Privacy Policy
Last updated: 21 September 2026 · Applies to ouridea.ai, app.ouridea.ai and all OurIdea.ai products (abi. Clone, abi. Clone for Consultants, abi. Launchpad, FirstFlight, SIGNAL & SIGNAL Academy, abi. Pro, abi. Max)
OurIdea.ai ("OurIdea", "we", "us", "our") provides AI-powered go-to-market engineering products and services, including abi. Clone and abi. Clone for Consultants, abi. Launchpad, FirstFlight, the SIGNAL methodology and SIGNAL Academy, and the abi. platform (Free, Pro and Max). This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and the rights you have over it.
This policy applies wherever you interact with us: our website, our checkout pages, the abi. platform application, SIGNAL Academy, and any emails or support communications.
1. Who we are
OurIdea.ai is the trading name of Adam Salley, a sole trader established in the United Kingdom. For data protection purposes, OurIdea.ai is the "data controller" of the personal data described in this policy.
| Trading as | OurIdea.ai (Adam Salley, sole trader, United Kingdom) |
|---|---|
| Data protection contact | privacy@ouridea.ai |
2. What data we collect
2.1 Information you give us directly
- Account & contact data: name, email address, company name, role, when you sign up, complete an intake form, or contact support.
- Sign-in credentials: you can sign in with an emailed link, with Google, or with a password. If you set a password, Supabase (our authentication provider, section 10) stores it as a salted hash; we never see or store the password itself. Before a password is accepted, your browser checks it against the Have I Been Pwned "Pwned Passwords" list using k-anonymity: only the first five characters of a SHA-1 hash of the password are sent to that service, which cannot identify you or your password from them, and nothing about you is sent with it. A password that appears in a known breach is refused. If you turn on two-step login, the authenticator secret is stored by Supabase against your account and is used only to verify the codes you enter.
- Purchase data: product purchased, plan/tier, billing address, processed via Stripe (we do not store your card details, see section 6).
- abi. Launchpad & SIGNAL Academy inputs: information you submit about your business, ideal customer profile (ICP), targets, and strategy answers, used to generate your deliverables and personalise the Academy.
- Communications: emails, support requests, and any feedback you send us.
2.2 Information we collect automatically
When you use the abi. platform we record product events: which screens are opened, when a map is built, when a checkout is started. These are stored in our own database, in your account's region, and are used to understand and improve the product. They are recorded only if you accept analytics on the banner shown the first time you visit; choose “Necessary only” and we record no product events. You can change your mind at any time from Settings or the Cookie Policy.
One thing is counted either way, and it needs no consent because it stores nothing on your device and carries no identifier: a plain count of page views, holding the date, the page, the site you came from, which of our own links brought you (the tag on the address, if any) and whether you are on a phone, tablet or desktop. There is no session or account identifier on it, so it cannot be linked to you or to any other visit. This is described in the same terms in the Cookie Policy.
We use no third-party analytics, advertising or tracking services in the platform: no Google Analytics, no advertising pixels, no session replay. What we store in your browser, and why, is listed in the Cookie Policy.
Our servers keep standard security logs (request times, error records) for a short period. Google Analytics 4 appears in this policy only as an integration you may connect so that abi. can read your own website metrics; we do not run it on our own sites.
2.3 Information from connected business tools (abi. only)
If you use abi. Pro or Max and connect a third-party tool (HubSpot, Stripe, Google Analytics 4, or others), we request read-only access to compute your GTM metrics. Specifically:
- CRM (HubSpot, Salesforce, Pipedrive): deal records to compute pipeline value, deal count, win/loss ratio, deal velocity and stage distribution. We do not access contact personal data, email threads, notes, or any personal information about your prospects or customers.
- Billing (Stripe, Chargebee): subscription records and payment events to compute MRR, ARR, churn, ARPU and CAC payback. We do not access card details, bank information, or full customer records.
- Web analytics (Google Analytics 4): aggregated session and conversion data by channel. We do not access individual visitor data, user IDs, or IP addresses from your website visitors.
No raw data storage. When we pull data from your connected tools, we compute the relevant metric, store the resulting number, and discard the raw payload. We do not build or retain a copy of your CRM, billing or analytics data.
3. How we use your data
- To create and operate your account and deliver the product(s) you've purchased.
- To generate your abi. Launchpad deliverables, SIGNAL Academy progress, and abi. weekly metrics and AI-generated insights.
- To send essential service communications (welcome emails, weekly digests, billing receipts, security notices).
- With your consent, to send occasional product updates or marketing emails (you can opt out at any time).
