Effective Date: July 31, 2026
Strongwall, Inc., a Delaware corporation ("Strongwall," "we," "our," or "us"), operates the website, web application, mobile and desktop applications, and developer API ("Services") available under the brand Strongwall.ai.
Strongwall, Inc. is the data controller for the personal information described in this Policy, meaning we determine why and how it is processed. Our contact details are provided in Section 16.
1. Definitions
For purposes of this Policy:
- "Services" means the Strongwall.ai website, web application, mobile applications for iOS and Android, desktop applications, and developer API.
- "User," "you," or "your" means any person accessing or using the Services.
- "User Content" means any text, files, images, or other material that you input into or generate through the Services.
- "Processing" means any operation performed on data, such as transmission, temporary caching, or deletion.
- "Session" means a single instance of user interaction with the Services.
- "Local Storage" means storage on your device or in your browser used by the Services. How information is used, transmitted, and protected depends on the type of information, as described in this Policy.
2. Introduction and Scope
Strongwall was founded on the principle that your data belongs to you. We minimize the information we collect and retain. Your chat history is kept on your device. To generate an AI response, the content needed for your request is transmitted over encrypted connections and processed transiently in memory; it is not retained after ordinary AI processing. If you choose to submit conversation content for support review, we retain it as described in Section 5. We also retain account, usage, and payment records and encrypted attachments for the periods described in Section 10. Device sync and person-to-person messaging use end-to-end encryption, as described in Section 11.
3. Information We Collect
We collect the following information to provide, secure, support, and measure the Services:
- Account data: account identifiers, authentication credentials and verification data, email if you choose an email-and-password account, and payment confirmation status.
- Device data: basic device information, OS type/version, and limited access logs for abuse prevention.
- Messaging metadata: information needed to register your devices, route and deliver encrypted messages, and manage messaging groups.
- Payment data: information received from payment processors and app stores, including payment confirmations, customer and transaction references, subscription plans and status, billing dates, amounts, and refund records. We do not store your payment card details.
- Developer API credentials: a hash of each API key used to verify it, its display prefix and optional name, the associated account, and creation, last-use, expiry, and revocation dates where applicable. We do not store the full API key after issuing it.
- Developer API usage and billing: account-linked records of the model used, request times, input and output token counts, credit balances, and credit purchases, usage charges, refunds, and adjustments, including associated payment references. These usage and billing records do not contain your prompts or responses.
- Website analytics: visits to public pages, page addresses and query parameters, selected button clicks, and signup steps, recorded with random per-tab identifiers and campaign information. This browser-based measurement stops when you sign in; the account-linked records described below are collected separately.
- Service usage and account events: records linked to your account, including the AI model used, request and processing times, input and output token counts (measures of text length), tool-call counts, and events such as account creation, sign-in, subscription activity, and your first AI message. These usage records do not contain your prompts or responses.
- Campaign attribution: campaign tags, advertising click identifiers, promo codes, and the landing pages you first and most recently visited, obtained from links you follow and your visits to our site. This information is stored in your browser and sent with your signup to associate the campaign with your account. Section 9 and our Cookie Policy describe browser storage.
- Support reports: conversation content and report details you choose to submit, linked to your account, together with information such as the AI model involved. Section 5 explains how we use these reports and their retention period.
- Website enquiries: the message and any contact or organisation details you provide through our website forms. Submissions are stored in our database and emailed to the relevant team to handle your enquiry.
- Sign-up country: the country derived from your sign-up request's network address, recorded as a two-letter code in an account-linked signup event and used for aggregate reporting. The network address itself is not retained in that event.
Providing account information is not a statutory obligation. To create an email-and-password account, you must provide both an email address and a password; without them, we cannot create that type of account. You can instead choose an account-number account, which does not require an email address. To sign in, you must supply the credentials for your chosen account type; without them, we cannot authenticate you. To activate a paid subscription, we need confirmation of payment from your chosen payment provider. Submitting conversation content for support review is optional.
4. How We Use Information and Our Lawful Bases
We use personal information to provide and support the Services, prevent abuse, maintain performance, measure usage and marketing effectiveness, and meet our legal obligations. Where UK data protection law applies, we rely on the following lawful bases:
- Providing the Services — contract: we use your account and subscription information, and process the content you submit, where necessary to authenticate you, administer your subscription, deliver the features you request, and provide support under our agreement with you.
- Security and reliability — legitimate interests: we use device information, access logs, and service usage metadata where necessary to protect accounts, prevent abuse, diagnose faults, and maintain a reliable service.
- Checking reported errors — legitimate interests: after investigating a support report, we may retain it for the period described in Section 5 where necessary to check whether errors recur and improve service reliability.
- Service measurement — legitimate interests: we use service usage metadata, account events, and signup country information where necessary to understand adoption and performance and improve the Services. For website-improvement statistics, we rely on legitimate interests only where the browser storage and access qualify for an exception to consent requirements and the conditions of that exception are met.
