Privacy Policy
Last updated: 28 August 2026
1. Who we are
AiDren is operated by a UK sole trader trading as AiDren, business address 47 Bengal Street, Ancoats, Manchester, M4 6BB. AiDren is the data controller for the personal data described in this policy.
We are registered with the UK Information Commissioner's Office (ICO), registration number ZCZ36167. Contact for privacy matters: [email protected].
Controller vs processor. For your account and billing data we are the controller. For the content of the API requests you send through the proxy, you are the controller and AiDren acts as your processor: we send the request text to a prompt-screening model to make a block/allow decision (see section 4), forward allowed requests to the LLM provider you have configured, and do not retain the request or response content (see section 3).
2. What we collect
- Account data — your email address, a securely hashed password, account creation and verification timestamps.
- Billing data — your chosen plan, subscription status and renewal dates, and a customer reference held by our payment processor. Card details are entered directly with Stripe and are never seen or stored by AiDren.
- Configured provider keys — the OpenAI, Anthropic, or Mistral API keys you add. These are encrypted at rest (AES-256-GCM) and are never displayed again or written to logs in plain text.
- Proxy decision logs — for each request routed through AiDren we record metadata only: timestamp, the subsystem involved, the block/allow decision, a short reason, and a confidence score. We do not store the prompt, the model response, or the documents scanned.
- Technical and security data — IP address, request headers, and rate-limit counters, used to operate the service securely and prevent abuse.
- Approximate sign-up location — when you create an account we make a one-off lookup of your IP address against a geo-IP service (ipapi.co) to record the approximate country and city you signed up from. We use this only to understand where our customers are based. We do not store the IP address used for this lookup, and we do not track your location after sign-up.
- Analytics data (only if you accept analytics cookies) — pages viewed, referrer, approximate location, device and browser type, collected via Google Analytics 4. See our Cookie Policy.
- Advertising and conversion data (only if you accept advertising cookies) — pages viewed, buttons clicked, and whether a visit led to a sign-up, collected via the Meta Pixel so we can measure and target ads we run on Facebook and Instagram. We have not enabled Advanced Matching, so we do not send Meta your email address or other contact details. See our Cookie Policy.
- Cookieless usage statistics — we also use Plausible Analytics, an EU-hosted, privacy-first tool that runs on every visit. It sets no cookies, stores no personal data and does not track you across sites or devices — it counts page views and clicks in aggregate only, so we can see which pages are useful. No consent is required for it because it processes no personal data.
- Correspondence — the content of emails and support messages you send us.
3. Why we use it, and our legal basis
| Purpose | Legal basis (UK GDPR) |
|---|---|
| Creating your account and providing the proxy, dashboard, and scanning services | Performance of a contract |
| Taking payment and managing subscriptions and renewals | Performance of a contract |
| Sending service emails: email verification, password reset, and renewal reminders | Performance of a contract; legal obligation (pre-renewal reminders under the Digital Markets, Competition and Consumers Act 2024) |
| Security, rate limiting, fraud and abuse prevention, and keeping decision logs | Legitimate interests (protecting our service and our customers) |
| Keeping accounting and tax records | Legal obligation |
| Understanding site usage through analytics | Consent (you can withdraw it any time via Cookie settings) |
| Measuring and targeting our advertising via the Meta Pixel | Consent (you can withdraw it any time via Cookie settings) |
| Responding to your enquiries | Legitimate interests |
We do not carry out automated decision-making that produces legal or similarly significant effects about you. The judge model makes block/allow decisions about requests, not about individuals, and does not profile you.
4. Who we share it with
We do not sell your personal data. We share it only with the service providers we need to run AiDren, each bound by a data-processing agreement:
- Stripe (Stripe Payments Europe Ltd / Stripe, Inc.) — payment processing and subscription billing.
- Resend (Resend, Inc.) — delivery of transactional emails.
- ipapi.co (Kloudend, Inc.) — a single geo-IP lookup at sign-up to derive your approximate country and city.
- Google (Google Ireland Ltd / Google LLC) — website analytics, only where you have accepted analytics cookies.
- Meta (Meta Platforms Ireland Limited) — ad measurement and targeting via the Meta Pixel, only where you have accepted advertising cookies. For pixel data AiDren and Meta are joint controllers for the collection and transmission of the event; Meta then processes it as an independent controller under its own privacy policy.
- Plausible (Plausible Insights OÜ, Estonia) — cookieless, EU-hosted aggregate usage statistics. Processes no personal data.
- Our hosting providers (UK-based) — the servers that run the marketing site, the dashboard, and the proxy. Enterprise customers may arrange a dedicated proxy deployment in another region, in which case their account data and decision logs are held in that region and covered by a separate data processing agreement.
- Our prompt-screening model provider (currently Google, via the Gemini API; we may fall back to another provider such as Anthropic) — the text of each API request is sent to a judge model to decide whether to block or allow it. Under the provider's paid API terms this content is not used to train their models, and we do not retain it.
- The LLM provider you configure (OpenAI, Anthropic, or Mistral) — your API requests are forwarded to the provider whose key you have added, so that provider can generate the response. For that request content you are the controller.
We may also disclose data where required by law, to establish or defend legal claims, or as part of a business sale or reorganisation.
5. International transfers
Some of the providers above process data outside the UK (for example in the EEA or the United States). Where they do, transfers are covered by UK adequacy regulations, the UK International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism.
6. How long we keep it
- Account data — for as long as your account is open, then deleted within 90 days of account closure (unless we must keep it longer for the reasons below).
- Proxy decision logs — retained on a rolling 12-month basis, then deleted.
- Billing and accounting records — 6 years from the end of the relevant tax year (UK tax law).
- Analytics data — retained by Google for 14 months.
- Advertising and conversion data — the pixel cookies expire after 3 months; event data held by Meta is retained under Meta's own policy (Meta states it deletes or de-identifies raw pixel event data within a maximum of 90 days).
- Support correspondence — up to 2 years.
7. Your rights
Under UK data protection law you have the right to access your data; to have it corrected or erased; to restrict or object to processing; to data portability; and to withdraw consent at any time (which does not affect processing already carried out). To exercise any of these, email [email protected]. We will respond within one month.
If you are not satisfied with how we handle your data you can complain to the ICO at ico.org.uk or on 0303 123 1113.
8. Security
All traffic is served over HTTPS. Passwords are hashed with bcrypt. Configured provider keys are encrypted at rest. Access to production systems is restricted and logged. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data and will notify you and the ICO of a personal data breach where the law requires.
9. Children
AiDren is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18.
10. Changes
We may update this policy. We will change the date above and, for material changes, notify account holders by email.
11. Contact
[email protected] — AiDren, 47 Bengal Street, Ancoats, Manchester, M4 6BB.