information when we believe it is necessary and we have a valid legal reason to do so under applicable law.
If you are located in the EU or UK, this section applies to you.
The General Data Protection Regulation (GDPR) and UK GDPR require us to explain the valid legal bases we rely on:
- Consent. We process your information if you have given us permission (i.e., consent) to use your personal information for a specific purpose. You can withdraw your consent at any time.
- Performance of a Contract. We may process your personal information when necessary to fulfill our contractual obligations to you, including providing the waitlist service you signed up for.
- Legal Obligations. We may process your information where necessary for compliance with our legal obligations, such as cooperating with a law enforcement body or regulatory agency.
- Vital Interests. We may process your information where necessary to protect your vital interests or the vital interests of a third party, such as situations involving potential threats to the safety of any person.
4. When and with whom do we share your personal information?
In short: We share information with specific third parties for the operation of our Services. We do not sell your personal information.
Vendors, Consultants, and Other Third-Party Service Providers. We share your data with third-party vendors who perform services on our behalf and require access to such information to do that work. We have contracts in place with our third parties designed to safeguard your personal information.
The third parties we may share personal information with:
- Beehiiv — newsletter / waitlist email storage and delivery (USA)
- Cloudflare — DNS hosting and email routing forwarding (USA)
- Vercel — website hosting (USA)
We may also need to share your personal information in the following situations:
- Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
5. Is your information transferred internationally?
In short: We may transfer, store, and process your information in countries other than your own.
Our servers, and those of our third-party service providers, are located in the United States. Regardless of your location, your information may be transferred to, stored by, and processed by us and the third parties listed in Section 4 above.
If you are a resident in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, then these countries may not necessarily have data protection laws or other similar laws as comprehensive as those in your country. However, we will take all necessary measures to protect your personal information in accordance with this Privacy Notice and applicable law.
European Commission’s Standard Contractual Clauses: We have implemented measures to protect your personal information, including by using the European Commission’s Standard Contractual Clauses (SCCs) for transfers of personal information between us and our third-party providers (Beehiiv, Cloudflare, Vercel). These clauses require all recipients to protect all personal information that they process originating from the EEA or UK in accordance with European data protection laws and regulations. Copies of these SCCs can be provided upon request.
6. How long do we keep your information?
In short: We keep your information for as long as necessary to fulfill the purposes outlined in this Privacy Notice unless otherwise required by law.
We will only keep your personal information for as long as necessary for the purposes set out in this Privacy Notice. No purpose in this notice will require us keeping your personal information for longer than until the subscriber unsubscribes, or after 24 months of inactivity (no email opens or link clicks), whichever comes first.
When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize such information, or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.
7. How do we keep your information safe?
In short: We aim to protect your personal information through a system of organizational and technical security measures.
We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process. These include HTTPS encryption in transit, SOC 2-compliant third-party providers (Beehiiv), DDoS protection (Cloudflare), and encrypted environment variables on our hosting platform (Vercel). However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Although we will do our best to protect your personal information, transmission of personal information to and from our Services is at your own risk.
8. Do we collect information from minors?
In short: We do not knowingly collect data from or market to children under 18 years of age or the equivalent age as specified by law in your jurisdiction.
We do not knowingly collect, solicit data from, or market to children under 18 years of age, nor do we knowingly sell such personal information. By using the Services, you represent that you are at least 18 or that you are the parent or guardian of such a minor and consent to such minor dependent’s use of the Services. If we learn that personal information from users less than 18 years of age has been collected, we will deactivate the entry and take reasonable measures to promptly delete such data from our records. If you become aware of any data we may have collected from children under age 18, please contact us at help@karsis.app.
9. What are your privacy rights?
In short: Depending on your state of residence in the US or some regions, such as the European Economic Area (EEA), United Kingdom (UK), Switzerland, and Canada, you have rights that allow you greater access to and control over your personal information.
