Signalcroft AI

Privacy Notice

What we collect, why we collect it, and what you can ask us to do about it.

Last updated 3 September 2026. Changed since 1 September 2026: our website no longer offers a cookie choice, because it sets no cookie and stores nothing on your device, and the three places that described that choice now say so.

In short. We collect the minimum needed to run the service: your name and email so you have an account, and what you use inside the platform so we can improve it. If you start a free trial we email you eight times over three weeks, three of those messages tell you what a subscription costs, and you can refuse the lot at sign-up or in one click from any of them. We do not sell your data, we do not use it to train AI models, and we do not run third-party advertising or tracking on our website.

Who we are

Signalcroft AI Ltd is the data controller for the personal data described here. We are registered in England and Wales, company number 17364692, with our registered office at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ.

We are registered with the Information Commissioner's Office, the UK data protection regulator, under registration number ZC209326. You can check that entry on the ICO's public register of fee payers.

For any privacy question, or to exercise any right below, email [email protected]. A person reads it and we aim to reply within five working days, and always within one month as the law requires.

What we collect, and why

WhatWhy we need itLawful basis
Name and emailTo create your account, sign you in, and send service messages such as your trial confirmation and password resetsContract
Your email address and your trial dates, while your trial runs and for three weeks from the day it startsTo send the eight-message trial sequence described below, three of which state what a subscription costs and invite you to take oneLegitimate interests, and the soft opt-in at regulation 22 of the Privacy and Electronic Communications Regulations for the three that ask you to buy
PasswordTo protect your account. We never store it: we keep only a one-way cryptographic hash, and we check new passwords against a public breach database so you cannot pick one already exposedContract
Sign-in sessionsTo keep you signed in securely and let you sign outContract
Which sections you openTo see which parts of the platform earn their place and which do not, so we improve the right thingsLegitimate interests
Ratings and posts you writeTo show your contributions to colleagues in your own organisationContract
Website visitsTo count visitors and see which pages work. No cookie is set, nothing is stored on your device, and we never store your IP addressLegitimate interests
Emails we send youTo keep a record that a message was sent and delivered, so we can help if something goes missingLegitimate interests
Name, job title and employer of a senior person at a firm we approach, taken from that firm's own website or from public trade coverageTo make one business approach to the person whose job it is to decide, rather than to a general address nobody ownsLegitimate interests, assessed and recorded before any approach. Your objection ends it immediately

Where we rely on legitimate interests, we have considered your rights and concluded that the processing is limited, expected, and does not override them. You can object at any time using the contact address above.

Email while your trial runs

Starting a free trial puts you on a fixed sequence of eight messages over three weeks. It is written once and sent to everyone on the same schedule. Nobody reads your account and decides to write to you.

We rely on legitimate interests, and on the soft opt-in at regulation 22 of the Privacy and Electronic Communications Regulations, which permits email about our own similar services to someone who gave us their address while considering buying one. That permission carries a condition and we meet it: the sign-up form offers you the choice to refuse the sequence at the point you give us the address, before anything is sent. The day-21 message asks a question and sells nothing, so it is research rather than marketing. We put it under the same refusal as everything else because that distinction matters to us and should not have to matter to you.

Every message in the sequence carries a one-click opt-out that needs no sign-in, no password and no reply. Using it stops the whole sequence at once, including the reminders about when your trial ends. It never affects your trial, your account, or any service message such as a password reset, and once you have opted out nothing puts you back on.

If we approached you and you never gave us anything

We research firms we think would benefit from what we do, and sometimes that research names a person: usually the chief executive, a managing partner or whoever owns technology decisions. We take that from the firm's own website or from public trade coverage. We do not buy lists, we do not scrape anything behind a login, and we hold nothing about you beyond your name, your role and where you work.

We rely on legitimate interests, and we assessed and wrote down that decision before approaching anyone rather than after. If we write to you, the first message says where we found you and how to stop it. One reply saying stop is enough: no form, no sign-in, no reason needed. We keep your name on a do-not-contact list afterwards, because that is the only way to be sure we do not write again.

You have the same rights here as anyone else in this notice, including the right to see what we hold and to have it deleted. An objection to marketing is absolute: we do not weigh it against anything.

What we do not do

Who else processes your data

We use a small number of suppliers to run the service. Each acts only on our instructions under a data processing agreement, except where the table says otherwise: our payment provider also decides some things for itself, because the law that governs payments requires it to.

SupplierWhat they doWhere
CloudflareHosts the platform and stores its databaseGlobal edge network, with EU and UK presence
ResendDelivers our emails to youEU region
Google WorkspaceOur business mailbox, when you email usEU and US
AnthropicProvides the AI models behind the serviceUS, under terms that forbid training on our data
StripeTakes your payment and holds your billing details. Your card number never reaches usUK, EU and US. On our instructions for the subscription itself, and a controller in its own right for payment processing, fraud prevention and the records financial regulation requires it to keep

Where a supplier processes data outside the UK, the transfer is covered by the UK International Data Transfer Addendum or equivalent safeguards approved under UK law.

Your organisation and what colleagues can see

If you sign up with a work email address, anything you post to the community board is visible to colleagues who share your email domain, and to nobody outside it. If you use a personal email provider such as Gmail or Outlook, you are treated as an organisation of one and no other member can see your posts or your name.

How long we keep it

Your rights

Under UK GDPR you can ask us to:

Email [email protected] and we will act without charge. If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you told us first so we can put it right.

Cookies and similar technology

Our website sets no cookie and stores nothing on your device. Each visit is counted on its own, on our own systems, and is not linked to any other visit, so there is no choice to make and nothing to withdraw. If you made a choice under the banner we ran before 2 September 2026, the record of it is removed from your browser the next time you visit and is never read.

The platform itself sets one essential cookie when you sign in, which keeps you signed in. It is required for the service to work and is not used for tracking.

Security

Everything travels over encrypted connections. Passwords are protected with strong, deliberately slow one-way hashing that meets current OWASP guidance. Access to the platform requires a valid session, and members of one organisation cannot see another organisation's people or content. We review the platform's security every day and fix problems as we find them.

If something goes wrong

If a breach occurs that is likely to risk your rights and freedoms, we will report it to the ICO within 72 hours of becoming aware, and tell you directly without undue delay where the risk to you is high.

Children

The service is sold to professionals and is not intended for anyone under 18. We do not knowingly collect data about children.

Changes to this notice

If we change how we use personal data, we will update this page and change the date at the top. Where a change materially affects you, we will tell you by email.