Privacy Policy
We do not sell your data, we do not keep your prompts, and you do not need an account to use any tool on this site. This policy sets out exactly what we do collect, why we collect it, how long we keep it, and how to make us delete it.
Key points at a glance
A summary for orientation only — the full policy below is what actually governs.
Prompts are not stored
Your input goes to the model provider for that one request and is not persisted by us.
Never sold
We do not sell, rent or trade your data — to anyone, for any purpose.
No account needed
Every tool works without signing up, so there is no profile to leak.
30-day response
GDPR and CCPA requests are answered within 30 days of receipt.
Who we are
AIToolsay operates aitoolsay.com and every AI tool, directory listing, glossary entry and article published on it. For the purposes of the UK and EU General Data Protection Regulation we are the data controller for the personal data described in this policy. For India's Digital Personal Data Protection Act we act as the Data Fiduciary.
Questions about anything here go to privacy@aitoolsay.com, and we answer them.
The short version
- You can use every tool on this site without an account. No email, no sign-up, no profile.
- What you type into a tool is sent to the AI provider that runs it, used to produce your result, and not stored by us afterwards.
- We never sell, rent, trade or licence personal data. There is no version of this business that depends on doing so.
- Analytics and advertising cookies stay off until you turn them on.
- You can ask us what we hold, ask for it back, or ask us to erase it — and we will do it within 30 days.
Data we collect
Prompts and tool input
When you run a tool, the text you enter is transmitted over an encrypted connection to the AI provider whose model powers that tool. It is used for that single request and returned to you as output.
We do not write your prompts to our database, we do not build a usage history against you, and we do not use your input to train any model. Transient copies may exist in server memory or provider logs for the seconds it takes to answer — that is a property of how the request is routed, not a store we can query.
Account data — only if you create one
Accounts are optional and exist for people who buy a service or manage a directory listing. Where you do create one we hold your name, email address, a hashed password, and any profile details you choose to add. We never see your password in readable form.
Billing data — only if you buy something
Payments are processed by our payment providers. We never see or store your full card number, CVV, or bank credentials — those go directly to the processor. We retain the transaction record (amount, currency, date, product, last four digits, gateway reference) because tax and accounting law requires us to.
Contact and submission data
If you email us, use the contact form, report an issue, request a tool or submit a listing, we keep what you sent so we can act on it and refer back to it. That includes your name, your email address and the content of your message.
Analytics — aggregate, and opt-in
With your consent we use Google Analytics 4 to count page views and tool usage in aggregate. It tells us which tools people find useful. It does not tell us who you are, and we have IP anonymisation enabled. If you never grant analytics consent, GA4 never loads.
Technical and security logs
Our servers keep short-lived logs — request URL, timestamp, HTTP status, truncated error trace, and a coarse IP record used for rate-limiting and abuse prevention. These are retained for up to 30 days and then rotated out. They exist so the site stays up and does not get abused.
Things stored only in your own browser
Bookmarks, saved tools, theme preference and language preference live in your browser's own storage. They never reach our servers. Clearing your browser data clears them.
What we do not collect
- No behavioural profiling. We do not build an advertising profile of you.
- No cross-site tracking. We do not follow you around the web.
- No device fingerprinting. We do not attempt to identify you when cookies are unavailable.
- No sale of data. Under CCPA/CPRA terms, we do not "sell" or "share" personal information, and we never have.
- No special-category data. We do not ask for health, biometric, religious, political or sexual-orientation data. Please do not put such data into a prompt.
Why we are allowed to process it (legal bases)
- Contract — to deliver a tool result, fulfil an order or run an account you asked us to create.
- Consent — analytics cookies, advertising cookies, and the newsletter. Withdrawable at any time, as easily as it was given.
- Legitimate interests — keeping the service secure, preventing abuse and fixing faults. We have weighed this against your rights and kept the data minimal and short-lived.
- Legal obligation — retaining invoices and tax records for the statutory period.
Who else sees your data
We share data only with processors who need it to run the service, and only under contract. We do not sell to, or share for advertising with, anyone.
- AI model providers — the provider whose model runs the specific tool you used receives your prompt for that request. Each operates under its own API terms and privacy policy.
- Payment processors — receive what they need to take a payment, directly from you.
