Privacy Policy

Last updated: 20 August 2026 (consent version 2026-08-20)

This policy explains what UserTold.ai collects, why we use it, who receives it, and the choices available to customers and interview participants.

At a Glance

  • You own your interview and project data.
  • We process interview content for the customer running the study.
  • We do not sell personal data or use it for advertising or cross-site profiling.
  • We do not use Customer Data to train general-purpose AI models.
  • We use Simple Analytics for anonymous, cookieless traffic statistics.
  • You can delete interviews and projects; saved OpenAI keys are encrypted and deletable.

Who We Are

UserTold.ai is operated by Aleksei Krasnoperov, NIF Z1580680X, a sole trader (empresario autónomo) established in Spain at Calle Periodista Tirso Marín 18 3 8I, 03540, Alicante, Spain. UserTold.ai is an information-society service under Ley 34/2002 (LSSI-CE).

For account, billing, security, and website data, the data controller is Aleksei Krasnoperov. No Data Protection Officer is appointed because one is not mandatory under GDPR Art. 37, and no Art. 27 representative is required because the controller is established in the EU.

Contact support@usertold.ai for privacy, identity, or billing requests.

Our Roles

  • For account, billing, security, support, and website data, UserTold is the controller.
  • For interview content collected by a customer—audio, optional screen recordings, transcripts, messages, interaction events, intake responses, and derived evidence—the customer is the controller and UserTold is its processor under the Data Processing Agreement.
  • If we use interview-derived data for our own processing improvements, we first de-identify and aggregate it. For that limited processing, UserTold acts as an independent controller and relies on legitimate interests. We do not use Customer Data to train internal or third-party general-purpose models.

What We Collect

Account and Sign-In Data

You may sign in with a password or one of the identity providers below. We use the returned identity only to authenticate you, link the correct account, and protect it.

Sign-in methodData received
Email and passwordEmail address and a unique salted password hash; never the plaintext password
GoogleProvider account ID, name, email address, and email-verification status
GitHubProvider account ID, username, name, and a verified email address
LinearProvider account ID, name/display name, email address, and the ID, name, and key of the associated Linear organization

Interview Data

When a participant uses a UserTold interview, we may process:

  • voice and chat responses;
  • audio recordings and generated transcripts;
  • screen recordings, only when enabled for the study;
  • clicks, focus changes, and navigation events observed during the interview;
  • intake or qualification answers; and
  • evidence and work generated from those materials.

The widget tells the participant that the session is recorded before requesting access. Its versioned disclosure covers UserTold's recording and processing, but the customer remains responsible for explaining its own identity, purpose, legal basis, and privacy notice.

Our pipeline is not designed to create voiceprints, identify speakers biometrically, or infer protected characteristics, and we do not use it for those purposes. A participant can stop recording by closing the widget. Deletion requests should normally go to the customer running the study; if that customer cannot be reached, contact us and we will route the request.

Billing Data

Polar acts as merchant of record. We receive the account email and billing event details such as amount, date, subscription, and payment status. We do not receive or store full payment-card numbers.

Security and Error Diagnostics

Our server logs record IP address, request path, and timestamp for security, abuse prevention, and debugging. Sentry receives technical error diagnostics such as the error type, application release and environment, browser/user-agent information, and pseudonymous correlation or session identifiers.

We configure error reporting to exclude or redact default personal information, cookies, authorization values, request bodies, query parameters, and customer content before transmission. An unexpected error may nevertheless contain limited personal data; Sentry is therefore treated as a subprocessor where an error occurs while we process Customer Personal Data.

Anonymous Website Analytics

We use Simple Analytics on UserTold pages to understand aggregate traffic and improve the service. It does not set analytics cookies, store visitors' IP addresses, or build advertising profiles. The statistics are not connected to a UserTold account or interview content.

Simple Analytics may process a page-route pattern, referring route, timestamp, language, screen and viewport size, browser/user-agent characteristics (retained in anonymized form), country inferred from browser time zone, time on page, and scroll depth. Before collection, UserTold replaces organization, project, interview, evidence, intake, study, and work identifiers in authenticated paths with generic placeholders; subsequent internal referring routes use those redacted patterns too. We disable campaign-parameter collection, and ordinary query parameters and URL fragments are excluded by default. Simple Analytics uses short-lived random measurements to distinguish page loads without creating a persistent visitor profile and respects Do Not Track by default.

Because this analytics does not store or access an analytics identifier on your device, we do not show a cookie-consent banner for it. You can prevent the measurement by enabling Do Not Track or blocking the analytics script.

Why We Use Personal Data

PurposeOur roleLegal basis under GDPR
Create, authenticate, and manage an accountControllerContract — Art. 6(1)(b)
Process payments and keep accounting recordsControllerContract and legal obligation — Art. 6(1)(b), (c)
Run interviews, create evidence and work, and operate enabled integrationsProcessorThe customer's documented instructions and legal basis, under the DPA
Secure, monitor, and debug the serviceController or processor, depending on the affected dataLegitimate interests — Art. 6(1)(f), and the DPA
Measure anonymous website usageControllerNo personal data is intended to be retained; where a measurement is personal data, legitimate interests — Art. 6(1)(f)
Improve processing, ranking, and prompts using de-identified aggregate dataIndependent controllerLegitimate interests — Art. 6(1)(f)
Send service and product messages to account holdersControllerContract or legitimate interests; existing business relationship

We do not make decisions that produce legal or similarly significant effects about a person solely by automated means.

