Privacy
A plain description of what this product actually does with data, written from the code rather than from a template. Where a real policy decision hasn’t been made yet, this page says so instead of inventing one.
Last updated 13 August 2026
Who we are
Audience Intel is operated by Cambray Design Limited, registered in England and Wales. Anything on this page, or any question about data we hold: ian@cambraydesign.co.uk.
What a report is built from
Reports are built from public information plus what you type in. No access to your systems is needed or asked for. These are the sources the product reads, taken from the connector and engine code rather than from marketing copy — so this list is a superset of the shorter one drawn on the homepage:
- AI assistants, asked the questions your buyers ask: OpenAI GPT, Google Gemini, Anthropic Claude and xAI Grok, called through the OpenRouter gateway.
- Search and place data: Google Search, Google Maps and Google Places, Google PageSpeed, and commercial search-demand and search-ranking data.
- Public registers and datasets: Companies House, and ONS Census data via Nomis.
- Public discussion and listings: Reddit, YouTube, and public review listings.
- Public web pages: your own website, and the public websites of the competitors named in your report.
Your own analytics are a separate matter. Google Analytics and Search Console are read onlyif you explicitly connect them. That connection is held by Pipedream; the credentials never reach our database — we store only an opaque account identifier.
What we hold about you
- Your email address, if you create an account or buy something. Accounts sign in by emailed link: there is no password column in the database, by design.
- What you enter to run a report: the website address, and where you supply them, a name, a company number and an email address.
- The reports themselves, and the PDF files generated from them.
- Purchase records: Stripe’s identifiers for the customer, checkout session and subscription, the amount, and the billing email.
- Technical usage records, including the caller’s IP address, used for rate limiting and abuse control.
- Which steps of the report form were reached, and how long each took. This is kept against a random one-off reference for that visit — not your IP address, not a cookie, and not anything you typed. It exists so we can see where the form loses people. It cannot be linked back to you.
- Waiting-list details, if you joined one: email, business name and sector.
- Research-study requests, if you asked for a published study by email — described in full below.
Reports, and who can see them
Every report is gated by a random token in its link. A report’s existence is never revealed to anyone without that link, and the token check fails closed. Generated PDF files are held in object storage and served through signed links that expire after seven days.
Payment
Payment is taken by Stripe, on Stripe’s own hosted checkout pages. Card details never reach our servers— this site loads no card fields and no Stripe card component at all; you are handed to Stripe and handed back. We store Stripe’s identifiers and the billing email so we can find your order, deliver what you bought, and open the billing portal for you.
Transactional email — sign-in links, report delivery, order confirmations, waiting-list confirmation — is sent through Resend, from reports@audienceintel.app.
Asking for a published study by email
Some published studies at /researchare split: the executive summary — the headline finding, the method, the sample and the stated limits — is free and public, and the deeper sections are sent by email. Each study page lists exactly which sections those are before it asks for anything.
When you ask for one, we store:
- the email address you gave, and the domain part of it separately, so requests can be grouped by the business they came from;
- which study you asked for, and when;
- the wording you were shown when you asked — not just a flag saying you agreed, but the sentence itself;
- whether you ticked the separate marketing box, and if you did, when and against what wording;
- where the request came from: the page that referred you and any
utm_tags on the link; - whether the email actually sent. If it didn’t, the failure and its reason are recorded and the page tells you on the spot — we do not say “check your inbox” for an email that was never sent.
Asking for the study is consent to receive that study and nothing else. Marketing follow-up is a separate box, unticked, in its own sentence, stored as its own field. It is never inferred from the fact that you asked for a document, and leaving it unticked has no effect on getting the study.
The emailed link is the key — there is no account and no password. It is signed, it opens only that one study, and it expires 30 days after it is sent. Asking again sends a fresh one. A repeat request updates the same record rather than creating a second one.
These records are readable by us alongside our other prospect data, which means a study request may be the reason we later get in touch. Where that contact is marketing, it happens only for people who ticked the marketing box, and the PECR rules in the next section apply on top of it. To be removed, email ian@cambraydesign.co.uk.
Outreach, and the PECR rules it follows
Any business-to-business outreach we send follows UK PECR’s corporate-subscriber rules, and the rule is enforced in code before anything can be sent rather than left to judgement:
- We email limited companies and LLPs only, verified against the Companies House register.
- Where corporate status cannot be confirmed — no match, an ambiguous match, a low-confidence match, or a company that isn’t active — the check fails closed and nothing is sent. Sole traders and ordinary partnerships are excluded on that basis.
- Every message identifies who sent it and carries a one-line opt-out.
- An opt-out in a reply is detected deterministically in code, before any model reads it, and the address is written to a suppression list that is consulted before every send.
To opt out, reply to the email or write to us and we will suppress your address.
Retention, transfers, and your rights
The third parties this product sends data to in order to function are named in the two sections above and in each report’s own method section. A formal sub-processor list will replace that description here when it is published.
Changes to this page
This page describes the product as it is built today. When the product changes, this page changes with it. See also the terms of use and the FAQ, which answers the same questions in less formal language.