Privacy policy
This page explains what personal data answerrails.com collects, why, where it goes and how long we keep it. We have tried to write it the way we build the product: say what is true, say it plainly, and do not claim more than we do.
Who we are
Celtic3d Ltd is the data controller for this site. We are a small company based in Aberdeen, Scotland, registered in Scotland under company number SC544480, with our registered office at 33 Corrennie Circle, Dyce, Aberdeen, AB21 7LD. There is no public counter at that address; visitors are by appointment only. AnswerRails™ is a trademark of Celtic3d Ltd, and our parent site is celtic3d.com.
For anything to do with your data, write to enquiries@answerrails.com. We are registered with the Information Commissioner’s Office under reference ZA204947.
The short version
- Non-essential cookies — analytics in particular — are set only if you accept them in the cookie banner. There is no advertising pixel and no third-party font on any page.
- The AI assistant only starts a conversation after you tick a consent box. Your messages go to an AI provider to be answered, and a transcript — normally anonymised — is kept for up to 180 days to improve the assistant.
- Nothing you type is used to train anyone’s AI model.
- You can ask us to show you, or erase, anything we hold about you. Details below.
Browsing the site
Like every web server, ours writes an access log containing your IP address, the page requested, the time, and your browser’s user-agent string. We use it to keep the site running and to investigate abuse. Access logs are kept for 180 days and are not combined with anything else. The site is hosted on Amazon Web Services in Ireland, and is delivered through Amazon’s content-delivery network, so a copy of the page you requested may be served from an edge server nearer to you.
Our blog posts do not take comments, and there is no visitor registration. If you follow a link to another website, that site’s privacy policy applies from then on.
Cookies and analytics
We manage cookies with the Complianz consent tool. Anything beyond the strictly necessary is set only after you accept it in the cookie banner, and you can change your choice at any time from the banner’s settings. The cookies this site can set fall into three groups:
- Consent preferences (strictly necessary). Complianz stores your cookie choices in cookies named
cmplz_*for one year, so that the banner does not ask you again. These hold your preferences and nothing else. - Analytics (with your consent). To understand how the site is used — which pages are read, where visitors come from, what they search for — we may run Google Analytics, which sets cookies named
_gaand_ga_*for up to two years and sends page-view data to Google under Google’s privacy policy, with IP addresses truncated. We also use Google Search Console, which tells us how the site appears in Google search; it sets no cookies and receives nothing from your browser. - The assistant’s own storage. The chat assistant uses browser storage rather than cookies — described in its own section below.
There is no advertising pixel, no social-media button that phones home, and no third-party font on any page. If we add a tool that sets cookies, it appears in the banner and on this page before it is switched on.
The AI assistant
The chat assistant on this site is AnswerRails itself — the product we sell, running on our own site. This is what happens when you use it.
Before you type anything
The assistant asks for your consent before it will send a message anywhere. Until you tick the box, no message leaves your browser. You can withdraw consent at any time from inside the chat window (“Edit consent”), and the assistant stops sending anything from that moment.
Where your messages go
To answer you, the assistant sends your message, the relevant passages from our own pages and documents, and the earlier turns of the same conversation to an AI provider. AnswerRails works with three providers, and because this site is where we test the product, we switch between them for testing and troubleshooting. At any given time your conversation goes to one of:
- Mistral AI (France) — our usual provider. Your messages are processed inside the European Union.
- OpenAI (United States).
- Anthropic (United States).
Separately, OpenAI provides the search that finds the relevant passages of our content for each question: your question is sent to OpenAI to be matched against our content, whichever provider then writes the answer.
We use every provider on paid, business terms under which conversation data is used only to answer the conversation underway and is not used to train the provider’s models. We will not use any plan that allows otherwise. Where a provider processes data in the United States, that is a transfer outside the UK, made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.
No other AI provider receives anything from this site. The assistant answers only from the content of this site and the documents we have given it; it has no access to any other data about you.
What we keep, and for how long
Because this site is where we test AnswerRails, conversation logging runs in one of three modes, and we switch between them as our testing requires. Whatever the mode, nothing is kept for longer than 180 days; after that it is deleted automatically.
- Anonymised — our usual setting. The transcript is stored against a random session identifier, not your IP address or anything that identifies your browser.
- Identified — used when we are testing the features that need it, such as human handoff or the privacy tooling itself. As well as the transcript, we store the session identifier, your IP address, your browser’s user-agent string, the page you came from, and a city-level location derived from the IP address.
- Off — no transcript is kept at all.
We read transcripts to see which questions the assistant answered well, which it refused, and which gaps in our documentation it exposed. If you type personal details into the chat — your name, your email address — they will be in the transcript; please don’t, unless you mean to.
When you give consent, we also record a receipt: the time, the wording you agreed to (as a hash), and the session identifier — and, in identified mode only, the IP address, user-agent and referring page. This is how we can show that consent was given, and it is kept for the same 180 days.
What the assistant stores in your browser
The assistant uses your browser’s storage, not cookies, and nothing in it is sent to anyone except as described above.
- Session storage (cleared when you close the tab): the session identifier, your consent choice, and the conversation so far, so the chat survives moving between pages.
- Local storage (kept until you clear it): the size and position you dragged the chat window to, and whether you minimised it. These are display preferences and contain no personal data.
Moderation
Every message is checked automatically for abusive or harmful content before it is answered. A message that fails the check is refused, and repeated failures end the session. This is automated, but it makes no decision about you beyond whether that message is answered.
When you email us
If you write to enquiries@answerrails.com, or ask the assistant to pass a question to a person, we keep your message and our reply in our mailbox for as long as the conversation is useful, and use it only to answer you. We do not add you to a mailing list.
Buying AnswerRails Pro
Pro licences are sold and delivered through Freemius, our merchant of record. When you buy, Freemius collects your name, email address, billing details and payment method under its own privacy policy; we never see your card details. We receive your name, email address and licence details so that we can support you and deliver updates. Licence and purchase records are kept for as long as the licence is active and then for six years, which UK tax law requires of us.
Our legal bases
Under UK GDPR (and PECR for cookies) we rely on your consent for the assistant conversation and for analytics cookies; on our legitimate interests in running a secure website and in improving the assistant for the access log and the anonymised transcripts; on performance of a contract when you buy or ask for support; and on legal obligation for purchase records.
Your rights
You have the right to ask what personal data we hold about you, to receive a copy of it, to have it corrected or erased, to object to or restrict how we use it, and to withdraw consent at any time. Email enquiries@answerrails.com and we will respond within one month. If you are asking about an assistant conversation, tell us roughly when it happened; where the transcript was anonymised we may need the session identifier from your browser to find it, and we will explain how to read it out.
If you are not happy with how we have handled your data, you can complain to the Information Commissioner’s Office at ico.org.uk. We would rather you told us first.
Changes to this policy
When what the site does changes, this page changes with it, and the effective date at the top moves. Substantive changes to how the assistant handles your data are also noted in the consent wording the assistant shows you.