Skip to main content
AIPolicyCompare
Legal

Privacy Policy

LAST UPDATED · 2026-05-27

This is what AIPolicyCompare collects, what we don't, and what you control. We've written it in plain English. The legal terms are the legal terms — but you shouldn't need a lawyer to understand any of this.

1.What we collect

Email addresses

When you subscribe to our policy-change alerts or weekly digest, we collect your email address (and, optionally, your professional role) via a form embedded on this site. The form submits directly to Kit.com (formerly ConvertKit), which acts as our email delivery processor. We use this only to send the updates you asked for.

Legal basis (GDPR): consent. You can withdraw consent at any time by clicking the unsubscribe link in any email we send you.

Analytics data

We use Google Analytics 4 and Microsoft Clarity to understand how visitors use this site — page views, session duration, scroll depth, click patterns. These scripts only load after you explicitly accept the cookie consent banner. If you decline or haven't made a choice, no analytics data is collected.

IP addresses are anonymised in GA4 via the anonymize_ip: true flag. We use Google's Consent Mode v2 to default all advertising and ad-personalisation storage to denied, even after you accept analytics. No advertising tracking is used. No cross-site tracking is used.

Legal basis (GDPR): consent.

Admin access logs

A small number of authorized administrators access internal, access-controlled management interfaces that let them review citations and exclude individual clauses from a platform's score. Those write operations are appended to an internal audit log with the timestamp, action, and citation identifier. This log contains no personal data about visitors — only what an administrator did and when. These internal interfaces are excluded from analytics tracking.

2.What we do not collect

  • No user accounts. You don't need one to read anything on this site.
  • No passwords.
  • No payment information.
  • No biometric data.
  • No advertising identifiers.
  • We do not sell data to third parties.
  • We do not use your data for advertising — ours or anyone else's.

3.Cookies

We use two categories of cookies / local storage:

  • Essential: a single localStorage entry called cookie_consent that remembers whether you accepted or declined analytics, plus a few entries that store your compare-tray selection and bookmarks. These never leave your browser and don't require consent.
  • Analytics: Google Analytics 4 sets one or more cookies (typically _ga,_ga_*) and Microsoft Clarity sets one or more (_clck,_clsk). These are loaded only after you accept analytics in the consent banner.
  • No advertising cookies. Ever.

You can change your cookie preferences at any time. See the Cookie Policy for the reset button.

4.Third-party processors

We rely on four third-party services. Each has its own privacy policy; if you have a question about how any of them handles your data, the linked policy is authoritative.

PROCESSORPURPOSEPRIVACY POLICY
Kit.com (ConvertKit)Email delivery for the newsletterkit.com/privacy ↗
VercelHosting and edge deliveryvercel.com/legal/privacy ↗
Google AnalyticsSite analytics (consent required)policies.google.com/privacy ↗
Microsoft ClaritySession-replay analytics (consent required)privacy.microsoft.com ↗

5.Your rights (GDPR — EU users)

If you're in the EU, EEA, UK, or Switzerland, you have the following rights under the GDPR (and equivalent local laws). To exercise any of them, email privacy@aipolicycompare.com.

  • Access: get a copy of any personal data we hold about you (in practice: your email address and subscription preferences).
  • Erasure: ask us to delete it. For email subscriptions, the unsubscribe link in any email handles this immediately. For analytics, declining consent prevents future collection.
  • Rectification: ask us to correct anything that's wrong.
  • Restriction: ask us to pause processing while a dispute is resolved.
  • Portability: get a structured copy of your data you can take elsewhere.
  • Objection: object to processing on legitimate-interest grounds. (All our processing is consent-based, so this rarely applies.)
  • Withdrawal of consent: at any time, with no effect on processing that was lawful before withdrawal.
  • Lodge a complaint: with your national data protection authority if you believe we've handled your data improperly.

6.Your rights (CCPA — California users)

If you're a California resident, you have these rights under the California Consumer Privacy Act (CCPA), as amended by the CPRA. To exercise any of them, email privacy@aipolicycompare.com.

  • Right to know: what personal information we collect, where we got it, why we collect it, and who (if anyone) we share it with.
  • Right to delete: ask us to delete the personal information we have about you.
  • Right to correct: ask us to fix inaccurate personal information.
  • Right to opt-out of sale or sharing: we do not sell or share personal information — see Section 7 below.
  • Right to non-discrimination: we won't treat you differently for exercising any of these rights.

7.Do Not Sell My Personal Information

AIPolicyCompare does not sell, rent, or share personal information with third parties for their marketing purposes. This section is provided to comply with the California Consumer Privacy Act (CCPA).

We collect only the data described in Section 1, use it only for the purpose it was collected (sending the emails you asked for; understanding how visitors use the site, when you've consented), and share it only with the processors named in Section 4 — each of whom acts on our behalf under a written processor agreement, not for their own purposes.

8.Data retention

  • Email subscriptions: retained for as long as you stay subscribed. When you unsubscribe via the link in any email, the deletion is processed by Kit.com.
  • Analytics data: retained per Google's and Microsoft's defaults (typically 14 months for GA4, 30 days to 13 months for Clarity depending on event type).
  • No other personal data is retained. We do not maintain a separate user database, server logs of visitor activity, or any other long-term store of personal information.

9.Children

AIPolicyCompare is built for legal, privacy, and product professionals — not children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, email privacy@aipolicycompare.com and we will delete it promptly.

10.Changes to this policy

We may update this policy from time to time. When we do, we'll update the “Last updated” date at the top of the page and, for material changes, note the change on the Updates page. Continued use of the site after the change means you've accepted the revised policy. If you don't, stop using the site and (if subscribed) unsubscribe.

11.Contact

Questions, requests, or complaints about privacy go to privacy@aipolicycompare.com. We aim to respond within 30 days; for GDPR / CCPA requests we respond within the deadlines those laws set (one month / 45 days respectively).

📢 POLICY UPDATES ALERT

AI Policy Intelligence Brief

Built for compliance officers, legal counsel, and SaaS founders. Join the early-access list — we'll email you when it launches. It will track high-value vendor term changes, training policy updates, and risk-rating modifications.