Privacy Policy
In short: we keep your account, your conversations and the decisions you save, because that is the product. Answering a question means sending it to the AI providers behind your council — OpenAI and Anthropic — which process it in the United States and, under their terms for API customers, do not train their models on it. We set no advertising or analytics cookies and we never sell your data. You can ask for a copy of your data, or for it to be erased, at any time.
1. Who is responsible for your data
The controller of the personal data processed through Link Council AI, within the meaning of Article 4(7) of the EU General Data Protection Regulation (GDPR), is:
The operator of this deployment has not published its name, postal address and contact email yet. Do not create an account here until it has.
Write to that address with any question about this policy or about your data. We have not appointed a data protection officer, because the GDPR does not require one for a service of this kind and size.
2. What this policy covers
This policy explains what personal data we process when you use the Link Council AI web application and the API behind it (together, "the service"): what we collect, why, on what legal basis, who receives it, how long we keep it, and which rights you have. It is information we owe you under Articles 13 and 14 GDPR — it is not something you are asked to consent to.
3. What we process, why, and for how long
| Data | Why | Legal basis | Kept for |
|---|---|---|---|
| Account details — your email address, display name, and password, which is stored only as a salted one-way hash. If you use Google: your Google account identifier, name and verified email address. | To create your account, sign you in, and contact you about it — for example with a password-reset link. | Performance of our contract with you (Art. 6(1)(b) GDPR). | Until your account is erased. |
| Your acceptance of our terms — the version of the Terms of Service you accepted and the moment you accepted it. | To know which terms apply to your account, and to be able to show it. | Art. 6(1)(b) GDPR, and our legitimate interest in evidencing the contract (Art. 6(1)(f) GDPR). | Until your account is erased. |
| Conversation content — the questions you ask, each model's answer, each model's structured position on your question (stance, self-reported confidence, key reasons and risks), the secretary's synthesis, and the decisions you save to your journal. | This is the service itself: showing you your council's answers, keeping your history, and keeping your decision journal. | Art. 6(1)(b) GDPR. | Until you ask us to delete it, or your account is erased. |
| Usage records — for each call to an AI model: the provider, the model, the number of tokens, the cost, whether it succeeded, when it happened, and which conversation it belonged to. They contain no text from your conversations. | To control what the service costs to run, plan capacity, and decide things such as which models to offer by default. | Our legitimate interest in running the service economically (Art. 6(1)(f) GDPR). | While your account exists; afterwards only in a form that can no longer be linked to you. |
| Sign-in sessions — when each session was issued and when it expires, stored against a one-way hash of its token rather than the token itself. | To keep you signed in, and to recognize a stolen session token if someone tries to reuse it. | Art. 6(1)(b) GDPR, and our legitimate interest in security (Art. 6(1)(f) GDPR). | A session lapses after 14 days without use; its record is kept until your account is erased. |
| Technical logs — IP address, time, request and trace identifiers, your account identifier when you are signed in, which operation ran and how long it took, errors, and the token count and cost of each AI call. Logs record what happened rather than what you wrote: they never contain your questions, and the only content that can reach them is a short excerpt of a model's reply — at most 60 characters — kept when the reply arrives malformed and the fault has to be diagnosed. | To keep the service secure, prevent abuse (for example by rate-limiting requests), find and fix faults, and measure cost. | Our legitimate interest in a secure, working service (Art. 6(1)(f) GDPR). | 14 days, then deleted automatically. |
We do not use your data for advertising, we do not build profiles of you, and we do not sell your personal data or share it with data brokers.
4. How your questions reach the AI models
Link Council AI does not run its own language models. When you put a question to your council, we send it to each model you seated, at that model's own provider:
- OpenAI — privacy policy
- Anthropic — privacy policy
What each model receives
- Your new question, the earlier questions in the same conversation, and that model's own earlier answers in it. A model never receives another model's answers — the council's opinions stay independent.
-
When you ask for a synthesis with
@secretary, each model is shown its own answer again and asked to restate its position in a fixed format. Those positions — not the full answers — are then sent to one of the two models, which acts as secretary.
What they do not receive
We do not send your name, email address, password or other account details to either provider. What you type into a conversation is sent as you wrote it, apart from the leading @mention that routes a follow-up, which is stripped before the call. Please do not include information you would not want a third party to process: health data or other special categories of data, other people's personal data, passwords, or confidential information you are not permitted to share.
