Legal

Privacy Notice

Last updated: 31/08/2026  ·  Version 1.0

The short version

We hold your account, billing and usage data to run the service and bill you correctly. When you run the AI policy checker, the document text you upload is sent to Anthropic (who provide the AI model) to be analysed, and the resulting report — which quotes parts of your document — is saved to your account. We don't sell your data, and we only send it to the handful of named processors below who help us run PolicyStack.

This summary is a courtesy, not the contract. The numbered terms below are what governs.

1. Who we are

1.1PolicyStack is a trading name of ELITE4U LTD, company number 14657268, registered in England and Wales. Registered office: Office 7775, 321-323 High Road, Romford, England, RM6 6AX. We are the controller of your account, billing and usage data.

1.2Our data protection contact is info@policystack.co.uk. We don't currently meet the criteria that require us to appoint a statutory Data Protection Officer, but this inbox is answered by a person and is the right place to raise anything about your data.

2. What we collect, and why

2.1Account data. Your name, email address, password (stored as a one-way cryptographic hash, never in plain text — or nothing, if you sign in with Google or Apple), your organisation's name, and the sector you work in. Used to run your account and personalise the policy library and checker to your sector.

2.2Marketing preference. Whether you've opted in to marketing email, and when you accepted our terms and the digital-content waiver at checkout (see the Terms of Sale) — kept as evidence of what you agreed to and when.

2.3Subscription and billing data. Which plan you're on, its status, the price and period you're billed for, and a reference id from our payment processor, Stripe. We don't store your card details ourselves — Stripe holds those.

2.4Credit ledger. A record of every credit granted to or spent from your account — a signup bonus, a monthly plan grant, a purchased pack, a spend on a check, or a refund — each with a timestamp. We keep this as a ledger, not a single running total, so your balance can always be reconciled and explained.

2.5Purchases. What you bought (a document pack, a single policy, a credit pack, or a subscription payment), the price, and its status (paid, refunded, failed), linked to a Stripe payment reference.

2.6Owned policies. Which policy documents your account has bought and can download.

2.7Reports. See §3 below — this is the output of the AI checker and needs its own explanation.

2.8Usage and traffic data. Which pages you (or an anonymous visitor, before signing up) view, and where you came from, so we can see what parts of the site are actually used. This is counted server-side from a salted hash of your IP address and browser type, combined with the day's date — nothing is stored on your device to do this, and the hash can't be linked to you the next day. See our Cookie Notice for exactly how this works.

3. The AI policy checker, specifically

3.1When you run a check, the text of the document you upload is sent to the Claude API, operated by Anthropic Ireland, Limited, to be analysed. We also keep the file itself, exactly as you uploaded it, in our own database — see §3.6 for what we do with it and §7.4 for how long we keep it.

3.2The result — a structured report on your document, which necessarily quotes short excerpts of your own document's text to explain its findings — is saved to your account under "Reports" so you can come back to it.

3.3Anthropic states that it does not use API inputs or outputs to train its models by default. We do not send your documents to any other AI provider, and we do not train any model on them ourselves — the improvement described in §3.6 is people reading documents and changing how the product works, not machine learning on your text.

3.4A failed or errored check is not charged a credit, and no report is saved from it — see the Terms of Sale §9.2.

3.5Please don't upload documents containing personal details about named children or staff, or other sensitive information, unless you have to — the checker only needs the policy text. See our Acceptable Use Policy. We ask this at the upload control itself, not only here, but it's an instruction, not a technical control — treat anything you upload as something that will be processed and retained as described above.

3.6We keep the documents you upload, and we use them to make the checker better. A document that the checker handled badly is the only reliable evidence that it handles that kind of document badly, so we retain every file submitted for a check — including ones where the check failed — and our own staff may read them to find where the analysis was wrong, what the corpus is missing, and which policy areas the product does not yet cover properly. This is described in the Terms of Sale as well. We never publish your document, share it with another customer, or pass it to anyone outside the processors named in §5. You can ask us to delete it at any time — see §7.4 and §8.

4. Our lawful basis for each purpose

4.1Running your account and delivering what you've bought (account data, billing, credit ledger, purchases, owned policies, reports) — necessary to perform our contract with you.

4.2Marketing email to existing customers about products like the ones you've bought — our legitimate interest in telling customers about relevant updates, balanced against your right to say no. You can opt out at any time, and every marketing email carries an unsubscribe link. We don't email anyone who hasn't bought from us or explicitly asked to hear from us.

4.3Usage and traffic analytics — our legitimate interest in understanding how the site is used so we can improve it. This is pseudonymous by design (a daily-rotating hash, not a persistent identifier), and your browser's Global Privacy Control or Do Not Track signal is honoured automatically. See the Cookie Notice for how it works.

4.4Complying with the law — for example keeping financial records, and responding to a lawful request from a regulator — a legal obligation.

4.5Preventing abuse of the service — our legitimate interest in keeping the free parts of the site working for the people they are for. Creating an account, and asking us what a document is, both cost us real money, so we count how many times each happens from one connection and stop at a limit set well above ordinary use. This uses the same daily-rotating hash described in §2.8 and the Cookie Notice; the raw IP address is never stored. Because a limit a browser setting could switch off would not be a limit, this specific counting is not disabled by Global Privacy Control or Do Not Track — those signals continue to be honoured for the analytics in §4.3.