- To maintain the security, integrity and performance of our systems, including fraud and abuse prevention.
- To comply with our legal and tax obligations.
4. AI processing
Several products use Anthropic's Claude API. What we send differs by product, and the difference matters, so we set it out separately rather than making one claim that would only be true of some of them.
- abi. Pro and Max insights, and SIGNAL Academy. We send computed metrics (numbers only), your ICP definition and your stated targets. We do not send your customers' names or your team's personal data for this purpose.
- abi. Launchpad and FirstFlight reports. We send the intake answers you provide about your business, which may include the names of people you have described.
- Voice interviews. If someone chooses to speak rather than type, their browser converts speech to text using a cloud service run by the browser vendor, which means the audio is sent to that vendor while they speak: Google for Chrome, Microsoft for Edge. We never receive or store the audio, only the resulting text. This is disclosed on the interview page before the microphone is switched on, and typing is always available instead.
- abi. Clone interviews. We send the interview conversation itself. That is personal data about the person being interviewed, including what they say about their own role and working day, and it is sent so the AI can conduct the interview and summarise it.
- abi. Clone document analysis. We send the text of documents you upload. If a document contains personal data, that personal data is sent.
- abi. Capture (screen capture). If someone records a working session with our browser extension, we receive a text record of that session: the hostname of each tab, a page title shortened to 120 characters, how long they spent on each, the name we infer for the system being used, and any note they type into the extension. The extension has no content scripts and cannot read the contents of a page. Full web addresses never leave the browser, because query strings routinely carry record identifiers, client names and access tokens. Recording is started deliberately, the extension badge shows while it is running, and it can be stopped at any time. Because page titles can incidentally name other people, a client on an invoice or a colleague in a mailbox, the person recording is asked to close anything they would not want captured before they begin, and the customer is responsible for telling the people involved. The text record is sent to Anthropic so the AI can infer which processes the session shows.
- Call Review. If a customer pastes a sales call transcript in for scoring, we send it to Anthropic to be scored against the SIGNAL methodology. We do not keep the transcript. What we store is the score, a short summary, the gaps identified, the suggested follow-up, and the label the customer gave the call, which usually includes the name of the company or person on the other end. Recording or transcribing a call happens in the customer's own tools under their own obligations: it is their responsibility to have had the right to record it and to have told the other participants, and our Terms say so.
- abi. Agent Studio. To propose changes to a process, we send that part of your map to Anthropic: the steps, the systems, the cadence, and the role or name recorded against each step. The workflow file you export is generated from your own map and downloaded by you. It contains no credentials, because we never hold any.
- abi. Governance. Each agent on your register carries a named owner and, where you have set one, an escalation contact. That is personal data about your own people and it is stored against your account. The register export is generated on request and downloaded by you.
- Shared links. You can create a link that shows a map, or a before-and-after reel, to anyone who has the URL. A map can name people. Anyone you send the link to can open it without signing in, so the decision to share is yours, as is the choice of who you send it to. A shared link can be revoked in the app, which stops it working.
For market research in abi. Launchpad and FirstFlight we also use Tavily to retrieve publicly available web results. We do not send your business content to Tavily; we send search terms.
Today, for every account, Claude is called through Anthropic's API and processed in the United States, in transit only. This is covered by Anthropic's data processing terms and nothing you send is retained for model training. When the EU region described in section 9 opens, accounts in it will use the same Claude models hosted inside the EEA instead; we will update this policy and tell affected customers before that happens.
AI output can be wrong. Reports, scores, summaries and insights are generated and should inform your judgement rather than replace it. Nothing in our products makes a decision about a person that has a legal or similarly significant effect without a human involved.
5. abi. Clone interviews and organisational maps
abi. Clone builds a model of how an organisation works, called an Clone. It can be built by hand for free, or built for you from AI interviews with your team on a paid plan. The interviews involve personal data, so it is worth being specific.
- Who the data is about. Employees, contractors and other colleagues of our customer who take part in an intake interview. Typically: name, work email, job title, department, the systems they use, the processes they own, and their answers about how their work actually gets done.
- Who decides what is collected. Where your employer has bought abi. Clone, your employer is the controller of that data and decides what is collected and why. We act as processor on their instructions. If you want your interview responses corrected or removed, the quickest route is your employer; you may also contact us and we will refer the request to them.
- Interviews are not appraisals. abi. Clone is a process mapping tool. We do not score individuals, and we do not present a person's answers to their employer as a performance record. Our Terms prohibit customers from using it for monitoring or appraisal.
