Privacy Policy
Last updated: 3 July 2026
Custom Artificial Intelligence Solutions (Pty) Ltd ("we", "us"), which operates AI Consensus and trades as "Custom AI Solutions", is committed to protecting your personal information in line with South Africa's Protection of Personal Information Act 4 of 2013 (POPIA). This policy explains what we collect, why, how we use and share it, how long we keep it, and your rights.
1. Who we are
AI Consensus is operated by Custom Artificial Intelligence Solutions (Pty) Ltd (trading as "Custom AI Solutions").
- Company registration number: 2016/377651/07
- Support email: support@ai-consensus.ai
- Physical address: available on request via support@ai-consensus.ai
2. Information Officer
- Name and title: Steven Glyn Johnstone, Managing Director
- Email: stevenjohnstone@me.com
- Registration with the Information Regulator: registered (reference 2026-061119)
You may contact the Information Officer to exercise your rights or ask any question about this policy.
3. What we collect
- Account data: your email address and authentication details (passwords stored as a one-way hash).
- Your content: the prompts, attachments (PDF, image, Word, text), conversations and results in your runs.
- Provider API keys (Unlimited plan): stored encrypted at rest; shown only as "set" and never displayed, returned, or logged again after saving.
- Billing data: handled by Paystack. We receive only a transaction reference, the last four digits of your card, and the amount — never the full card number.
- Usage logs: basic technical records (run status, timing, token/cost data, error codes) needed to run, support, and secure the service.
- Communications: if you contact support, your email and the content of your request.
4. Our POPIA role
- For account, billing, usage data, and the content of individual users, we determine the purpose and means of processing and are the Responsible Party.
- If you are a business and you include personal information about other people (e.g. employees or clients) in your prompts, you are the Responsible Party for that embedded information and we act as your Operator. You warrant that you have the authority and lawful basis to submit it and for us to process it as directed by your use of the service. Business customers may request a separate Operator/data-processing addendum.
5. How your content is processed — cross-border transfer
To produce your result, your prompt, attachments, and generated output are sent to:
- Anthropic (Claude) — United States
- OpenAI (ChatGPT) — United States
- Google (Gemini) — United States
We use these providers on their paid, commercial API tiers. On those tiers, the providers state that your content is not used to train their models: Anthropic does not train its models on API inputs or outputs; OpenAI does not use API-submitted data to train its models and retains it only briefly for abuse-monitoring before deletion; and Google does not use paid Gemini API data to train its models. That processing is carried out under each provider's standard API data-processing terms. We do not use your content to train any model, and we do not sell your personal information.
Lawful basis for transfer: This transfer is necessary for the performance of our contract with you (POPIA s.72) — the service cannot function without it. You also give explicit consent at checkout as an additional basis. The United States has not been found by the Information Regulator to offer protection equivalent to POPIA. We contractually require providers to apply appropriate security, but we cannot guarantee that recipient-country law is identical to POPIA.
Provider log retention: Even on no-training tiers, providers may retain API logs for security, abuse-monitoring, debugging, or legal compliance under their own policies. We do not control that retention. Please review the privacy policies of Anthropic, OpenAI, and Google.
Bring-your-own-key (Unlimited plan): If you connect your own provider API keys, prompts sent using those keys are also processed under your own provider accounts and settings. Provider retention, no-training options, billing, and account status for your own keys are governed by your agreement with each provider and are outside our control.
6. Why we use your information and lawful bases
We process your data to create and manage your account; authenticate and secure it; generate and deliver results; process payments and prevent fraud; provide support; debug and improve the service; and comply with law and respond to lawful requests. Our lawful bases are contractual necessity, consent, legitimate interest (running a secure commercial service), and legal obligation.
7. Who we share information with
We may share information with the three AI providers above; Paystack (payments); our hosting and infrastructure providers — Vercel Inc. (application hosting, United States) and Supabase (database and file storage, hosted in the United States, AWS region us-east-1 / N. Virginia); email, logging, and security providers used to run the service; professional advisers bound by confidentiality; and regulators, courts, or law enforcement where required by law or valid legal process. We do not sell personal information.
8. Retention and deletion
We keep your content and account data while your account is active. You can delete individual conversations at any time. If you ask us to delete your account, we remove your personal data within 30 days, except records we must keep by law (e.g. payment records for tax). To request deletion, email support@ai-consensus.ai.
9. Special and children's information
You must not submit "special personal information" (health, biometric data, race or ethnic origin, religious or philosophical beliefs, political persuasion, trade-union membership, sex life, or criminal behaviour) or the personal information of anyone under 18 unless you are legally authorised and the processing is lawful. We do not knowingly process such data for our own purposes and may remove it or suspend the account if submitted unlawfully.
10. Security and data breaches
We use reasonable, appropriate measures — encryption in transit and at rest, restricted access, and provider API keys encrypted with a key held outside the application database. No system is perfectly secure. If a security breach affects your personal information, we will notify the Information Regulator and affected users as required by POPIA.
11. Cookies
We use only essential session cookies to sign you in and keep your session. We do not use advertising or third-party tracking cookies. If this changes we will update this policy and seek consent where required.
12. Your POPIA rights
You may ask whether we hold your information; request access, correction, or deletion; object to processing; and withdraw consent where processing is based on consent. You may complain to the Information Regulator of South Africa — website: https://inforegulator.org.za/, email: complaints.IR@justice.gov.za. To exercise a right, contact our Information Officer. We respond within a reasonable time and within 30 days.
13. Supplemental notice for EEA & UK residents
We do not currently offer our services to, or monitor the behaviour of, individuals in the European Economic Area or the United Kingdom, so the EU/UK GDPR does not currently apply. If that changes, this section will be activated and an EU/UK representative appointed where required. Where the EU GDPR or UK GDPR does apply, our legal bases are performance of a contract, legitimate interests, consent, and legal obligation; international transfers to the US providers rely on contractual necessity, consent, and, where available, Standard Contractual Clauses in the providers' data terms; and you additionally have rights to data portability, restriction of processing, and complaint to your local supervisory authority.
14. Changes
We may update this policy. Material changes will be posted here with a new effective date.
Privacy Policy · Terms of Service · Refund & Cancellation Policy