This privacy policy ("Policy") explains what personal data we collect when you use https://assay.it and the application at https://app.assay.it (together, the "Service"), why we collect it, who we share it with, and what you can do about it.
assay.it is an experiment, not a company. It is built and run by one person, and it is priced to cover what the infrastructure costs rather than to make money. There is no sales team, no advertising network and no data brokerage behind it. We have written this policy to be read, not to be survived — if something here is unclear, ask us at ask@assay.it and we will answer in plain language.
The controller of your personal data under the EU General Data Protection Regulation ("GDPR") and the UK GDPR is:
Dmitry Kolesnikov
Email: ask@assay.it
Postal address available on request at ask@assay.it while our registered
address is being set up.
We have not appointed a Data Protection Officer. We are not required to have one, and given the size of the business you will always reach the person who actually runs the Service at the address above.
Summary (TL;DR)
This summary is for your convenience only; the numbered sections below are what governs.
What we collect. Your name and email address (from your sign-in provider), the documents, links and prompts you submit for analysis, the analyses we generate for you, your credit balance and payment records, and basic technical logs. More on the information we collect
What we do not collect. We do not collect special categories of data (health, biometrics, political or religious views, and similar). We do not ask for them and you should not submit them. We never see or store your full payment card number.
Do we share data with third parties? Yes — we have to, in order to run the Service. The content you submit is sent to AI models we access through Amazon Bedrock so that it can be analysed. We use a small, named set of infrastructure providers and we list every one of them. See the full list of service providers
Do we sell your data or train on your documents? No. We do not sell or share your personal data for money or for cross-context behavioural advertising, and we do not use the documents you submit to train AI models — neither our own nor anyone else's. More on how we handle your documents
Do we track you? No. There is no advertising tracker, no analytics tag and no third-party cookie on the Service. That is also why you are not being asked to dismiss a cookie banner. More on cookies and tracking
How do we protect your information? Data is encrypted in transit and at rest, hosted on AWS in the EU (Ireland), and access is restricted to the operator of the Service. More on security
What can you do about it? You can access, correct, export or delete your data, object to processing, and complain to a supervisory authority. Write to ask@assay.it and we will act within 30 days. More on your rights
Privacy Policy Sections
- Information we collect
- The documents you submit for analysis
- How we use your information
- Legal basis for processing
- Service providers and disclosure
- Cookies and tracking
- How we protect your information
- How long we keep your information
- Data breach notification
- International data transfers
- Personal data inside the documents you submit
- Children
- US state privacy laws
- Your privacy rights
- Changes to this policy
- Contact us
1. Information we collect
Information you give us
Account information. To use the Service you sign in through our identity provider, Auth0. We receive and store a unique account identifier, your email address and, where your sign-in provider supplies it, your name. We do this so that we can create your account, show you your own analyses and no one else's, and email you when a job finishes.
If you sign in using a third-party account such as Google or GitHub, we receive from that provider only the identifier, email address and name described above. We do not receive your password, and we never see it. Your use of that provider is governed by its own privacy policy.
Content you submit. The links, documents and research prompts you send for analysis, and the analyses ("dossiers") we produce from them. This is covered separately in section 2, because it is the most sensitive thing you entrust to us.
Payment information. Credits are sold to you by Stripe as merchant of record, not by us, and the payment is taken on a page hosted by Stripe. We never receive or store your card number, CVC or expiry date. What we receive back from Stripe and store is a payment reference, the amount, the currency, the date and whether it succeeded — enough to credit your account and to keep our own income records. Stripe collects your billing address and tax-location data directly from you, as the seller, under its own privacy policy; we do not see it. See section 5.
Messages you send us. If you email us for support or to exercise a privacy right, we keep that correspondence so we can answer it and show, if challenged, that we answered it.
Special category data. We do not intentionally collect or process special categories of personal data — data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data about sex life or sexual orientation. Please do not submit documents containing such data for analysis.
