Privacy Notice
Last updated: 11 August 2026
This notice explains how CloseDeck Limited (“we”, “us”), a company registered in England & Wales (company no. 17187412, registered office Suite Ra01, 195-197 Wood Street, London, United Kingdom, E17 3NU), handles personal data through setpal.io (the “Service”), currently accessible at coach-io-live.vercel.app. We are the data controller for the limited personal data we hold about you as a user. For UK GDPR purposes our contact point is eric@closedeck.co.uk.
This notice covers setpal.io only. CloseDeck Limited operates other services, which collect different data for different purposes and have their own privacy notices. Using one does not mean your data is shared with another - we do not combine personal data across our products.
Please don’t paste other people’s personal data
setpal.io is designed to work with anonymised conversations. You should remove names, email addresses, phone numbers and other identifying details before pasting DMs or screenshots, and crop any screen recording to the conversation itself. If you do input personal data about third parties, you act as the controller for that data and are responsible for it - see our Terms of Service.
1. What we collect
Account data: your email address, and (if you sign in with Google) your basic Google profile such as name and avatar. Profile data: the voice and offer details, and any anonymised client results or testimonials, you choose to enter. Content: the messages and pasted conversations you type or paste in, and the responses generated for you, saved as your session history. Screenshots and screen-recording frames are different: they are sent to our AI provider to generate your reply, but they are never saved. We keep only a marker recording that an image was attached, plus a short written summary of where the conversation had got to - the stage reached, any objection raised, what to do next - so that reopening a session does not lose its context. That summary is generated automatically and written so as to leave out names, usernames, @handles, contact details and direct quotations. We do not keep the image itself. A screen recording you select is processed entirely inside your browser and is never uploaded to us at all. Usage data: counts of messages sent, for limits and basic analytics. Billing data: if you take a paid plan, your subscription plan and status, and identifiers linking your account to our payment processor, Stripe. Your card details go directly to Stripe and never touch our servers. Technical data: data needed to keep you signed in and run the app securely.
2. How and why we use it (lawful bases)
We process account, profile, content and usage data to provide and operate the Service and to keep your history available to you - on the basis of our legitimate interests (and, where you have an account, performance of our agreement with you) in delivering a working product. We use usage data to enforce fair-use limits and improve reliability, on the basis of our legitimate interests. We process billing data to manage your subscription and take payment - performance of our agreement with you - and keep transaction records where the law (e.g. tax law) requires it. We rely on your consent for any optional (non-essential) cookies.
3. AI processing
To generate responses, the content you submit is sent to our AI subprocessor, Anthropic, and processed by automated models under Anthropic’s commercial terms. Anthropic does not use your content to train its models, and automatically deletes API inputs and outputs within 30 days, except where it must retain them to enforce its usage policy or to comply with law. Output is automated and may be inaccurate; you remain responsible for reviewing it.
4. Who processes your data (subprocessors)
We use trusted providers to run the Service: Supabase (database and authentication), Anthropic (AI model processing), Vercel (application hosting), Upstash (rate-limiting to prevent abuse), Stripe (payment processing for paid plans), Google (optional sign-in) and Cloudflare (a security check on the sign-in, sign-up and password-reset pages only, described below).
Nothing on this list receives anything from an ordinary page view. Each one is involved only when you do the corresponding thing - sign in, pay, or send a message. Fonts and other page assets are served from our own domain, so browsing the site does not disclose your IP address to any other company.
The Cloudflare security check. On the sign-in, sign-up and password-reset pages we use Cloudflare Turnstile to tell real people apart from automated attacks. It runs only on those three pages, not while you use the app. Cloudflare receives your IP address and limited technical signals about your browser in order to decide whether the request looks automated. Cloudflare does not use this to build an advertising profile, and Turnstile does not show you puzzles or track you across sites. We rely on our legitimate interest in keeping accounts secure - and this specific measure is also what allows us to protect your account from password-guessing attacks, which we could not do otherwise.
