Opens Oct 17.Officially operating from October 17. We are still in development and testing. Get notified when orders open:
Suggested questions
Powered by AI · PollyX
Last updated: 7 August 2026 · Effective date: 21 July 2026
The data controller responsible for your personal data is:
If you have any questions about how we handle your personal data, or wish to exercise any of your rights under the GDPR, please contact us at the email above. We will respond within 30 days.
When you create an account we collect your email address and a hashed password (we never store your plaintext password). This data is necessary to provide you with access to the service.
We use Stripe to process payments, through Stripe Managed Payments. Under it Stripe, via its Link service, acts as our merchant of record: it handles the transaction, collects and remits any VAT or sales tax, and sends the receipt. Your card statement shows the purchase as sold through Link. We do not store your credit card numbers or full payment details - these are handled entirely by Stripe and its PCI-DSS compliant payment partners. We retain transaction records (amount, date, plan purchased) for legal and tax compliance purposes.
When you generate a report you provide information such as a company name, industry, location, website URL and competitor names. This data is used solely to generate the report you requested.
Reports are generated using Claude, an AI model by Anthropic, which performs both the analysis and live web search, and are stored in your account so you can access them at any time. Your report inputs are sent to Anthropic to produce the report. Reports contain the AI-generated analysis and source references, which may include links to and short excerpts of publicly posted third-party content (see 2.6).
We collect basic server logs (IP address, browser type, pages visited, timestamps) to maintain the security and performance of the service. We do not use this data for advertising or profiling.
To produce a report we read publicly available content about the report subject: news articles, public YouTube videos and comments, public posts on X, Reddit, Bluesky, Mastodon, Hacker News, TikTok and Instagram, app-store and marketplace reviews, and public web pages. Some of this content is personal data - a username attached to a publicly posted opinion.
Instagram content is collected through Meta's official Instagram Graph API hashtag endpoints, using PollyX's own business account. These endpoints return no usernames, so we never receive the identity of Instagram posters. For Instagram and TikTok, stored reports keep only the post link, date and engagement counts - no captions and no account names, and our analysis aggregates this content rather than reproducing it. For YouTube, stored API data is deleted after 30 days (see section 4). Verbatim quotes from other platforms appear only where the platform's terms permit display, and always link to the original post.
We use a small number of trusted third-party services to operate PollyX. Each acts as a data processor under a written Data Processing Agreement (DPA):
| Processor | Purpose | Location |
|---|---|---|
| Supabase | Authentication and database (stores your account and reports) | EU (AWS Frankfurt) |
| Vercel | Website hosting and request processing | USA (SCCs apply) |
| Stripe | Payment processing (merchant of record through Stripe Managed Payments and Link) | Ireland (Stripe Technology Europe) and USA (SCCs apply) |
| Anthropic (Claude) | AI report generation and live web search - receives your report inputs (e.g. company name, industry, focus) | USA (SCCs apply) |
| Tavily | Live web search during report generation - receives search queries containing the report subject | USA (SCCs apply) |
| Trigger.dev | Runs report-generation jobs - processes report inputs and your email | USA (SCCs apply) |
| Resend | Sends transactional emails - receives your email address and message content | USA (SCCs apply) |
| Google (YouTube Data API) | Fetches public YouTube video data for reports | USA (SCCs apply) |
| Meta Platforms (Instagram Graph API) | Fetches public Instagram posts for a searched hashtag via Meta's official API - returns no usernames | USA (SCCs apply) |
| Apify | Collects public social-web content (X, TikTok, Reddit) during report generation | USA (SCCs apply) |
| xAI | Licensed retrieval of public X posts during report generation | USA (SCCs apply) |
| GDELT Project | Public news intelligence - no personal data transmitted | USA (public data only) |
SCCs = Standard Contractual Clauses approved by the European Commission for international data transfers.
PollyX uses YouTube API Services to build the YouTube portion of a sentiment report. By using PollyX you also agree to be bound by the YouTube Terms of Service. Google's handling of any data it receives is governed by the Google Privacy Policy.
