Opens Oct 17.

Polly
PollyX Assistant · Online
Hi! I'm Polly 👋 I can answer any questions about PollyX - how reports work, what's included, pricing, or anything else. What would you like to know?

Suggested questions

Powered by AI · PollyX

Back to home
PollyX

Privacy Policy

Last updated: 7 August 2026 · Effective date: 21 July 2026

This Privacy Policy explains how PollyX ("we", "us", "our") collects, uses, stores and protects your personal data. It is written in compliance with the EU General Data Protection Regulation (GDPR) (Regulation 2016/679) and applicable national data protection laws.

1. Data Controller

The data controller responsible for your personal data is:

Lernspark Ltd
Trading as PollyX (pollyx.org)
Registered in Ireland, company number 822174

If you have any questions about how we handle your personal data, or wish to exercise any of your rights under the GDPR, please contact us at the email above. We will respond within 30 days.

2. What Data We Collect and Why

2.1 Account Data

When you create an account we collect your email address and a hashed password (we never store your plaintext password). This data is necessary to provide you with access to the service.

  • Legal basis: performance of a contract (Art. 6(1)(b) GDPR)
  • Retention: for the lifetime of your account; deleted within 30 days of account closure

2.2 Payment Data

We use Stripe to process payments, through Stripe Managed Payments. Under it Stripe, via its Link service, acts as our merchant of record: it handles the transaction, collects and remits any VAT or sales tax, and sends the receipt. Your card statement shows the purchase as sold through Link. We do not store your credit card numbers or full payment details - these are handled entirely by Stripe and its PCI-DSS compliant payment partners. We retain transaction records (amount, date, plan purchased) for legal and tax compliance purposes.

  • Legal basis: performance of a contract; legal obligation (Art. 6(1)(b) and (c) GDPR)
  • Retention: 7 years (EU tax record requirements)

2.3 Report Input Data

When you generate a report you provide information such as a company name, industry, location, website URL and competitor names. This data is used solely to generate the report you requested.

  • Legal basis: performance of a contract (Art. 6(1)(b) GDPR)
  • Retention: stored as part of your report; deleted with your account or on request

2.4 Generated Report Content

Reports are generated using Claude, an AI model by Anthropic, which performs both the analysis and live web search, and are stored in your account so you can access them at any time. Your report inputs are sent to Anthropic to produce the report. Reports contain the AI-generated analysis and source references, which may include links to and short excerpts of publicly posted third-party content (see 2.6).

  • Legal basis: performance of a contract (Art. 6(1)(b) GDPR)
  • Retention: indefinitely while your account is active; deleted within 30 days of account closure or upon request

2.5 Usage and Technical Data

We collect basic server logs (IP address, browser type, pages visited, timestamps) to maintain the security and performance of the service. We do not use this data for advertising or profiling.

  • Legal basis: legitimate interests - ensuring system security and stability (Art. 6(1)(f) GDPR)
  • Retention: 90 days

2.6 Public Content Analysed in Reports

To produce a report we read publicly available content about the report subject: news articles, public YouTube videos and comments, public posts on X, Reddit, Bluesky, Mastodon, Hacker News, TikTok and Instagram, app-store and marketplace reviews, and public web pages. Some of this content is personal data - a username attached to a publicly posted opinion.

Instagram content is collected through Meta's official Instagram Graph API hashtag endpoints, using PollyX's own business account. These endpoints return no usernames, so we never receive the identity of Instagram posters. For Instagram and TikTok, stored reports keep only the post link, date and engagement counts - no captions and no account names, and our analysis aggregates this content rather than reproducing it. For YouTube, stored API data is deleted after 30 days (see section 4). Verbatim quotes from other platforms appear only where the platform's terms permit display, and always link to the original post.

  • Legal basis: legitimate interests - market and opinion research on publicly available statements (Art. 6(1)(f) GDPR)
  • Retention: source references live as long as the report they belong to; deleted with the report or the account. Raw collection data is processed in memory during generation only and never stored.
  • Your rights: if a report references your public post and you object, contact us (section 11) and we will remove it.

3. Third-Party Processors

We use a small number of trusted third-party services to operate PollyX. Each acts as a data processor under a written Data Processing Agreement (DPA):

ProcessorPurposeLocation
SupabaseAuthentication and database (stores your account and reports)EU (AWS Frankfurt)
VercelWebsite hosting and request processingUSA (SCCs apply)
StripePayment processing (merchant of record through Stripe Managed Payments and Link)Ireland (Stripe Technology Europe) and USA (SCCs apply)
Anthropic (Claude)AI report generation and live web search - receives your report inputs (e.g. company name, industry, focus)USA (SCCs apply)
TavilyLive web search during report generation - receives search queries containing the report subjectUSA (SCCs apply)
Trigger.devRuns report-generation jobs - processes report inputs and your emailUSA (SCCs apply)
ResendSends transactional emails - receives your email address and message contentUSA (SCCs apply)
Google (YouTube Data API)Fetches public YouTube video data for reportsUSA (SCCs apply)
Meta Platforms (Instagram Graph API)Fetches public Instagram posts for a searched hashtag via Meta's official API - returns no usernamesUSA (SCCs apply)
ApifyCollects public social-web content (X, TikTok, Reddit) during report generationUSA (SCCs apply)
xAILicensed retrieval of public X posts during report generationUSA (SCCs apply)
GDELT ProjectPublic news intelligence - no personal data transmittedUSA (public data only)

SCCs = Standard Contractual Clauses approved by the European Commission for international data transfers.

