Privacy Policy
Last updated: 9 October 2026
Gairė watches the web pages you choose and tells you when they change. This policy says what personal data that takes, why we hold it, who else handles it, and what you can do about it.
It covers gaire.lt, the dashboard, the alerts we send, and the connection for AI agents.
Who is responsible
Gairė is run by MB Moku Programuoti, legal entity code 305756289, registered at A. Vivulskio g. 41, Vilnius, Lithuania. We are the data controller for the data described here.
Write to maksim@mokuprogramuoti.lt about anything in this policy.
What we hold
We hold only what the service needs to work.
- Your account
- The email address you sign in with. If you sign in with Google, Google also gives us the name and picture on your Google account. The settings you choose: name, company, time zone, language and quiet hours.
- Sign-in records
- For each device you sign in on: the time, the IP address, the browser and operating system, and the city and country the IP address points to. You can see them and end them under Settings → Security.
- Sign-in emails asked for
- When a sign-in link is asked for, we keep a one-way hash of the email address and of the IP address it was asked from, so that we can limit how many of those emails we send.
- Your watches
- The address of each page you watch, what you asked us to look for, anything you type to describe it, and your corrections and ratings.
- What we find
- Each check and its result, the changes we detect, and screenshots of the page taken to show a change. These are copies of other people's pages, not information about you, but they are tied to your account.
- Recipients
- For each person or system you send alerts to: the name you give it, and a phone number, an email address or a webhook address. Also whether it has been verified and whether it has opted out.
- Messages
- Every alert, verification code and digest we send: its text, where it went, and what the delivery provider reported back.
- Connected agents
- If you connect an AI agent: the app's name, what you allowed it to do, when it was connected and when it was last used.
- Setup reports
- When a page cannot be set up, we keep a report so that we can fix it: your email address, the page's address, what you typed about it, and the AI's conversation about the page. The report is emailed to us.
- Usage counts
- How many messages your account has sent in a month, how many a number or address has received, and how many AI runs your account has made in a day. We keep them to hold accounts to their limits.
- Numbers that stopped our texts
- If a phone replies STOP to one of our texts, or the person uses the stop link that an alert leads to, we keep a one-way hash of that number, so that no account can have us text it again.
- Technical logs
- Our web host logs each request with its IP address and browser. Before you sign in, a bot check by Cloudflare reads your IP address and browser details when you load a page to watch. We set three cookies; see Cookies.
Each watch has a public record page. Anyone who has its link can see the name you gave the watch, the page's address, how often we checked it and what we caught or missed. It does not show who you are or who gets the alerts. The link inside an alert opens a page that shows that one change to anyone who has the link.
We do not buy data about you, we do not build advertising profiles, and the site carries no analytics or advertising trackers.
If someone added you as a recipient
An account holder can add other people to receive alerts. If that is you, we hold the phone number or email address they entered, the name they gave you, the messages we sent you, and whether they were delivered.
We send no alerts until the number or address has been confirmed with a code sent to it.
To stop the messages: every alert email has an unsubscribe link at the bottom. For text messages, open the link in an alert and choose "Stop these texts" on that page; you can also ask the person who added you, or write to maksim@mokuprogramuoti.lt and we will stop them ourselves.
You have the same rights over this data as an account holder; see Your rights.
Why we use it, and on what legal basis
- To run your account and your watches
- Checking pages, detecting changes, sending the alerts you asked for, and showing you the history. Legal basis: our contract with you (GDPR Article 6(1)(b)).
- To send alerts to the recipients you add
- Legal basis: our legitimate interest, and yours, in delivering the alerts you set up to people who confirmed the number or address (Article 6(1)(f)).
- To keep the service secure and within its limits
- Sign-in records, the limit on sign-in emails, the bot check, usage counts, the numbers that stopped our texts, and stopping misuse. Legal basis: our legitimate interest in a service that is safe and not abused (Article 6(1)(f)).
- To fix what goes wrong
- When a check fails, a page cannot be set up, or you report a missed change, we look at that watch or page and its records. Legal basis: our contract with you, and our legitimate interest in a service that works (Article 6(1)(b) and (f)).
- To meet legal duties
- If the law requires us to keep something or hand it over, we do. Legal basis: legal obligation (Article 6(1)(c)).
We make no automated decisions about you that have a legal or similarly significant effect. We do not send marketing.
