Assist · Legal information
Personal Data Processing Policy
Official Assist document. The Russian version is legally binding; this translation is provided for convenience.
# Assist Personal Data Processing Policy
Version: v1.0
Date: June 8, 2026
Operator: Individual Entrepreneur Fomenko Bogdan Igorevich, INN 346104066000, OGRNIP 325344300020762.
Single contact for privacy, support, security and complaints: dev@assistgroup.tech.
This English text is provided for information. The Russian version is the binding legal text.
## 1. Roles and Scope
The personal data operator is Individual Entrepreneur Fomenko Bogdan Igorevich. The user is the data subject and is also responsible for lawful submission of third-party data to Assist, including speech of conversation participants, names, roles, business information and other context.
This policy applies to assist-ai.ru, the Assist desktop app, API, payments, emails, support requests and legal acceptances.
## 2. Data Subject Categories
Assist may process data of registered users, site visitors, payers and saved-payment-method holders within payment-provider data, support contacts, and conversation participants whose speech or information is submitted by the user with a lawful basis.
## 3. Data Categories
Assist may process account data, security data, billing data, legal-audit data, app settings, selected audio-source settings, local STT model state, text transcript, AI prompt, server-side chat history if enabled in a specific backend version, support requests, cookie/localStorage preferences and technical site/API data.
Assist does not store full card numbers or CVV. Masked PAN, cardId, rebillId or tokens received from T-Bank are used only for payments, saved cards, auto recharge and accounting.
## 4. Audio, Local STT and AI
The user manually starts processing and selects microphone and/or system audio. In the current desktop flow, speech recognition runs locally through the STT model installed in the user's app data directory. The local STT model may be downloaded through GitHub downloads/updates.
After local recognition, text transcript, selected context, language and prompt may be sent to backend and an external AI provider to generate output. A backend audio-upload endpoint may exist and use an external speech-to-text provider if enabled and disclosed in the interface.
Assist does not use voice to identify a person. If voice is later used for identification or verification, biometric-data assessment and separate legal formalisation will be required.
## 5. Processing Purposes
Data is processed for registration, email verification, login, password reset, providing the app/API/AI output, local and server transcript processing, balance accounting, payments, card binding, auto recharge, receipts, legal acceptances, support, security, anti-abuse, legal compliance, accounting, tax purposes and rights protection.
## 6. Legal Grounds
Depending on the scenario, processing is based on contract performance, user consent, recurring-payment consent, legal obligations for payments/fiscal/accounting/tax records, rights protection and applicable legal requirements.
Consent may be withdrawn via dev@assistgroup.tech. Withdrawal does not affect processing required for contract performance, law, accounting, security, claims or rights protection.
## 7. Processing Operations
The operator may collect, record, organise, accumulate, store, update, retrieve, use, transfer, provide, anonymise, block, delete and destroy personal data using automated, non-automated or mixed processing, including transmission over the Internet.
## 8. External Recipients and International Transfers
Data may be transferred to the recipients and categories below, depending on product version and enabled features.
| Recipient | Country/region | Purpose | Data categories | Trigger |
|---|---|---|---|---|
| T-Bank and related payment/fiscal services | Russia | payments, card binding, receipts, auto recharge, refunds | email, amount, paymentId, orderId, customerKey, cardId, rebillId, masked PAN, payment status | payment, card binding, auto recharge, refund |
| Resend or another email provider | USA/EU/other | transactional emails | email, username, email event, technical event | registration, email verification, welcome, password reset, service notice |
| DeepSeek-compatible/OpenAI/other AI provider | foreign infrastructure | AI output generation | text transcript, prompt, language, mode, technical context | when user sends text to AI |
| OpenAI speech-to-text or another STT provider | foreign infrastructure | audio recognition if backend audio upload is enabled | audio, language, technical context | only when the feature is used |
| GitHub | USA/other | STT model, app updates and release assets | IP, user-agent, technical request | model or update download |
| Hosting, CDN, infrastructure, logs | Russia/other | site/API operation, security, diagnostics | IP, user-agent, request metadata, technical events | site/API use |
Where applicable law requires operator notification or international-transfer notification, the operator follows the relevant process before such processing or transfer.
## 9. Cookies and LocalStorage
The site uses required cookies/localStorage for operation, language and cookie preferences. Analytics or marketing cookies are used only with consent if enabled. Details: /cookie-policy.
The desktop app may use local storage for user settings, lawful-use acknowledgement for the current legal version, UI states and technical parameters.
## 10. Retention
Account data is retained while the user uses Assist and afterwards as required for law, accounting, security and claims. Payment and fiscal records are retained under applicable law. Legal acceptances are stored as evidence and are not overwritten. Transcripts and server-side chat history follow the actual backend retention logic. The local STT model and local settings remain on the user's device until removed.
In v1, deletion/export is handled through support: email dev@assistgroup.tech from the account email. After verification, data is deleted or exported within a reasonable period except where retention is required by law, accounting, security or rights protection.
## 11. User Rights
Users may request access, correction, deletion, restriction, consent withdrawal, export, recipient and transfer information, auto-recharge cancellation and saved-payment-method removal where available. Requests are sent to dev@assistgroup.tech. The operator may request account ownership verification.
## 12. Security
Assist uses TLS, server-side authorisation, password hashing, access separation, payment-data minimisation, sensitive webhook-log redaction, legal-acceptance audit, admin access control and error monitoring.
Assist does not claim ISO 27001, SOC 2, PCI DSS as its own certification or GDPR-ready status unless such documents are actually obtained and published.
## 13. Incidents
If a personal-data incident occurs, the operator assesses the incident, limits consequences and, where applicable law requires, follows notification procedures. Suspected leaks or vulnerabilities may be reported to dev@assistgroup.tech.
## 14. Children
Assist is not intended for persons below the age at which they can independently accept service terms under applicable law.
## 15. Changes
New versions are published on this page. Material changes may require re-acceptance or separate notification.
## 16. Contact
dev@assistgroup.tech
Return to the product
The public Assist pages explain the core features and data-processing model.
Go to homepage