Privacy policy
Last updated 24 August 2026
AI Windes is free, carries no advertising and sells nothing, so there is no commercial reason for us to collect more than we need. This page describes exactly what we hold.
What we collect
Your email address
Collected when you request a sign-in link. It is the only account identifier — there is no password, no username and no profile.
Sign-in tokens
Each sign-in link is stored as a SHA-256 hash rather than the token itself, alongside its issue and expiry times. Someone who obtained our token store could not use it to sign in as you. Tokens are single-use and expire after 15 minutes.
Rate-limiting records
We record timestamps against your email address and IP address so a single address cannot be mail-bombed and a single host cannot spray sign-in links. These records are discarded after an hour.
Server logs
Ordinary web-server logs — request paths, status codes, timestamps and IP addresses — kept for operational and security purposes only.
Analytics
We use Google Analytics to count visits and see which pages get read. It records the pages you view, how you arrived, and coarse device and browser details, against a randomly generated identifier held in a cookie on your device. That identifier is not your email address and is never joined to your account. Google derives an approximate location from your IP address rather than storing the address itself. We use this to decide what to write next and what to fix — nothing else.
What we do not collect
- Your conversations. Chats exist in your browser's memory for the current visit and are never sent to storage on our side. Refreshing the page clears them.
- Payment details. There is nothing to pay, so we never ask for a card.
- Advertising or ad-targeting cookies. No advertising network is loaded on this site and nothing here feeds one.
- Any special-category data. We have no field that asks for it and no reason to want it.
Cookies and local storage
- One essential cookie holds your signed session so you stay logged in. It is HTTP-only, cannot be read by scripts, and expires after 30 days.
- Your light/dark theme choice is kept in your browser's local storage. It never leaves your device.
- Google Analytics sets two cookies holding the random identifier described above, so repeat visits can be told apart and grouped into sessions. Neither names you.
The analytics cookies are the only non-essential ones we set. If you would rather not be counted, browser tracking protection or any content blocker will stop the tag loading, and Google publishes an opt-out add-on for Google Analytics.
Who we share it with
Two processors. TrueEmailer delivers sign-in links and contact-form messages and holds our mailing list; your address is passed to them for that purpose and no other. Google receives the analytics data described above — never your email address, and nothing that ties a visit to your account. We do not sell, rent or trade personal data, and there is no advertising network involved.
Mailing list
Signing up adds your address to our list so we can send occasional product updates — a materially changed catalogue, a new capability, a change to these terms. Every message carries an unsubscribe link, and unsubscribing does not affect your ability to sign in.
How long we keep it
- Email address: until you ask us to delete it.
- Sign-in token hashes: cleared shortly after expiry.
- Rate-limiting records: about one hour.
- Contact-form messages: kept in our inbox as long as needed to resolve the matter.
- Analytics records: held by Google for the retention window configured on our property.
Your rights
You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it entirely. Because your email address is the only identifier we hold, emailing us from that address is enough to prove the request is yours.
Deletion is immediate and complete: the address is removed from our records and from the mailing list. Write to contact@aiwindes.com.
Security
Sign-in tokens are hashed at rest, sessions are cryptographically signed and tamper-evident, session cookies are HTTP-only and served over HTTPS in production, and sign-in requests are rate limited. No system is perfect, but we hold very little, which is the most effective protection available.
Children
This service is intended for professional use and is not directed at children under 16. We do not knowingly collect their data.
Changes
If we change this policy in a way that affects you, we will email the address on your account before the change takes effect. The revision date at the top of this page always reflects the current version.
Contact
Any question about this policy, or any request about your data, goes to contact@aiwindes.com.