What the providers do with it
Both providers process your conversation content on our behalf, as processors under data-processing terms (Art. 28 GDPR). Under their current terms for API customers, neither uses API inputs or outputs to train its models. Each may keep them for a limited period — generally no more than 30 days — to detect abuse, or for longer where the law requires it or where content has been flagged as violating its usage policies. Both process data in the United States; see section 6.
No automated decisions about you
The council's answers, confidence figures and recommendations are generated automatically, but they are information for you to weigh. We make no decision about you based solely on automated processing within the meaning of Article 22 GDPR.
5. Who else receives your data
- Our hosting provider, which runs the servers and the database the service uses, acting as our processor.
- Our email delivery provider, which sends password-reset emails on our behalf and receives your email address and the message.
- Google, if you choose to sign up or sign in with Google. Google authenticates you and tells us your account identifier, name and verified email address. Google handles the sign-in itself as an independent controller, under its own privacy policy.
- Authorities and courts, only where we are legally obliged to disclose data, or where it is necessary to establish, exercise or defend legal claims.
6. Transfers outside the EU and EEA
OpenAI and Anthropic are based in the United States and process data there, and our hosting and email providers may do so as well. Where a recipient is certified under the EU–U.S. Data Privacy Framework, the transfer relies on the European Commission's adequacy decision for it (Art. 45 GDPR). Otherwise it relies on the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR), with additional safeguards where they are needed. You can ask us for a copy of the safeguards that apply.
7. Cookies
We only use cookies the service needs in order to work. They are strictly necessary within the meaning of Article 5(3) of the ePrivacy Directive, which is why we do not ask for your consent to them. We use no analytics, advertising or social-media cookies and no tracking pixels, and our sign-in and sign-up pages load nothing from third parties.
| Cookie | Purpose | Lasts |
|---|---|---|
council.auth |
Keeps you signed in to the web app. | Until you close your browser — or, if you choose "Keep me signed in", until your session lapses after 14 days without use. |
.AspNetCore.Antiforgery.* |
Protects our forms against cross-site request forgery. | Until you close your browser. |
.AspNetCore.Identity.External, .AspNetCore.Identity.Application |
Set by our API while it completes a sign-in with Google. | Until you close your browser; the first is removed as soon as the sign-in completes. |
8. How we protect your data
- Passwords are stored only as salted, iterated one-way hashes, never in readable form.
- Session tokens are stored only as hashes, so a copy of our database cannot be used to sign in as you.
- All traffic is encrypted in transit, and browsers are told to connect over HTTPS only.
- Repeated failed sign-ins lock an account for a few minutes, and password-reset requests are rate-limited.
- Operational logs can be read only by people we have authorized to maintain the service.
No system is perfectly secure. If a personal data breach is likely to result in a high risk to your rights and freedoms, we will tell you without undue delay (Art. 34 GDPR).
9. Your rights
Under the GDPR you have the right to:
- Access your personal data and receive a copy of it (Art. 15).
- Rectification of data that is inaccurate or incomplete (Art. 16).
- Erasure of your data, including your whole account (Art. 17).
- Restriction of processing, for example while the accuracy of data is contested (Art. 18).
- Data portability — your account details and conversation content in a structured, machine-readable format (Art. 20). You can also copy any saved decision as Markdown from its page at any time.
- Lodge a complaint with a data protection supervisory authority, in particular in the EU member state where you live, where you work, or where you believe the infringement took place (Art. 77).
Right to object (Art. 21 GDPR). Where we process your data on the basis of our legitimate interests, you may object at any time on grounds relating to your particular situation. We will then stop, unless we can demonstrate compelling legitimate grounds that override your interests, or need the data to establish, exercise or defend legal claims.
To exercise any of these rights, email the operator's contact address. The service does not yet offer self-service export or account deletion, so we handle these requests by hand. We reply within one month; for complex requests that period can be extended by two further months, in which case we tell you why within the first month (Art. 12(3) GDPR). Exercising your rights is free. We may ask you to confirm a request from the email address of your account, so that we only ever hand your data to you.
10. Do you have to give us your data?
To create an account we need an email address and a password, or a Google account; without them we cannot provide the service. Everything you type into a conversation is up to you.
11. Children
The service is not directed at children. You must be at least 18 years old to create an account, and we do not knowingly process data about anyone younger. If you believe a child has created an account, tell us and we will delete it.
12. Changes to this policy
We will update this policy when the service or the law changes. Every version carries the version date shown at the top of this page. If a change materially affects how we use your data, we will tell you before it takes effect, by email or in the service.