PRIV PRIVACY NOTICE · LAST REVIEWED 2026-08-22

Privacy, in plain words.

The short version

We collect as little as this website and Scout need to work. We don't sell data, run ads, or buy lists. Ever. This single canonical notice covers our website, your TAIGL account (the shared identity you use across TAIGL apps, including Scout), and the Scout service itself. The app links here — the app's concise in-app summary in Settings is a short layer on top of this page, not a separate authoritative source.

Who we are

THE AI GROWTH LAB LTD (company number 17413033) is the controller for this website, the TAIGL account and Scout. Our registered office is 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ. General business/controller contact: info@theaigrowthlab.co.uk. Privacy rights and data-protection complaints: support@theaigrowthlab.co.uk. Our website is https://theaigrowthlab.co.uk. If a data protection officer is appointed, contact details will be published here.

What we collect and why

We only use what we collect for the purposes listed below. Nothing is collected for advertising.

  • Website — waitlist email — so we can tell you when Scout opens. Held until you unsubscribe (one click, gone).
  • Website — contact message (email and your message) — so a person can reply. Not fed to any model.
  • Website — usage analytics — pages read, taps, rough region — to improve the site. See “Analytics, disclosed by name”.
  • TAIGL account — the shared identity you use across TAIGL apps. Created via Supabase Auth (with Google as an external identity provider where you choose “Continue with Google”, or a six-digit email code via Resend where configured). We store the account identifier (email and provider subject where used), verification status, and account security/audit events.
  • Scout — what you submit (transient source) — the text, public URL, or screenshot/image you choose to analyse, plus the lens you selected (Person, Company or Conversation) and your topic. This is the sole source for that one analysis. Scout is for users aged 18+ in a professional/business context.
  • Scout — server-side records we create — the Opportunity Brief and related server-side records for that analysis: executive summary, opportunity score + score basis, key signals, risks, recommended actions, AI confidence, and provenance (with observed/inferred tiers and source excerpts). These live as server-side Scout jobs/results/provenance/flags tied to your account; they are erased via Erase my Scout Lite data (POST /v1/scout/account/erase) and do not include your device-saved briefs.
  • Device-saved briefs (on this device only) — if you tap Save, a copy of the brief is stored on this device (LocalBriefStore saved_briefs.json). The app confirms “Saved briefs remain on this device.” It remains there until you choose Delete saved briefs on this device; it is not stored in your account and is not deleted by the server-side erasure.
  • Scout — app/device signals you trigger — analysis requests, success/failure status, flags/reports you submit, and your separate server-erasure / device-delete actions.
  • Account-deletion request evidence — the email you submit on /account/deletion plus any note, the request ID, time, and the pending-verification outcome. User-ID binding is deliberately left unbound until a person verifies you own the account (see “Deletion”).

Purposes (why we use each category)

  • Provide Scout — run the bounded opportunity analysis you asked for and return the Opportunity Brief. Source text/URL/image is decrypted only to perform that analysis. Scout does not provide employment, credit, insurance, housing, eligibility, criminal-background or other high-stakes decisions.
  • Provide your TAIGL account — create, sign you in, keep you signed in on that device, and restore your session after a long idle. Server-side Scout data is erased via the server erasure; your device-saved briefs are separately managed on the device (see “Retention”).
  • Process deletions and erasures — handle verified account-deletion requests and your in-app Scout product-data erasures.
  • Operate and improve the website — serve pages, measure what people read, answer enquiries, and send the waitlist email you requested.
  • Trust, safety and compliance — prevent abuse, handle flags/moderation, and keep the minimal audit records we must keep by law (see “Retention”).

We do not use your data to make a solely automated decision about you that has a legal or similarly significant effect. We do not intentionally infer or analyse special-category personal data (such as race, ethnicity, political opinions, religion, trade-union membership, genetic, biometric, health, sex life or sexual orientation) or criminal-offence data as part of Scout.

Analytics, disclosed by name

This website uses PostHog (product analytics) where you have given consent via the banner. No other analytics for launch — Microsoft Clarity is not used for the Scout launch surface. No advertising pixels. PostHog acts as a processor on our behalf under its DPA. The current PostHog Website project is configured for the US ingestion host https://us.i.posthog.com with IP anonymisation enabled, person profiles limited to identified_only, and — after the Website minimisation update — session replay and console capture disabled for the Website code path (project-level capture settings are otherwise minimised to what is necessary). IP addresses are handled per PostHog’s current published policy. Analytics only runs if you click Accept on the cookie banner. You can change this anytime via Cookie preferences in the footer.

