Privacy Notice
What we collect, why we collect it, and what you can ask us to do about it.
Last updated 3 September 2026. Changed since 1 September 2026: our website no longer offers a cookie choice, because it sets no cookie and stores nothing on your device, and the three places that described that choice now say so.
In short. We collect the minimum needed to run the service: your name and email so you have an account, and what you use inside the platform so we can improve it. If you start a free trial we email you eight times over three weeks, three of those messages tell you what a subscription costs, and you can refuse the lot at sign-up or in one click from any of them. We do not sell your data, we do not use it to train AI models, and we do not run third-party advertising or tracking on our website.
Who we are
Signalcroft AI Ltd is the data controller for the personal data described here. We are registered in England and Wales, company number 17364692, with our registered office at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ.
We are registered with the Information Commissioner's Office, the UK data protection regulator, under registration number ZC209326. You can check that entry on the ICO's public register of fee payers.
For any privacy question, or to exercise any right below, email [email protected]. A person reads it and we aim to reply within five working days, and always within one month as the law requires.
What we collect, and why
| What | Why we need it | Lawful basis |
|---|---|---|
| Name and email | To create your account, sign you in, and send service messages such as your trial confirmation and password resets | Contract |
| Your email address and your trial dates, while your trial runs and for three weeks from the day it starts | To send the eight-message trial sequence described below, three of which state what a subscription costs and invite you to take one | Legitimate interests, and the soft opt-in at regulation 22 of the Privacy and Electronic Communications Regulations for the three that ask you to buy |
| Password | To protect your account. We never store it: we keep only a one-way cryptographic hash, and we check new passwords against a public breach database so you cannot pick one already exposed | Contract |
| Sign-in sessions | To keep you signed in securely and let you sign out | Contract |
| Which sections you open | To see which parts of the platform earn their place and which do not, so we improve the right things | Legitimate interests |
| Ratings and posts you write | To show your contributions to colleagues in your own organisation | Contract |
| Website visits | To count visitors and see which pages work. No cookie is set, nothing is stored on your device, and we never store your IP address | Legitimate interests |
| Emails we send you | To keep a record that a message was sent and delivered, so we can help if something goes missing | Legitimate interests |
| Name, job title and employer of a senior person at a firm we approach, taken from that firm's own website or from public trade coverage | To make one business approach to the person whose job it is to decide, rather than to a general address nobody owns | Legitimate interests, assessed and recorded before any approach. Your objection ends it immediately |
Where we rely on legitimate interests, we have considered your rights and concluded that the processing is limited, expected, and does not override them. You can object at any time using the contact address above.
Email while your trial runs
Starting a free trial puts you on a fixed sequence of eight messages over three weeks. It is written once and sent to everyone on the same schedule. Nobody reads your account and decides to write to you.
- Days 0, 1, 3 and 7 help you get started and tell you the date your fourteen days end.
- Days 11, 13 and 14 state what a subscription costs and invite you to take one. These are direct marketing, and we describe them as such rather than calling them anything else.
- Day 21 goes only to people whose trial ended without subscribing, and asks one question about what would have made it worth paying for.
We rely on legitimate interests, and on the soft opt-in at regulation 22 of the Privacy and Electronic Communications Regulations, which permits email about our own similar services to someone who gave us their address while considering buying one. That permission carries a condition and we meet it: the sign-up form offers you the choice to refuse the sequence at the point you give us the address, before anything is sent. The day-21 message asks a question and sells nothing, so it is research rather than marketing. We put it under the same refusal as everything else because that distinction matters to us and should not have to matter to you.
Every message in the sequence carries a one-click opt-out that needs no sign-in, no password and no reply. Using it stops the whole sequence at once, including the reminders about when your trial ends. It never affects your trial, your account, or any service message such as a password reset, and once you have opted out nothing puts you back on.
If we approached you and you never gave us anything
We research firms we think would benefit from what we do, and sometimes that research names a person: usually the chief executive, a managing partner or whoever owns technology decisions. We take that from the firm's own website or from public trade coverage. We do not buy lists, we do not scrape anything behind a login, and we hold nothing about you beyond your name, your role and where you work.
