← Back to AI Consensus

Privacy Policy

Version 1.0 | Effective Date: January 18, 2026 | Last Updated: January 18, 2026
GDPR & CCPA Compliant

1. Data Controller Information

The AI Consensus is the data controller responsible for your personal data.

Company Name The AI Consensus™
Contact Email privacy@theaiconsensus.com
Support Email support@theaiconsensus.com
Location United States

3. Information We Collect

3.1 Account Information

3.2 Payment Information

Payment Security: Payment processing is handled by Stripe (PCI DSS Level 1 certified). We do NOT store full card numbers or CVV codes. We only receive: last 4 digits, card brand, and expiration date.

3.3 Usage Data

3.4 Technical Data

4. How We Use Your Information

4.1 Primary Purposes

4.2 Secondary Purposes (Legitimate Interest)

We Do NOT:
  • Sell personal data to third parties
  • Use your questions for training third-party AI models
  • Share identifiable data for marketing purposes
  • Process data for purposes incompatible with original collection

5. Information Sharing & Third-Party Processors

5.1 AI Model Providers (Data Processors)

Your questions are sent to the following AI providers:

Provider Model Privacy Policy
OpenAI ChatGPT privacy.openai.com
Anthropic Claude anthropic.com/privacy
Google Gemini policies.google.com/privacy
DeepSeek DeepSeek See provider website
Perplexity Perplexity See provider website
Alibaba Qwen See provider website
xAI Grok See provider website

Note: Each provider processes data under their own terms. We have no control over their data practices after transmission.

5.2 Payment Processor

Stripe Inc. processes all payments. They are PCI DSS Level 1 certified. View Stripe's Privacy Policy

5.3 Legal Disclosures

We may disclose data if:

6. International Data Transfers

For EU/EEA Users: Your data is transferred to and processed in the United States. We rely on Standard Contractual Clauses (SCCs) approved by the EU Commission to ensure adequate protection.

6.1 Safeguards We Use

6.2 For UK Users

Data is transferred under the UK International Data Transfer Agreement (IDTA). UK adequacy decisions are honored where applicable.

7. Data Retention Periods

Data Type Retention Period
Account Data While account is active + 30 days after closure
Free Tier Discussions Not retained (deleted at session end)
Professional Tier Discussions 90 days, then automatic deletion
Enterprise Tier Discussions Permanent unless deletion requested
Backup Data 90 days (encrypted), then permanently deleted
Legal/Tax Records 7 years (financial regulations)
Anonymized Data Retained indefinitely for research

8. Your Rights (GDPR Chapter III)

All Users Have the Right To:
Right Description GDPR Article
Access Request a copy of personal data we hold Article 15
Rectification Correct inaccurate data Article 16
Erasure "Right to be forgotten" - delete your data Article 17
Restriction Limit how we process your data Article 18
Portability Receive data in machine-readable format Article 20
Object Object to processing based on legitimate interests Article 21
Withdraw Consent For consent-based processing Article 7

How to Exercise Your Rights

  1. Email: privacy@theaiconsensus.com
  2. Subject line: "Data Rights Request - [Type]"
  3. Include: Account email, specific request, verification details
  4. We respond within 30 days (GDPR requirement)

Data Portability Format

EU/EEA Users: You may lodge complaints with your national Data Protection Authority. See EDPB Member List

9. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the following rights:

Categories of Personal Information Collected

We Do NOT:
  • Sell personal information
  • Share for cross-context behavioral advertising
  • Process sensitive personal information beyond necessary use

CCPA Request Process

10. Cookies & Tracking Technologies

10.1 Essential Cookies (Cannot Disable)

10.2 Analytics Cookies (Can Opt-Out)

10.3 Preference Cookies (Can Clear)

For more details, please see our Cookie Policy.

11. Data Security Measures

11.1 Technical Safeguards

11.2 Organizational Safeguards

11.3 Breach Notification

EU Users: In the event of a data breach, we will notify you and the relevant supervisory authority within 72 hours of discovery as required by GDPR Article 33.

12. Children's Privacy

13. Changes to This Policy

14. Contact Information

General Privacy Questions

Data Rights Requests

EU Online Dispute Resolution

EU users may use the Online Dispute Resolution platform: ec.europa.eu/consumers/odr

The AI Consensus
United States