Privacy Policy
LAST UPDATED · 2026-07-10
This is what AIRIN collects, what we don't, and what you control. We've written it in plain English. The legal terms are the legal terms — but you shouldn't need a lawyer to understand any of this.
1.What we collect
Email addresses
When you subscribe to our policy-change alerts or weekly digest, we collect your email address (and, optionally, your professional role) via a form embedded on this site. The form submits directly to Kit.com (formerly ConvertKit), which acts as our email delivery processor. We use this only to send the updates you asked for.
Legal basis (GDPR): consent. You can withdraw consent at any time by clicking the unsubscribe link in any email we send you.
Analytics data
We use two kinds of analytics, and both are consent-gated: a first-party usage log on our own infrastructure (described in full below), and Google Analytics 4(Google's measurement service) to understand traffic sources and improve the site.
Consent & your choice. When you first visit, a banner asks about analytics. In the EU, EEA, UK, and Switzerland we use an opt-in model — nothing non-essential (no IP-derived data stored, no Google Analytics) runs until you accept. Everywhere else we use an opt-outmodel, and the "Do Not Sell or Share" / reject control turns analytics off; we also honor the Global Privacy Control browser signal automatically as a valid opt-out. Google Analytics runs under Google Consent Mode v2 with advertising signals denied by default, so no advertising or cross-site profile is built from your visit.
As part of our first-party analytics and to protect the service from automated and fraudulent traffic, when you consent we log your IP address and derive your approximate location from it (see below). Your IP address is personal data, so we ask for your consent where the law requires it, retain it for at most 90 days, and you have the access and deletion rights set out in Sections 5 and 6.
Usage & analytics events
We keep a first-party, privacy-preserving log of how the site is used. It records which verified citationsget consumed (when a "jump to exact text" link or citation anchor is followed), which of our machine/API endpoints are requested, and page views— the path you visited and, on the first page of a visit only, the host name of the site you arrived from (for example "google.com" — never the full web address).
To measure aggregate engagement — such as how long a page is read, how many pages a visit includes, and the path taken from one page to the next — page views within a single visit are linked by an anonymous, ephemeral session identifier. This identifier is a random value generated in your browser's sessionStorage; it is not a cookie, it is automatically erased the moment you close the tab, it is never shared with any third party, it is never linked across different websites, and it is never tied to your identity or account. It exists only to group one visit's page views together so the aggregate numbers are meaningful.
Each event records: the page or endpoint path, the platform and citation identifier involved, a coarse client class derived from the User-Agent header (browser / AI agent / bot / API client), the anonymous session identifier described above, and — for page views — the referring site's host and the previous in-site path. For page views we additionally record, to understand our audience and to detect automated or purchased (non-human) traffic:
- Your IP address and its network range, and — where a network dataset is available — the associated network/hosting operator (ASN). Your IP address is personal data.
- Approximate location derived from that IP: country, region, and city (never a precise/GPS location).
- Device type, browser, and operating-system family (e.g. "mobile / Safari / iOS"), and any UTM campaign tags in the link you arrived from.
We use these to measure reach and audience, attribute traffic to sources/campaigns, and distinguish genuine visitors from bots and automated or "bought" traffic (security & fraud prevention). Legal basis (GDPR): our legitimate interest in understanding and securing the service — and, where the law requires consent for storing this data on EU/EEA/UK visitors, your consent. We still store no account, name, or emailwith these events, we build no advertising profiles, and we never sell this data. Retention: raw IP addresses are kept for at most 90 days, then deleted or irreversibly aggregated (see Section 8). You may request access to or deletion of data associated with your IP (Sections 5–6).
Ask AI questions
When you use the Ask AI feature, we store the question you submitted so we can review answer quality, detect abuse, and pre-generate better cited answers to common questions. Each stored record contains: the question text (capped at 2,000 characters), the time it was asked, whether a cited answer was found, the persona you selected, which platforms the question matched, and the same coarse client class described above. These records are identity-free — no IP address, no account identifier, and no cookie is stored with them — and they are read only by a small number of authorized administrators.
Before storage, the question text is automatically run through a server-side redaction filter that replaces anything shaped like an email address, phone number, payment-card number, or API key/credential with a [redacted] marker. This filter is a safety net, not a guarantee — please don't paste confidential contract text, personal details, or credentials into Ask; naming the platform and your concern is all it needs.