We rely on legitimate interests, and we assessed and wrote down that decision before approaching anyone rather than after. If we write to you, the first message says where we found you and how to stop it. One reply saying stop is enough: no form, no sign-in, no reason needed. We keep your name on a do-not-contact list afterwards, because that is the only way to be sure we do not write again.
You have the same rights here as anyone else in this notice, including the right to see what we hold and to have it deleted. An objection to marketing is absolute: we do not weigh it against anything.
What we do not do
- We do not sell or rent your personal data to anyone.
- We do not use your personal data, your content or your usage to train AI models, and our AI supplier is contractually barred from training on it.
- We do not run third-party advertising, marketing pixels or analytics trackers on our website. Our measurement is our own and stays on our own systems.
- We do not store your IP address in our website analytics.
Who else processes your data
We use a small number of suppliers to run the service. Each acts only on our instructions under a data processing agreement, except where the table says otherwise: our payment provider also decides some things for itself, because the law that governs payments requires it to.
| Supplier | What they do | Where |
|---|---|---|
| Cloudflare | Hosts the platform and stores its database | Global edge network, with EU and UK presence |
| Resend | Delivers our emails to you | EU region |
| Google Workspace | Our business mailbox, when you email us | EU and US |
| Anthropic | Provides the AI models behind the service | US, under terms that forbid training on our data |
| Stripe | Takes your payment and holds your billing details. Your card number never reaches us | UK, EU and US. On our instructions for the subscription itself, and a controller in its own right for payment processing, fraud prevention and the records financial regulation requires it to keep |
Where a supplier processes data outside the UK, the transfer is covered by the UK International Data Transfer Addendum or equivalent safeguards approved under UK law.
Your organisation and what colleagues can see
If you sign up with a work email address, anything you post to the community board is visible to colleagues who share your email domain, and to nobody outside it. If you use a personal email provider such as Gmail or Outlook, you are treated as an organisation of one and no other member can see your posts or your name.
How long we keep it
- Account details: while your account is open, and for up to 90 days after you close it in case you return or a dispute arises.
- Sign-in sessions: up to 30 days, then they expire automatically.
- Usage records: up to 24 months, after which they are aggregated so they no longer identify you.
- Website analytics: up to 24 months.
- Email delivery records: 12 months. The contents of any message containing a password are erased as soon as it is delivered.
- Which trial messages you were sent: for as long as your account is open, so a message can never be sent twice. If you opt out, we keep a record of that refusal for as long as we hold your address, because it is the only way to be certain the choice stays honoured.
- Records we must keep by law, such as accounting records, are kept for the period the law requires.
Your rights
Under UK GDPR you can ask us to:
- Give you a copy of the personal data we hold about you.
- Correct anything inaccurate.
- Delete your data. Deleting your account removes your profile, sessions, posts, ratings and saved notes.
- Restrict or object to processing, including anything we do on the basis of legitimate interests.
- Receive your data in a portable, machine-readable format.
- Withdraw consent at any time where we relied on it. Withdrawing consent does not affect anything done before you withdrew it.
Email [email protected] and we will act without charge. If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you told us first so we can put it right.
Cookies and similar technology
Our website sets no cookie and stores nothing on your device. Each visit is counted on its own, on our own systems, and is not linked to any other visit, so there is no choice to make and nothing to withdraw. If you made a choice under the banner we ran before 2 September 2026, the record of it is removed from your browser the next time you visit and is never read.
The platform itself sets one essential cookie when you sign in, which keeps you signed in. It is required for the service to work and is not used for tracking.
Security
Everything travels over encrypted connections. Passwords are protected with strong, deliberately slow one-way hashing that meets current OWASP guidance. Access to the platform requires a valid session, and members of one organisation cannot see another organisation's people or content. We review the platform's security every day and fix problems as we find them.
If something goes wrong
If a breach occurs that is likely to risk your rights and freedoms, we will report it to the ICO within 72 hours of becoming aware, and tell you directly without undue delay where the risk to you is high.
Children
The service is sold to professionals and is not intended for anyone under 18. We do not knowingly collect data about children.
Changes to this notice
If we change how we use personal data, we will update this page and change the date at the top. Where a change materially affects you, we will tell you by email.