gairėLietuviškai

Privacy Policy

Last updated: 9 October 2026

Gairė watches the web pages you choose and tells you when they change. This policy says what personal data that takes, why we hold it, who else handles it, and what you can do about it.

It covers gaire.lt, the dashboard, the alerts we send, and the connection for AI agents.

Who is responsible

Gairė is run by MB Moku Programuoti, legal entity code 305756289, registered at A. Vivulskio g. 41, Vilnius, Lithuania. We are the data controller for the data described here.

Write to maksim@mokuprogramuoti.lt about anything in this policy.

What we hold

We hold only what the service needs to work.

Your account
The email address you sign in with. If you sign in with Google, Google also gives us the name and picture on your Google account. The settings you choose: name, company, time zone, language and quiet hours.
Sign-in records
For each device you sign in on: the time, the IP address, the browser and operating system, and the city and country the IP address points to. You can see them and end them under Settings → Security.
Sign-in emails asked for
When a sign-in link is asked for, we keep a one-way hash of the email address and of the IP address it was asked from, so that we can limit how many of those emails we send.
Your watches
The address of each page you watch, what you asked us to look for, anything you type to describe it, and your corrections and ratings.
What we find
Each check and its result, the changes we detect, and screenshots of the page taken to show a change. These are copies of other people's pages, not information about you, but they are tied to your account.
Recipients
For each person or system you send alerts to: the name you give it, and a phone number, an email address or a webhook address. Also whether it has been verified and whether it has opted out.
Messages
Every alert, verification code and digest we send: its text, where it went, and what the delivery provider reported back.
Connected agents
If you connect an AI agent: the app's name, what you allowed it to do, when it was connected and when it was last used.
Setup reports
When a page cannot be set up, we keep a report so that we can fix it: your email address, the page's address, what you typed about it, and the AI's conversation about the page. The report is emailed to us.
Usage counts
How many messages your account has sent in a month, how many a number or address has received, and how many AI runs your account has made in a day. We keep them to hold accounts to their limits.
Numbers that stopped our texts
If a phone replies STOP to one of our texts, or the person uses the stop link that an alert leads to, we keep a one-way hash of that number, so that no account can have us text it again.
Technical logs
Our web host logs each request with its IP address and browser. Before you sign in, a bot check by Cloudflare reads your IP address and browser details when you load a page to watch. We set three cookies; see Cookies.

Each watch has a public record page. Anyone who has its link can see the name you gave the watch, the page's address, how often we checked it and what we caught or missed. It does not show who you are or who gets the alerts. The link inside an alert opens a page that shows that one change to anyone who has the link.

We do not buy data about you, we do not build advertising profiles, and the site carries no analytics or advertising trackers.

If someone added you as a recipient

An account holder can add other people to receive alerts. If that is you, we hold the phone number or email address they entered, the name they gave you, the messages we sent you, and whether they were delivered.

We send no alerts until the number or address has been confirmed with a code sent to it.

To stop the messages: every alert email has an unsubscribe link at the bottom. For text messages, open the link in an alert and choose "Stop these texts" on that page; you can also ask the person who added you, or write to maksim@mokuprogramuoti.lt and we will stop them ourselves.

You have the same rights over this data as an account holder; see Your rights.

Why we use it, and on what legal basis

To run your account and your watches
Checking pages, detecting changes, sending the alerts you asked for, and showing you the history. Legal basis: our contract with you (GDPR Article 6(1)(b)).
To send alerts to the recipients you add
Legal basis: our legitimate interest, and yours, in delivering the alerts you set up to people who confirmed the number or address (Article 6(1)(f)).
To keep the service secure and within its limits
Sign-in records, the limit on sign-in emails, the bot check, usage counts, the numbers that stopped our texts, and stopping misuse. Legal basis: our legitimate interest in a service that is safe and not abused (Article 6(1)(f)).
To fix what goes wrong
When a check fails, a page cannot be set up, or you report a missed change, we look at that watch or page and its records. Legal basis: our contract with you, and our legitimate interest in a service that works (Article 6(1)(b) and (f)).
To meet legal duties
If the law requires us to keep something or hand it over, we do. Legal basis: legal obligation (Article 6(1)(c)).

We make no automated decisions about you that have a legal or similarly significant effect. We do not send marketing.

How AI is used

When you add a page, or correct what a watch looks for, we send the page's address, an outline of its structure, a few sample rows and anything you typed to Anthropic's Claude models, to work out what to watch. Your email address, your phone numbers and your recipients are not sent. If the setup fails, that conversation goes into the setup report described above.