4. YouTube API Services

PollyX uses YouTube API Services to build the YouTube portion of a sentiment report. By using PollyX you also agree to be bound by the YouTube Terms of Service. Google's handling of any data it receives is governed by the Google Privacy Policy.

What we access. Publicly available data only, through two read-only endpoints: search.list, to find public videos discussing the brand being analysed, and commentThreads.list, to read the public top-level comments on those videos. PollyX never asks you to sign in to YouTube or Google, requests no OAuth permissions, and has no access to any private account, channel, watch history or subscriber data.

What we store, and for how long. A new report lists the title, channel name, publish date and link of each video used, together with short quoted extracts from public comments, shown as cited evidence for its findings. We keep that material for 30 days. YouTube's API developer policies set a 30-day limit on storing data of this kind, so an automated job removes it from every report once it passes that age. What remains after 30 days is our own analysis: the sentiment score, the written themes and the number of videos the report was built on. The report page says plainly when the video list has been removed and when that happened. You can also delete your account at any time from Settings, which erases your reports and everything inside them immediately.

How to have YouTube data removed. You can delete your account at any time from Settings, which erases your reports and every YouTube record inside them immediately. If you are not a PollyX customer and believe a report contains YouTube data relating to you, email contact@pollyx.org and we will remove it within seven calendar days, as required by YouTube API Developer Policy III.E.4.g. You do not need an account to make that request.

Whose numbers are whose. Video titles, channel names, publish dates and links come from the YouTube Data API and are shown as the API supplies them. Every score, theme, percentage and ranking in a PollyX report is PollyX's own calculation - independently derived, and never a metric published, supplied or endorsed by YouTube. PollyX does not publish a YouTube-specific sentiment verdict, a YouTube volume rating or a YouTube audience profile, and never infers age, race, religion, political leaning, sexual orientation or health status from YouTube data.

What we do not do. We do not re-host, re-upload, download or embed YouTube videos for playback. We do not place advertising against YouTube content, do not present it as our own, and do not sell or redistribute YouTube data to third parties. Every video a report relies on is credited with a link back to YouTube so you can watch the original and check our reading of it.

PollyX does not request access to your Google account, so there is no PollyX permission to withdraw. You can review or revoke any third-party access to your Google account at any time via the Google security settings page.

5. International Data Transfers

Some of our processors operate outside the European Economic Area (EEA). For processors in the United States, we rely on the EU Standard Contractual Clauses (SCCs) as approved by the European Commission under Decision 2021/914. Your account data and reports stored in Supabase reside within the EU (AWS eu-central-1, Frankfurt).

Anthropic (United States): report generation uses the Claude models by Anthropic, whose processing takes place in the United States under the EU Standard Contractual Clauses referenced above. When you generate a report, the inputs you provide (such as the company name, industry, location and analysis focus) are transmitted to Anthropic to produce the report. As a precaution, do not include personal or confidential information in your report inputs if you would prefer it not be processed outside the EEA.

6. Your Rights Under the GDPR

As a data subject under the GDPR you have the following rights. To exercise any of them, email us at contact@pollyx.org.

Right of access (Art. 15)
You can request a copy of all personal data we hold about you.
Right to rectification (Art. 16)
You can ask us to correct inaccurate or incomplete personal data.
Right to erasure (Art. 17)
Delete your account and all its data yourself, immediately, under Settings. You can also request deletion by email. Payment records are retained by our payment provider as required by law.
Right to restriction of processing (Art. 18)
You can ask us to pause processing of your data in certain circumstances.
Right to data portability (Art. 20)
You can request your data in a structured, machine-readable format (JSON).
Right to object (Art. 21)
You can object to processing based on legitimate interests, including for direct marketing.
Right to withdraw consent
Where processing is based on consent, you may withdraw it at any time without affecting prior processing.
Right to lodge a complaint
You have the right to lodge a complaint with your national supervisory authority. In Spain: Agencia Española de Protección de Datos (www.aepd.es). In the EU: your local Data Protection Authority.

We will respond to all requests within 30 calendar days. In complex cases we may extend this by a further 60 days, in which case we will notify you.

7. Cookies

PollyX uses only strictly necessary cookies to maintain your authenticated session. We do not use advertising cookies, tracking pixels, or third-party analytics cookies. No cookie consent banner is required for strictly necessary cookies under the EU ePrivacy Directive.

CookiePurposeExpiry
sb-access-tokenSupabase authentication session token1 hour
sb-refresh-tokenSupabase session refresh token7 days

8. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss or disclosure. These include:

  • All data in transit is encrypted using TLS 1.2+
  • All data at rest is encrypted (AES-256) by Supabase/AWS
  • Passwords are stored as bcrypt hashes - never in plaintext
  • Access to production systems is restricted to authorised personnel
  • Payment data never touches our servers - handled entirely by Stripe

Authorised PollyX administrators may access account information - including your email address and the subjects of the reports you generate - strictly for the purposes of operating, supporting and securing the service. Administrators cannot view your password, which is stored only as a one-way bcrypt hash and is never accessible to anyone, including us.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay, as required by Art. 33–34 GDPR.

9. Children's Privacy

PollyX is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at contact@pollyx.org and we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes we will notify you by email (to the address on your account) and update the "Last updated" date at the top of this page at least 14 days before the changes take effect. Continued use of PollyX after the effective date constitutes acceptance of the updated policy.

11. Contact Us

For any privacy-related questions, requests, or complaints:

Response time: within 30 calendar days