Privacy Policy — MaksHub
Effective date: June 3, 2026 | Version 1.0
1. General
This Privacy Policy (hereinafter — the "Policy") describes how personal data of users of the MaksHub mobile application (hereinafter — the "App") and the related web service (hereinafter collectively — the "Service") are processed.
Data Controller:
- Name: Verslobotas, MB
- Company code (įmonės kodas): 306997072
- Registered address: Perkūnkiemio g. 19, LT-12120 Vilnius, Lithuania
- Phone: +370 655 97328
- Email: verslobot@gmail.com
By using the Service you confirm that you have read this Policy and agree to its terms. If you do not agree — please stop using the Service and uninstall the App.
This Policy is prepared in accordance with the requirements of the General Data Protection Regulation (GDPR, EU Regulation 2016/679) and other applicable data protection laws.
2. Data We Collect
2.1. Data you provide directly
- Email address — required; used as the account identifier and for communication.
- Name (or display name) — required; shown in your profile and in chats.
- Phone number — optional; used for SMS-code login or Telegram account linking.
- Avatar — optional; profile picture uploaded by the user.
- Homework submissions — text answers, photos, videos, audio, and documents attached to assignments.
- Chat messages — text, voice messages, files, and photos sent in product chats.
- Lesson notes — text notes you create while progressing through lessons.
2.2. Data collected automatically
- Lesson and course progress — which lessons are unlocked, completion marks, time of last access.
- Device push token (Expo Push Token / FCM Token / APNs Token) — for delivering push notifications about new lessons and messages.
- Internal user identifier (UUID) — generated at registration.
- IP address and basic session data — collected by servers for security purposes; retained in logs for no more than 30 days.
- Basic device information (platform: iOS / Android, OS version, app version) — for technical support and compatibility.
2.3. Data we do NOT collect
- Precise or approximate geolocation.
- Contacts from the address book.
- Calendar, fitness, or health data.
- Biometric data.
- Financial transactions or payment instrument details (in-app purchases are not available).
- Racial/ethnic origin, political opinions, religious or philosophical beliefs.
3. Purposes of Processing
We process your personal data exclusively for the following purposes:
- Registration and authentication — creating an account, signing in via Apple, Google, or email.
- Providing the Service — opening courses, saving progress, reviewing homework, communicating in chats with mentors.
- Communication with you — service notifications (e.g. mentor reply to homework, new chat message, new lesson).
- Technical support — responding to your inquiries and diagnosing technical issues.
- Security — preventing unauthorised access, fraud, and rule violations.
- Legal compliance — storing data and providing information pursuant to requests by competent authorities.
We do not use your data for advertising or marketing on behalf of third parties, interest-based ad profiling, or selling data to anyone.
4. Legal Bases for Processing
- Consent — provided by the user during registration in the App.
- Performance of a contract — the public offer for access to the Service published on the website.
- Legitimate interests — ensuring the security of the Service, fraud prevention, improving functionality.
- Legal obligation — compliance with applicable law.
5. Where Data Is Stored
We use regional data separation:
- For users from the Russian Federation — data is stored on servers in Moscow, Russia (Timeweb infrastructure), in compliance with Article 18 of Federal Law No. 152-FZ requiring primary recording and storage of Russian citizens' personal data in Russia.
- For users from all other countries — data is stored on servers in Frankfurt, Germany (Supabase, EU region), in compliance with GDPR.
Media files (photos, videos, audio, documents) are stored in Cloudflare R2 object storage with corresponding geographic separation.
All data is encrypted in transit (HTTPS / TLS 1.2+) and at rest (AES-256).
6. Who Has Access to Your Data
We do not sell or transfer your data to third parties for marketing purposes. Access is limited to:
- Authorised staff of Verslobotas, MB — for technical support and handling inquiries.
- Mentors of the relevant product — can view homework content and chat messages only within their own course.
- Infrastructure providers acting under our instructions:
- Supabase (database, authentication, push notifications) — US / EU.
- Cloudflare (R2 file storage and network infrastructure) — global.
- Apple Push Notification Service — for iOS push delivery.
- Firebase Cloud Messaging (Google) — for Android push delivery.
- Timeweb Cloud — Russian hosting for users from Russia.
Transfer of data to government authorities is only possible upon a written request issued in accordance with applicable law.
7. Retention Periods
- Account data is retained for as long as your account is active.
- Upon account deletion — all personal data is deleted within 30 days, except where retention is required by law (e.g. accounting documents).
- Access logs and system journals are retained for no more than 90 days.
- Backup copies may contain deleted data for up to 35 days after deletion.
8. Your Rights
Under GDPR you have the right to:
- Access — find out what data we hold about you.
- Portability — receive a copy of your data in a machine-readable format.
- Rectification — correct inaccurate data.
- Erasure — delete your account and associated data.
- Restriction — limit processing of certain types of data.
- Withdrawal of consent — this will result in inability to use the Service.
- Lodge a complaint with a supervisory authority (the State Data Protection Inspectorate of Lithuania or the authority in your country of residence).
Send requests to verslobot@gmail.com. Response time — up to 30 calendar days.
You can delete your account yourself:
9. Security
We implement technical and organisational measures to protect your data:
- Encryption in transit (TLS 1.2+).
- Encryption at rest (AES-256).
- Database access only via secure VPN tunnels and a restricted set of IP addresses.
- Passwords stored as cryptographic hashes (Argon2 / bcrypt).
- Regular access audits.
- Two-factor authentication for all staff with access to production systems.
Despite all measures, it is impossible to completely eliminate the risk of a data breach. In the event of a security incident we will notify affected users and the supervisory authority within the timeframes required by law (72 hours under GDPR).
10. Cookies and Analytics
The mobile App does not use cookies for marketing or tracking purposes. Only technical session identifiers are stored inside the App (via secure Keychain / Keystore storage).
The web version uses only functionally necessary cookies (session storage). Third-party analytics systems (Google Analytics, Facebook Pixel, etc.) are not used in the mobile App.
11. Children
The Service is not intended for use by children under 13 years of age (or the applicable digital age of consent in your country). We do not knowingly collect data from children. If you are a parent and discover that your child has registered with the Service — contact us and we will delete their data.
12. International Data Transfers
Data of users from the EU is processed on servers located in the EU. Data of users from Russia is stored in Russia. When contacting support, your information may be viewed by a staff member located in a different jurisdiction — this is covered by appropriate Data Processing Agreements (DPAs) and Standard Contractual Clauses (SCCs) in accordance with GDPR.
13. Policy Changes
We may update this Policy from time to time. We will notify you of significant changes by email or through a notification in the App at least 14 days before the changes take effect. The date of the last change is indicated at the top of this document.
14. Contact
For any questions related to personal data processing:
- Email: verslobot@gmail.com
- Phone: +370 655 97328
- Postal address: Perkūnkiemio g. 19, LT-12120 Vilnius, Lithuania
Data Controller responsible for personal data processing: Verslobotas, MB.
This document is also available in Russian. In case of discrepancy between language versions, the Russian version prevails.