Trust

How we handle data

This page states what data Momentum Terminal holds, what protects it, and which providers process it. It describes the system as it runs today; where a measure arrives with commercial launch, it says so. Questions: hello@momentumterminal.pl.

Last reviewed: 3 Jul 2026

Product

01

What Momentum is

Momentum Terminal, operated by Momentum AI sp. z o.o., provides data on Polish registered companies and the people who hold roles in them. The company and officer records are sourced from public registries and filings: the National Court Register (KRS), the Central Register of Beneficial Owners (CRBR), and companies’ own published financial statements. How and why we process registry persons’ data is set out in the Article 14 privacy notice.

Data held

02

What we store, and about whom

Two groups of people appear in our systems: customers who create accounts, and registry persons who appear in the public filings we serve.

Customers

AccountEmail address, name, sign-in method, and (for password sign-in) a password hash. Plan tier and trial dates.
SessionsSigned-in sessions, including the IP address and browser user agent they were opened from. Sessions are stored server-side and can be revoked.
Chat contentIf you use the AI chat, your messages and the answers (including the company data cited in them) are stored with your account.
Your workLists, notes, saved screens, and saved queries you create in the product.

Registry persons

Identity and roleFirst and last names, role or function, citizenship, and appointment dates, as filed in KRS and CRBR.
PESELThe national ID number is present in the source filings. It is never displayed in the product and never returned by any API; wherever a record is shown, PESEL is masked to its first digit.

Security

03

Measures in place today

TransportTraffic to the product is encrypted in transit (TLS).
PasswordsStored as scrypt hashes, never in plain text.
Two-factorTOTP two-factor authentication with one-time backup codes, available on every account.
SessionsServer-side sessions with a seven-day cap; each session can be revoked individually, and account deletion revokes all of them immediately.
Audit logA hash-chained, append-only audit log records data-access events, including the IP address and user agent they came from.
Database accessThe application writes only to its own schema: least-privilege access to the database.

Defaults

04

Private by default

There is no analytics script, no tracking pixel, and no third-party script on any page of the product or this site.

CookiesTwo cookies carry the product: the session cookie (“authjs.session-token”; prefixed “__Secure-” over HTTPS) keeps you signed in, with a seven-day cap, and the “lang” cookie remembers your EN or PL choice. The sign-in flow briefly sets the framework’s own CSRF and redirect cookies. There are no advertising, analytics, or third-party cookies.
FontsSelf-hosted. Pages make no font request to Google or any other third party.

Sub-processors

05

Who processes data on our behalf

When you use the AI features, your queries and the company data used to answer them are processed by Anthropic, and your search query text is embedded by OpenAI. Both run on their default United States endpoints today; EU routing for the language model is planned. AI features require a verified email address.

Active today

Anthropic

Data terms

Large language model (Claude) behind the AI features: chat, question answering, and query interpretation.

Data: user-typed queries and chat messages; company data returned by tools while answering (can include officers' names as filed).

United States (default API endpoint today); EU routing planned

Text embeddings for semantic search and screening (query understanding).

Data: search and screener query text typed by the user.

United States (default API endpoint today)

OAuth sign-in (identity provider) - only for users who choose to sign in with Google.

Data: sign-in identity from the Google profile: email, name, avatar URL.

Per Google account terms (global provider)

Hostinger

Data terms

Infrastructure hosting for the database server.

Data: all service data at rest (accounts, sessions, audit log, registry data).

EU-based provider; datacenter region of the specific server pending verification

Configured, not active

Integrated in the codebase but holding no data today; listed for transparency. Each begins processing only when the corresponding feature is switched on at launch.

Transactional email (sign-in links, email verification, team invites, data-request verification). Not active: no email is sent today.

Data: recipient email address; message content including verification links.

United States

Upstash

Data terms

Redis for rate limiting. Not active: not provisioned; no data is stored there today.

Data: rate-limit counters keyed by IP address or email.

Region selected at provisioning

Payment processing and subscription billing. Activates when billing launches; no payment can be made today.

Data: billing details; VAT numbers.

US headquarters; Irish EU entity for EU customers

Register last updated 2026-07-03. We update this list before any new provider begins processing customer data.

Hosting

06

Where the data lives

The database is self-managed PostgreSQL on a server with an EU-based hosting provider; we are confirming the datacenter region of that specific server and are moving to managed, region-pinned infrastructure before commercial launch. Separately, AI queries are processed in the United States by the providers listed above.

Rights

07

Your rights

Account holdersYou can export a copy of your data (JSON) and delete your account yourself, from account settings. Deletion removes your content, scrubs personal fields, and revokes every session immediately.
Registry personsIf you appear in the registry data we serve, you can request access, correction, deletion, objection, or portability through the data subject request form. Requests are verified by an emailed challenge before they are actioned.

Agreements

08

Data processing agreement

Our data-processing terms are summarised in the Data Processing Addendum (draft, pending counsel review). To arrange a signed DPA, write to hello@momentumterminal.pl.