Privacy Policy
Last updated 20 August 2026. Plain English, no legalese we don't have to use.
Who this covers
This policy applies to hamishai.org, the Agency Platform (Studio, at hamishai.org/studio), and the client portal (hamishai.org/portal). Hamish AI is the data controller for hamishai.org's own services. For the Agency Platform, each agency using it is the data controller for their own clients' data — Hamish AI acts as a processor on their behalf. If you're a client of an agency using this platform, your agency is who to contact about your data first; they can reach us if they need to.
What we collect
Depending on how you use the site or platform, this can include:
- Contact details you give us directly — name, email, phone number, business name.
- Business informationabout companies we or an agency using the platform research — publicly available details like a business's website, location, and category.
- Account data — login email, organisation details, plan and billing status.
- Content you create in the platform — prospect notes, client requests, generated outreach drafts, and similar.
- Payment information, handled entirely by Stripe — we never see or store your card details.
How we use it
To actually deliver the service: running the prospecting and research tools, managing client requests, generating AI drafts, processing payments, and keeping you updated about your account. We don't sell your data, and we don't use it to train AI models beyond what's needed to generate the specific output you asked for.
Who else sees it
A small number of specific services we rely on to run the platform, each only seeing what they need to do their job:
- Anthropic (Claude) — processes text to generate research, drafts, and analysis. Not used to train Anthropic's models.
- Supabase — hosts our database, with row-level security enforcing that one organisation's data is never visible to another.
- Stripe — processes payments. Agency Platform tenants who connect their own Stripe account are paid directly by their clients; we never hold that money.
- Resend — sends transactional emails (invoices, notifications).
- Microsoft — only if you explicitly connect an Outlook inbox for reply detection, and only to check whether a message exists, never its content.
- PostHog — first-party product analytics (which pages are visited, which features are used). No advertising trackers, no cross-site tracking, and no data sold or shared with ad networks.
How long we keep it
For as long as your account is active, plus a reasonable period afterwards in case you want to reactivate or need a record for a dispute. If you ask us to delete your data (see below), we do — some operational records (like security logs) are kept in an anonymised form rather than deleted outright, since they don't identify you once the link to your account is removed.
Your rights
Under UK GDPR, you can ask to see what we hold about you, correct it, or have it deleted. In practice:
- Agency Platform tenants can export everything held about their organisation from Studio → Settings, or request full account deletion from the same page.
- An agency's own clients should contact that agency directly — they can remove your data from their side of the platform on request.
- For anything else, or if your agency isn't reachable, email us at HamishWebDesign1@gmail.com and we'll help directly.
Security
Every organisation's data is isolated at the database level (row-level security), not just in application code. Connections are encrypted in transit. Access to production data is limited to what's needed to run and support the platform.
Changes to this policy
If this changes in a way that affects how your data is handled, we'll update the date at the top of this page. Significant changes will be communicated directly, not just posted quietly here.
Questions
Email HamishWebDesign1@gmail.com and we'll get back to you.