- Hosting and infrastructure — our servers and CDN.
- Email delivery — for transactional mail and, if you subscribed, the newsletter.
- Analytics — only after you consent.
- Legal — where we are compelled by a valid legal order. We will tell you unless we are legally prohibited from doing so.
International transfers
Our providers may process data outside your country, including in the United States. Where personal data leaves the UK or EEA we rely on Standard Contractual Clauses or an adequacy decision, and we satisfy ourselves the recipient's safeguards are adequate before we send anything.
How long we keep things
- Prompts and tool output — not retained.
- Server and security logs — up to 30 days.
- Contact and support messages — up to 24 months, so we can pick up a thread you started.
- Account records — while the account is open, then deleted within 90 days of closure.
- Invoices and tax records — as long as tax law requires, typically 6–8 years. This one we cannot shorten on request.
- Newsletter subscription — until you unsubscribe.
Your rights
Wherever you live, we will honour the following. You do not need to cite a law to exercise them.
- Access — get a copy of what we hold about you.
- Rectification — have inaccurate data corrected.
- Erasure — have your data deleted, subject to records we must keep by law.
- Portability — receive your data in a machine-readable format.
- Restriction and objection — tell us to stop a particular processing activity.
- Withdraw consent — at any time, without affecting what was lawful before you withdrew.
- No automated decisions — we do not make decisions with legal effect about you by automated means.
- Non-discrimination — exercising any of these will never get you a degraded service.
Email privacy@aitoolsay.com or use the privacy centre. We respond within 30 days. We may ask you to confirm your identity first, and only to the extent needed to be sure we are not handing your data to someone else.
If you are unhappy with our answer you may complain to your national supervisory authority — in the UK the ICO, in the EU your local DPA, and in India the Data Protection Board. We would rather you came to us first, but it is your right either way.
Children
This service is not directed at children under 13, and we do not knowingly collect their personal data. If you believe a child has submitted information to us, write to privacy@aitoolsay.com and we will delete it promptly.
Security
All traffic is encrypted in transit with TLS. Passwords are hashed, never stored in readable form. Administrative access is restricted and logged, and our servers are patched on a routine schedule. Not retaining prompts is itself a security measure: there is no archive of what people typed for anyone to steal.
No system is perfectly secure. If you find a vulnerability, please report it to security@aitoolsay.com — we will not pursue researchers who act in good faith and give us a reasonable chance to fix the issue before disclosure.
Changes to this policy
When this policy changes, the current version replaces it at this URL and the last-updated stamp at the top of the page moves. Where a change materially reduces your rights we will give prominent notice on the site before it takes effect.
Contact
Privacy and data-protection matters: privacy@aitoolsay.com. Security reports: security@aitoolsay.com. Anything else: the contact page.
Everything you wanted to ask
Still stuck? Our team answers every message.
Still have a question? We usually reply within one working day. Report Issues A broken tool or a missing page? Tell us. Submit your AI tool Add your AI tool to our directory.
Does AIToolsay store my prompts?
No. Your prompt is sent to the AI provider to answer that one request and is not written to our database. We do not build a history of what you have typed, and we do not use it to train models.
Do you sell my data?
No — not to advertisers, not to data brokers, not to anyone. Under CCPA/CPRA definitions we neither "sell" nor "share" personal information, and we never have.
Do I need an account to use the tools?
No. Every tool works without signing up. Accounts exist only for people who buy a service or manage a directory listing.
Which AI providers can see what I type?
Only the provider whose model powers the specific tool you are using. Each operates under its own API terms and privacy policy.
How do I get my data deleted?
Email privacy@aitoolsay.com or use the privacy centre. We complete verified erasure requests within 30 days, apart from invoices and tax records that law requires us to keep.
Is this policy GDPR and DPDP compliant?
Yes. We identify a legal basis for every processing activity, honour access, correction, erasure and portability within 30 days, and use Standard Contractual Clauses for transfers outside the UK and EEA.
What happens if there is a data breach?
We will notify the relevant supervisory authority within 72 hours where the law requires it, and tell affected people directly where there is a high risk to their rights.
Something here unclear?
Legal writing is easy to get wrong. If any part of this page is ambiguous — or you think it is mistaken — tell us and we will fix the wording.