Security & data protection · Public page
Where your data goes, in plain terms
This page is written for the practitioner about to load a witness statement — and for the IT or compliance colleague who has to sign the platform off. Plain answers first; the full privacy policy sits behind it.
Your documents never leave your machine
Witness statements and reports are analysed entirely in your browser. They are not uploaded to our servers and are never sent to any AI model.
Hosted in London
Hosting is pinned to Vercel's London region; our databases live in Supabase's London (AWS eu-west-2) region. Storage does not leave the UK.
Nothing you submit trains any AI
No data you enter is used to train any model — ours or anyone else's. Anthropic does not train on API inputs.
What happens to a witness statement I load into a rebuttal tool?
It stays on your computer. The document is opened, text-extracted and
analysed inside your web browser. Nothing in it reaches our servers, and nothing in it
is sent to any AI model. The extracted data lives in your browser's session storage and
is deleted automatically when you close the tab. We keep no copy — there is nothing on
our side to breach, subpoena or leak.
What happens when I ask the research assistant a question?
The text of your question is sent to Anthropic's Claude API to generate the answer, and
a copy — capped at 2,000 characters — is logged on our servers so we can check answer
quality. That log records the question, its subject scope and result counts only. It is
not linked to your name, email or account, and it is deleted automatically
after 60 days.
- Do not put client names, addresses or claim references in a research question — the platform never needs them to answer a question of law or rate methodology.
Is anything I do used to train AI models?
No. Nothing you submit — questions, documents, account details — is used
to train any AI model, ours or a third party's. Anthropic does not use API inputs to
train its models.
Where is the platform hosted, and what ever leaves the UK?
Hosting and databases are pinned to London. Three narrow functions involve transfers,
each under the UK-US Data Bridge or UK adequacy regulations:
| Processor | What it receives | Where |
|---|---|---|
| Vercel (hosting) | Standard web traffic | United Kingdom — London (lhr1) |
| Supabase (accounts, data) | Name, email, anonymised logs | United Kingdom — AWS London |
| Anthropic (research answers) | Question text only | United States — UK-US Data Bridge, SCCs |
| Twilio SendGrid (email) | Your email address | United States — UK-US Data Bridge, SCCs |
| Postcodes.io / OpenRouteService | Postcodes and coordinates only | UK / Germany (EU adequacy) |
What do you hold about me, and for how long?
Deliberately little.
No marketing use, no profiling, no automated decision-making, no selling of data.
No payment details are collected — access comes with Forum membership.
| Data | Why | Kept for |
|---|---|---|
| Name and email | Your account | While the account is active; deleted within 30 days of a request |
| Research question text (anonymised) | Answer quality checks | 60 days, then deleted automatically |
| Template-integrity diagnostics | Detecting changed insurer report formats | No more than 6 months |
| Documents you analyse | — | Never stored; session data clears when the tab closes |
Why do the rebuttal tools contact postcode services?
To test a rate surveyor's branch-distance claims, the tool asks Postcodes.io (UK) and
OpenRouteService (Germany) to geocode postcodes and compute driving distances. Only the
postcode or map coordinates are sent — never names, claim references, or anything else
from the statement.
Who can get into the platform?
Registration requires email confirmation and manual approval by the
platform administrator — an account does not exist until a person has approved it.
- Every connection is encrypted (HTTPS/TLS).
- Passwords are bcrypt-hashed; sessions are secure token-based.
- Server APIs require a valid authenticated session and restrict cross-origin requests.
- Our hosting and database providers hold SOC 2 Type II certification.
What are my rights, and who do I complain to?
All the usual UK GDPR rights — access, rectification, erasure, restriction, portability
and objection. Write to us and we respond within one calendar month. If you believe we
have fallen short, you can complain to the Information Commissioner's Office at
ico.org.uk or on 0303 123 1113.
Data controller
Steve Evans — credit-hire.ai
sae@credithire.org.uk
The formal statement of everything on this page, with legal bases, lives in the privacy policy. If your firm needs anything further for its supplier review, ask — you will get a straight answer.
Steve Evans — credit-hire.ai
sae@credithire.org.uk
The formal statement of everything on this page, with legal bases, lives in the privacy policy. If your firm needs anything further for its supplier review, ask — you will get a straight answer.