Privacy Policy
Your privacy matters to us. This policy explains how STRIX SOLUTIONS collects, uses, and protects your information across our website, products, and mobile applications.
Last updated: September 21, 2026
1. Introduction
STRIX SOLUTIONS ("STRIX," "we," "our," or "us") is a technology company that operates the website strixbuild.com and develops a range of software products, web applications, and mobile apps. This Privacy Policy describes how we collect, use, and share information across all of our properties.
By using our website, products, or mobile applications, you agree to the collection and use of information in accordance with this policy. If you do not agree with this policy, please do not use our services.
2. Scope
This Privacy Policy applies to:
- Our corporate website at strixbuild.com.
- All products and services operated by STRIX SOLUTIONS, including those hosted on subdomains of strixbuild.com (for example, completeit.strixbuild.com and titi.strixbuild.com).
- Our mobile applications distributed through the Apple App Store and Google Play Store.
Section 14 describes additional, product-specific information that supplements this policy. In the event of a conflict, the product-specific section controls for that product.
3. Information We Collect
We collect the following categories of information:
- Contact information you voluntarily provide when you reach out to us — such as your name, email address, and the contents of your message.
- Account information required to register for and use our products — such as your name, email address, and an encrypted password. When you authenticate, we issue access tokens that identify your session.
- User-generated content that you submit to our products — such as notes, text, files, images, or recordings you upload or create. The categories of content depend on the product; see Section 14 for details.
- Usage data collected automatically — including your IP address, browser type, device identifiers, operating system, referring URLs, pages or screens viewed, feature interactions, and the dates and times of your activity.
- Cookies and similar technologies that help us understand how our services are used and improve your experience. See Section 5 for details.
4. How We Use Your Information
We use the information we collect for the following purposes:
- To provide, operate, maintain, and improve our website, products, and mobile apps.
- To authenticate users, secure accounts, and prevent fraud, abuse, and unauthorized access.
- To process the content you submit to our products and generate the outputs you request (for example, AI-generated tasks — see Section 6).
- To respond to inquiries and provide customer support.
- To analyse usage patterns, troubleshoot problems, and improve performance and reliability.
- To send you service-related notifications (for example, account or security alerts).
- To comply with legal obligations and enforce our Terms of Service.
5. Cookies and Tracking Technologies
Our website and products may use cookies — small text files stored on your device — and similar technologies (such as local storage and secure token storage on mobile devices) to keep you signed in, remember your preferences, and understand how our services are used.
You can control cookies through your browser settings. Disabling cookies may prevent you from signing in or using certain features of our products.
6. Third-Party Services and AI Processing
We rely on selected third-party service providers to operate our business — for example, cloud hosting, email delivery, analytics, error monitoring, and artificial intelligence processing. These providers may receive and process information on our behalf under contractual confidentiality and data-protection obligations.
Some of our products use third-party artificial intelligence services to process user-submitted content. When AI processing is used, the content you submit is transmitted to the AI provider to generate a response, and that provider may temporarily retain the content in accordance with its own terms. The specific AI providers used by each product are listed in Section 14.
We encourage you to review the privacy practices of any third-party services we rely on. We do not sell your personal information to third parties.
7. Data Sharing
We do not sell, trade, or rent your personal information. We share information only in the following circumstances:
- With service providers who assist us in operating our website, products, and business, subject to confidentiality and data-protection obligations.
- When required by law, regulation, legal process, or enforceable governmental request.
- To protect the rights, property, or safety of STRIX SOLUTIONS, our users, or the public.
- In connection with a merger, acquisition, restructuring, or sale of assets, subject to the confidentiality of your information.
8. Data Security
We take reasonable technical and organisational measures to protect the information we collect — including encrypted password storage, transport-layer encryption (HTTPS/TLS), token-based authentication, and access controls. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.
9. Data Retention
We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, to provide our services, to comply with legal obligations, to resolve disputes, and to enforce our agreements. When information is no longer needed, we delete or anonymize it. You may request deletion of your account and associated data at any time (see Section 11).
10. International Data Transfers
STRIX SOLUTIONS and some of our service providers operate internationally. Your information may be transferred to, stored in, or processed in countries other than the one in which you reside. Where required, we take appropriate safeguards to ensure that such transfers comply with applicable data-protection laws.
11. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate or incomplete information.
- Request deletion of your personal information and your account.
- Object to or restrict certain types of data processing.
- Receive a copy of your information in a portable format.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with your local data-protection authority.
To exercise any of these rights, please contact us at the email address provided in Section 16.
12. Children's Privacy
Except for Titi (Section 14.2), our services are not directed to children under the age of 16, and we do not knowingly collect personal information from children through them. If you believe we may have collected information from a child under 16 through such a service, please contact us and we will take steps to delete it.
