Privacy
Privacy policy
Last updated 29 April 2026.
Who we are
The Shoothill AI Trust Index (the “Service”) is operated by Shoothill Ltd, a company registered in England and Wales with company number 5885234. Shoothill Ltd is the data controller for personal data processed through the Service. You can reach us at webenquiry@shoothill.com.
What we collect
- Account data — first name, last name, email address, hashed password, and the email verification status. Created when you sign up.
- Marketing opt-in — a single boolean recorded at sign-up indicating whether you agreed to receive product news from Shoothill. You can change it at any time by emailing us.
- Usage data — sign-in timestamps, feature interactions (which models you watch, alert rules you create, digests you have received), and basic request metadata such as IP address and user agent.
- Contact and request submissions — the contents of the contact form and the request-a-model form, plus the submitter’s IP address and user agent for spam protection.
- Comparison prompts — if you use the Compare Models feature, the prompts you submit and the responses returned by the AI providers are stored against your account so you can review past runs.
Why we process it
- To provide the Service — authenticating you, running the benchmarks you ask for, sending the alerts and digests you have subscribed to. Legal basis: performance of a contract.
- To keep the Service safe — rate-limiting, abuse detection, debugging operational issues. Legal basis: legitimate interest in operating a secure platform.
- To send product news — only if you opted in at sign-up. Legal basis: consent.
- To respond to enquiries — when you submit the contact form. Legal basis: legitimate interest in answering business enquiries.
Who we share it with
We do not sell personal data. We share it with a small set of processors who power the Service:
- Cloudflare, Inc. — hosting, edge compute, and the database that backs the Service.
- Twilio SendGrid — transactional email delivery (verification, password reset, alerts, digests).
- AI providers (OpenAI, Anthropic, Google, xAI) — only when you use the Compare Models feature; the prompt you submit is sent to the providers you select. Public benchmark runs use a fixed test catalogue and do not include your data.
Some of these providers process data outside the UK or EEA. Where they do, transfers are protected by the UK’s International Data Transfer Addendum or Standard Contractual Clauses.
How long we keep it
Account data is kept for as long as your account is active, and for up to 12 months after deletion to resolve any disputes or audit issues. Usage logs are kept for 30 days. Contact and request submissions are kept for 24 months so we can refer back to a conversation. Comparison prompts and responses are kept for the lifetime of your account or until you delete them, whichever is sooner.
Your rights
Under UK GDPR you have the right to access the personal data we hold about you, ask us to correct it, ask us to delete it, ask us to restrict or stop processing it, and to receive a copy in a portable format. You can also withdraw your consent to marketing email at any time. Email webenquiry@shoothill.com and we will respond within one month. If you are not happy with our response you can complain to the Information Commissioner’s Office at ico.org.uk.
Cookies
We use a small number of strictly necessary cookies to keep you signed in and to remember your light/dark theme choice. We do not run third-party analytics or advertising cookies on the Service.
Changes to this policy
We may update this policy from time to time. The “last updated” date at the top of this page will reflect the most recent change. Material changes will be communicated by email to active account holders.