How AI is used
When you add a page, or correct what a watch looks for, we send the page's address, an outline of its structure, a few sample rows and anything you typed to Anthropic's Claude models, to work out what to watch. Your email address, your phone numbers and your recipients are not sent. If the setup fails, that conversation goes into the setup report described above.
If you connect an AI agent to your account, it can see and do what you allowed on the consent screen, and the company behind that agent handles what it reads under its own terms. You can disconnect an agent at any time under Settings → Agents.
Who else handles your data
We use the providers below to run Gairė. Each one, as our data processor, handles only what its job needs.
- Supabase (database and file storage)
- Everything of record: your account, watches, results, recipients and messages. Stored in Stockholm, Sweden.
- Hostinger (the server that checks pages)
- Loads the pages you watch and hands alerts on for sending. Located in Vilnius, Lithuania.
- Vercel (web hosting)
- Serves the site and the dashboard from Stockholm. Its request logs, with your IP address and browser, are processed in the United States.
- Google Firebase Authentication (sign-in)
- Your sign-in email address, IP address and browser. Processed in the United States.
- Cloudflare (bot check)
- Your IP address and browser details, when you load a page to watch before signing in. Processed in the United States and the European Economic Area.
- Resend (email delivery)
- Recipients' email addresses and the emails we send them, the address you sign in with and the sign-in link we email to it, and the setup reports sent to us. Stored in the United States.
- Infobip (text messages)
- Recipients' phone numbers and the texts we send them. Stored and processed in the European Union; Infobip's support staff may open them from outside it.
- Anthropic (AI models)
- What is described under How AI is used. Processed in the United States and other countries.
To load the pages you watch we also use network providers: internet connections in Lithuania and, for a few sites, a page-loading service in the United States that fetches the page through a Lithuanian address. They receive the page's address and nothing about you.
We do not sell personal data, and we share it with no one else unless the law requires it.
Data outside the EU
Your account, your watches and their history are stored in the EU. Five providers process part of your data outside it, mainly in the United States: Google (your sign-in), Cloudflare (the bot check before you sign in), Resend (the emails we send and the addresses they go to), Anthropic (the AI features) and Vercel (our web host's logs).
Those transfers rely on the safeguards EU law provides: the European Commission's standard contractual clauses or the EU–US Data Privacy Framework, as each provider's data processing terms set out. Write to us if you want a copy of the terms that apply.
How long we keep it
- Your account, watches, recipients and their history
- Until you remove them or delete your account.
- Screenshots of a change
- 30 days after the change. The record of the change itself stays.
- Sign-in records
- Until you delete your account.
- Sign-in emails asked for
- One day.
- Setup reports
- 90 days.
- Usage counts
- These outlast a removed recipient or a deleted account, so that a limit cannot be reset by deleting and starting again. They hold numbers and no content. Messages an account sent, under its internal identifier, and messages a number or address received, with the number or address scrambled: this month and the last. AI runs: one day.
- Numbers that stopped our texts
- Until the person whose number it is asks us to remove it.
- Diagnostic records of our own page loads
- Up to 14 days.
- Web host logs
- Kept by our web host for a limited time, under its own retention.
When you delete your account, your sign-in, account, watches, recipients, messages, setup reports and history are erased from our database at once. The usage counts and the numbers that stopped our texts stay. Copies in our database provider's backups go when those backups expire.
Your rights
Under the GDPR you can:
- See your data and download it. Settings → Privacy → Export your data gives you all of it as one file.
- Correct it. Most of it you can edit in the dashboard.
- Delete it. Settings → Danger zone erases your history or your whole account.
- Object to how we use it, or ask us to restrict it.
- Take it elsewhere: the export is a machine-readable JSON file.
For anything the dashboard cannot do, write to maksim@mokuprogramuoti.lt. We answer within one month.
If you think we have handled your data wrongly, you can complain to the State Data Protection Inspectorate of Lithuania (vdai.lrv.lt), or to the authority where you live.
Keeping it safe
Connections to Gairė are encrypted, and access to the database is limited to the people who run the service. If a breach puts your data at risk, we will tell you and the regulator as the law requires.
Children
Accounts are for adults. We do not knowingly open one for anyone under 18; if you believe one exists, write to us and we will delete it.
Changes to this policy
When this policy changes we update the date at the top. If a change matters to how we use your data, we email account holders before it takes effect.