Signalcroft AI

Privacy Notice

What we collect, why we collect it, and what you can ask us to do about it.

Last updated 28 July 2026. This is the first published version.

In short. We collect the minimum needed to run the service: your name and email so you have an account, and what you use inside the platform so we can improve it. We do not sell your data, we do not use it to train AI models, and we do not run third-party advertising or tracking on our website.

Who we are

Signalcroft AI Ltd is the data controller for the personal data described here. We are registered in England and Wales, company number 17364692, with our registered office at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ.

For any privacy question, or to exercise any right below, email [email protected]. A person reads it and we aim to reply within five working days, and always within one month as the law requires.

What we collect, and why

WhatWhy we need itLawful basis
Name and emailTo create your account, sign you in, and send service messages such as your trial confirmation and password resetsContract
PasswordTo protect your account. We never store it: we keep only a one-way cryptographic hash, and we check new passwords against a public breach database so you cannot pick one already exposedContract
Sign-in sessionsTo keep you signed in securely and let you sign outContract
Which sections you openTo see which parts of the platform earn their place and which do not, so we improve the right thingsLegitimate interests
Ratings and posts you writeTo show your contributions to colleagues in your own organisationContract
Website visitsTo count visitors and see which pages work. No cookie is set unless you consent, and we never store your IP addressLegitimate interests, and consent for any cross-visit identifier
Emails we send youTo keep a record that a message was sent and delivered, so we can help if something goes missingLegitimate interests

Where we rely on legitimate interests, we have considered your rights and concluded that the processing is limited, expected, and does not override them. You can object at any time using the contact address above.

What we do not do

Who else processes your data

We use a small number of suppliers to run the service. Each acts only on our instructions under a data processing agreement.

SupplierWhat they doWhere
CloudflareHosts the platform and stores its databaseGlobal edge network, with EU and UK presence
ResendDelivers our emails to youEU region
Google WorkspaceOur business mailbox, when you email usEU and US
AnthropicProvides the AI models behind the serviceUS, under terms that forbid training on our data

Where a supplier processes data outside the UK, the transfer is covered by the UK International Data Transfer Addendum or equivalent safeguards approved under UK law.

Your organisation and what colleagues can see

If you sign up with a work email address, anything you post to the community board is visible to colleagues who share your email domain, and to nobody outside it. If you use a personal email provider such as Gmail or Outlook, you are treated as an organisation of one and no other member can see your posts or your name.

How long we keep it

Your rights

Under UK GDPR you can ask us to:

Email [email protected] and we will act without charge. If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you told us first so we can put it right.

Cookies and similar technology

Our website sets no cookie until you choose. If you accept, we store a single identifier so we can tell a returning visitor from a new one. If you decline, we still count the visit but cannot link it to any other visit. You can change your choice at any time using the link in our website footer.

The platform itself sets one essential cookie when you sign in, which keeps you signed in. It is required for the service to work and is not used for tracking.

Security

Everything travels over encrypted connections. Passwords are protected with strong, deliberately slow one-way hashing that meets current OWASP guidance. Access to the platform requires a valid session, and members of one organisation cannot see another organisation's people or content. We review the platform's security every day and fix problems as we find them.

If something goes wrong

If a breach occurs that is likely to risk your rights and freedoms, we will report it to the ICO within 72 hours of becoming aware, and tell you directly without undue delay where the risk to you is high.

Children

The service is sold to professionals and is not intended for anyone under 18. We do not knowingly collect data about children.

Changes to this notice

If we change how we use personal data, we will update this page and change the date at the top. Where a change materially affects you, we will tell you by email.