Lawful basis

UK GDPR requires a lawful basis for each purpose. Our adopted working bases for the launch are documented in the Scout DPIA and Third-Party Data LIA and are reviewed when the processing changes materially:

  • TAIGL account/auth and your own information necessary to provide Scout: Contract (Article 6(1)(b)) — necessary to perform the service you requested.
  • Scout analysis of your own submitted content: Contract (Article 6(1)(b)) — necessary to provide the analysis you asked Scout to perform.
  • Security, abuse prevention, moderation and service integrity (including proportionate operational logs and fraud checks): Legitimate interests (Article 6(1)(f)) — documented, necessary and balanced against your interests.
  • Ordinary third-party professional/business personal data you supply to Scout: Legitimate interests (Article 6(1)(f)) — only where the documented Scout Third-Party Data LIA’s purpose, necessity and balancing tests remain satisfied and the stated safeguards remain in place.
  • Non-essential analytics/cookies: Consent (where UK law requires it) — you can withdraw via Cookie preferences.
  • Waitlist / direct email where consent is the adopted route: Consent — you can unsubscribe at any time.
  • Data-rights, deletion, and data-protection complaint handling: Legal obligation where UK data-protection law requires it; otherwise legitimate interests for proportionate accountability/evidence, as documented.

We do not rely on Article 9 (special-category) or Article 10 (criminal-offence) conditions for the Scout launch because we do not intentionally analyse those categories; Scout must not be used to intentionally infer them (see Terms). If such data is incidentally present, we minimise and do not intentionally surface it.

Recipients and processors

We share personal data only where needed to provide the service, and only with processors/recipients as evidenced for the current launch:

  • Website analytics processor — PostHog (consent-gated, see above). No Clarity for launch.
  • TAIGL identity and account infrastructure — Supabase Auth as processor for the TAIGL account/auth and database (current TAIGL projects `ai-business-engine` and `taigl-staging` are eu-west-1 Ireland; Supabase DPA provides controller→processor terms and UK transfer addendum treatment for applicable onward transfers).
  • Authentication email delivery — Resend where Supabase custom SMTP via Resend is configured (transactional/auth OTP delivery). Resend’s current DPA describes Resend as processor for customer content and notes primary US processing with transfer safeguards including UK coverage.
  • Hosting/backend processor — Railway for the Scout service and the web deletion-request intake at /v1/account/deletion-request. Railway’s DPA describes Railway as processor and states primary US processing with Data Privacy Framework / UK SCCs-Addendum safeguards where applicable.
  • Authentication provider where you choose it — Google for “Continue with Google” (minimal authentication scope only; Google’s own privacy terms govern Google’s processing of your Google Account activity; UCH/Drive/Gmail scopes remain separate and are never bundled with sign-in).
  • Scout AI analysis — governed multi-provider architecture — TAIGL uses a governed AI-routing layer. Depending on the requested task, TAIGL may process submitted content using approved AI services from OpenAI API, Google Gemini API and/or Anthropic API. The router selects one approved provider/model for that request — it does not send every submission to every provider. Selection is constrained not only by task quality, cost and performance but by privacy/data-sensitivity eligibility as a hard pre-ranking gate (no provider receives customer data until its route is governed/approved and its legal/vendor evidence is current). No provider/model route is activated in this Website wave; the public processor/subprocessor disclosure and transfer map at release will reflect only the providers actually activated, with no implication that all three process every Scout request.
  • Safety and support — our people who verify deletion requests, review flags, and handle complaints, on a need-to-know basis.

We do not share for third-party marketing. If a recipient changes materially, we will update this notice before the change.

International transfers

Some service providers process or allow access to personal information outside the UK. Where a transfer is restricted under UK data-protection law, we use an applicable adequacy arrangement or appropriate safeguard, such as the UK International Data Transfer Agreement/Addendum (UK IDTA/Addendum) / Standard Contractual Clauses structure, and assess the transfer where required. The providers and relevant arrangements are described below or can be requested from support@theaigrowthlab.co.uk.

  • Supabase: primary project region eu-west-1 (Ireland) for TAIGL projects `ai-business-engine` / `taigl-staging`; current Supabase DPA provides controller→processor SCC architecture and UK addendum for applicable onward transfers.
  • Railway: primary US processing per DPA; DPA provides UK SCCs/Addendum / DPF route where applicable.
  • Resend (auth email where configured): primary US processing; DPA notes processor role and UK transfer coverage.
  • PostHog: current Website project ingestion is https://us.i.posthog.com (US); PostHog DPA/subprocessor documentation applies; describe actual configured region/host accurately without claiming zero onward transfer unless subprocessors prove it.
  • Google (where chosen): authentication is a separate recipient flow; Google’s privacy terms govern Google’s processing.
  • AI providers (when activated): each provider’s legal entity, region, and transfer mechanism will be recorded in the MIR/provider evidence and reflected here only when a governed route is live.