Information generated by your use of the Service
Usage and billing records. We record each analysis job you run: its identifier, status, timestamps, the size of the input, the compute and model resources it consumed, and the credits it cost. We need this to price the job, to run your balance, to answer "why was I charged this", and to understand what the Service costs us to operate.
Technical logs. Our servers produce operational logs containing information such as IP address, request time, the endpoint called, response status and error diagnostics. We use them to keep the Service running, to investigate faults and to detect abuse. Account identifiers are not written to logs in human-readable form.
Information we receive from others
We receive account information from your sign-in provider and payment confirmations from Stripe, as described above. We do not buy personal data, we do not enrich your profile from data brokers, and we do not receive data about you from marketing partners or affiliates.
2. The documents you submit for analysis
The Service exists to read a document and check the claims it makes. That means you hand us material that may be commercially sensitive — a vendor whitepaper you are evaluating, a benchmark, an internal design document. This section says exactly what happens to it.
What we do with it. When you submit a link, we fetch the page at that address from the public internet, as an ordinary browser would. When you upload a text or Markdown file, its contents are sent to us. In either case the content is stored in our storage, passed to AI models for analysis, and used to produce your dossier. The dossier is stored so that you can come back and read it.
Where it goes. The content is processed by large language models that we access through Amazon Bedrock, an AWS service. The models used are Amazon Nova and Anthropic Claude models. In the course of verifying claims, the Service may also run searches against public search engines and fetch publicly available pages; search queries derived from your document are therefore visible to those services. We do not send your content to any other recipient.
It is not used for training. We do not use your documents, prompts or dossiers to train, fine-tune or evaluate any AI model, and we do not permit our providers to do so. Amazon Bedrock does not use inputs or outputs to train models and does not share them with the model providers whose models it serves.
Who can see it. Your dossiers are private to your account. They are not published, not indexed, and not shown to other users. Access is enforced on every request against your account identifier. As the operator, we have the technical ability to access stored content, but we only do so where it is necessary to fix a fault you have reported, to investigate abuse or a security incident, or where the law requires it.
What you should not submit. Please do not submit material you are not permitted to disclose, material subject to a confidentiality obligation you would breach by submitting it, or material containing other people's personal data. See section 11 and our Terms of Service.
3. How we use your information
We use the information described above only for the following purposes:
- To create and administer your account and authenticate you.
- To run the analyses you ask for and to store and deliver the results to you.
- To price jobs, maintain your credit balance, take payment and issue receipts.
- To email you about your account and your jobs — for example, that an analysis finished or failed, that your balance is exhausted, or that a payment succeeded. These are service messages and you cannot opt out of them while you hold an account.
- To provide support when you contact us.
- To keep the Service secure and available: monitoring, fault diagnosis, backup, rate limiting, and detecting and preventing abuse or fraud.
- To understand aggregate cost and usage of the Service so that we can price it sustainably and decide what to build next. We do this from aggregate and job-level metrics, not by reading your documents.
- To comply with our legal obligations, in particular tax and accounting law, and to establish, exercise or defend legal claims.
We will not use your information for anything materially different from the above without telling you first and, where the law requires it, obtaining your consent.
No automated decisions about you. The Service generates automated analysis of documents. It does not make automated decisions about you that produce legal effects or similarly significantly affect you, and we do not profile you.
4. Legal basis for processing
If you are in the EEA or the UK, we must have a legal basis for each processing activity. Ours are:
- Performance of a contract (GDPR Article 6(1)(b)) — creating and running your account, running the analyses you request, storing and delivering your dossiers, taking payment and maintaining your credit balance, and sending you service messages about your jobs and your account. Without this processing we cannot provide the Service.
- Legal obligation (Article 6(1)(c)) — keeping accounting and tax records of your purchases for the periods required by Finnish law, and responding to lawful requests from authorities.