Titi is designed to be used by children aged 3 to 8, but only under an account opened and managed by a parent or legal guardian. Before a child can talk to Titi, the parent must give separate, recorded consents in the app. The child's profile holds only a nickname and an age chosen by the parent. Section 14.2 describes what is processed, by whom, and how to delete it.
13. Mobile Applications
Our mobile applications may request permissions to access certain device features (such as storage or the microphone) solely to provide the functionality you request. These permissions can be revoked at any time through your device settings.
Mobile apps authenticate users by storing access tokens in the operating system's secure storage (Keychain on iOS, Keystore on Android). When you sign out, these tokens are removed.
14. Product-Specific Information
Each of our products may collect additional information or rely on specific third-party services. The sections below describe how this Privacy Policy applies to each product. New products will be added here as they launch.
14.1 Complete-It
Complete-It is an AI-powered productivity application available at completeit.strixbuild.com and through our iOS and Android mobile apps. It extracts actionable tasks from unstructured content that you submit.
- Account data: email address, name, and an encrypted password hash. We use Laravel Sanctum to issue personal access tokens for authentication.
- User-submitted content: notes, text, emails, meeting transcripts, voice recordings, and similar unstructured content that you submit for task extraction. This content is stored in our database in association with your account.
- Generated content: tasks, tags, priorities, due dates, and assignees that the application generates from your content. You can edit, delete, or export this data at any time.
- AI processing: content you submit is sent to Google Gemini (Gemini 2.5 Flash) to generate structured tasks. Google's processing of that content is governed by Google's own terms and privacy policies. We do not use your content to train AI models.
- Mobile app data: our mobile app stores your access token in secure device storage and may cache data locally to enable offline access. Cached data is cleared when you sign out.
- Retention: your content, tasks, and account data are retained for as long as your account is active. You can delete individual items, clear your account, or request full account deletion at any time.
14.2 Titi
Titi (listed in the stores as "Titi: AI drugar") is a voice companion that talks with children aged 3 to 8 in Serbian. It is available through our iOS app on the Apple App Store and our Android app on Google Play, and is served from titi.strixbuild.com. The account belongs to a parent or legal guardian; children have no account of their own and cannot change any settings. The consent texts shown in the app, in Serbian, form part of this policy for Titi.
What we collect, how, and why
| Data | How it is collected | Why |
|---|---|---|
| Parent's email address | Entered by the parent when opening the account. | Signing in and managing the account. It is also used, in memory only, to slow down repeated failed sign-in attempts. |
| Password | Entered by the parent. We store only a hash of it. | Signing in and confirming account deletion. |
| Child's nickname and age | Entered by the parent in the app. The nickname has at most 24 characters and may be a real first name; the age is between 3 and 8. | So that Titi can address the child by name and suit the conversation to the child's age. |
| Child's voice | The phone's microphone, only while a conversation is active: on the child's screen, or on the diagnostic screen in the parent area (Tehnički podaci, Technical details) when the parent starts a conversation there with Probudi Titija. The echo test on that screen uses the microphone on the phone only and sends nothing. The microphone also picks up other sounds in the room, including other people's voices. | Turning speech into text so that Titi can answer. |
| Conversation text | What the child says, as turned into text from the voice, and what Titi answers. | Composing Titi's replies and checking them for safety. |
| Blocked topics | Entered by the parent in the parent area. | So that Titi avoids those topics. |
| Reports | Sent by the parent from the app: a reason chosen from a fixed list and the Titi sentence being reported. | Reviewing and correcting Titi's mistakes. |
| Conversation records | Created by our server: start and end time, duration, number of exchanges, and how the conversation ended. | Showing the parent how much the child talked; the daily time limit. |
| Usage and cost records | Created by our server for each exchange: seconds of speech, amount of text processed, cost, and response times. | Cost accounting; the daily time limit. |
| Safety events | Created by our server whenever the safety check steps in: the kind of event, the action taken, the time, and a fingerprint (SHA-256 hash) of what the child said, not the words themselves. | Protecting the child; showing the parent which kinds of events happened. |
| Consent records | Created when the parent gives or withdraws a consent: its type and version, a fingerprint (SHA-256) of the exact text, the time, and the app version. | Proof that consent was given. |
| Identifiers | Account, child, conversation, and device identifiers created by our server and the app. The device identifier is a random value created once per app installation; it is not the advertising ID, the IMEI, or the Android ID. | Running the service and tying each conversation to the parent's device. |
| Technical data | The IP address and the identifiers above, in our server logs. A random installation ID and the IP address, sent to Expo when the app checks for updates. | Security and abuse prevention; delivering app updates. |
Titi does not collect location, contacts, photos, files, the advertising ID, or anything else from the phone. It shows no advertising and includes no advertising, analytics, or tracking libraries.
Who receives the data
Nothing is sent to OpenAI, ElevenLabs, or Microsoft Azure Speech until the parent allows it on the consent screen, on the card "Slanje razgovora trećim stranama" (Sending conversations to third parties), with the button "Dozvoljavam slanje" (I allow sending). Until then our server does not start a conversation.
