Legal
Privacy Policy
Last updated: June 2026. Data controller: James A. Lang, trading as Velinor — james@velinor.io.
1. What we collect
- Email address and name — collected when you create an account via Clerk. Email is required; name is optional.
- Scorecard inputs — the description of your AI use case that you submit to the "Test Your Use Case" tool. This is sent to the Anthropic API to generate your scorecard and is not stored after the response is returned.
- Case study submissions — the URL and optional note you provide when submitting a case to our database. Stored alongside your email for editorial review.
- Session data — Clerk stores a session token in a secure HTTP-only cookie to keep you signed in.
- Analytics — only collected with your explicit consent (see Section 7). If you decline, no analytics are loaded.
2. How we use your data
- Email — to authenticate you, send account-related messages, and attribute case submissions.
- Scorecard inputs — to generate your EU AI Act risk classification and AIBlindspot scorecard via Claude (Anthropic). Inputs are discarded after the response.
- Case submissions — to review, classify, and publish AI failure cases to the public database, credited to your submission.
- Analytics (consented only) — to understand how the scoring tool is used and improve the product.
3. Legal basis (UK GDPR)
- Authentication data — performance of a contract. You cannot use registered features without an account.
- Scorecard inputs — legitimate interests. Processing is in-memory only and immediately discarded.
- Analytics — explicit consent. You choose at the cookie banner.
4. Third parties
Clerk (clerk.com) — authentication and session management. They store your email and session tokens on our behalf. Privacy policy: clerk.com/legal/privacy.
Anthropic (anthropic.com) — AI processing of scorecard inputs. Under our usage terms, inputs are not used for model training. Privacy policy: anthropic.com/legal/privacy.
Netlify (netlify.com) — hosting and CDN. Netlify processes request metadata (IP, user agent) for security and performance.
Supabase (supabase.com) — database. Stores case study data, submissions, and the risk index. Hosted in the EU.
5. Your rights (UK GDPR)
You have the right to access, correct, delete, restrict processing of, and receive a portable copy of your personal data. To exercise any of these rights, email james@velinor.io. We will respond within 30 days. If you are unhappy with our response, you can complain to the ICO at ico.org.uk.
6. Data retention
- Account data (email, name) — held until you delete your account via Clerk.
- Case submissions — held indefinitely; approved submissions become part of the public database.
- Scorecard inputs — not stored. Processed in-memory and discarded immediately after the response.
- Rate-limit cookies — expire after 48 hours.
- Analytics events — 90 days.
7. Cookies
We use two categories of cookies:
- Strictly necessary — Clerk session token. Required for authentication. Cannot be declined.
- Analytics — loaded only if you click "Accept" on the cookie banner. Used to understand platform usage. You can change your preference at any time by clearing your browser's localStorage for this site.
8. International transfers
Clerk and Anthropic are US-based. Data transfers to these providers are covered by standard contractual clauses (SCCs) under the UK GDPR adequacy framework.
9. Contact
For any privacy questions or to exercise your rights: james@velinor.io
Velinor, United Kingdom
These pages are also subject to our Terms of Service.