Privacy Policy
In force from 2026-09-05·English is the only version
We are a small business selling a tool to other businesses, and the personal data we hold is mostly the plain fact that you have an account. The two things people usually want to know are in §5 — what happens to the advertising copy you submit — and §11, how long we keep things.
1.Who is responsible for your data
The controller is AngleVerdict, Sokolska 30, Katowice, Poland. For anything in this notice, write to privacy@angleverdict.com.
We serve customers internationally, and this notice covers all of them. Because we are established in the European Union, the GDPR governs everything we do with personal data — not only data about people in Europe — so the standard described here is the one we apply to every customer and every visitor, wherever you are. The rights in §12 are given to everyone on the same terms. Where the law where you live gives you more than this notice does, you keep that too.
We have not appointed a data protection officer. We are not required to under art. 37 GDPR: we do not carry out large-scale monitoring or process special-category data as a core activity. The address above reaches the person who decides these questions.
2.Who this notice is about
It covers three groups:
- Customers and their team members — the people who hold accounts and use the service.
- Visitors to our website, including anyone who tries the demo without an account.
- People named in content a customer submits, where that happens. For that data the customer is the controller and we act on their instructions — §8.
It does not cover the audiences our customers advertise to. We do not receive, hold or process data about the people who see our customers’ advertising. We have no tracking pixel, no advertising integration and no connection to any advertising account.
3.What we collect
- Account data — your email address, the workspace you belong to and your role in it, sign-in and session records, and the hashed single-use tokens behind our magic links. We do not use passwords, so we never hold one.
- Content you submit — the advertising copy you paste in for a check, and anything you type into the product such as labels, notes on a dispute, evidence descriptions and outcome reports. What we keep of it is set out in §5.
- Check records — for every check, an append-only entry recording that it happened, when, for which workspace and user, which rules matched, and the pack, policy and classifier versions used. These entries do not contain your advertising copy.
- Billing data — your subscription, plan, invoices, usage counts and your customer and subscription identifiers at Stripe. We never receive or store card numbers; Stripe handles the payment itself.
- Correspondence — the emails you send us and our replies, including support requests and complaints.
- Technical data — IP address, browser and device information, and the pages you request. Our network provider sees your IP address for every request in order to route and protect it, and tells us the country it came from.
- Error reports — diagnostic events when something breaks, with personal data filtered out before they are sent.
- Product analytics — only if you opt in (§14).
- Demo data — §6.
Almost all of this comes from you. The exceptions are subscription and payment status, which comes from Stripe, and technical data, which comes from your browser and our network provider.
4.Why we process it, and on what basis
- To provide the service you asked for — running checks, generating rewrites, keeping your history and audit trail, managing your workspace and seats, and supporting you. Basis: performance of a contract, art. 6(1)(b).
- To take payment and manage your subscription. Basis: performance of a contract, art. 6(1)(b).
- To keep the service secure and working, and to prevent abuse — rate limiting, fraud and abuse prevention, error monitoring, and keeping records of what the system did. Basis: our legitimate interests in running a service that is not degraded or defrauded, art. 6(1)(f).
- To improve the rules and the product — using aggregated signals about which rules fired, which verdicts were overridden or disputed, and outcomes customers report. Basis: legitimate interests, art. 6(1)(f).
- To send service messages — sign-in links, billing notices, changes to these documents and to our terms. Basis: performance of a contract, art. 6(1)(b), and legitimate interests.
- To understand how the product is used through analytics. Basis: your consent, art. 6(1)(a), which you can withdraw at any time in §14.
- To meet our tax and accounting obligations. Basis: legal obligation, art. 6(1)(c).
- To establish, exercise or defend legal claims if we have to. Basis: legitimate interests, art. 6(1)(f).
Where we rely on legitimate interests we have weighed them against your rights, and you can object — §12. Giving us your email address is necessary to have an account; without it we cannot provide the service. Everything else you give us is optional in the sense that the feature it powers is optional.
5.The advertising copy you submit
This is the part customers ask about, so it is set out in full. What we keep depends on what you used:
- A plain check: we do not keep the text. It is processed to produce the verdict and is not written to your audit trail. What survives there is the check record described in §3 — rule identifiers, versions, a length and a hash — which cannot be used to reconstruct what you wrote.
