Privacy policy
Last updated 5 October 2026
This policy explains how autoai.im (“autoai”, “we”, “us”), operated by the operator of autoai.im, handles personal data. We follow the UK General Data Protection Regulation and the Data Protection Act 2018.
Two kinds of data
- Customer account data — information about the businesses and people who sign up to autoai. For this data we are the controller.
- Visitor data — conversations and contact details from people who chat with an assistant on a customer’s website. For this data the customer is the controller and we are their processor, acting on their instructions under our data processing terms. If you chatted with an assistant on someone else’s website, please contact that business about your data.
What we collect from customers
- Account details: name, email address, password (stored as a secure hash), business name and team members.
- Content you add: website addresses, pages we crawl for you, uploaded files, text and Q&As.
- Billing details: plan and subscription status. Card payments are handled by Stripe; we never see or store full card numbers.
- Technical data: IP address, browser type and log data needed to keep the service secure and working.
How we use it
- To provide the service you signed up for (contract).
- To bill you and keep financial records (contract and legal obligation).
- To keep the service secure, prevent abuse and fix problems (legitimate interests).
- To send service emails such as invitations, lead notifications and usage alerts (contract). We don’t send marketing emails without your consent.
AI processing
To write answers, the visitor’s question, recent conversation and relevant parts of the assistant’s knowledge are sent to our AI provider, Anthropic, which processes them on our behalf. Under Anthropic’s commercial terms, data sent through its API is not used to train its models.
Who we share data with
We use a small number of trusted providers (sub-processors): Anthropic (AI answers), Stripe (payments), our hosting and email delivery providers. Each is bound by contract to protect your data. We don’t sell personal data. Some providers may process data outside the UK; where they do, we rely on appropriate safeguards such as the UK International Data Transfer Addendum or adequacy regulations.
Cookies and storage
On autoai.im we use a session cookie to keep you logged in, a security cookie to protect forms, and a small preference cookie so our public pages know you’re signed in. We don’t use advertising or analytics cookies. The chat widget on customers’ websites sets no cookies; it keeps the current conversation in the visitor’s browser storage so it survives page changes.
How long we keep data
- Account data: while your account is open, and deleted within 30 days of you deleting your workspace (except records we must keep for tax purposes, usually six years).
- Visitor conversations and leads: until the customer deletes them or their workspace.
- Server logs: up to 14 days.
Your rights
You can ask to access, correct, delete or export your personal data, object to or restrict how we use it, and withdraw consent where we rely on it. Email [email protected]. You can also complain to the Information Commissioner’s Office (ico.org.uk).
Security
Data is encrypted in transit (HTTPS), passwords are hashed, each workspace’s data is isolated, and access is limited to people who need it.
Changes
We’ll update this page if anything changes and tell customers by email about significant changes.