- Voice interviews. Interviews may be taken by speaking rather than typing. Speech is converted to text by the speech recognition built into your own browser. Depending on your browser and operating system that conversion may happen on your device, or may be sent to your browser vendor for processing under their privacy policy. We receive only the resulting text. We do not receive or store an audio recording.
- Our access. Our personnel can view a customer's map and the responses behind it in order to deliver and support the Service. That access is limited to that purpose and is covered by the confidentiality obligations in our mutual NDA and section 9 of our Terms.
- Optional secondary uses. A customer may separately permit us to study their map to improve our capability, and to feature it in our marketing either anonymised or attributed. Those permissions are optional, granted independently, recorded with a date, and refusable without consequence. They are set out in section 11 of our Terms. Where material is published while permission is in force, later withdrawal stops future use but does not require us to unpublish what already exists. Any right you have as an individual to withdraw consent to the processing of your own personal data is separate, and is unaffected by that.
5b. Maps you build for someone else
Some customers use abi. Clone to map organisations other than their own: consultants, agencies and managed service providers mapping a client, or a group mapping a subsidiary. This section explains who is responsible for what when that happens, because the ordinary two-party description above no longer fits.
The chain
When you map a business other than your own, there are three parties rather than two:
| The mapped organisation | Is the controller of its own employees' personal data. It decides that its processes should be mapped and why. |
|---|---|
| You, our customer | Are a processor acting on that organisation's instructions, under whatever contract you hold with them. |
| OurIdea.ai | Is a sub-processor. We process on your instructions, and you remain responsible to your client for engaging us. |
What this requires of you
If you map an organisation you do not own, you confirm that:
- you have that organisation's authority to map it, and to invite its people to be interviewed;
- your contract with them permits you to engage sub-processors, and you have given them any notice that contract requires;
- you will tell the people you invite what the interview is for, as we tell them at the start of every interview; and
- you will not upload anything you are not permitted to share with us.
We cannot verify any of this, so we rely on you. It is the same undertaking any processor gives its own sub-processor.
Proposal maps built on assumptions
abi. Clone lets you build a proposal map for a business you have not yet spoken to, using publicly available information and your own judgement about how a business of that type probably operates. These maps are marked as assumptions in the product and in anything exported from it, and they cannot be presented as a completed audit.
A proposal map should contain no personal data. Describe roles, not people. If you record a named individual you have found publicly, you become responsible for having a lawful basis to do so, and you should be able to answer that person if they ask.
What happens when an engagement ends
As between you and us, the maps in your account are yours and we act only on your instruction. We do not have a separate relationship with the organisations you map, and we will not act on their instructions without yours, because we have no way to verify who they are.
When you ask us to, or within 30 days of your account closing, we will return or delete the maps in your account. If your client wants to keep the map after your engagement ends, the practical route is for them to open their own account and for you to rebuild or hand over the content. We are working on a direct transfer and will document it here when it exists.
Branding
abi. Clone is not white-labelled today. Maps, exports and interview pages carry OurIdea branding, and the people you interview are told they are speaking to abi., an assistant provided by OurIdea on your behalf. If you need something different, contact us before you rely on it.
6. Lawful basis for processing (UK GDPR)
- Contract performance (Art. 6(1)(b)): processing needed to deliver the product or service you purchased.
- Legitimate interests (Art. 6(1)(f)): system security, fraud prevention, service improvement, and aggregated analytics, balanced against your rights and never used for invasive profiling.
- Consent (Art. 6(1)(a)): marketing emails and non-essential cookies; you can withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)): retaining transaction records for UK tax and accounting law (7 years).
7. Payments
All payments are processed by Stripe. We never see or store your full card number, CVC, or bank details. Stripe acts as an independent controller for payment processing and is certified to PCI-DSS Level 1. See Stripe's Privacy Policy for details.
8. Data retention
| Data type | Retention period |
|---|---|
| Account data (name, email, company) | Duration of your relationship with us, plus 90 days after account closure |
| Sign-in credentials (password hash, authenticator secret) | Until you change or remove them, or your account is closed. The Pwned Passwords check keeps nothing: the five-character hash prefix is not stored by us and is not personal data |
| Weekly metric snapshots (abi.) | 24 months from creation |
| Monthly aggregate snapshots (abi.) | 36 months from creation |
| AI insight reports (abi.) | 24 months from generation |
| abi. Launchpad / SIGNAL Academy deliverables | Duration of access entitlement, plus 12 months |
| Interview conversations and the map built from them (abi. Clone) | Duration of your subscription, plus 90 days after account closure. Deleted sooner on request from you or from the person interviewed |
| Documents you upload, and the text extracted from them | Duration of your subscription, plus 90 days. You can delete an individual document at any time from the app |
| Product event records (only where analytics is accepted) | 14 months |
| Consent records (what was accepted, when, which policy version) | 6 years, as evidence that consent was obtained |
| Account administration records (plan, region and access changes) | 6 years |
| Email/communication logs | 12 months |
| Integration connection records (OAuth tokens) | Duration of subscription, plus 90 days |
| Billing & transaction records | 7 years (UK statutory requirement) |
Data is deleted within 30 days of the relevant retention period expiring, or immediately upon a valid deletion request (subject to our right to retain billing records as required by law).