- One exception, and it only affects API calls: if you send an
Idempotency-Keyheader, we cache that request’s verdict — including the phrases it flagged, which are fragments of your copy — for 24 hours, so that repeating the same call returns the same answer instead of billing you twice. It is deleted after that. - A rewrite: we keep your original text, with the variant we generated, so the two can be compared and so your audit trail means something later.
- A creative you put under ongoing monitoring: we keep the text, because re-checking it when the rules change is the whole feature.
- A batch check: we keep each submitted item for the life of the job and its results.
- Notes, evidence descriptions, disputes and outcome reports are kept as you wrote them, because they are the record.
In every case the text is sent to our model provider to produce the verdict — §7. Advertising copy is not usually personal data, but it can contain it if you put it there. Please do not submit special-category data (art. 9), which the service is not built to handle.
6.The demo on our website
Anyone can paste a piece of copy on our home page and get a verdict without an account. To run it and to stop it being abused we process:
- your IP address, which we hash immediately with a rotating secret salt and never store in readable form;
- a hash of the text you pasted, so a repeat paste can be recognised as one;
- a browser fingerprint hash, where available, for the same purpose;
- an anti-bot check by our network provider, which may set its own cookie or storage entry;
- your email address, if you go on to ask for a sign-in link from the demo, so the demo can be connected to the account you create.
The text you paste into the demo is not stored — only its hash. These records are kept for 7 days and then deleted automatically. Our basis is our legitimate interest in offering a working demonstration that cannot be used to drain the service, art. 6(1)(f).
7.AI processing, and our model provider
Part of the check is performed by a large language model supplied by Anthropic (Anthropic PBC, United States). The text you submit is sent to Anthropic’s API to produce the verdict, the reasoning and any rewrite, and comes back to us. Anthropic acts as our processor under our commercial agreement with them.
Your text is not used to train any model — ours or theirs. Anthropic’s commercial terms prohibit training on API submissions. They retain submissions briefly for their own abuse monitoring under those terms and then delete them.
Because Anthropic is in the United States, this is a transfer outside the EEA — §10.
8.When we act on your instructions instead of our own
For the personal data you choose to put into content you submit, you are the controller and we are your processor: we process it to run the check you asked for and for nothing else. The terms that govern that relationship — the art. 28(3) GDPR terms — are §11 of our Terms of Service, and they apply without you having to sign anything separately.
For everything else — your account, your billing, your use of our website, security — we are the controller, and this notice applies.
9.Who else sees your data
We do not sell personal data and we do not share it for anyone else’s marketing. We use the following service providers, each processing only what their function needs:
- Anthropic (United States) — the language model behind verdicts and rewrites.
- Stripe (Ireland and United States) — payments, subscriptions and invoicing.
- Railway — hosting for our application and database.
- Cloudflare — content delivery, protection against attacks and abuse, the anti-bot check on our demo, and object storage for data exports.
- Resend — sending our emails, including sign-in links.
- Sentry — error monitoring, with personal data filtered before events are sent.
- PostHog (EU region) — product analytics, only if you have opted in.
- Grafana Cloud and BetterStack — operational metrics, traces, logs and uptime monitoring.
We put data processing terms in place with each of them, and we will not add a provider that processes your personal data without giving customers at least 30 days’ notice. Ask us and we will tell you which providers are in use and where.
We also disclose data where the law requires it, to our professional advisers under a duty of confidence, and to a buyer if the business is ever sold — in which case we would tell you.
10.Where your data is processed
We are established in the European Union. The providers in §9 operate in the European Union and in the United States, so your data is processed in both — wherever in the world you are, and whichever advertising market you are checking against. Model inference (Anthropic) and parts of Stripe’s payment infrastructure are in the United States. Several of the operational providers are US organisations whose processing locations follow their own terms rather than ours; ask us about a particular one and we will tell you what we know.
Where personal data protected by the EU or UK GDPR is sent to the United States, we rely on the European Commission’s Standard Contractual Clauses — with the UK Addendum for data covered by the UK GDPR — together with encryption in transit and at rest and access limited to what each provider needs to do its job. Ask us and we will tell you which safeguard covers a particular transfer.
