Privacy Policy
Last updated: 10 October 2026
How AI Reads Law uses personal data, your rights under UK GDPR and, where applicable, EU GDPR, and how to request deletion.
1. Who is responsible
Edge Agents Works Ltd, registered in England and Wales (company number 16163651), at 77 Watling Street, Radlett, England, WD7 7JA, United Kingdom, is the controller of personal data described here. This policy covers our website, mobile and browser apps and support. For privacy questions or requests, contact us. It is a privacy notice, not consent to every processing activity.
2. Data we process
We receive account and sign-in details; questions, documents, images, extracted text and generated responses; feedback and support correspondence. Technical data can include IP address, device and app version, language, selected jurisdiction, timestamps, usage events, errors and diagnostic records. Stores and billing providers supply purchase identifiers, subscription status and transaction information; they handle payment-card details. Data comes from you, your device, sign-in and billing providers, and material you submit about other people.
3. Purposes and lawful bases
We process account, consultation and purchase data to perform our contract: authenticate you, generate responses, store your work and supply paid access. Our legitimate interests include security, fraud prevention, troubleshooting, service improvement and responding to enquiries, balanced against your rights. Legal obligations cover required accounting, regulatory and lawful disclosure records. We rely on consent where required for optional tracking or a specifically identified use; it can be withdrawn. Required data is needed for the relevant feature; without it that feature may not work.
4. AI processing and sensitive material
AI and search providers receive your request and relevant context, which may include document text, images and previous messages. The third-party providers used depend on the feature and configuration. Processing occurs on external servers, not only your device. Provider retention, safety review and permitted data use depend on their applicable terms; do not assume zero retention or an absolute no-training guarantee. Ask us about current providers and controls before submitting material that requires particular protections. Avoid unnecessary sensitive or third-party data. Health, criminal-offence and other specially protected data requires an additional lawful condition; these terms alone are not explicit consent.
5. Analytics, support and access
Analytics and crash reporting help identify failures and improve the Service. Depending on the platform and configuration, diagnostic or AI telemetry can contain request or response content as well as technical metadata. Authorised staff and providers may access relevant data for support, security, troubleshooting or legal requirements; do not assume every consultation is inaccessible to humans. Access and processing must be limited to the relevant purpose. AI outputs assist you; they are not our automated decisions about your legal rights or eligibility.
6. Recipients and disclosures
We use third-party providers for hosting, storage, authentication, AI processing and search, analytics, crash reporting, payment processing, subscription management and customer support. App stores also process purchases. The providers used vary by feature and platform. They receive data needed for their role and may act as processors or independent controllers, particularly for store payments and advertising measurement. We may disclose data when law requires, to protect rights and security, to professional advisers, or during a business transfer with appropriate protections. This notice does not grant permission to sell private documents or publish consultations. Contact us for information about current recipients and their roles.
8. Retention and deletion
Account and consultation data is kept while needed to provide the Service. Request deletion in the app or write to us from your registered email; we may verify your identity using reasonable measures. Deletion restricts account access and starts removal of associated content. Server cleanup is designed to purge residual soft-deleted account and consultation records after a 90-day retention period; document content can be erased earlier. Storage queues, backups and provider systems may complete separately, so deletion is not an instant wipe of every copy. Accounting, security, dispute and legally required records may remain for as long as their purpose or legal retention duty requires, then be deleted or anonymised. Deletion does not cancel subscriptions.
9. International processing
Providers may process data outside the UK, including the United States and the countries in which AI providers operate, where laws may differ. International transfers are subject to applicable data-protection requirements; the relevant mechanism depends on the recipient and may include adequacy decisions or recognised contractual safeguards. Contact us for the countries receiving your data and the applicable safeguards, or to request a copy where available.
10. Security
We use technical and organisational measures appropriate to the risks, including access controls. No online service or storage is completely secure. Protect your account and devices, minimise sensitive uploads and report suspected security problems. The Service is not a substitute for a professional’s secure client file or a guaranteed confidential legal channel.
11. Your rights and complaints
Where applicable you can request access, correction, erasure, restriction and portability, object to processing based on legitimate interests, and withdraw consent without affecting earlier lawful processing. Rights have legal exceptions. Send a request; we normally respond within one month, subject to lawful extensions or clarification. You may complain to the UK Information Commissioner’s Office or your competent local authority, and raise concerns with us first if you wish. UK law and the English reference text do not remove mandatory local data-protection rights.
12. Children and policy updates
The Service is not intended for children under 13. Contact us if a child has supplied personal data so we can take appropriate steps. Users must also meet the eligibility conditions in our Terms. We update this notice when practices change and communicate material changes appropriately. The English version is the reference version; translations assist understanding and do not override mandatory language or privacy rights.