Privacy Policy
How PM101 collects, uses and protects your personal data under UK GDPR.
Version 1.0. Last updated July 2026.
Who we are
PM101 is operated by [COMPANY NAME] (company number [COMPANY NUMBER]), registered at [REGISTERED ADDRESS]. We are the data controller for personal data processed through this site and app. Our ICO registration reference is [ICO REGISTRATION NUMBER].
Contact us about privacy at hello@pm101.co.uk.
What we collect
- Account: email, display name, optional avatar, role and industry preferences, workspace membership.
- Project content: anything you type or upload into a PPM project, including files (PDF, DOCX, XLSX, CSV, TXT, MD) and the text we extract from them.
- Usage: counters of prompt runs, video jobs and assistant chats per calendar month, so we can enforce free-tier limits.
- Search and assistant history: your last 50 site searches and the PM Assistant responses you have seen.
- Optional integrations: Telegram user id if you link the bot; connected Slack channels or Google Drive files if you attach them to an agent.
- Billing metadata: subscription state and the email you paid with. Card details never touch us; they are held by Stripe.
- Cookies: a session cookie for authentication and, only if you consent, a single Google Analytics 4 cookie.
Lawful bases and how we use it
- Contract: to give you the account, tools and paid features you signed up for.
- Legitimate interests: to keep the service secure and reliable, prevent abuse, and understand aggregate product usage.
- Consent: for the optional GA4 analytics cookie and for any marketing email you opt into.
- Legal obligation: to keep billing records for the periods UK tax and consumer law require.
Support staff can only read your project content when you explicitly grant access from Project → Settings → Support access. Every grant is time-limited, read-only, audit-logged and emailed to you. See the Security & Privacy overview for the mechanics.
Sub-processors
We use the following third parties to process customer data. We do not sell your data and we do not permit any provider to train third-party models on your private project content.
| Vendor | Purpose | Region |
|---|---|---|
| Lovable | Hosting, platform, edge runtime | EU / global CDN |
| Supabase (via Lovable Cloud) | Postgres database, authentication, storage, edge functions | EU |
| Stripe | Payments, subscriptions and billing | Global |
| Google (OAuth) | Federated sign-in | Global |
| Apple (Sign in with Apple) | Federated sign-in | Global |
| Lovable AI Gateway | LLM inference; routes to OpenAI, Anthropic and Google models depending on task | Provider-dependent |
| ElevenLabs | Voice generation for slideshow videos | US |
| Firecrawl | Web scraping for the news feed and user-supplied URLs | US |
| Telegram | Optional bot messaging (only if you link your Telegram account) | Global |
| Slack / Google Drive connectors | Only used if you connect them to an agent | Global |
| Transactional email (via Lovable) | Sign-up, password reset and unsubscribe emails | EU |
International transfers
Primary hosting is in the EU. Where a sub-processor is outside the UK or EEA (Stripe, ElevenLabs, Firecrawl, connectors, LLM providers), transfers rely on UK approved safeguards, primarily the Standard Contractual Clauses and the UK International Data Transfer Addendum.
Retention
Retention windows are enforced by a nightly automated purge job for operational data, and by user-triggered deletion for account and project data.
| Data | Retention |
|---|---|
| Account data (profile, roles, workspaces) | Life of the account |
| Project content, uploads and extracted text | Until you delete the project or the account |
| Billing records (subscriptions, invoices) | 7 years after the last transaction (UK statutory) |
| Search history, PM Assistant cache, video jobs | 30 to 90 days (rolling) |
| Usage counters and product analytics | 12 to 13 months |
| Email delivery logs and unsubscribe tokens | 30 to 90 days |
| Support and marketing lists (tier interest, coupon requests) | 24 months |
| Unsubscribe suppressions | Kept for the life of the app to honour your choice |
Your rights
- Access and portability: browse and export your content from your projects.
- Rectification: edit account and project data in-app at any time.
- Erasure: delete a project from Project → Settings → Danger zone, or delete your entire account from Profile → Danger zone. Deletion is immediate and cascades through storage and the database.
- Restriction and objection: email us and we will action within 30 days.
- Withdraw consent: use the cookie banner control, or the unsubscribe link in any non-essential email.
- Complain to the ICO: you have the right to complain to the UK Information Commissioner's Office at ico.org.uk. We would prefer the chance to fix things first.
Requests to hello@pm101.co.uk get a response within 30 days, as required by UK GDPR.
Cookies and analytics
We use strictly necessary cookies for sign-in and CSRF protection. One further cookie (Google Analytics 4) is only set if you accept it in the cookie banner. You can withdraw that consent at any time by clearing the banner choice or by declining on next visit.
Automated decision-making
We do not make decisions with legal or similarly significant effect using automated processing. AI features generate drafts you are always in control of reviewing, editing and using.
Children
PM101 is for people aged 16 and over. This is our chosen floor, stricter than the UK GDPR default of 13, because the service is aimed at working professionals. If you believe a child under 16 has created an account, tell us and we will delete it.
Changes to this policy
We will update the version number and "last updated" date whenever this policy changes. Material changes are announced by in-app notice or email before they take effect.
Contact
Any privacy question, DSAR or security report: hello@pm101.co.uk. We aim to acknowledge within two working days.
See also the Terms of Service and the Security & Privacy overview.