- Legitimate interests (Article 6(1)(f)) — keeping the Service secure and available, preventing abuse and fraud, understanding aggregate usage and cost, and establishing or defending legal claims. We have considered your interests and rights against ours and consider this processing proportionate; you may object at any time as described in section 14.
- Consent (Article 6(1)(a)) — only where we ask for it separately and explicitly, for example if we ever send you optional product news. You may withdraw consent at any time, without affecting processing already carried out.
Note that consent is not the legal basis for the core Service. Withdrawing consent to optional messages does not close your account, and closing your account is not a substitute for asking us to erase your data — see section 14.
5. Service providers and disclosure
We cannot run the Service alone, and we would rather name our providers than hide behind "trusted partners". Each of the following processes personal data on our behalf, under a contract that restricts them to our instructions:
- Amazon Web Services (AWS) — hosting, compute, storage, databases and outbound email, in the EU (Ireland) region. Everything you store with us is stored on AWS.
- Amazon Bedrock (AWS) — the AI models that analyse your documents, including Amazon Nova and Anthropic Claude models. Content sent to Bedrock is not used to train models and is not shared with the model providers.
- Auth0 (Okta) — sign-in, sign-up and identity. Auth0 holds your login identity and email address.
One provider sits outside that description, because it is not acting on our behalf:
- Stripe — sells you credits as merchant of record, through its Link service, and takes the payment. Stripe is not our processor for this. It is the seller and an independent controller of the personal data it collects from you at checkout — your payment details, billing and tax location, and the purchase record — and it processes that data for its own purposes under its own privacy policy, including to meet its tax and anti-fraud obligations. We receive back from Stripe only a payment reference, the amount, the currency, the date and whether the payment succeeded. Please read Stripe's privacy policy for what it does with the rest.
In addition, when the Service verifies claims it fetches public web pages and queries public search engines. Those requests come from our infrastructure, not from your browser, and they carry search terms derived from the document being analysed.
Beyond the above, we disclose personal data only:
- where you ask or direct us to;
- where we are legally required to — for example a binding order from a court or competent authority. Where we are permitted to tell you about such a request, we will;
- where it is necessary to establish, exercise or defend legal claims, or to protect the rights, safety or property of you, us or others;
- to our professional advisers (such as an accountant or lawyer) under a duty of confidentiality;
- if the business is sold or transferred, to the acquirer, who must continue to handle your data under terms no less protective than this policy. We will tell you before your data is transferred and give you the opportunity to close your account and have your data erased first.
We do not sell your personal data. We do not sell or rent it, we do not share it for cross-context behavioural advertising, and we do not disclose it to advertisers, data brokers or marketing partners. We have never done so.
6. Cookies and tracking
We do not use advertising cookies, analytics cookies, tracking pixels, web beacons or fingerprinting on the Service. We do not run Google Analytics or any comparable third-party analytics product, and we do not build a profile of your browsing.
The application keeps your session in browser memory rather than in a persistent cookie, so signing in does not leave a tracking cookie on your device. Our identity provider, Auth0, may set cookies on its own domain to maintain your sign-in session; those are strictly necessary for authentication and are governed by Auth0's privacy policy.
Because we set no cookies that require consent under the ePrivacy rules, we do not show you a cookie banner. If that ever changes, we will ask for your consent before setting such cookies, and we will update this section first.
Do Not Track and Global Privacy Control
Since we do not track you across sites, there is nothing for a Do Not Track or Global Privacy Control signal to switch off. We treat such a signal as a valid request to opt out of any sale or sharing of personal data, which we do not do in any event.
7. How we protect your information
We take the following measures, which we consider appropriate to the risk and to the size of the business:
- All traffic to the Service is encrypted in transit with TLS; plain HTTP is not served.
- Stored data is encrypted at rest by our infrastructure provider.
- Authentication is delegated to Auth0; we never handle or store your password. API requests are authorised with short-lived signed tokens, and every read of your data is scoped to your own account identifier.