If you connect an AI agent to your account, it can see and do what you allowed on the consent screen, and the company behind that agent handles what it reads under its own terms. You can disconnect an agent at any time under Settings → Agents.

Who else handles your data

We use the providers below to run Gairė. Each one, as our data processor, handles only what its job needs.

Supabase (database and file storage)
Everything of record: your account, watches, results, recipients and messages. Stored in Stockholm, Sweden.
Hostinger (the server that checks pages)
Loads the pages you watch and hands alerts on for sending. Located in Vilnius, Lithuania.
Vercel (web hosting)
Serves the site and the dashboard from Stockholm. Its request logs, with your IP address and browser, are processed in the United States.
Google Firebase Authentication (sign-in)
Your sign-in email address, IP address and browser. Processed in the United States.
Cloudflare (bot check)
Your IP address and browser details, when you load a page to watch before signing in. Processed in the United States and the European Economic Area.
Resend (email delivery)
Recipients' email addresses and the emails we send them, the address you sign in with and the sign-in link we email to it, and the setup reports sent to us. Stored in the United States.
Infobip (text messages)
Recipients' phone numbers and the texts we send them. Stored and processed in the European Union; Infobip's support staff may open them from outside it.
Anthropic (AI models)
What is described under How AI is used. Processed in the United States and other countries.

To load the pages you watch we also use network providers: internet connections in Lithuania and, for a few sites, a page-loading service in the United States that fetches the page through a Lithuanian address. They receive the page's address and nothing about you.

We do not sell personal data, and we share it with no one else unless the law requires it.

Data outside the EU

Your account, your watches and their history are stored in the EU. Five providers process part of your data outside it, mainly in the United States: Google (your sign-in), Cloudflare (the bot check before you sign in), Resend (the emails we send and the addresses they go to), Anthropic (the AI features) and Vercel (our web host's logs).

Those transfers rely on the safeguards EU law provides: the European Commission's standard contractual clauses or the EU–US Data Privacy Framework, as each provider's data processing terms set out. Write to us if you want a copy of the terms that apply.

How long we keep it

Your account, watches, recipients and their history
Until you remove them or delete your account.
Screenshots of a change
30 days after the change. The record of the change itself stays.
Sign-in records
Until you delete your account.
Sign-in emails asked for
One day.
Setup reports
90 days.
Usage counts
These outlast a removed recipient or a deleted account, so that a limit cannot be reset by deleting and starting again. They hold numbers and no content. Messages an account sent, under its internal identifier, and messages a number or address received, with the number or address scrambled: this month and the last. AI runs: one day.
Numbers that stopped our texts
Until the person whose number it is asks us to remove it.
Diagnostic records of our own page loads
Up to 14 days.
Web host logs
Kept by our web host for a limited time, under its own retention.

When you delete your account, your sign-in, account, watches, recipients, messages, setup reports and history are erased from our database at once. The usage counts and the numbers that stopped our texts stay. Copies in our database provider's backups go when those backups expire.

Cookies

We set three cookies, each for a year, and none of them tracks you: your language, your light or dark theme, and whether the dashboard's sidebar is collapsed.

Your sign-in is kept in your browser's storage by Firebase Authentication. If you sign in with Google, Google sets its own cookies on its own pages. The bot check that runs before you sign in is loaded from Cloudflare.

There are no analytics, advertising or social media cookies, which is why there is no cookie banner.

Your rights

Under the GDPR you can:

  • See your data and download it. Settings → Privacy → Export your data gives you all of it as one file.
  • Correct it. Most of it you can edit in the dashboard.
  • Delete it. Settings → Danger zone erases your history or your whole account.
  • Object to how we use it, or ask us to restrict it.
  • Take it elsewhere: the export is a machine-readable JSON file.

For anything the dashboard cannot do, write to maksim@mokuprogramuoti.lt. We answer within one month.

If you think we have handled your data wrongly, you can complain to the State Data Protection Inspectorate of Lithuania (vdai.lrv.lt), or to the authority where you live.

Keeping it safe

Connections to Gairė are encrypted, and access to the database is limited to the people who run the service. If a breach puts your data at risk, we will tell you and the regulator as the law requires.

Children

Accounts are for adults. We do not knowingly open one for anyone under 18; if you believe one exists, write to us and we will delete it.

Changes to this policy

When this policy changes we update the date at the top. If a change matters to how we use your data, we email account holders before it takes effect.