Security & Sub-processors
Last updated: 20 September 2026
We know you're trusting us with access to your CRM, billing, and analytics data. Here's a plain-English overview of how we protect it. For the full legal detail, see our Privacy Policy.
1. How we protect your data
- Encryption: all data is encrypted in transit (TLS 1.2+) and at rest in our database provider (Supabase/AWS).
- Access control: your account data is isolated using row-level security (RLS) policies; your data is never visible to other customers, and access is limited to authenticated requests for your own account.
- Read-only integrations: when you connect HubSpot, Stripe, GA4 or other tools, we request read-only OAuth scopes wherever the provider supports it. We cannot modify or delete data in your connected tools.
- Minimal data retention: we compute the metrics you need and discard raw payloads from connected tools; we don't build a shadow copy of your CRM or billing data.
- Authentication: you can sign in with an emailed link, with Google, or with a password (Supabase Auth). Passwords are checked against known data breaches before they are accepted (see 2b), and optional two-step login with an authenticator app is available in Settings.
- Least-privilege team access: only authorised OurIdea team members can access production systems, and only as needed to provide support or maintain the service.
2. Sub-processors
We use the following third-party providers ("sub-processors") to deliver our products. We carry out due diligence on each provider and only share the minimum data necessary for them to perform their function.
| Sub-processor | Purpose | Location | Data shared |
|---|---|---|---|
| Supabase (running on Amazon Web Services) | Database, authentication, storage and server-side functions. AWS is Supabase's infrastructure provider, not a supplier we contract with directly | UK (eu-west-2, London) | All account & platform data |
| Anthropic | AI insight, reports, interviews and document analysis (Claude API), all accounts | USA (processed in transit, not retained for training) | Varies by product: metrics and ICP for insights; interview conversations and uploaded document text for the abi. Clone. See the Privacy Policy, section 4 |
| Sign in with Google, where chosen | USA / global | Email address and login identity | |
| Google Analytics 4 | Visitor analytics on the marketing site ouridea.ai only. Not used inside the abi. platform | USA / global | Pages viewed, approximate location, device, where the site's cookie banner permits |
| Make.com | Workflow automation (scheduled metric pulls, emails) | EU | Account & metrics data in transit |
| Resend | Transactional email (welcome, digest, receipts) | EU/USA | Name, email address, email content |
| Stripe | Payment processing | USA (UK IDTA / SCCs in place) | Billing & payment data (not stored by us) |
| Netlify | Website & app hosting / CDN | Global | Website traffic logs |
We'll update this page if our sub-processor list changes, and notify customers of material changes by email where required.
2a. Data regions
All data is currently held in the United Kingdom (AWS eu-west-2, London), and AI processing runs through Anthropic in the United States, in transit only. The UK holds a European Commission adequacy decision, renewed in December 2025, so EU and EEA customers can use it without additional transfer safeguards.
An EU region, with data at rest and AI processing inside the EEA, is in preparation and is not available yet. abi. Max customers can register interest in the app; we will agree a date in writing and confirm by email once an account has actually been moved. Until that confirmation, no account has EU residency, whatever has been requested. Our Data Processing Agreement is available to business customers on request.
2b. Breached-password checking
When you set or reset a password, your browser checks it against Pwned Passwords, a public corpus of passwords exposed in known data breaches, and we refuse any password that appears in it. This is deliberately not a sub-processing arrangement: the check uses k-anonymity, so your browser sends only the first five characters of a SHA-1 hash of the candidate password and compares the returned list locally. The password itself never leaves your device, nothing identifying you is sent, and we never learn which password you chose. If the service is unreachable the check is skipped rather than blocking you from creating an account.
3. Reporting a security issue
If you discover a security vulnerability, please report it responsibly to security@ouridea.ai. Please don't access, modify, or delete other users' data, and give us reasonable time to investigate and fix the issue before any public disclosure. We won't take legal action against good-faith security research conducted in line with this policy.
4. Incident response
In the event of a data breach affecting your personal data, we'll notify affected customers without undue delay, and the ICO within 72 hours where required under UK GDPR.
5. Questions
For security or compliance questions (including requests for a DPA: see our DPA template), email adam@ouridea.ai.