Cymru Digital Intelligence

Privacy

This page is a placeholder, not a finished privacy policy. A proper policy — reviewed against UK GDPR — needs to be written and published here before this app is used with real customer data at scale.

What's true today, in plain terms:

  • We collect the business information and pain-point descriptions you enter, and the email address you give us to send your report to.
  • Your answers are sent to Google's Gemini API to help write your report's explanations — it never sees your email address or any payment information.
  • If you unlock a paid report, payment itself is handled entirely by Stripe — we never see or store your card details.
  • Report links are sent by email via Resend, our email delivery provider.
  • Report links expire 30 days after they're generated. Anyone with the link can view the report until then, so treat it like a sensitive document.
  • We keep identifiable assessment information only for as long as we need it to provide the service, support the report, and meet legitimate legal/accounting obligations. Our current working retention period for completed assessment information is 90 days. Unfinished assessments may be removed or redacted after 30 days of inactivity. After that period, identifying details and customer-entered free text may be removed. Some structured records may be retained where there is a legitimate reason to do so, and will continue to be protected in the same way as any other assessment record.
  • You can ask us to delete or anonymise your data at any time, before those periods — get in touch and we'll action it.

See docs/PRIVACY_AND_DATA_HANDLING.md in the project repository for the full internal data-handling notes this page will be based on.