What we access. Publicly available data only, through two read-only endpoints: search.list, to find public videos discussing the brand being analysed, and commentThreads.list, to read the public top-level comments on those videos. PollyX never asks you to sign in to YouTube or Google, requests no OAuth permissions, and has no access to any private account, channel, watch history or subscriber data.
What we store, and for how long. A new report lists the title, channel name, publish date and link of each video used, together with short quoted extracts from public comments, shown as cited evidence for its findings. We keep that material for 30 days. YouTube's API developer policies set a 30-day limit on storing data of this kind, so an automated job removes it from every report once it passes that age. What remains after 30 days is our own analysis: the sentiment score, the written themes and the number of videos the report was built on. The report page says plainly when the video list has been removed and when that happened. You can also delete your account at any time from Settings, which erases your reports and everything inside them immediately.
How to have YouTube data removed. You can delete your account at any time from Settings, which erases your reports and every YouTube record inside them immediately. If you are not a PollyX customer and believe a report contains YouTube data relating to you, email contact@pollyx.org and we will remove it within seven calendar days, as required by YouTube API Developer Policy III.E.4.g. You do not need an account to make that request.
Whose numbers are whose. Video titles, channel names, publish dates and links come from the YouTube Data API and are shown as the API supplies them. Every score, theme, percentage and ranking in a PollyX report is PollyX's own calculation - independently derived, and never a metric published, supplied or endorsed by YouTube. PollyX does not publish a YouTube-specific sentiment verdict, a YouTube volume rating or a YouTube audience profile, and never infers age, race, religion, political leaning, sexual orientation or health status from YouTube data.
What we do not do. We do not re-host, re-upload, download or embed YouTube videos for playback. We do not place advertising against YouTube content, do not present it as our own, and do not sell or redistribute YouTube data to third parties. Every video a report relies on is credited with a link back to YouTube so you can watch the original and check our reading of it.
PollyX does not request access to your Google account, so there is no PollyX permission to withdraw. You can review or revoke any third-party access to your Google account at any time via the Google security settings page.
Some of our processors operate outside the European Economic Area (EEA). For processors in the United States, we rely on the EU Standard Contractual Clauses (SCCs) as approved by the European Commission under Decision 2021/914. Your account data and reports stored in Supabase reside within the EU (AWS eu-central-1, Frankfurt).
Anthropic (United States): report generation uses the Claude models by Anthropic, whose processing takes place in the United States under the EU Standard Contractual Clauses referenced above. When you generate a report, the inputs you provide (such as the company name, industry, location and analysis focus) are transmitted to Anthropic to produce the report. As a precaution, do not include personal or confidential information in your report inputs if you would prefer it not be processed outside the EEA.
As a data subject under the GDPR you have the following rights. To exercise any of them, email us at contact@pollyx.org.
We will respond to all requests within 30 calendar days. In complex cases we may extend this by a further 60 days, in which case we will notify you.
PollyX uses only strictly necessary cookies to maintain your authenticated session. We do not use advertising cookies, tracking pixels, or third-party analytics cookies. No cookie consent banner is required for strictly necessary cookies under the EU ePrivacy Directive.
| Cookie | Purpose | Expiry |
|---|---|---|
| sb-access-token | Supabase authentication session token | 1 hour |
| sb-refresh-token | Supabase session refresh token | 7 days |
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss or disclosure. These include:
Authorised PollyX administrators may access account information - including your email address and the subjects of the reports you generate - strictly for the purposes of operating, supporting and securing the service. Administrators cannot view your password, which is stored only as a one-way bcrypt hash and is never accessible to anyone, including us.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay, as required by Art. 33–34 GDPR.
PollyX is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at contact@pollyx.org and we will delete it promptly.
We may update this Privacy Policy from time to time. When we make material changes we will notify you by email (to the address on your account) and update the "Last updated" date at the top of this page at least 14 days before the changes take effect. Continued use of PollyX after the effective date constitutes acceptance of the updated policy.
For any privacy-related questions, requests, or complaints: