Last updated: 4 September 2026
We know you're trusting us with access to your CRM, billing, and analytics data. Here's a plain-English overview of how we protect it. For the full legal detail, see our Privacy Policy.
We use the following third-party providers ("sub-processors") to deliver our products. We carry out due diligence on each provider and only share the minimum data necessary for them to perform their function.
| Sub-processor | Purpose | Location | Data shared |
|---|---|---|---|
| Supabase (running on Amazon Web Services) | Database, authentication, storage and server-side functions. AWS is Supabase's infrastructure provider, not a supplier we contract with directly | UK (eu-west-2, London) | All account & platform data |
| Anthropic | AI insight, reports, interviews and document analysis (Claude API), all accounts | USA (processed in transit, not retained for training) | Varies by product: metrics and ICP for insights; interview conversations and uploaded document text for the abi. Clone. See the Privacy Policy, section 4 |
| Sign in with Google, where chosen | USA / global | Email address and login identity | |
| Google Analytics 4 | Visitor analytics on the marketing site ouridea.ai only. Not used inside the abi. platform | USA / global | Pages viewed, approximate location, device, where the site's cookie banner permits |
| Make.com | Workflow automation (scheduled metric pulls, emails) | EU | Account & metrics data in transit |
| Resend | Transactional email (welcome, digest, receipts) | EU/USA | Name, email address, email content |
| Stripe | Payment processing | USA (UK IDTA / SCCs in place) | Billing & payment data (not stored by us) |
| Netlify | Website & app hosting / CDN | Global | Website traffic logs |
We'll update this page if our sub-processor list changes, and notify customers of material changes by email where required.
All data is currently held in the United Kingdom (AWS eu-west-2, London), and AI processing runs through Anthropic in the United States, in transit only. The UK holds a European Commission adequacy decision, renewed in December 2025, so EU and EEA customers can use it without additional transfer safeguards.
An EU region, with data at rest and AI processing inside the EEA, is in preparation and is not available yet. abi. Max customers can register interest in the app; we will agree a date in writing and confirm by email once an account has actually been moved. Until that confirmation, no account has EU residency, whatever has been requested. Our Data Processing Agreement is available to business customers on request.
If you discover a security vulnerability, please report it responsibly to security@ouridea.ai. Please don't access, modify, or delete other users' data, and give us reasonable time to investigate and fix the issue before any public disclosure. We won't take legal action against good-faith security research conducted in line with this policy.
In the event of a data breach affecting your personal data, we'll notify affected customers without undue delay, and the ICO within 72 hours where required under UK GDPR.
For security or compliance questions (including requests for a DPA — see our DPA template), email adam@ouridea.ai.