We do not transfer for advertising.

Retention — how long we keep things

UK GDPR storage limitation requires a justified period or purpose-based criterion — not one universal period.

  • Successful Scout raw source (text/URL/image): purge immediately after successful analysis.
  • Failed/incomplete Scout raw source: hard purge within 24 hours (FAILED_JOB_TTL_SECONDS = 24h, purge_reason "ttl_24h"). The encrypted source is never kept as a stored profile.
  • Device-saved briefs (on this device): until you delete them on this device via Delete saved briefs on this device (“Saved briefs remain on this device.”). Not stored in your account; not affected by server erasure.
  • Server-side Scout records (jobs/results/provenance/flags): while needed to provide your Scout product record, until you invoke Scout server erasure or the TAIGL account is deleted (via Erase my Scout Lite data POST /v1/scout/account/erase). You can verify the dual erasure split in apps/scout_lite/repository.py:delete_jobs_for_principal vs LocalBriefStore.kt.
  • Active TAIGL account/auth identity: while the account remains active; delete on verified account-deletion request except minimum records independently required for security/rights evidence.
  • Waitlist subscription: until unsubscribe/withdrawal, with minimal suppression evidence if required to honour a future opt-out.
  • Website analytics: PostHog’s current Website project has a 12-month event-retention setting, but automatic enforcement of that setting is currently disabled, so we do not present that setting as a guaranteed 12-month deletion. Our retention criterion for these analytics is set by us as controller: we collect them only where you have consented, and we keep them only while reasonably necessary for Website/product-usage measurement, service improvement, and launch/operational diagnostics. We review whether continued retention is necessary at least every 90 days — and additionally on any material change to the analytics purpose, configuration or provider, or if the project is decommissioned — and we delete or anonymise analytics that are no longer necessary using the provider controls available at that time. The Website code path has session replay and console capture disabled, so no new Website replay is collected from that path.
  • General contact/support conversation: until resolved, then up to 12 months unless an active dispute/rights matter justifies longer.
  • Data-rights / completed account-deletion handling record: 3 years after closure (minimal metadata/outcome, not unnecessary Scout source content; earlier deletion if no longer necessary and no dispute).
  • Data-protection complaint handling record: 3 years after closure (minimal record only; active regulatory/legal dispute may be held longer under documented legal hold).
  • Security/abuse/fraud operational audit records: 12 months from event/closure unless linked to an active investigation, repeated abuse pattern or legal hold.
  • Company accounting and tax records: records of THE AI GROWTH LAB LTD are kept for 6 years from the end of the last company financial year they relate to, or longer where the applicable company-record rules require it. Records from a preceding sole-trader period are kept under the self-employed rule that applied to that period: at least 5 years after the 31 January submission deadline for the relevant tax year, or longer where required. These accounting rules are not a reason to retain Scout source content.
  • AI provider request/response data: provider-specific minimum consistent with the selected API/DPA and TAIGL’s transient-source design — no production AI provider is currently activated in this wave; each activated provider’s retention/training terms will be recorded before customer data is routed to it. Current official materials indicate: OpenAI business API data not used for training by default; Google Gemini Paid Services do not use prompts/responses to improve Google products; Anthropic commercial inputs/outputs not used for training by default with standard up-to-30-day retention. These are evidence inputs, not activation.
  • What may legitimately remain after account deletion: records we must keep to meet legal, financial, security or abuse-prevention obligations (for example billing, tax, fraud, and complaint evidence as above) may persist on their governed purpose-based criteria. This is the same disclosure that appears on /account/deletion. We do not keep data indefinitely “just in case”.

A legal/regulatory/security hold may temporarily keep the minimum relevant records longer while the documented need exists. This schedule is reviewed at launch and whenever Scout persistence, payments, AI providers, analytics, age scope, collection, profiling scale, account model or legal obligations change materially.

Your rights

Under UK GDPR you have rights over your personal data, depending on the lawful basis and context:

  • Access, correction, and deletion (erasure) — ask to see, correct, or delete your data.
  • Restriction and objection — ask us to pause certain uses or to object where the basis is legitimate interests or direct marketing. For Scout third-party subjects, an objection will trigger a review of whether compelling grounds exist for any continuing processing.
  • Data portability — receive certain data you provided in a portable form where the basis is consent or contract and processing is automated.
  • Not subject to solely automated decisions with legal or similarly significant effects, including profiling — you can ask for human review. Scout does not make eligibility, employment, credit or other high-stakes decisions.
  • Withdraw consent where we rely on consent (for example analytics cookies or waitlist) — withdrawing does not affect prior lawful use; use Cookie preferences or unsubscribe.