In some regions (like the EEA, UK, Switzerland, and Canada), you have certain rights under applicable data protection laws. These may include the right (i) to request access and obtain a copy of your personal information, (ii) to request rectification or erasure; (iii) to restrict the processing of your personal information; (iv) if applicable, to data portability; and (v) not to be subject to automated decision-making. In certain circumstances, you may also have the right to object to the processing of your personal information. You can make such a request by contacting us using the contact details provided in Section 14 below.
We will consider and act upon any request in accordance with applicable data protection laws.
If you are located in the EEA or UK and you believe we are unlawfully processing your personal information, you also have the right to complain to your Member State data protection authority or the UK data protection authority.
If you are located in Switzerland, you may contact the Federal Data Protection and Information Commissioner.
Withdrawing your consent: If we are relying on your consent to process your personal information, you have the right to withdraw your consent at any time by contacting us using the contact details in Section 14 below.
Opting out of marketing and promotional communications: You can unsubscribe from our marketing and promotional communications at any time by clicking the unsubscribe link in the emails that we send, by emailing vero@karsis.app and requesting removal, or by contacting us using the details in Section 14 below.
10. Controls for do-not-track features
Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track ("DNT") feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage, no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this Privacy Notice.
11. Do United States residents have specific privacy rights?
In short: If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may have the right to request access to and receive details about the personal information we maintain about you and how we have processed it, correct inaccuracies, get a copy of, or delete your personal information.
Categories of personal information we collect
We have only collected one category of personal information in the past twelve (12) months:
- A. Identifiers — specifically: email addresses
We have NOT collected any of the following categories: personal information as defined in the California Customer Records statute, protected classification characteristics, commercial information, biometric information, internet or network activity, geolocation data, audio/visual data, professional or employment-related information, education information, inferences, or sensitive personal information.
How we use and share personal information
We use your email to deliver the pre-launch newsletter and notify you of launch. We share it with our third-party service providers (Beehiiv, Cloudflare, Vercel) as described in Section 4 above. We do not sell or share personal information for cross-context behavioral advertising. We have not sold or shared any personal information for a business or commercial purpose in the preceding twelve (12) months.
Your rights
You may have the right, depending on your state of residence, to:
- Right to know whether or not we are processing your personal data
- Right to access your personal data
- Right to correct inaccuracies in your personal data
- Right to request the deletion of your personal data
- Right to obtain a copy of the personal data you previously shared with us
- Right to non-discrimination for exercising your rights
- Right to opt out of targeted advertising, data sale, or profiling (not applicable — we do none of these)
How to exercise your rights
Email us at help@karsis.app to exercise any of the above rights.
12. Forward-looking statement regarding the KARSIS application
This Privacy Policy currently covers the pre-launch waitlist operated at karsis.app. The KARSIS mobile application, currently in development, will include an in-app AI agent named "VERO" powered by OpenAI’s gpt-4o-mini model. VERO will be used inside the app to verify user-submitted proof of task completion.
The waitlist landing page itself does NOT use any AI processing — only post-launch KARSIS app users will interact with VERO. Once the KARSIS application is publicly released, this Privacy Policy will be updated to include full disclosures about VERO’s data processing, retention practices, and user rights specifically related to AI processing.
Subscribers to the waitlist who do not download the KARSIS app at launch will never have their data processed by an AI system through this service.
13. Do we make updates to this notice?
In short: Yes, we will update this notice as necessary to stay compliant with relevant laws.
We may update this Privacy Notice from time to time. The updated version will be indicated by an updated "Last updated" date at the top of this Privacy Notice. If we make material changes to this Privacy Notice, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this Privacy Notice frequently to be informed of how we are protecting your information.
14. How can you contact us about this notice?
If you have questions or comments about this notice, you may email us at help@karsis.app.
The data controller is:
Milan Horvath
Hungary
15. How can you review, update, or delete the data we collect from you?
Based on the applicable laws of your country or state of residence in the US, you may have the right to request access to the personal information we collect from you, details about how we have processed it, correct inaccuracies, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information. These rights may be limited in some circumstances by applicable law. To request to review, update, or delete your personal information, please email help@karsis.app.
This Privacy Notice was generated using Termly’s Privacy Policy Generator and tailored to KARSIS’s actual processing footprint by Milan Horvath.