Privacy Policy
In effect from 31 August 2026. If you are a consultant, section 1 and section 5 are the two your own client will ask about.
1. Two different roles, and the difference matters
Most privacy policies describe one relationship. This service has two, because our customers are consultants who work on other organisations' systems.
For the material you bring into the platform, we are your processor and you are the controller. That is your uploaded documents, the configuration we read from an environment you connect, the guides and deliverables you generate, and the questions you ask. You decide what goes in, what it is for, and how long it stays. We act on your instructions and do not decide anything about it ourselves.
For your own relationship with us we are the controller: your account, your billing, support conversations, and ordinary website analytics.
If you are a consultant, the first of those is the part your own client will ask you about, and this page is written so you can hand it to them.
2. What we process as your processor
Documents you upload, and everything derived from them: extracted text, page structure, the searchable index, terminology, and any guide or deliverable generated from them. Configuration read from an environment you connect, which is setup data rather than transactional records. The questions you ask and the answers returned, kept so a conversation can be reopened.
Credentials for a connected environment. These are encrypted with AES-256-GCM before they reach storage and are never returned to any screen or API response, including after you save them. They belong to your subscription rather than to a project, and removing a connection deletes the stored credential.
We ask you not to upload personal data a project does not need. Configuration and design documents rarely require it, and the least risky data is the data that was never sent.
3. What we process as controller
Account: your name, email address, hashed password, and which seats you hold. Passwords are hashed with scrypt and a per-password salt; we never store or see the password itself.
Billing: plan, seat count, billing history and the currency you chose. Card details are handled entirely by Stripe and never reach our servers.
Support and contact: whatever you send us, kept so we can answer and refer back to it.
Analytics: the page path, how long a page was read, the referring site's hostname, any campaign tags in the link, the country reported by our network provider, and the browser's user agent string. Your IP address is hashed with a secret salt to count returning visitors and is not stored in the clear. Requests that look like crawlers are discarded rather than recorded.
4. Why we are allowed to process it
For your account and your subscription: performance of our contract with you. For security, fraud prevention, product analytics and answering your messages: our legitimate interests in running a service that works and is not abused. For tax and accounting records: a legal obligation. Where we ask for consent, such as marketing email, consent is the basis and you can withdraw it at any time.
For Customer Content we do not determine a basis of our own. You do, as controller, and we process it on your instructions.
5. Who else processes it
We use the providers below. Each is engaged under terms requiring appropriate security and permitting them to process the data only to provide their service to us. This list is generated from the same file the application reads, so it does not drift from what the code actually calls.
| Provider | What it does | What reaches it | Where |
|---|---|---|---|
| Render | Application hosting and the primary database | Everything stored by the service, including account records, uploaded documents, configuration readings and sealed credentials | United States (Oregon) |
| Cloudflare R2 | File storage | Toolkit files, uploaded source documents and generated exports | Global object storage |
| Anthropic | Generating answers, guides and deliverables | Extracts of your documents and configuration readings relevant to a request, and the text of the request | United States |
| Voyage AI | Embeddings and reranking, which make documents searchable | Text extracted from your documents, and your search queries | United States |
| Stripe | Payments and subscription billing | Billing name, email, card details and payment history. Card numbers never reach our servers | United States and European Union |
| Resend | Transactional email | Your email address and the contents of the messages we send you | United States |
6. An environment you connect is not one of them
An Oracle environment you connect is not a sub-processor of ours. It is your system or your End Client's, and we read it only when you ask us to, using credentials you supply.
We read it only when you ask us to, with credentials you supply, and we do not write to it. Whether you may grant that access is a question between you and its owner, and our Terms make it your responsibility because we have no way to verify it.
7. Artificial intelligence, and training
Parts of the service send extracts of your material to Anthropic and Voyage AI so that answers, guides, deliverables and search can work at all. Only the parts relevant to a request are sent, not your whole corpus.
We do not train models on Customer Content, and we do not use one customer's content to improve results for another. Our AI providers are engaged on terms that do not permit them to train their models on what we send.
Model output is a draft. Our Terms require you to check it before relying on it, and that obligation exists because we cannot check it for you.
8. Where it goes
Our hosting and most of our providers are in the United States, so your data is transferred outside the United Kingdom and the European Economic Area. Where that happens we rely on the transfer mechanisms our providers offer, which for each of the above is a set of Standard Contractual Clauses or an equivalent approved mechanism.
If your engagement or your client's policies restrict where their information may be sent, check that against this section before uploading anything. It is easier to decide now than to withdraw it later.
9. How it is protected
Traffic is encrypted in transit. Passwords are hashed with scrypt. Credentials for a connected environment are sealed with AES-256-GCM and never returned. Access to a project is re-checked from the database on every request rather than trusted from a cookie or a session claim, so removing someone's access takes effect immediately.
Staff access to Customer Content is limited to those who need it, and we access it only to run the service, to fix a fault you have reported, or where the law requires it.
No service is perfectly secure. If a breach affects your data we will tell you without undue delay and give you what you need for your own notifications.
10. How long it is kept
Customer Content is kept while your account is active and for 30 days after it ends, so you can export it. After that it is deleted on our normal schedule, with backups expiring in turn.
You can delete documents, projects and connections yourself at any time, which removes them from the live service immediately.
Billing records are kept as long as tax law requires. Analytics is aggregate and retained only as long as it is useful for understanding the site.
11. Your rights
You can ask for a copy of your personal data, correct it, delete it, restrict or object to processing, or ask us to send it elsewhere. Email us and we will respond within 30 days. Records we must keep by law are the one exception.
If you are unhappy with how we have handled a request you can complain to your data protection regulator, which in the United Kingdom is the Information Commissioner's Office.
12. If your data reached us through a consultant
If you are an End Client, or an individual whose information appears in a document a consultant uploaded, we are that consultant's processor and not the controller of it. We cannot lawfully act on a request about that data without their instruction, and we may not be able to identify you within it.
Contact the consultant or firm you are working with. If you cannot, write to us and we will pass the request to the account holder concerned.
13. Cookies
We use cookies that the service needs to function: a signed session cookie when you are signed in, a short-lived cookie during a password reset, and cookies remembering which project and workstream you last opened so a reload does not lose your place. Your currency preference and a few interface preferences are kept in the browser's own storage rather than sent to us.
We do not use advertising cookies and we do not share data with advertising networks. Our analytics sets no tracking cookie: returning visitors are counted with a salted hash of the IP address instead.
14. Changes and contact
We may update this policy. For material changes we will give reasonable notice by email or in the product. This version is in effect from 31 August 2026.
Privacy questions, a data subject request, or a data processing agreement for your client’s file: hello@u2xai.com. We answer these at the same address rather than a separate alias, so a request never bounces.