Data Partners and Their Roles

The word “partner” does not mean that every service has the same legal role. The categories below distinguish services that process Customer Personal Data from services used for our own account and website operations.

Customer-Data Subprocessors

These providers may process Customer Personal Data to operate the service:

ProviderRole and purposeData involved
CloudflareInfrastructure, application delivery, storage, and security subprocessorCustomer content, stored media, and request metadata
OpenAIAI, realtime conversation, transcription, and evidence-processing subprocessorAudio, transcripts, prompts, and generated outputs required for the requested feature; BYOK calls use the customer's API key
SentryError-monitoring subprocessorMinimized and redacted technical diagnostics; limited Customer Personal Data only if present in an unexpected error

Customers give general authorization for these subprocessors under the DPA. We remain responsible for their processing and give prior notice of intended additions or replacements so customers can object on reasonable data-protection grounds.

Account, Billing, and Website Providers

These services support UserTold's own controller activities; they are not all subprocessors of customer interview data:

ProviderRoleData involved
Google, GitHub, and LinearOptional sign-in providersThe identity fields listed under “Account and Sign-In Data”
PolarMerchant of record and independent payment providerEmail and transaction/subscription details; payment credentials are handled by Polar
Simple AnalyticsAnonymous website analytics providerCookieless aggregate usage measurements listed above; no account identity or interview content is sent by UserTold

Customer-Directed Integrations

When a customer enables an integration, the customer directs us to send the selected data to that destination:

DestinationPurposeData sent
GitHubCreate or update issues in selected repositoriesCustomer-selected work and evidence-derived content, plus the references needed for synchronization
LinearCreate and synchronize issues in the selected workspaceCustomer-selected work and evidence-derived content, workspace/team identifiers, and delivery status

GitHub and Linear process this data under the customer's relationship and settings with those services. Disabling an integration stops new transfers but does not automatically delete data already sent there.

AI and Your OpenAI Key

If a customer uses Bring Your Own Key (BYOK), the OpenAI key is encrypted at rest, used only for calls requested through that project, never disclosed to other customers, and deletable in Project Settings. We store the outputs needed by the service—such as transcripts and evidence—but do not retain a separate copy of the raw provider request/response stream for our own purposes.

If we propose training on Customer Data in the future, we will update this policy, give at least 30 days' notice, and obtain opt-in consent where consent is required. We will not retroactively train on previously collected Customer Data without the required permission.

Special-Category Data

Free-form interviews can incidentally include special-category data under GDPR Art. 9, such as health information, beliefs, or political opinions volunteered by a participant. We do not solicit it or use it to infer protected characteristics. A customer whose study predictably requests such data must establish an Art. 9 condition—typically explicit consent—before opening the widget.

International Transfers

Simple Analytics states that its analytics data is hosted in the EU. Other providers, including Cloudflare, OpenAI, Sentry, Google, GitHub, Linear, and Polar, may process data outside the EEA. Where a restricted transfer occurs, we use an applicable adequacy decision, the EU Standard Contractual Clauses, and supplementary measures or a transfer-impact assessment where required. Contact us to request information about the applicable mechanism.

Retention and Deletion

  • Account data — while the account is active, then deleted with the account except where retention is legally required.
  • Interview data — until the customer deletes it. Deleted interviews and projects remain recoverable for 30 days and are then permanently erased.
  • Closed accounts — Customer Personal Data is erased from active systems immediately and cannot be recovered through the product.
  • Encrypted backups — residual copies rotate out within 90 days. If a backup is restored, prior deletions are re-applied.
  • Billing records — retained for 7 years for accounting compliance.
  • Server logs — retained for 30 days.
  • Anonymous analytics — retained as aggregate statistics for trend comparison; it is not linked to an account or persistent visitor profile.

Subprocessor deletion can take up to 30 days. We may retain limited records where law requires it or where necessary to establish or defend legal claims.

Customers can delete interviews through the Interviews page or API and projects through Project Settings. To delete an account, contact support@usertold.ai. A participant should first contact the customer running the study; we assist customers with valid data-subject requests under the DPA.

Your Rights

Subject to applicable law, you may ask to access, correct, erase, restrict, or receive a portable copy of your personal data; object to processing based on legitimate interests; and withdraw consent without affecting earlier lawful processing. We respond to verified requests within one month unless the law permits an extension.

You may complain to your local supervisory authority. In Spain, this is the Agencia Española de Protección de Datos (AEPD), www.aepd.es.

California residents may also request access, correction, or deletion of covered personal information and may limit qualifying uses of sensitive personal information. We do not sell or share personal information for cross-context behavioral advertising and do not discriminate against anyone for exercising a privacy right.

Cookies and Local Storage

We use strictly necessary cookies or browser storage to authenticate users, preserve security, and provide requested product behavior. Simple Analytics does not add analytics cookies or a persistent browser identifier. We do not use advertising cookies.

Security

See Security for the technical and organizational measures used to protect data.

Communications

We send transactional messages needed for billing, security, and material service changes. We may send relevant product messages to account holders under our existing business relationship. Product messages include an unsubscribe option; opting out does not stop transactional messages.

Changes and Contact

We may update this policy. We notify account holders of material changes and request renewed acceptance where the change requires it.

For questions, rights requests, or custom terms, email support@usertold.ai.