Trust

Security & Sub-processors

Last updated: 4 September 2026

We know you're trusting us with access to your CRM, billing, and analytics data. Here's a plain-English overview of how we protect it. For the full legal detail, see our Privacy Policy.

Data hosted in the UK (AWS eu-west-2)
Read-only integration access
No raw CRM/billing data stored
Encrypted in transit (TLS) & at rest

1. How we protect your data

2. Sub-processors

We use the following third-party providers ("sub-processors") to deliver our products. We carry out due diligence on each provider and only share the minimum data necessary for them to perform their function.

Sub-processorPurposeLocationData shared
Supabase (running on Amazon Web Services)Database, authentication, storage and server-side functions. AWS is Supabase's infrastructure provider, not a supplier we contract with directlyUK (eu-west-2, London)All account & platform data
AnthropicAI insight, reports, interviews and document analysis (Claude API), all accountsUSA (processed in transit, not retained for training)Varies by product: metrics and ICP for insights; interview conversations and uploaded document text for the abi. Clone. See the Privacy Policy, section 4
GoogleSign in with Google, where chosenUSA / globalEmail address and login identity
Google Analytics 4Visitor analytics on the marketing site ouridea.ai only. Not used inside the abi. platformUSA / globalPages viewed, approximate location, device, where the site's cookie banner permits
Make.comWorkflow automation (scheduled metric pulls, emails)EUAccount & metrics data in transit
ResendTransactional email (welcome, digest, receipts)EU/USAName, email address, email content
StripePayment processingUSA (UK IDTA / SCCs in place)Billing & payment data (not stored by us)
NetlifyWebsite & app hosting / CDNGlobalWebsite traffic logs

We'll update this page if our sub-processor list changes, and notify customers of material changes by email where required.

2a. Data regions

All data is currently held in the United Kingdom (AWS eu-west-2, London), and AI processing runs through Anthropic in the United States, in transit only. The UK holds a European Commission adequacy decision, renewed in December 2025, so EU and EEA customers can use it without additional transfer safeguards.

An EU region, with data at rest and AI processing inside the EEA, is in preparation and is not available yet. abi. Max customers can register interest in the app; we will agree a date in writing and confirm by email once an account has actually been moved. Until that confirmation, no account has EU residency, whatever has been requested. Our Data Processing Agreement is available to business customers on request.

3. Reporting a security issue

If you discover a security vulnerability, please report it responsibly to security@ouridea.ai. Please don't access, modify, or delete other users' data, and give us reasonable time to investigate and fix the issue before any public disclosure. We won't take legal action against good-faith security research conducted in line with this policy.

4. Incident response

In the event of a data breach affecting your personal data, we'll notify affected customers without undue delay, and the ICO within 72 hours where required under UK GDPR.

5. Questions

For security or compliance questions (including requests for a DPA — see our DPA template), email adam@ouridea.ai.

Related: Privacy Policy · Cookie Policy · Acceptable Use Policy · Refund & Cancellation Policy