4.6Keeping and studying uploaded documents to improve the checker (§3.6) — our legitimate interest in a compliance tool that gets the answer right, set against your interest in your own document. We think the balance holds because a policy submitted for marking is a work document rather than personal information, we ask you not to include personal details in it (§3.5), the file is never published or shared, and you can have it deleted on request. If you would rather we did not keep yours, tell us and we will delete it.

5. Who we share it with

5.1We share data with a small number of named processors, each engaged only to do the job described:

  • Stripe (payment processing) — your billing details and what you're charged for.
  • Resend (transactional and marketing email) — your email address and the content of the email we send you.
  • Vercel (application hosting) — the infrastructure the website and its server code run on.
  • Supabase (database hosting) — the managed PostgreSQL database that holds your account, your reports and the documents you upload. Our instance is hosted in the London (eu-west-2) region.
  • Anthropic Ireland, Limited (the AI model behind the policy checker) — the text of any document you submit for a check. See §3 and §6.

5.2We don't sell your data, and we don't share it with anyone for their own marketing purposes.

5.3We may disclose data where the law requires it — for example to a regulator, a court, or in response to a lawful request from a law enforcement body.

6. Sending data outside the UK

6.1Anthropic Ireland, Limited is our counterparty for the AI checker, but document text you submit may be processed by systems outside the UK. Where that happens, the safeguard relied on is the EU Standard Contractual Clauses together with the UK Addendum, as incorporated into Anthropic's Data Processing Addendum. We have not relied on the UK Extension to the EU-US Data Privacy Framework for this transfer, and your data does not stay exclusively within the UK.

6.2We haven't independently verified Anthropic's current certifications or the exact retention period Anthropic applies to processed content, and we don't repeat specific figures here that we can't stand behind — if you need that detail for your own compliance records, ask us and we'll get you Anthropic's current documentation.

7. How long we keep it

7.1Account, billing, purchase and credit-ledger data is kept for as long as your account is open, and for a period afterwards to meet our legal and accounting obligations (typically up to six years for financial records).

7.2Reports — including the quoted excerpts of your documents they contain — are kept for as long as your account is open, so you can refer back to your check history. We don't currently run an automatic deletion timer on reports, and there is no self-service "delete this report" control in your account yet. If you want a report deleted, email info@policystack.co.uk and we will delete it — this is a genuine gap between where we want to be and where the product is today, and we'd rather say so than claim a control that doesn't exist yet.

7.3Usage and traffic data is stored against a hash that rotates every day (see the Cookie Notice), so it's never linkable across days by design — it isn't a persistent record of "this browser's" history in the way a long-lived identifier would be.

7.4Documents you upload for a check are kept indefinitely, for the purpose described in §3.6. We do not run a deletion timer on them, because a document's usefulness in showing us where the checker is wrong does not expire. There is no self-service delete control for them; if you want yours deleted, email info@policystack.co.uk and we will delete it, and closing your account deletes them too. As with §7.2, we would rather describe the product as it is than claim a control it does not have.

7.5If you close your account, we delete or anonymise personal data we no longer need to keep for a legal reason, within a reasonable time.

8. Your rights

8.1Under UK data protection law, you have the right to:

  • ask us what personal data we hold about you, and get a copy of it (access);
  • ask us to correct data that's wrong or incomplete (rectification);
  • ask us to delete data we no longer have a good reason to keep (erasure) — including a saved report, per §7.2;
  • ask us to restrict how we use your data in some circumstances (restriction);
  • get your data in a portable format, or ask us to send it directly to another provider, where we process it by consent or under a contract and by automated means (portability);
  • object to processing based on our legitimate interests, including marketing and analytics, at any time (objection);
  • withdraw consent, where we rely on it, at any time, without affecting anything done before you withdrew it.

8.2To use any of these, email info@policystack.co.uk. We'll respond within one month.

9. Automated decisions

9.1The AI checker produces an automated analysis of your document, but it doesn't make a decision about you or your business with legal or similarly significant effect — it produces a report for you to read and act on, not an automatic outcome. See §3 and the Terms of Sale §12 for the disclaimer that goes with every analysis.

10. Keeping it secure

10.1We use industry-standard measures to protect your data — encrypted connections, hashed passwords, and access to production data limited to people who need it to run the service. No system is completely secure, and we treat any suspected breach as urgent and will tell you and the ICO where the law requires it.

11. If you're a controller relying on us

11.1When you upload a document to the checker, you remain the controller of any personal data it contains, and we act as a processor on your instructions. We've described how we handle that data throughout this notice.

11.2A full data-processing agreement, covering the standard processor obligations, and a named list of sub-processors, isn't published as a separate document yet. If you need one for your own compliance records — for example for an Ofsted or CQC data-protection review — email info@policystack.co.uk and we'll provide it directly. We're noting this as an outstanding item rather than implying it already exists as a page.

12. Complaining to the ICO

12.1If you're unhappy with how we've handled your data, we'd like the chance to put it right first — email info@policystack.co.uk. You also have the right to complain directly to the Information Commissioner's Office, the UK's data protection regulator, at ico.org.uk/make-a-complaint, or by calling 0303 123 1113.

13. Changes to this notice

13.1We may update this notice as our processing changes. We'll post the new version here with an updated date and version number, and tell existing customers by email of any material change.

13.2Version history: 1.0 — 31/08/2026 — first published version.

PolicyStack is a trading name of ELITE4U LTD, registered in England and Wales, company number 14657268.

Registered office: Office 7775, 321-323 High Road, Romford, England, RM6 6AX

Contact: info@policystack.co.uk