Legal

Privacy Policy

This page says what data Copula collects, why, how long it is kept and what you can ask for at any time. It is short because very little is collected.

Who is responsible

Copula is a personal studio with one person behind it. My name is Boris, I am the one who decides what happens to your data, and the only one with access to it. There is no team, no agency, and nobody else it gets passed to for advertising.

For anything in this text, write to me at hello@copuladev.com.

What is collected and why

Prompts by email

If you enter a keyword and your email address on the prompts page, that address and that keyword are stored, so I know which prompt to send and where you came from. The basis is your consent, given by ticking the box before you send it. The address goes to a list at Brevo, the service I send those emails through, and stays there until you unsubscribe. Unsubscribing is one click at the bottom of every email, and you can also write to me and I will delete it by hand.

Partners

For people who recommend Copula, their name, their code and the agreed commission are kept in a private list that only I can open. It is used only to pay what was agreed.

Contact form

When you send a contact form on the website, the name, the email address or phone number, the message you typed and a referral code, if there is one, are stored. The basis is your own request to be contacted. That data is used only to answer you and to prepare a quote. It goes on no mailing list and is never used for marketing. If you arrive through a partner link, its code is kept in your browser for this visit only, so it can travel with your message, and it is deleted when you close the tab.

Email and Telegram

If you write to me directly, what stays is what you typed, in my inbox or in the chat. For Telegram their own terms apply as well, since the message travels through their service before it reaches me. If that bothers you, use email or the form instead.

An account, if you ever open one

The website has no login and no accounts today. When it does, what will be stored is the email address, the password in hashed form and the state of the subscription. The basis is the contract between you and me. A password is never stored in readable form, not even I can see it, and every check of who is allowed to do what happens on the server, not in your browser.

Technical logs

The hosting provider keeps ordinary server logs: IP address, browser type and the time of the request. They exist so the website stays available and secure, on the basis of legitimate interest. I do not use them for anything else.

What is not collected

There is no tracking pixel, no profiling and no mailing list. The website sets no cookie that is not strictly necessary for it to work, which the cookie policy covers in detail. The only outside code the page loads is Cloudflare's visit counter, which works without cookies and sees visits only as totals.

Who else sees the data

  • The hosting provider, which serves the website and stores messages sent through the form.
  • The email provider, through which replies arrive and leave.
  • Cloudflare, which counts visits without cookies and shows them only as totals: which pages were opened, where the visit came from, the browser and the country.
  • Brevo, which holds the prompt list and sends those emails.
  • Telegram, but only if you write to me that way.

Data is never sold, traded or passed to anyone for advertising. When accounts and payments arrive, this list will gain a payment processor and an accountant, and it will be written here before the first account is opened.

How long it is kept

  • Enquiries and correspondence: up to twenty four months from the last message, if nothing comes of it. If something does, for as long as the work runs and afterwards for as long as tax law requires.
  • Accounts, once they exist: while the account exists, plus thirty days after deletion, which is how long backups live.
  • Server logs: briefly, under the hosting provider's own rules.

How it is kept

All communication with the website runs over an encrypted connection. Messages from the form sit in the hosting provider's account, which is locked with two factor authentication. Once accounts exist, passwords will be hashed with a current algorithm, the session will live in a cookie JavaScript cannot read, and every permission check will happen on the server, on every request.

Your rights

You can ask for a copy of your data, a correction, deletion, a restriction of processing or object to it, and you can ask for your data in a portable form. Write to hello@copuladev.com and you will have an answer within thirty days at the latest, usually the same day.

If you believe I have handled something wrongly, you can also contact the Serbian Commissioner for Information of Public Importance and Personal Data Protection, or the supervisory authority in your own country.

Changes

If this policy changes, the date below changes with it. Once there are accounts, significant changes will also arrive by email.

Last updated on 19 September 2026.