- Storage holding your documents and dossiers is private and not publicly readable; links to your own results are time-limited.
- Access to production systems is limited to the operator of the Service, using individually held credentials with multi-factor authentication and least-privilege permissions.
- Card data never reaches our systems; it is handled by Stripe, a PCI-DSS Level 1 service provider.
We do not hold a formal security certification such as SOC 2 or ISO 27001, and we will not claim one. No system is perfectly secure, and we cannot guarantee that our safeguards will never be defeated. If you would not put a document in an ordinary cloud service, think twice before submitting it here.
8. How long we keep your information
We keep personal data only as long as we need it for the purposes set out in this policy:
- Account information — for as long as your account is open, and deleted within 30 days after you close it or ask us to erase it.
- Submitted documents and generated dossiers — retained in your account so that you can go back to them, until you delete them or close your account, and in any case deleted within 30 days of account closure. You can ask us to delete an individual analysis at any time.
- Job and credit ledger records — retained while your account is open and for as long as needed to resolve billing questions.
- Payment and accounting records — retained for the period required by Finnish accounting and tax law, currently six years from the end of the calendar year in which the transaction took place. We cannot delete these earlier, even if you ask, because we are required by law to keep them.
- Technical logs — retained for up to 90 days, then deleted, except where a specific entry is needed to investigate an ongoing security or abuse incident.
- Support correspondence — retained for up to two years from the last message.
Backups are kept on a rolling basis and are overwritten in the ordinary course. Data you have asked us to erase may persist in a backup for a short period after deletion from live systems; it is not restored to live use, and it is deleted as the backup rotates.
Where we cannot delete data at the end of its retention period, we anonymise it or isolate it from further processing until deletion is possible.
9. Data breach notification
If a personal data breach occurs, we will notify the competent supervisory authority — the Office of the Data Protection Ombudsman in Finland — without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to your rights and freedoms.
Where the breach is likely to result in a high risk to you, we will also tell you directly, without undue delay, in plain language: what happened, what data was involved, what we are doing about it, and what you should do. We will not wait for a full forensic conclusion before telling you that something has happened.
10. International data transfers
The Service is hosted in the European Union (AWS Ireland, eu-west-1), and that is where your account data, your documents and your
dossiers are stored.
Some processing nevertheless takes place outside the EEA:
- Some of the AI models we use are served through cross-region inference, which means the content of an analysis request may be processed by AWS in a region outside the EEA, including in the United States, depending on capacity at the time.
- Auth0 (Okta) and Stripe are US-headquartered and may process data outside the EEA.
- Support correspondence may be handled from wherever the operator happens to be.
Where personal data is transferred outside the EEA or the UK to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where relevant), as incorporated into our data processing agreements with AWS, Auth0 and Stripe, together with the supplementary technical measures those providers apply, in particular encryption in transit and at rest.
You can ask us at ask@assay.it for details of the safeguards applying to a specific transfer.
11. Personal data inside the documents you submit
Documents contain people. A whitepaper has named authors; a blog post has a byline; a design document may name colleagues. Where a document you submit contains personal data about someone else, you decide what to submit and why — you are the controller of that data, and we process it on your behalf as your processor.
That means you are responsible for having a lawful basis for submitting it, for telling those people where you are required to, and for not submitting material you are not entitled to disclose. We ask you to keep such data to the minimum the analysis actually requires, and not to submit documents whose purpose is to profile or assess an individual.
For that processing we will: act only on your instructions; keep the content confidential; apply the security measures in section 7; use only the providers listed in section 5 as sub-processors; help you respond if one of those people exercises their rights; and delete the content when you delete it or close your account.
If you are using the Service for work and need a written data processing agreement under GDPR Article 28, contact us at ask@assay.it and we will provide one at no charge.
If you are the author or subject of a document that someone else has submitted for analysis and you have a concern about it, write to us at ask@assay.it. Note that analyses are private to the user who requested them and are not published by us.
