Last updated: January 1, 2026
1. Introduction
Forklar Meg ("we", "us", "our") is committed to protecting your privacy. This privacy policy explains how we collect, use, store and protect your personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act.
2. Data Controller
The data controller for the personal data processed in Forklar Meg is:
3. What Information Do We Collect?
We collect the following categories of personal data:
3.1 Automatically collected information:
- User ID without a name (created automatically). It is not linked to your name, but it follows you between sessions and ties your analyses together — so it is not anonymous in the legal sense.
- Time of service use
- Technical device information (for troubleshooting only)
3.2 Information you provide:
- Documents you upload for analysis
- Questions you type or speak into the Explainer (free text about a situation)
- Audio you record yourself — when you speak a question into the Explainer, or record audio in Blackbox. The recording is sent for speech-to-text only when you choose that.
- Location — only if you choose to attach a place to a Blackbox entry. The app then reads your position and turns it into an address. Stored encrypted on your phone, not on our servers.
- Email address (only upon registration or support)
3.3 Local data (never uploaded):
In the "Resources" section, you can register your sick days and absence for sick child. These data are stored ONLY locally on your device:
- Local Storage: These data are stored only on your phone (Local Storage)
- No upload: Forklar Meg never sends, processes or stores this information on our servers
- Your control: If you delete the app, these data are permanently deleted. We have no way to recover them
3.5 Sensitive Data (GDPR Art. 9)
Some documents you choose to upload may contain sensitive personal data, in particular health information – for example self-certified sick leave, sick notes, care days for children, or insurance matters concerning illness or disability. Under GDPR Article 9 these are "special categories" with stricter rules.
- Legal basis: Your explicit consent (Art. 9(2)(a)). You give it by choosing to upload the document for analysis, and you can withdraw it at any time.
- Withdrawing consent: Delete the analysis, or delete all your data under Settings. Withdrawal does not affect processing already carried out.
- Extra protection: National ID numbers, account numbers, phone numbers and email addresses are removed automatically before the text is sent for AI analysis. Blackbox, which may contain health-related absence records, is stored encrypted on your device. Nothing leaves the phone unless you actively choose to have an audio recording transcribed or a log summarised — and you are asked for consent first.
You are never required to upload a document containing health data. If you prefer, you can remove or black out such information before uploading.
3.6 Evidence you log yourself — your responsibility
Audio recordings, photos and notes you log in Blackbox are stored locally on your own device and are not uploaded by the app; the text fields are additionally stored encrypted. The lawfulness of the capture itself is your responsibility: recording conversations you take part in is generally legal, covert recording of conversations between others is a criminal offence (Norwegian Penal Code section 205), photos of people can generally not be shown publicly without consent (Copyright Act section 104), and sharing degrading or clearly private recordings can be a criminal offence even towards a single recipient (Penal Code section 267 a). Privacy law may additionally apply to your own use and sharing of recordings — the exemption for purely private purposes is narrow. The app reminds you of this before you log evidence for the first time.
4. Legal Basis (GDPR Art. 6)
We process your personal data based on the following legal grounds:
- Contract (Art. 6(1)(b)): Processing necessary to fulfill the agreement to provide the service to you.
- Legitimate interest (Art. 6(1)(f)): To improve the service and ensure secure operation.
- Consent (Art. 6(1)(a)): For processing that requires your explicit consent.
5. How Do We Use the Information?
Your personal data is used to:
- Analyze documents and text you submit
- Store history of your analyses
- Improve service quality (aggregated, non-content statistics only — never training on your documents)
- Provide technical support
- Fulfill legal obligations
6. Sharing of Information
We share your information with:
- OpenAI: Used for five purposes: primary AI analysis of documents, semantic search (an extract of the document text is sent on every analysis to find relevant law), speech-to-text and text-to-speech in Blackbox, and answering law questions in the Explainer. Your question is sent together with the retrieved statutory text, after national ID numbers, phone numbers and e-mail addresses have been removed; if our word search finds no clear match, the question is also sent to a second OpenAI service (embeddings) to find similar laws. The question is not stored by us. The answer is kept with no link to you and without the question text, so that an identical question can get the same answer again for 14 days; the answer may repeat details you typed in. USA, Standard Contractual Clauses. Never used to train models.
