Legal
Privacy
Draft pending review. This describes what Cairnflow actually does today. It has not yet been through a professional legal review.
The short version
Cairnflow reads public conversations on third-party platforms and scores them as potential leads. Posting is always your action: reply drafts are text you review and post yourself, and no Cairnflow feature contacts anyone. We hold your account details, the campaigns you create, and the results of scans you run.
What we collect
- Account data. Your email address, name and avatar, from the identity provider you sign in with. Sessions, so you stay signed in.
- What you tell us about your product. Campaign descriptions, target audience, keywords and any website URL you give us to analyse.
- Public source content. Posts and questions matching your campaign. We read them through official platform APIs, open protocols, published feeds, and public web pages that the site’s own
robots.txtpermits us to read. We never access anything behind a login, a paywall or a private group, and we never work around a site that has asked automated clients to stay out. - Operational data. Request logs, audit records of security-relevant actions, usage counts for billing and quotas, and error reports.
Automated processing
Campaign descriptions, website excerpts and public source text are sent to AI providers so Cairnflow can understand your product, score leads and draft replies. We do not send your account credentials or billing details. Where an AI feature is unavailable or disabled, Cairnflow falls back to deterministic scoring rather than failing.
Two providers are used, for different steps. OpenAI (US) handles product understanding and reply drafting. DeepSeek (China) scores leads — that step sends the public source text and your campaign description. There is no UK or EU adequacy decision for China, so that transfer relies on standard contractual clauses. Both are listed on our subprocessors page.
How long we keep it
| Data | Kept for |
|---|---|
| Raw source payloads | 30 days, then deleted |
| AI prompt inputs and outputs (redacted) | 90 days, then redacted |
| Background job payloads | 180 days, then redacted |
| Email delivery events | 365 days, then summarised |
| Usage records and security audit logs | 730 days |
These windows are enforced by scheduled purge jobs, not by policy alone. Your campaigns and leads are kept for as long as your workspace exists.
Your rights
From Settings → Danger zone you can export your data or request deletion of your account.
- Export. A JSON copy of the records held about you: your profile, workspace memberships and anything you wrote. It does not include your workspace’s lead data, which belongs to the workspace rather than to you individually.
- Deletion. Confirmed by typing your own email address, then held for 7 days during which you can cancel. We complete it within 30 days at the latest.
What deletion removes: your account, sign-in identities and sessions, workspace memberships, notification settings and any email addresses we hold for you. You will no longer be able to sign in.
What survives, and why: work you did inside a workspace — campaigns, leads and notes — belongs to that workspace and stays with your team, with your name removed from it. Security audit records are kept with the actor anonymised. Billing records are kept because we are required to retain financial records. A record that your deletion request was made and completed is also kept, because we have to be able to show that we honoured it.
If you are the only person in your workspace: deleting your account also permanently deletes that workspace and everything in it — campaigns, leads, scans and reply drafts. It is your data and nobody else’s, so you do not need anyone’s help to erase it. Settings shows you exactly which workspaces this affects before you confirm.
If your workspace has other active members, we will not delete it — that would erase their work too. Transfer ownership to one of them, or remove them from the workspace, and then request deletion again.
Who else processes your data
We use a small number of subprocessors — hosting, database, authentication, AI, email, payments and analytics. They are listed individually, with what each one handles, on the subprocessors page.
Cookies and analytics
Cairnflow sets a session cookie so you stay signed in. There is no advertising tracking and we do not sell data. Product analytics are handled by PostHog on its EU infrastructure.
Third-party content
Public posts we surface remain the property of their authors and the platforms they were posted on, and are shown under those platforms’ terms. Stack Exchange content is licensed CC BY-SA and is displayed with its author, a link to the original and its licence.
Contact
For anything on this page, including a data request you cannot complete yourself, email support@cairnflow.io. We respond within 30 days.