Retention: stored Ask questions are deleted automatically after 180 days. Deletion on request: because these records carry no identifier, we cannot look them up by your name or email — if you typed something into Ask that you want removed sooner, email privacy@airinetwork.com with the question text (or a distinctive part of it) and we will delete the matching records. Legal basis (GDPR): our legitimate interest in maintaining and securing the answer service.
If you are signed in when you use Ask, the question and its answer are additionally saved to your private Ask history so you can revisit them; that copy is tied to your account and you can delete individual saved answers at any time from My Ask, or remove them all by deleting your account from Settings.
Error diagnostics
When something breaks, we log an anonymized error diagnostic so we can fix it: a short error message, the page path where it happened, and a truncated technical stack trace. These are automatically scrubbed of anything email-shaped and carry no IP address, cookie, account, or personal identifier. They describe what broke, never who hit it.
Admin access logs
A small number of authorized administrators access internal, access-controlled management interfaces that let them review citations and exclude individual clauses from a platform's score. Those write operations are appended to an internal audit log with the timestamp, action, and citation identifier. This log contains no personal data about visitors — only what an administrator did and when. These internal interfaces are excluded from the usage event log.
2.What we do not collect
- No account required to read anything on this site. An optional account (see §2a) unlocks saved stacks, alerts, and API keys.
- No passwords — accounts use Google sign-in or a one-time email link; we never store a password.
- No payment information — purchases are handled entirely by Stripe; we never see your card.
- No biometric data.
- No advertising identifiers, and no cross-site advertising profiles — Google Analytics' ad features are denied by default under Consent Mode v2.
- We do not sell or share your personal information (see Section 7). Sponsors and partners receive only aggregated, non-identifying analytics — never your IP or an individual-level record.
- We do not use your data to build advertising profiles.
2a.If you create an account
Accounts are optional. If you sign in (Google OAuth or a one-time email link), we store the minimum needed to provide the account features:
- Your email address and, for Google sign-in, your name and avatar URL (from Google).
- Your saved platform stack and the platforms you watch for policy-change alerts.
- API keys you create — stored only as a one-way hash, never the key itself.
Authentication is handled by Supabase (our processor). You can export everything tied to your account, or delete your account entirely, at any time from Settings — deletion immediately removes your profile, stack, watches, alerts, and keys. Watching a platform delivers alerts to your in-app inbox only; it never emails you unless you separately subscribe to the email digest.
3.Cookies
We use these categories of cookies / local storage:
- Essential: a few
localStorageentries that store your compare-tray selection, saved stack, and bookmarks. These never leave your browser and don't require consent. - Consent preference: your analytics choice is stored in one
localStorageentry (airin_consent) plus a matching first-party cookie, so we remember it and honor it. It holds only your yes/no choice — no personal data. - Analytics session identifier (sessionStorage — not a cookie): to compute aggregate engagement metrics (time on page, pages per visit, click paths), we store a single random, anonymous session identifier in your browser's
sessionStoragefor the duration of one visit. It is not a cookie, it is erased when you close the tab, it never leaves your browser except as an opaque value attached to our first-party usage events, and it identifies a visit — never a person. - Analytics cookies (consent-gated): when you consent, Google Analytics sets its own first-party cookies (
_ga,_ga_*) to measure traffic. These are not set until you accept (or, outside the EU/UK, until you decline to opt out), and never at all if you reject analytics or send a Global Privacy Control signal. - No advertising cookies.Google Analytics' advertising features run denied-by-default under Consent Mode v2; we set no advertising cookies and build no cross-site ad profile.
See the Cookie Policy for the full inventory of what is stored locally.
4.Third-party processors
We rely on six third-party services. Each has its own privacy policy; if you have a question about how any of them handles your data, the linked policy is authoritative.
| PROCESSOR | PURPOSE | PRIVACY POLICY |
|---|---|---|
| Kit.com (ConvertKit) | Email delivery for the newsletter | kit.com/privacy ↗ |
| Vercel | Hosting and edge delivery | vercel.com/legal/privacy ↗ |
| Supabase | Account authentication & storage (only if you create an account) | supabase.com/privacy ↗ |
| Stripe | Payment processing (only if you purchase) | stripe.com/privacy ↗ |
| Anthropic | AI reasoning for the Ask AI feature (only if you use it) — the question you type, plus the relevant published policy citations, are sent to generate a cited answer. Your account identity is not sent, and Anthropic does not use this input to train its models. | anthropic.com/legal/privacy ↗ |
| Google Analytics | Traffic measurement (only with your consent) — page views, sources, and device/region breakdowns. Runs under Google Consent Mode v2 with advertising signals denied by default; no advertising profile is built. IP anonymization is enabled. | policies.google.com/privacy ↗ |
4a.Processing record
For procurement, privacy, and security review, AIRIN publishes a structured privacy processing record that maps each processing activity to the data categories, purpose, lawful basis, processor, retention posture, and user-rights path. The privacy policy on this page remains the canonical user-facing notice.