To exercise any right, email support@theaigrowthlab.co.uk — a person answers. For general enquiries, use info@theaigrowthlab.co.uk. We may need to verify your identity, which is why web deletion requests are held as pending verification rather than acted on instantly.

If someone has used Scout to analyse information about you

Scout may receive personal information about you indirectly if a user chooses to analyse text, a public URL, or a screenshot/image that relates to you.

  • Categories: professional/business text, URL-derived text, screenshot-derived text, and the resulting bounded Opportunity Brief (executive summary, opportunity score with basis, key signals, risks, recommended actions, AI confidence, and provenance with observed/inferred tiers).
  • Source: supplied by a Scout user and, for URL cases, one public HTTPS page selected by that user (no autonomous people scraping, no bulk third-party dossier database, no persistent subject dossier by default).
  • Purpose: to produce the single bounded opportunity analysis that user requested.
  • Lawful basis: legitimate interests (Article 6(1)(f)), subject to the documented Scout Third-Party Data LIA (purpose, necessity, balancing) and the safeguards below.
  • Safeguards and limits: user-triggered source only; professional/business context (18+); no high-stakes decision support; no intentional special-category or criminal-offence inference; no systematic biometric identification; raw source transient/purged as above; outputs framed as assistive analysis, not verified facts or eligibility decisions; accessible rights/objection route via support@theaigrowthlab.co.uk.
  • Your choices: you can object to processing based on legitimate interests, request erasure/restriction, and expect TAIGL to review whether compelling grounds exist for any continuing processing. Because the raw source is transient, TAIGL may no longer hold the original submitted source and will confirm that, plus erase/restrict any remaining server-held Scout record that can be linked to you after proportionate verification.

For some one-off user-supplied analyses, directly providing this privacy information to the person may be impossible or involve disproportionate effort — for example where TAIGL has no reliable contact route and obtaining one would require additional intrusive data collection. Where TAIGL relies on that Article 14 exception, the reasoning and safeguards are documented in the Scout DPIA. The exception is assessed contextually, not treated as a blanket rule. We publish this dedicated third-party notice and maintain a rights/objection route as alternative safeguards.

Third-party personal data you provide to Scout

If you submit information about another person to Scout, you must have all permissions, rights, lawful bases or other authority required in the circumstances. Where consent or permission is legally required, obtain it before submission. Do not submit material where doing so would unlawfully breach privacy, confidentiality, intellectual-property rights, contractual duties or applicable law. Do not intentionally submit or request inference of special-category or criminal-offence data. Scout is designed for publicly shared professional/business material you choose to supply; you remain responsible for that source material and for how you use Scout’s output. Your authority as a user is a contractual safeguard — it does not transfer TAIGL’s own controller duties (lawful basis, transparency, minimisation, security, retention, and rights) to you.

Complaints — data-protection complaints and the ICO

If you wish to raise a data-protection complaint with TAIGL, contact support@theaigrowthlab.co.uk — this is the adopted route for privacy/rights/deletion/complaints.

How we handle complaints and rights requests: we record a complaint/rights request with a reference, date, and outcome; we acknowledge receipt within 30 days; we investigate without undue delay, inspecting relevant Scout/account/audit evidence and the applicable Privacy/Terms version; we provide progress updates where required; we give a written outcome including any correction/erasure/restriction/escalation and your ability to complain to the ICO; we keep minimal evidence of the handling process (see “Retention”: complaints 3 years, rights/deletion 3 years). Where a dispute or regulatory enquiry is active, a documented legal hold may keep the minimum relevant evidence longer. This procedure is adopted for Scout launch governance and is intended to satisfy the Data (Use and Access) Act 2025 (Royal Assent 19 June 2025) complaint-handling duties under section 103 / DPA 2018 s164A, in force since 19 June 2026.

You also have the right to lodge a complaint with the supervisory authority. In the UK that is the Information Commissioner’s Office (ICO): ico.org.uk/make-a-complaint · helpline 0303 123 1113 · ico.org.uk.

Cookies

We use only what is necessary for the site to work and the minimum consent-gated analytics described above. A banner asks before non-essential cookies run. See Cookie preferences in the footer to change your choice.

In-app privacy summary

Scout shows a concise privacy summary in Settings and on the analysis submit surface (for example the “Inputs encrypted; purged after analysis (failed inputs held ≤24h)” caption). That in-app summary is a short, layered notice that links to this page as the canonical Privacy Notice. The canonical web notice prevails if there is any inconsistency.

Changes to this notice

We will update this page when our processing or our legal advice changes, and we will publish the new “LAST REVIEWED” date at the top. For material changes, we will bring them to your attention before the new use starts.

Contact

General enquiries: info@theaigrowthlab.co.uk. Privacy, rights, deletion and data-protection complaints: support@theaigrowthlab.co.uk.