12. Children
The Service is a professional tool intended for adults. Under our Terms of Service you must be at least 18 years old to use it. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at ask@assay.it and we will delete the account and the data.
13. US state privacy laws
If you are a resident of a US state with a comprehensive consumer privacy law — including California, Virginia, Colorado, Connecticut, Utah and Texas — you may have specific rights. We extend the following to all users regardless of where they live, so there is nothing special you need to invoke:
- To know and to access — what personal data we hold about you, where it came from, why we process it and who we disclose it to. Sections 1 to 5 answer this for every user; write to us for a copy of your own data.
- To correct — inaccurate personal data we hold about you.
- To delete — your personal data, subject to records we are legally required to keep.
- To portability — a copy of your data in a portable, machine-readable format.
- To opt out of sale, sharing and targeted advertising — we do not sell or share personal data and we do not do targeted advertising, so there is nothing to opt out of.
- To limit the use of sensitive personal information — we do not collect sensitive personal information as defined by those laws.
- To be free from discrimination — we will not degrade the Service or charge you a different price for exercising a privacy right.
- To appeal — if we decline a request, we will tell you why, and you may appeal by replying to our decision. We will respond to an appeal within 45 days. If we deny the appeal you may complain to your state Attorney General.
To exercise any of these, email ask@assay.it. You may use an authorised agent; we may ask for proof of authorisation and verify your identity before acting.
California "Shine the Light". We do not disclose personal data to third parties for their own direct marketing purposes, so there is nothing to report under California Civil Code § 1798.83.
Automated decision-making. We do not use automated decision-making or profiling to make decisions about you that produce legal or similarly significant effects.
14. Your privacy rights
Depending on where you live, you have some or all of the following rights. If you are in the EEA or the UK, you have all of them:
- Access — to know whether we process your data and to receive a copy of it.
- Rectification — to have inaccurate data corrected and incomplete data completed.
- Erasure — to have your data deleted, unless we are legally required to keep it.
- Restriction — to have processing paused while a dispute about accuracy or lawfulness is resolved.
- Portability — to receive the data you gave us in a structured, commonly used, machine-readable format, and to have it sent to another provider where technically feasible.
- Objection — to object at any time to processing based on our legitimate interests. If you object, we will stop unless we can show compelling legitimate grounds that override your interests, or we need the data for legal claims.
- Withdrawal of consent — where processing is based on consent, to withdraw it at any time.
- Complaint — to lodge a complaint with a data protection supervisory authority.
How to exercise them. Email ask@assay.it. You do not need to use a particular form of words. We will respond within 30 days; if a request is complex we may extend this by a further 60 days and will tell you why within the first 30. Exercising these rights is free. We may ask you to confirm control of the email address on your account before we act, and we may refuse or charge for requests that are manifestly unfounded or excessive — we will explain if we do.
Deleting your account. You can also simply ask us to close your account and erase your data. Note that unused credits are dealt with under the Terms of Service, and that we must retain payment records for the statutory period described in section 8.
Complaining. We would prefer you told us first, and we will take it seriously. But you have the right to go straight to a supervisory authority. In Finland this is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto, tietosuoja.fi). If you live elsewhere in the EEA you may complain to your local authority; in the UK, to the Information Commissioner's Office (ico.org.uk).
15. Changes to this policy
We may update this policy as the Service changes or the law does. The date at the top of the page always shows when it last changed.
If a change materially affects how we handle your personal data — a new category of data, a new purpose, a new provider that receives your documents, or a shorter route to disclosure — we will email the address on your account at least 14 days before it takes effect, so that you have time to close your account first if you disagree. Minor clarifications take effect when posted. We will not apply a materially worse policy retroactively to data we already hold.
16. Contact us
Questions, requests and complaints about this policy or about your data all go to the same place, and a person reads them:
Dmitry Kolesnikov
Email: ask@assay.it
Postal address available on request at ask@assay.it while our registered
address is being set up.