← Back to Solutions Engine

Privacy Notice

Last updated: 7 September 2026

This Notice explains how Solutions Engine Limited, a company registered in England and Wales ("we", "us", "our"), collects, uses, shares, and protects personal data when you use solutionsengine.ai and the associated application (the "Service"). We act as the data controller for personal data we collect about you in connection with the Service. Where you upload your own business content and your customers' details into the Service, you are the controller of that content and we act as your processor.

If you have any question about this Notice, or you want to exercise a privacy right, email support@solutionsengine.ai.

1. Personal data we collect

  • Account data: name, email address, profile picture (where you sign in with a third-party provider), authentication identifiers, organisation or workspace name, and your role within that workspace.
  • Content you provide: documents, decks, brand material, images, links, knowledge you add to your workspace, prompts you write, and the outputs the Service generates for you. This content may contain personal data about you, your colleagues, or your prospects — you decide what to upload.
  • Usage and telemetry: pages generated, features used, credits consumed, device and browser identifiers, IP address, referring pages, and log timestamps.
  • Support and communications: messages you send to support, feedback, and account-related correspondence.
  • Payment-related data: collected and processed by Paddle as Merchant of Record. We receive only summary information (plan, subscription status, billing country, invoice records, and the last four digits of a card where shown on an invoice). We never receive or store full card numbers.

We do not intentionally collect special category data (such as health, biometric, or political data), and we ask that you do not upload it to the Service.

2. Signing in with Google and other providers

You can create an account and sign in using Google. When you do, Google shows you a consent screen and, if you approve, shares a limited set of information with us. We request only the following scopes:

  • openid — a stable identifier so we can recognise your account on future sign-ins.
  • .../auth/userinfo.email — your email address, used as your account identity, to send service and account emails, and to match you to workspace invitations.
  • .../auth/userinfo.profile — your name and profile picture, used to display who you are inside your workspace.

We do not request access to your Gmail, Google Drive, Calendar, Contacts, or any other Google service, and we cannot read or modify them. We store the information above alongside your account record for as long as your account exists, so you can sign back in. We do not sell it, use it for advertising, or share it with third parties other than the infrastructure providers listed in section 4 who host our authentication and database systems on our behalf, or where required by law.

Limited Use disclosure. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Information received from Google APIs is never used to train generalised artificial intelligence or machine learning models, is never sold, and is never used for advertising purposes.

You can revoke our access at any time from your Google Account permissions page, or by deleting your Solutions Engine account (see section 8).

3. How we use your data, and our legal bases

  • Provide the Service — create and maintain your account, authenticate you, run AI generation, store and render your work, share links you choose to publish (legal basis: performance of a contract).
  • Billing and credits — meter usage, apply plan limits, issue invoices, handle refunds (contract / legal obligation).
  • Security and fraud prevention — detect abuse, rate-limit, secure accounts, investigate incidents, maintain audit logs of workspace access (legitimate interests in keeping the Service safe).
  • Service improvement — analyse aggregated and de-identified usage to improve features and reliability (legitimate interests). We do not use your private content to train foundation models.
  • Customer support — respond to your enquiries and diagnose faults, which may involve a member of staff accessing your workspace where you ask us to (contract / legitimate interests).
  • Legal obligations — accounting and tax records, responding to lawful requests (legal obligation).
  • Marketing — occasional product updates by email. You can opt out at any time using the link in the email or by contacting us (consent, or legitimate interests for existing customers).

The Service uses AI models to generate content on your instruction. This is not automated decision-making that produces legal or similarly significant effects about you, and we do not use it to profile you.

4. Who we share data with

We do not sell personal data. We share it only with the following categories of recipient, each under a written contract that limits what they may do with it:

  • Cloud infrastructure and database — hosting, storage, authentication, and content delivery for the application and your files.
  • AI model providers — prompts and the context needed to answer them are sent to language and image model providers (currently Anthropic, OpenAI, and Google) to generate your outputs. These providers act as our processors under agreements that prohibit training on our data and apply zero or short retention windows.
  • Merchant of Record (Paddle) — sale of the product, subscription management, payments, sales tax and VAT compliance, and invoicing. Paddle is an independent controller for payment data it collects.
  • Email delivery, analytics, and error monitoring — to send transactional email and to understand faults and usage.
  • Professional advisers — legal, accounting, and insurance advisers where reasonably required.
  • Business transfers — if we are involved in a merger, acquisition, or sale of assets, your data may transfer to the successor entity under the protections of this Notice.
  • Authorities — where required by law, or to establish, exercise, or defend legal claims, or to protect the rights, property, or safety of any person.

Within your workspace, content is visible to other members of that workspace according to the permissions your administrator sets. If you publish a share link, anyone with that link can view the content you shared, subject to the controls you apply.

5. International transfers

We are based in the United Kingdom, and some of our providers are located in the United States and the European Economic Area. Where personal data is transferred outside the UK or EEA, we rely on appropriate safeguards such as the UK International Data Transfer Agreement and Addendum, EU Standard Contractual Clauses, or an adequacy decision, together with additional technical measures such as encryption in transit.

6. Data retention

  • Account and workspace content — kept while your account is active, and deleted or anonymised within 90 days of account closure, unless we must keep it longer by law.
  • Billing and tax records — kept for seven years to meet UK accounting and tax requirements.
  • Security, audit, and access logs — typically kept for up to 12 months.
  • Support correspondence — kept for up to 24 months after the enquiry is closed.
  • Backups — deleted content may persist in encrypted backups for a short rolling window before being overwritten.

7. Security

We use technical and organisational measures appropriate to the risk, including encryption in transit (TLS), encryption at rest for stored content, row-level access controls so a workspace can only reach its own data, least-privilege role separation for staff, audit logging of privileged access, dependency and configuration scanning, and multi-factor authentication on administrative systems. No system is perfectly secure, but where a breach is likely to result in a risk to your rights we will notify the relevant supervisory authority, and you, without undue delay.

8. Your rights and choices

Subject to applicable law, you have the right to access your personal data, correct it, erase it, restrict or object to its processing, receive it in a portable format, and withdraw any consent you have given. If you are in the UK or EEA you may lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner's Office. If you are a California resident, you also have the right to know, delete, and correct your personal information, and to not be discriminated against for exercising those rights; we do not sell or share personal information as those terms are defined under the CCPA.

You can update most account details in the app. To delete your account and the content in it, email support@solutionsengine.ai from your account address, or use the account deletion option in the app where available. We verify requests and respond within one month, and will tell you if we need longer for a complex request.

9. Cookies and similar technologies

We use strictly necessary cookies and local storage for authentication, session management, security, and remembering your workspace and interface preferences. Where analytics or performance cookies are used in your region, they are subject to your consent and can be withdrawn at any time. We do not use advertising cookies and we do not operate cross-site tracking for advertising.

10. Children

The Service is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Changes to this Notice

We may update this Notice as the Service develops. We will change the "last updated" date above and, where changes are material, notify you by email or in the app before they take effect.

12. Contact

Solutions Engine Limited, registered in England and Wales.
Privacy enquiries and data rights requests: support@solutionsengine.ai