- Google Firebase & Cloud Vision: Authentication, storage and text recognition (OCR) in images. EU + USA, data processing agreement in place. We do not collect usage statistics.
- RevenueCat: Subscription and payment management (USA, Standard Contractual Clauses)
- Sentry: Crash and error reporting (USA, Standard Contractual Clauses)
We never sell your personal data to third parties.
7. Storage and Security
Your data is stored on servers within the EEA. Your analyses and history are stored in Sweden (Google Cloud region europe-north2, Stockholm), and uploaded document files in Belgium (europe-west1). The data is protected with:
- Encryption in transit (TLS/SSL)
- Encryption at rest
- Access control and logging
- Regular security audits
Documents you upload are deleted automatically 24 hours after the analysis, and personal ID numbers are removed automatically before AI processing. Explanations (analyses) are kept until you delete them.
8. Your Rights (GDPR Art. 15-22)
You have the following rights:
- Access: You can request a copy of all information we have about you.
- Rectification: You can request that incorrect information be corrected.
- Erasure: You can request that your information be deleted ("right to be forgotten").
- Restriction: You can request that processing be restricted.
- Data portability: You can request to receive your data in a machine-readable format.
- Objection: You can object to certain types of processing.
- Automated decisions: You have the right not to be subject to decisions based solely on automated processing that have legal effects for you. See section 8.5.
To exercise your rights, use "Delete all my data" in settings, or contact us at support@forklaraimeg.no.
8.5 Automated Processing (GDPR Art. 22)
The Service analyses your document automatically using AI. It does not make decisions about you.
- Article 22 covers decisions based solely on automated processing that produce legal effects or similarly significantly affect you. The Service produces an explanation – it does not grant, refuse, price or decide anything concerning you. You decide yourself what to do with the explanation.
- The explanation is AI-generated and can contain errors. If an analysis contains incorrect information about you, the right to rectification (Art. 16) and erasure (Art. 17) applies – see section 8.
- All AI-generated content in the app is marked as such, in line with the EU AI Act Article 50.
- We do not use your documents for profiling, and we do not build behavioural profiles across users.
9. Retention Period
We store your information for the following periods:
- Uploaded documents: Deleted automatically after 24 hours
- AI provider (OpenAI): Content may be retained up to 30 days solely for abuse monitoring, then deleted. Never used for training.
- Analysis results: Until you delete them
- Explainer quota: The number of questions per day is stored per user, and deleted with the account
- Explainer statistics: One anonymous note per answer listing which laws and sections were looked up, and the day it happened. No question text, no user ID, no time of day
- Blackbox incidents: Stored locally until you delete
- Account information: Until account is deleted
- Invoices/payment info: 5 years (accounting law)
10. Right to Complain
If you believe we process your personal data in violation of privacy regulations, you have the right to complain to the Data Protection Authority:
11. Changes
We may update this privacy policy from time to time. For material changes, you will be notified in the app.
12. Legal References
This privacy policy is prepared in accordance with:
- EU General Data Protection Regulation (GDPR) - Regulation (EU) 2016/679
- Norwegian Personal Data Act - Act on the processing of personal data (LOV-2018-06-15-38)
About this website
This website measures page views with Vercel Web Analytics. The measurement runs from our own domain, without cookies and without a third party. What is recorded is which page was opened, which page you came from, country and browser type. To count unique visits Vercel creates a hash of the request that is replaced daily; your IP address is not stored. The measurement says nothing about who you are, and it is not linked to your use of the app.
Questions? Contact us at support@forklaraimeg.no