- Marketing measurement and other non-exempt analytics — consent: where browser storage or access requires consent, including for advertising attribution, consent is the basis for the associated processing of personal information. Legitimate interests do not replace consent where it is required.
- Meeting legal duties — legal obligation: we process personal information where necessary to meet obligations under UK law or other law recognised for this purpose by UK data protection law, including responding to data protection rights requests and handling privacy complaints. Where necessary to establish, exercise, or defend legal claims, we rely on our legitimate interests in protecting our legal rights.
Where we rely on legitimate interests, we consider whether our use of the information is necessary and whether your interests, rights, and freedoms override those interests. Section 17 explains your right to object and how to withdraw consent where consent is the basis for processing. We do not engage in targeted advertising, profiling, or resale of data.
5. How We Do Not Use Information
Strongwall operates under an ephemeral-processing model for ordinary AI requests: we do not retain prompts after processing or store your chat history, except for content you choose to submit in a support report as described below. Stored attachments are encrypted as described in Section 10. We do not train AI models on user data or sell or share your data with third parties for their own purposes. Strongwall cannot recover chat history that exists only on your device.
If you choose to submit a conversation report for support, we receive and store the conversation content and report details you submit, linked to your account, so our support team can investigate the issue and check whether errors recur. We retain these reports only for as long as needed for those purposes, up to one year from submission, and then delete them. Your applicable data protection rights, including the right to request deletion in the circumstances described in Section 17, continue to apply.
6. Infrastructure Providers
We use cloud hosting and infrastructure providers to operate the Services. Where they process personal information on our behalf, they do so under data protection agreements. The content-processing limits in Sections 5, 10 and 11 apply to our use of this infrastructure. Section 14 explains our international transfer safeguards.
7. Authentication and Account Security
Users authenticate using Strongwall-issued account keys or usernames/passwords. Data is encrypted with AES-256 at rest and TLS 1.3 in transit. Pseudonymous and anonymous accounts are supported.
8. Data Breach Notification
If a personal data breach occurs, we will promptly investigate and take steps to contain it and reduce its effects. Where UK GDPR applies, we will notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of the breach, unless it is unlikely to result in a risk to individuals' rights and freedoms. Where a breach is likely to result in a high risk to affected individuals, we will also notify them without undue delay, subject to applicable legal exceptions. We will meet any other breach notification obligations that apply.
9. Cookies and Analytics
We set no cookies, on any part of the Services, and we load no third-party advertising or analytics scripts. We use self-hosted analytics to produce aggregate statistics about visits to the marketing site. This measurement uses no cookies and uses random per-tab identifiers to record visits and interactions, as described in Section 3. This browser-based measurement stops when you sign in. We separately collect account-linked service usage metadata and account events, including during signed-in use, as described in Section 3.
We use browser storage to maintain your sign-in session, remember your settings, and keep your chat history on your device. These functions are separate from the marketing measurement described below.
We also store campaign attribution information, including campaign tags and advertising click identifiers, in your browser for up to 30 days to measure which campaigns lead to signups and subscriptions. Section 3 describes how attribution information is associated with your account.
Clearing site data removes the information stored in your browser, including your locally stored chat history, but does not delete information already sent to us. Our Cookie Policy lists the browser storage items and explains how to inspect them.
10. Data Retention and Deletion
Retention depends on the type of information:
- Account and service metadata: we retain account profiles and events, device registrations, messaging group membership, daily and monthly usage totals, and developer API credentials and request-usage records until account deletion. The shorter periods for detailed AI request usage and message delivery records are described below.
- Invoices and payment transaction records: we retain these records for tax and accounting purposes for seven years after the filing date or due date of the relevant tax return, whichever is later, including after account deletion. We retain records longer where required by applicable law or where necessary for unresolved tax proceedings, and delete them when that additional need ends. They are separate from the account event records described above.
- Detailed AI request usage records: records become eligible for automatic deletion 48 hours after the request begins. Cleanup runs as new requests are recorded, so deletion may occur later than 48 hours. This period does not apply to developer API request-usage records.
- Developer API financial records: records of credit purchases, usage charges, refunds, and adjustments follow the seven-year tax and accounting retention schedule described above, including its exceptions and retention after account deletion.
- Encrypted AI attachments: we retain images and documents uploaded for use in AI conversations until you delete your account, at which point we delete the stored attachments.
- Device-sync data: temporary encrypted copies are deleted when both devices confirm that sync is complete. Sessions older than five minutes are cleared when a new sync session starts, so incomplete sessions may remain longer during periods of inactivity.
- Encrypted message delivery: queued messages are deleted when the receiving device acknowledges receipt. Unacknowledged messages expire 30 days after being queued and are no longer available for delivery. Temporary signals, such as typing indicators and receipts, expire after 60 seconds. Expired records are removed by cleanup scheduled to run hourly; deletion may take longer if cleanup is delayed.