Some of these providers process data outside the UK and EEA - Anthropic and Stripe process in the United States. Where data is transferred outside the UK/EEA we rely on appropriate safeguards, namely the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the provider’s certification under the UK-US and EU-US Data Privacy Framework. You can ask us for details of the safeguards that apply to a particular transfer.
4A. Where your data is stored
Your account and your conversations are stored in the United Kingdom. Our database (Supabase) runs in the London region, and our application servers (Vercel) run in London too. That covers your email address, your saved sessions and message history, your usage counts and your plan details.
Some processing still happens outside the UK, and we would rather say so than imply otherwise. When you send a message to the coach, its contents go to Anthropic in the United States to generate the reply. Payments are handled by Stripe, and the sign-in security check by Cloudflare, both of which operate internationally. These transfers rely on the safeguards described in section 4 above, and you can ask us which one applies to a particular transfer.
4B. Our EU representative
We are established in the United Kingdom. Where we offer the Service to people in the European Economic Area, EU GDPR Article 27 requires us to designate a representative in the EEA. Contact eric@closedeck.co.uk for our representative’s current details. You may contact either us or our representative about any matter relating to your personal data.
5. Cookies
We use strictly-necessary cookies to keep you signed in and run the app; these do not require consent. Any optional preferences are only stored if you accept them in the consent banner, and you can decline without losing core functionality. Full details, and how to change your choice, are in our cookie policy.
6. Retention
We keep your account, profile and session data for as long as your account is active - we do not run an automatic deletion job, so nothing you save disappears on you. You can delete individual sessions at any time.
Deleting your account removes your account, profile, sessions and usage records from our database, and immediately cancels any active subscription and deletes your customer record at Stripe. Content sent to our AI subprocessor is separately deleted by them within 30 days, as described above. Two things necessarily survive: encrypted database backups, which roll off on our provider’s own schedule and are not accessible for day-to-day use; and billing and transaction records, which we and Stripe must keep for six years under UK tax law.
We keep a minimal security log of significant account events - signing up for a paid plan, exporting your data, a plan change, and account deletion - so that we can detect and investigate a personal data breach, as we are required to do, and so we can show that we acted on a request you made. It records the event, the time and an account identifier. It never records message content, and never the contents of an export.
We keep those log entries for 12 months and then delete them automatically. Entries relating to a deleted account are stripped of the link to you at the point of deletion and expire on the same schedule. Twelve months is chosen because breaches are often discovered long after they happen, and a log that has already been erased cannot tell us who was affected.
7. Your rights
Under UK GDPR you have rights to access, correct, delete, restrict and object to processing of your personal data, and to data portability. You can exercise the main ones directly in the app: use Export my data to download everything we hold about you, and Delete account to erase it, both from your account settings under Data controls. For anything else - correction, restriction, objection, or a question about this notice - contact us at eric@closedeck.co.uk and we will respond within one month. You also have the right to complain to the UK Information Commissioner’s Office (ico.org.uk), or to your local supervisory authority if you are in the EEA.
7A. If you are in the United States
We do not sell or share your personal information, and we do not use it for cross-context behavioural advertising. We set no advertising or analytics trackers of any kind. There is therefore no sale or sharing for you to opt out of.
If your browser or extension sends a Global Privacy Control signal, we detect it and automatically treat it as a refusal of all optional storage - you do not need to do anything else. Residents of California and other US states with comprehensive privacy laws have rights to know, delete, correct and obtain a copy of their personal information; the in-app Export my data and Delete account controls fulfil these, and you can also contact eric@closedeck.co.uk. We will not discriminate against you for exercising any of these rights.
8. Security
Data is transmitted over encrypted connections and stored with access controls so that each user can only access their own records. No system is perfectly secure, but we take reasonable measures to protect your data.
9. Changes and contact
We may update this notice; the “last updated” date above will change. For any privacy question or request, contact CloseDeck Limited at eric@closedeck.co.uk.