5.Your rights (GDPR — EU users)
If you're in the EU, EEA, UK, or Switzerland, you have the following rights under the GDPR (and equivalent local laws). To exercise any of them, email privacy@airinetwork.com.
- Access: get a copy of any personal data we hold about you (in practice: your email address and subscription preferences).
- Erasure: ask us to delete it. For email subscriptions, the unsubscribe link in any email handles this immediately. For accounts, delete everything yourself from Settings.
- Rectification: ask us to correct anything that's wrong. Account stack data is editable in Settings. For newsletter/Kit profile fields such as email or role, email privacy@airinetwork.com; we will update the subscriber record in Kit or send a fresh confirmation link if the change requires reconfirming consent.
- Restriction: ask us to pause processing while a dispute is resolved.
- Portability: get a structured copy of your data you can take elsewhere.
- Objection: object to processing on legitimate-interest grounds. (All our processing is consent-based, so this rarely applies.)
- Withdrawal of consent: at any time, with no effect on processing that was lawful before withdrawal.
- Lodge a complaint: with your national data protection authority if you believe we've handled your data improperly.
6.Your rights (CCPA — California users)
If you're a California resident, you have these rights under the California Consumer Privacy Act (CCPA), as amended by the CPRA. To exercise any of them, email privacy@airinetwork.com.
- Right to know: what personal information we collect, where we got it, why we collect it, and who (if anyone) we share it with.
- Right to delete: ask us to delete the personal information we have about you.
- Right to correct: ask us to fix inaccurate personal information, including newsletter/Kit profile fields handled through privacy@airinetwork.com.
- Right to opt-out of sale or sharing: we do not sell or share personal information — see Section 7 below.
- Right to non-discrimination: we won't treat you differently for exercising any of these rights.
7.Do Not Sell My Personal Information
AIRIN does not sell, rent, or share personal information with third parties for their marketing purposes. This section is provided to comply with the California Consumer Privacy Act (CCPA).
We collect only the data described in Section 1, use it only for the purposes it was collected (sending the emails you asked for; providing your account features; first-party audience analytics and security/fraud prevention, including IP-derived location retained for at most 90 days), and share it only with the processors named in Section 4 — each of whom acts on our behalf under a written processor agreement, not for their own purposes. Google Analytics is used as a service provider under Google's CCPA-restricted data-processing terms, with advertising signals denied by default. We do not sell it.
Platform sponsors and partners who pay for analytics about their listing receive only aggregated, non-identifying reporting (for example: total visits, country/device breakdowns, traffic sources, and bot-vs-human quality signals). They never receive your IP address or any individual-level record. That is not a sale or share of personal information.
How to opt out:use the "Do Not Sell or Share / Reject" control on the consent banner (re-openable anytime), or send a Global Privacy Control signal from your browser — we honor it automatically. Opting out turns off Google Analytics and stops any IP-derived data from being stored.
8.Data retention
- Email subscriptions: retained for as long as you stay subscribed. When you unsubscribe via the link in any email, the deletion is processed by Kit.com.
- Usage events: the first-party usage log (Section 1) carries no account, name, email, or cookie. It does record your IP address and IP-derived approximate location for page views. Raw IP addresses (and raw event rows) are retained for a maximum of 90 days, after which they are permanently deleted or irreversibly aggregated (aggregates carry no IP).
- Ask AI questions: stored identity-free (redacted and capped as described in Section 1) and deleted automatically after 180 days. You can request earlier deletion by emailing us the question text.
- Account data: retained for as long as your account exists, and deleted immediately when you delete your account from Settings. If you never create an account, none is held.
9.Children
AIRIN is built for legal, privacy, and product professionals — not children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, email privacy@airinetwork.com and we will delete it promptly.
10.Changes to this policy
We may update this policy from time to time. When we do, we'll update the “Last updated” date at the top of the page and, for material changes, note the change on the Updates page. Continued use of the site after the change means you've accepted the revised policy. If you don't, stop using the site and (if subscribed) unsubscribe.
11.Contact
Questions, requests, or complaints about privacy go to privacy@airinetwork.com. We aim to respond within 30 days; for GDPR / CCPA requests we respond within the deadlines those laws set (one month / 45 days respectively).
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.