11.How long we keep things
- Account and workspace data — while your account is open, then deleted or anonymised within 90 days of it closing.
- Check records (your audit trail) — while your account is open and for 12 months afterwards. They contain no advertising copy. Because the trail is append-only and hash-chained, entries are not deleted individually; where one contains personal data we redact the data and record the redaction, which preserves the chain.
- Advertising copy we keep (rewrites, monitored creatives, batches) — until you delete it or close your account, and in any case no more than 12 months after your last activity on it.
- Billing records and invoices — 5 years from the end of the calendar year in which the tax fell due, which is the retention the tax and accounting law we are subject to requires of us.
- Sign-in links — valid for 15 minutes; unused records are purged within 7 days.
- Demo records — 7 days (§6). The secret salts used to hash IP addresses are rotated every 30 days and retired salts are discarded after 90.
- Error reports — 90 days. Analytics — for the retention period of that service, and only if you opted in.
- Correspondence — 24 months, or longer where it relates to a complaint or a claim.
Where a period is not fixed above, we keep data for as long as we need it for the purpose in §4, and longer only where the law requires it or where we need it for a legal claim.
12.Your rights
These are the rights the GDPR gives, and we give them to every customer and visitor, wherever you live — we do not run a second, thinner standard for people outside Europe. You have the right to:
- ask what we hold about you and get a copy (art. 15);
- have inaccurate data corrected (art. 16);
- have data erased (art. 17);
- restrict how we use it (art. 18);
- receive it in a portable, machine-readable form (art. 20);
- object to processing based on our legitimate interests, including on grounds relating to your particular situation (art. 21);
- withdraw consent at any time, without affecting what we did before you withdrew it (art. 7(3)) — for analytics, in §14.
Write to dsar@angleverdict.com or privacy@angleverdict.com from the address on your account, or tell us how else to identify you. We answer within one month; if a request is complex we may take up to two further months and will tell you why within the first. It costs you nothing unless a request is manifestly unfounded or excessive.
Some data survives a request: we keep what tax law requires us to keep, and we keep the integrity of the audit trail as described in §11. We will tell you if that applies to your request.
If you are unhappy with how we handle your data you can complain to a supervisory authority. Ours is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych). If you are in the EU or the EEA you can go to the authority in the country where you live or work; if you are in the United Kingdom, to the Information Commissioner’s Office; and if you are elsewhere, to whichever data protection authority has jurisdiction where you are. We would rather you came to us first, at privacy@angleverdict.com.
13.Automated decisions
The verdict is produced automatically (see §10 of our Terms of Service), but it is a piece of information about a piece of text — not a decision about a person. We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing, and we do not profile you.
The automated limits we do apply — rate limits on the demo, the usage ceiling on a plan — are volume controls, and you can always reach a person about one at support@angleverdict.com.
15.How we protect it
- Everything travels over TLS, and is encrypted at rest by our hosting providers.
- Every request is scoped to your workspace, so one customer’s data cannot be reached from another’s session.
- Sign-in is by single-use emailed link. There are no passwords for anyone to steal, reuse or leak.
- IP addresses in our demo records are hashed with a rotating secret salt and never stored in readable form.
- Administrative actions and data-rights actions are written to an append-only, hash-chained log, so a change to the record is detectable.
- Access to production data is limited to those who need it to operate the service.
No system is perfectly secure. If a breach is likely to result in a high risk to your rights we will tell you without undue delay, and we will notify our supervisory authority as art. 33 requires. If you think you have found a vulnerability, please write to security@angleverdict.com.
16.Children
The service is for business use by adults. It is not directed at children and we do not knowingly collect data about anyone under 18. If you believe we have, tell us and we will delete it.
17.Changes to this notice
We will publish any new version here with a new date. Where a change materially affects how we use your personal data, we will email account holders at least 30 days before it takes effect.
18.Contact
Privacy questions and rights requests: privacy@angleverdict.com or dsar@angleverdict.com
Security: security@angleverdict.com
Everything else: support@angleverdict.com
Version 2026-09-05. Read this together with our Terms of Service, whose §11 carries the data processing terms that apply when we handle personal data on your behalf.