- OpenAI, L.L.C. (United States) turns the child's speech into text, composes Titi's replies, and checks them for safety. It receives the child's voice while a conversation is active, the conversation text, the child's nickname and age, and the topics the parent has blocked (the last three as part of Titi's instructions). OpenAI keeps these records for up to 30 days for abuse monitoring and does not use them to train its models.
- ElevenLabs (Eleven Labs Inc., United States) turns Titi's replies into a synthetic voice when selected or when it takes over from the other service. It then receives the text of Titi's replies, including a reply that our safety check later stops before the child hears it. That text can contain the child's nickname, when Titi addresses the child by name, and what the child said, because Titi sometimes repeats the child's question. ElevenLabs may retain the text and generated audio in its service history; zero retention is not enabled on this account.
- Microsoft Azure Speech (Microsoft) turns Titi's replies into a synthetic voice when selected or when it takes over after a timeout or error. It then receives the text of Titi's reply, which may contain the child's nickname or words Titi repeats from the child. The reply may be stopped by the safety check before the child hears it.
- Expo (650 Industries, Inc., United States) delivers app updates (EAS Update). Each time the app starts, it asks Expo whether an update is available; that request carries a random installation ID, the IP address, the platform, and the app and update versions, and, if an update fails to start, the error message. Expo receives no voice, conversation text, email address, or child data.
- Hetzner Online GmbH (Germany) hosts our servers. The data we store and our server logs are kept on its servers in Germany.
OpenAI, ElevenLabs, and Microsoft Azure Speech are the only AI services that may receive the child's voice or the conversation text. OpenAI receives the voice and text; ElevenLabs or Microsoft Azure Speech receives Titi's reply text and generates audio. We do not sell data or use conversations to train our own AI models. ElevenLabs' use of submitted content to improve its models depends on the account's data-use setting, which must be disabled before Titi sends it children's data.
How long we keep it
- Voice and conversation text: our server does not store audio recordings or conversation text; it holds them in memory only while the conversation lasts. OpenAI keeps them for up to 30 days (see above). ElevenLabs may retain the text sent for speech generation and the generated audio in its service history. If the parent reports a Titi sentence, we keep that sentence with the report.
- Child profile, blocked topics, conversation records, safety events, and reports: kept while the account exists and deleted when the account is deleted.
- Server logs: may contain IP addresses, the identifiers above, the child's age, and the text of blocked topics. We do not write conversation text to the logs, but in rare error situations an error record may contain the text of a Titi reply. Logs are overwritten on a rolling basis once they reach a fixed size (at most 50 MB per service), so how long a line survives depends on how busy the service is.
- Usage and cost records: one record per exchange, kept after the account is deleted for cost accounting. They contain no email address, nickname, or conversation content. While the account exists they are linked to the random device identifier; when the account is deleted they are unlinked from the device and the account and keep only the random identifiers of the exchange and of the deleted conversation. The daily usage totals are deleted with the account (and a child's totals with that child's profile).
- Consent records and the account record: after deletion we keep the withdrawn consent records (without child data) and a record that the account existed and when it was closed (without the email address or password), as proof that consent was given.
- Deleted database records may remain in the database's free space and journal until they are overwritten in normal operation.
- On the phone: sign-in tokens are kept in the operating system's secure storage (Keychain on iOS, Android Keystore on Android) and removed when the parent signs out. Uninstalling the app removes everything the app keeps on the phone.
Withdrawing permission and deleting the account
- Withdrawing permission: in the app, open Za roditelje (For parents), answer the parental gate, and go to Nalog (Account) → Dozvola za slanje podataka (Permission to send data) → Povuci dozvolu (Withdraw permission). From that moment the app turns off the microphone, closes the connection, and returns to the consent screen; our server ends any conversation still running on the account's other phones, starts no new conversation, and nothing more is sent to OpenAI, ElevenLabs, or Microsoft Azure Speech. Titi works again only if the parent gives permission again. Data already sent remains subject to each provider's retention policy.
- Deleting the account in the app: Za roditelje → parental gate → Nalog → Obriši nalog (Delete account). The consent screen offers the same Obriši nalog at the bottom, so an account can be deleted without giving (or giving again) any consent. Deletion requires the account password and cannot be undone. It removes the child profile, blocked topics, conversation records, safety events, reports, daily usage totals, devices, sign-in tokens, the email address, and the password.
- Deleting the account by email: if you cannot use the app, or have forgotten the password, follow the steps on Delete your Titi account.
For any other request about Titi data (access, correction, or a copy), contact us as described in Section 16.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, products, or legal requirements. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you through our services. We encourage you to review this policy periodically.
16. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at:
STRIX SOLUTIONS
Email: info@strixbuild.com
Website: strixbuild.com