Privacy policy

Private by design.

Last updated: 20 August 2026. This draft must be checked against the exact production providers, company details and retention settings before launch.

Our core promise

The Scripts is designed for sensitive workplace situations. We do not sell the content of your workplace conversations. We do not use your conversation content to train AI models by default. If a future optional product-improvement programme uses conversation content, it must require separate, explicit opt-in consent.

What we process

We may process your account details, subscription status, product usage events and the workplace situation content you choose to provide. Please avoid real names and unnecessary sensitive personal information.

Why we process it

We process information to provide Script Coach, preserve conversation context you choose to save, secure and improve the service, manage subscriptions and meet legal obligations.

AI processing

Script Coach sends the minimum context needed to the configured AI provider through a server-side endpoint. The production integration should disable model-training use and unnecessary provider-side storage where the provider supports this. The exact provider and retention configuration must be listed here before public launch.

Hosting and payments

The production architecture is prepared for Supabase for authentication/database and Stripe for subscription billing. Those providers act under their own data-processing terms. Do not claim a provider is active here until it is actually configured in production.

Retention and deletion

Users should be able to delete individual conversation threads and request account deletion. Production retention periods must be configured and documented, with only legally required payment/accounting records retained where applicable.

Your UK data rights

Depending on the lawful basis and circumstances, UK GDPR rights can include access, correction, erasure, restriction, objection and data portability. Users should also be told how to complain to the ICO.

Security

Production should use encrypted transport, row-level security, least-privilege service credentials, secure server-side secrets and access logging. API keys must never be exposed in browser code.

Contact

Add the legal entity name, registered address and privacy contact email here before launch.