- Person-to-person messaging attachments: encrypted attachments expire 30 days after upload is initiated. Cleanup is scheduled hourly to delete expired attachments and their server records. Deletion may take longer if cleanup is delayed or storage is unavailable; failed deletions are retried.
- Support reports: we retain reports only as long as needed to investigate issues and check whether errors recur, up to one year from submission, and then delete them, as described in Section 5.
- Website enquiries: both the database records and resulting emails are retained indefinitely.
- Backups: after information is deleted from our active systems, copies may remain in backups for up to seven days.
Strongwall cannot recover chat history that exists only on your device. Attachments are stored encrypted. AI attachments are decrypted temporarily to process your requests. Person-to-person messaging attachments remain end-to-end encrypted and cannot be read by Strongwall.
11. AI Data Processing
Ordinary AI processing is ephemeral: your prompt is processed transiently in memory to generate a response and is not retained after that processing. If you choose to submit conversation content in a support report, we retain that report as described in Section 5. Stored attachments are handled as described in Section 10. Your content, including content submitted in support reports, is never used to train models. AI inference necessarily requires your prompt to be readable, briefly, by the systems generating the response; it is protected by ephemeral processing and no-retention terms. End-to-end encryption — where not even Strongwall can read content — protects device sync and person-to-person messaging.
12. Security
Strongwall employs encryption (AES-256/TLS 1.3), firewalls, and strict access controls. No system is completely secure.
13. Legal Requests and Warrant Canary
Strongwall cannot disclose data it does not store. Where required by law, Strongwall may disclose information retained under this Policy to courts, regulators, or law enforcement authorities, limited to what is necessary to meet the legal requirement. Strongwall maintains a Warrant Canary program and publishes regular confirmations that no secret data requests have been received.
14. International Use
Strongwall is based in the United States. All server-side processing of personal information takes place in the United States. Information stored locally on your device remains on that device unless you use a feature that transmits it, as described in this Policy.
For transfers to our service providers that require safeguards under UK data protection law, we rely on the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, incorporated into our agreements with those providers. You can contact us at legal@strongwall.ai for information about these safeguards or to request a copy.
15. Updates
We may update this Policy to reflect changes in our Services or how we process personal information. We will publish the revised Policy with an updated effective date and notify you of material changes through the Services or other appropriate means before those changes take effect. Where a change requires your consent, we will ask for it separately before beginning that processing.
16. Contact Information and Privacy Complaints
To ask a privacy question, exercise your data protection rights, or make a complaint about how we handle your personal information, contact us using either of the following:
- Email: legal@strongwall.ai
- Mail: Strongwall, Inc., c/o A Registered Agent, Inc., 8 The Green, Suite A, Dover, Delaware 19901 USA
We will acknowledge your privacy complaint within 30 days of receiving it, investigate it without undue delay, keep you informed of our progress, and communicate the outcome without undue delay. This complaint acknowledgement period is separate from the deadline for responding to a data protection rights request.
If UK data protection law applies to your personal information, you also have the right to complain to the Information Commissioner's Office (ICO), the UK data protection regulator. Information about raising a complaint is available at ico.org.uk/make-a-complaint.
17. Your UK Data Protection Rights
If UK data protection law applies to your personal information, you have the following rights, subject to the conditions and exceptions provided by law:
- Access: ask whether we process your personal information and receive a copy of it, together with information about our processing.
- Correction: ask us to correct inaccurate personal information or complete information that is incomplete.
- Deletion: ask us to delete your personal information in circumstances where the law requires us to do so.
- Restriction: ask us to limit our use of your personal information in certain circumstances, such as while we check its accuracy.
- Portability: receive personal information you have provided to us in a structured, commonly used, machine-readable format where we process it by automated means on the basis of consent or a contract. You may also ask us to transmit it to another controller where technically feasible.
- Objection: object, for reasons relating to your particular situation, to processing based on legitimate interests. We must stop that processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or need the information for legal claims. You can object to processing for direct marketing at any time.
- Withdrawal of consent: where we rely on your consent, withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
To exercise these rights, use the contact details in Section 16. We normally respond free of charge and without undue delay, within one month. We may request information reasonably necessary to verify your identity. Where the law permits, we may extend the response period by up to two further months because of the complexity or number of your requests; we will notify you of the extension and our reasons within the initial one-month period. Any adjustment to the deadline for identity verification or necessary clarification will be made only as permitted by law.
If we cannot fulfil all or part of your request, we will explain why and tell you how to complain to the ICO or seek a judicial remedy.
18. Automated Decisions
We do not currently make decisions about you based solely on automated processing that have legal or similarly significant effects. If we introduce such decisions, we will update this Policy and provide the required information about their purposes, how they work, and their likely effects before the processing begins. Where UK data protection law applies, we will provide the required safeguards, including a way to make representations, request human review, and challenge a decision.
19. Age Requirements
The Services are intended for people aged 18 or older, as required by our Terms of Service. If you believe someone under 18 has created an account, please contact us using the details in Section 16 so we can investigate.