9. Where your data is stored
Every account has a data region, shown in the app under Settings → Billing.
- United Kingdom (default). Your account and platform data is stored in Supabase (PostgreSQL) hosted in AWS eu-west-2, London. This applies to all Free and Pro accounts and to Max accounts that have not chosen otherwise. The United Kingdom is covered by a European Commission adequacy decision (renewed December 2025), so customers in the EU/EEA can use the UK region without additional transfer safeguards.
- European Union (in preparation). An EU region, with data at rest in Frankfurt and AI processing in the same region, is being built for customers who need data kept inside the EEA. It is not available yet. abi. Max customers can register interest in the app and we will agree a date with them in writing; nothing moves, and no claim of EU residency applies, until we have confirmed the move by email. Until then every account, including one that has registered interest, is stored in the United Kingdom as described above.
The following leave the storage region:
- Anthropic (Claude API), for every account today. Processed in the United States, in transit only, not stored for training.
- Stripe, payment processing, United States, with Standard Contractual Clauses and the UK addendum in place. Stripe holds payment identity, not your platform data.
- Google, only if you sign in with Google, for login identity.
Business customers who need it can request our Data Processing Agreement, which sets out our obligations as a processor, the sub-processors below and the transfer mechanisms relied on. Email adam@ouridea.ai.
10. Sub-processors
We use the following sub-processors to operate our products. A current version of this list is also maintained on our Security & Sub-processors page.
| Sub-processor | Purpose | Location | Data shared |
|---|---|---|---|
| Supabase | Database hosting, authentication, file storage and server-side functions. Supabase runs on Amazon Web Services infrastructure, which is therefore a sub-processor of Supabase rather than a supplier we contract with directly | UK (AWS eu-west-2, London) | All account & platform data |
| Anthropic | AI insights, reports, interviews and document analysis (UK region accounts) | USA (in transit only) | Varies by product, see section 4. Includes interview content and uploaded document text |
| Sign in with Google, where chosen | USA / global | Email address and login identity | |
| Google Analytics 4 | Visitor analytics on our marketing site ouridea.ai only. Not used inside the abi. platform | USA / global | Pages viewed, approximate location, device. Set only where the site's cookie banner permits |
| Google, or Microsoft in Edge | Browser speech recognition, only if a participant chooses to speak | USA | Audio of what they say, in transit. We do not receive it |
| Tavily | Public web search for market research | USA (in transit only) | Search terms only |
| Make.com | Workflow automation | EU | Account & metrics data in transit |
| Resend | Transactional email delivery | EU/USA | Name, email address, email content |
| Stripe | Payment processing | USA (SCCs/UK IDTA in place) | Billing & payment data (not stored by us) |
| Netlify | Website & app hosting | Global CDN | Website traffic logs |
11. Your rights
Under UK GDPR, you have the right to:
- Access: request a copy of all personal data we hold about you (provided as a JSON export within 30 days).
- Rectification: ask us to correct inaccurate data within 14 days.
- Erasure: ask us to delete your account and associated data (processed within 30 days, subject to statutory retention obligations).
- Restriction: ask us to pause processing without deleting your account (e.g. disable an integration via Settings → Integrations).
- Portability: receive your data in a machine-readable format.
- Object: object to processing based on legitimate interests, or withdraw consent for marketing at any time.
- Complain: lodge a complaint with the Information Commissioner's Office (ICO) if you believe we have mishandled your data.
To exercise any of these rights, email privacy@ouridea.ai with the relevant subject line (e.g. "Data Access Request" or "Deletion Request"). We will respond within 30 days.
12. Children's privacy
Our products are intended for business use by adults (18+) acting on behalf of their organisation. We do not knowingly collect personal data from children.
13. Changes to this policy
We may update this policy from time to time to reflect changes in our practices or legal requirements. Material changes will be notified by email or via an in-app notice. The "last updated" date at the top of this page reflects the most recent revision.
14. Contact us
For any questions about this policy or how we handle your data, contact privacy@ouridea.ai or adam@ouridea.ai.