Draft — not yet reviewed, not yet complete

This document was drafted as a starting point and has not been reviewed by a qualified person. It is missing company details that the law requires, so the bracketed markers below are placeholders, not facts:

  • COMPANY LEGAL NAME
  • COUNTRY OF ESTABLISHMENT
  • REGISTERED ADDRESS
  • CONTACT EMAIL

Privacy policy

This policy explains what DownlineAI does with personal data, and what you can do about it.

1. Who is responsible

[COMPANY LEGAL NAME — FILL IN AT ADMIN → LEGAL], established in [COUNTRY OF ESTABLISHMENT — FILL IN AT ADMIN → LEGAL], registered address [REGISTERED ADDRESS — FILL IN AT ADMIN → LEGAL], is the controller of the data described in section 2. Contact us about anything on this page at [CONTACT EMAIL — FILL IN AT ADMIN → LEGAL].

Members also store details of their own prospects in DownlineAI. For that data the member is the controller and we are their processor — see section 6.

2. What we collect and why

Account data

Your name, email address, hashed password, username, plan, referral code and who invited you. We need it to give you an account and to run the service. Lawful basis: performance of our contract with you.

Payment data

Subscriptions and AI-credit top-ups are handled by Stripe. Card numbers never reach our servers. We store the Stripe customer and subscription identifiers, your plan, your subscription status, renewal dates and invoice references. Lawful basis: contract, and our legal obligation to keep accounting records. Stripe is an independent controller for fraud prevention and payments; see stripe.com/privacy.

Chat transcripts

Conversations with either AI assistant — the public recruiter on member pages and the private assistant inside the application — are stored in our database, together with the account or visitor conversation they belong to. The text of each message is also sent to a large language model backend to generate a reply. Do not type anything into the chat that you would not want processed that way. Lawful basis: contract for members; for a visitor on a member's page, the member's legitimate interest in answering them.

Leads collected by the AI

When a visitor gives an email address to the public AI recruiter and confirms that it may be shared, we store that address, the message it came with, the page it came from and the date and manner of the confirmation, and pass it to the member who owns the page. We do not store an address that has not been confirmed. Lawful basis: consent, recorded with the record. See section 6.

Technical data

Your IP address, request times and rate-limit counters, used to keep the service up and stop abuse. Server error logs record the path and the error, never message contents or credentials. Lawful basis: our legitimate interest in security and availability.

Usage and billing meters

Token counts, costs and timestamps of metered AI calls, so we can bill them and show you what you spent. Lawful basis: contract.

3. Cookies and local storage

We do not use advertising, analytics or tracking cookies, and there is no cookie banner because there is nothing to consent to. What we do set:

  • a session cookie when you sign in, so the site knows it is you. It is strictly necessary for a service you asked for;
  • if a member puts our chat widget on their own website, the widget stores an opaque conversation id in that site's local storage so a returning visitor keeps the same conversation. It is not a fingerprint and it identifies nobody across sites;
  • an optional access-code cookie in non-public test environments.

Under the ePrivacy rules these are exempt from consent because they are strictly necessary to provide the service requested. We say so here rather than staying silent about it.

4. Who we share data with

  • Stripe — payments, invoicing and the customer portal.
  • The AI model provider — the text of chat messages and the prompt we build around it, in order to generate a reply. Depending on our configuration this is either a model we run ourselves or a third-party inference provider. Chat content leaves our application to be processed by a model.
  • Our hosting provider — which stores the database and serves the site.
  • Anyone we are legally required to disclose to, and a buyer if the business is sold.

We do not sell personal data and we do not share it with advertisers.

5. International transfers

Our payment and model providers may process data outside your country. Where that happens we rely on the transfer mechanisms in those providers' own terms, such as the European Commission's standard contractual clauses.

6. Data members collect about other people

Members use DownlineAI to keep details of prospects and team members, and to run an AI assistant that can be given an email address by a visitor. For that data:

  • the member decides what to collect and why, and is the controller;
  • we act on the member's instructions as their processor;
  • the AI recruiter asks the visitor to confirm before an email address is stored or passed to the member, and we record when and how that confirmation was given;
  • if the member has switched lead capture off, no address is stored at all;
  • a request about data held by a member should go to that member; write to us at [CONTACT EMAIL — FILL IN AT ADMIN → LEGAL] and we will pass it on and help.

7. How long we keep things

  • Account data: while your account exists, then deleted or anonymised within 90 days of closure.
  • Invoices and payment records: as long as tax and accounting law requires, which is commonly 7–10 years.
  • Chat transcripts and leads: until the member deletes them or the account is closed.
  • Technical logs and rate-limit data: short-lived; error logs are kept no longer than needed to fix the problem.

8. Your rights

If the GDPR or the UK GDPR applies to you, you have the right to: access your data; have it corrected; have it erased; restrict or object to processing; receive it in a portable format; withdraw consent at any time where processing is based on consent; and not be subject to a decision with legal effect based solely on automated processing. The AI writes text and suggests wording — it does not make decisions about you.

To use any of these, email [CONTACT EMAIL — FILL IN AT ADMIN → LEGAL]. We answer within one month. You can also complain to the data protection authority in the country you live in, or to the supervisory authority in [COUNTRY OF ESTABLISHMENT — FILL IN AT ADMIN → LEGAL].

9. Security

Passwords are stored hashed. Sessions are signed tokens. Payments are handled entirely by Stripe. No system is perfectly secure; if a breach affects you and the law requires it, we will tell you.

10. Children

DownlineAI is for people aged 18 and over. We do not knowingly collect data from children.

11. Changes

We post changes here and, where they matter, tell you in the application.