Privacy Policy
Moxie Consulting Limited, trading as ATTENT10N ("we", "us", "our"), registered in England and Wales (Company Number 15889846), operates the ATTENT10N platform at attent10n.ai. This Privacy Policy explains how we collect, use, store, and protect information when you use our services.
We are committed to transparency about our data practices. If anything in this policy is unclear, contact us at privacy@attent10n.ai.
1. What We Collect
Information you provide directly
| Data | When | Why |
|---|---|---|
| Email address | Account creation, magic link login | Authentication, account communications |
| Brand name and category | Audit setup | Running your ATTENT10N audit |
| Market selection (UK/US) | Onboarding | Ensuring geographically relevant results |
| Competitor names | Audit setup (paid tiers) | Competitive analysis within your report |
| Brand attributes | Audit setup (optional) | Calibrating Brand Promise Alignment scoring |
| Payment information | Subscription purchase | Processed by Stripe; we never see or store card details |
Information we collect automatically
| Data | How | Why |
|---|---|---|
| Session cookie | Set on login (30-day expiry) | Keeping you logged in |
| IP address | Server logs | Security, abuse prevention |
| Browser and device type | Server logs | Debugging, service improvement |
Information we do not collect
- We do not collect passwords (we use magic link authentication)
- We do not collect personal data about consumers or end-users of the brands we audit
- We do not use third-party tracking pixels, advertising cookies, or behavioural analytics
- We do not sell or share your data with advertisers
2. How We Use Your Data
We use the information we collect to:
- Provide the service: Run brand audits, generate reports, manage your account and subscription
- Communicate with you: Send magic link login emails, audit completion notifications, and subscription confirmations
- Improve the service: Analyse aggregate, anonymised usage patterns to improve report quality and platform performance
- Maintain security: Detect and prevent fraud, abuse, and unauthorised access
- Comply with legal obligations: Respond to lawful requests from authorities where required
We will not use your data for any purpose beyond what is described here without your explicit consent.
3. How We Process Brand Audit Data
When you run an ATTENT10N audit, our platform:
- Queries publicly available AI platforms (such as ChatGPT, Claude, Gemini, and Perplexity) with consumer-style questions about your brand's category
- Collects publicly available review data from platforms such as Google, Trustpilot, and others
- Analyses publicly available web content about your brand (websites, social media profiles, press coverage, Wikipedia)
- Scores your brand using our proprietary Attention Score Algorithm
All data sources used in the audit process are publicly available. We do not access any private accounts, internal systems, or non-public data belonging to the brands we audit.
Your audit results (scores, reports, and underlying data) are stored in our database and associated with your account. You may request deletion of your audit data at any time (see Section 7).
4. Data Storage and Security
| Aspect | Detail |
|---|---|
| Hosting | Railway (cloud infrastructure) |
| Database | SQLite with WAL mode, server-side |
| Encryption in transit | HTTPS/TLS on all connections |
| Authentication | Magic link tokens (1-hour expiry), session cookies (30-day expiry, signed with itsdangerous) |
| Payment processing | Stripe handles all payment data; we store only Stripe customer and subscription IDs |
| Email delivery | Resend (transactional email only) |
| Access controls | Admin access restricted to the founding team |
We implement reasonable technical and organisational measures to protect your data against unauthorised access, alteration, disclosure, or destruction. However, no method of electronic storage or transmission is 100% secure.
5. Data Retention
| Data type | Retention period |
|---|---|
| Account information (email, preferences) | Until you delete your account, plus 30 days for backup recovery |
| Audit reports and scores | Until you delete your account or request deletion |
| Session cookies | 30 days from last login |
| Magic link tokens | 1 hour (auto-expire) |
| Server logs (IP, access) | 90 days, then automatically deleted |
| Payment records | As required by UK tax law (typically 6 years) |
On account deletion, we remove your personal data and audit results within 30 days. Aggregated, anonymised data (such as category-level benchmarks that cannot identify you or your brand) may be retained indefinitely.
6. Third-Party Services
We share data with the following third-party services, solely to operate the platform:
| Service | Purpose | Data shared |
|---|---|---|
| Stripe | Payment processing | Email, subscription tier (Stripe handles all card data directly) |
| Resend | Transactional email | Email address, email content |
| Railway | Cloud hosting | All platform data (hosted on their infrastructure) |
| AI Platforms (OpenAI, Anthropic, Google, Perplexity) | Running consumer queries as part of audits | Brand name, category, consumer-style queries (no personal data) |
| Serper / SerpAPI | Web search data collection | Brand name, search queries (no personal data) |
We do not sell, rent, or trade your personal information to any third party. We do not share your data with advertisers.
Each third-party provider processes data under their own privacy policies and under contractual obligations to us.
7. Your Rights
Under the UK GDPR and Data Protection Act 2018, you have the right to:
- Access your personal data (request a copy of what we hold)
- Rectify inaccurate or incomplete data
- Erase your data ("right to be forgotten")
- Restrict processing in certain circumstances
- Data portability (receive your data in a structured, machine-readable format)
- Object to processing based on legitimate interests
- Withdraw consent at any time where processing is based on consent
To exercise any of these rights, email us at privacy@attent10n.ai. We will respond within 30 days.
If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
8. Legal Basis for Processing
We process your personal data under the following legal bases (UK GDPR Article 6):
| Purpose | Legal basis |
|---|---|
| Providing the service, managing your account | Performance of a contract |
| Payment processing | Performance of a contract |
| Security and fraud prevention | Legitimate interest |
| Service improvement (anonymised analytics) | Legitimate interest |
| Marketing communications (if opted in) | Consent |
| Legal compliance | Legal obligation |
9. International Data Transfers
Our hosting infrastructure and some third-party services may process data outside the UK. Where this occurs, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the UK ICO
- Adequacy decisions where applicable
- Contractual commitments from service providers
10. Children
ATTENT10N is a business intelligence service designed for professionals. We do not knowingly collect data from anyone under the age of 18. If we become aware that a user is under 18, we will delete their account and data.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a notice on the platform. The "Last updated" date at the top reflects the most recent revision.
12. Contact
For any questions about this Privacy Policy or your data:
Email: privacy@attent10n.ai
Company: Moxie Consulting Limited (trading as ATTENT10N)
Company Number: 15889846
Location: United Kingdom
Registered in England and Wales · Company Number 15889846