consensor Privacy Policy
Effective: [DATE OF LAUNCH] · Version: 1.0 (draft)
Who we are: consensor is operated by Bluelabs Pty Ltd (ACN 701 379 964), an Australian company ("consensor", "we", "us").
Contact: privacy@consensor.io · [REGISTERED ADDRESS, AUSTRALIA]
EU/UK representative: [TO BE APPOINTED BEFORE SERVING EU/UK USERS]
The short version
- We keep as little as possible: your email, your subscription status, and the numbers behind your receipts.
- We don't keep your code or prompts. A job's full output is stored encrypted, only you can open it, and it deletes itself after 7 days.
- The AI models that do your jobs are run by providers who have agreed not to train on your data and not to keep it.
- No ads, no tracking, no selling or sharing your data. Ever.
- You can see, export or delete everything we hold, in one click.
Everything below is the detail behind those five lines.
1. What this policy covers
This policy covers the consensor website (consensor.io), the consensor connector you add to Claude or other AI tools, and the optional consensor add-on for Claude Code. It applies to everyone who uses consensor, wherever they are.
We write to the strictest privacy standard we're subject to, the EU General Data Protection Regulation (GDPR), and apply it to everyone. The policy also meets the UK GDPR, the Australian Privacy Act 1988 (Australian Privacy Principles), the California Consumer Privacy Act as amended (CCPA/CPRA), and Canada's PIPEDA.
2. What we collect, why, and on what legal basis
| What | Why we need it | Legal basis (GDPR) | How long we keep it |
|---|---|---|---|
| Email address and sign-in details (from Google or an email link) | To create your account and let you sign in | Contract | Until you delete your account |
| Subscription status (active or not, plan, renewal date) | To know whether your jobs should run | Contract | Until you delete your account, plus any period the law requires for financial records |
| Job records: time, model used, token counts, cost, and the receipt figures | To run your allowance, show your receipts and monthly totals, and stop abuse | Contract; legitimate interest (preventing abuse) | Until you delete your account |
| Job content: the code, text or files you hand to consensor | To do the job | Contract | Not stored after the job finishes, except the output below |
| Job output | So you can open the full result later | Contract | Encrypted, private to you, deleted automatically after 7 days (or sooner if you delete it) |
| Timing data (only if you turn it on): usage percentages and token counts from the Claude Code add-on | To measure the extra time consensor gives you, "at your pace" | Consent, which you can withdraw at any time | Stored under a random ID, not your email. Deleted when you turn it off or delete your account |
| Support emails | To answer you | Legitimate interest | 2 years after the conversation ends |
| Security logs (IP address, request time, error codes) | To keep the service secure and working | Legitimate interest | 30 days |
We never collect: your payment card details (Stripe handles them; see §4), precise location, contacts, or anything from your device beyond what the add-on above describes, and only if you turn it on.
We never infer your age, health, emotions, beliefs or anything else sensitive from what you send.
3. What happens to the work you send
When you hand a job to consensor:
- It passes through HOURGLASS, our deterministic security gate, which checks it before and after the AI model. HOURGLASS records only a fingerprint (hash) of each request and its verdict code, never the content.
- The job goes to an AI model provider through OpenRouter. We only route to providers that have committed not to train on your data and not to retain it after the response. The providers we use, and the countries they operate from, are listed at consensor.io/providers.
- The result comes back to you. The full output is encrypted and stored for 7 days so you can open it, then deleted.
We don't read your jobs. Our staff can't open your stored outputs without your explicit permission for a support request.
4. Who we share data with (sub-processors)
We share data only with the services needed to run consensor, and only what each one needs. We don't sell data, share it for advertising, or let anyone use it to train AI.
| Service | What it does for us | Data it handles | Location |
|---|---|---|---|
| Cloudflare, Inc. | Hosting, security, storage, database | All service data (encrypted at rest) | Global network; US company |
| Stripe, Inc. / Stripe Payments Australia | Payments and subscriptions | Your name, email, payment card, billing address (we never see your card) | US / Australia / Ireland |
| OpenRouter, Inc. | Routes jobs to AI model providers | Job content, in transit only | US |
| AI model providers (listed at consensor.io/providers) | Run the models that do your jobs | Job content, in transit only; no training, no retention | As listed |
| Google (Google Workspace) | Our email, for support | Your emails to us | US / global |
We'll update this list before adding a new sub-processor, and email active users about material changes.
We may disclose data if the law requires it (for example, a valid court order). Where we're allowed to, we'll tell you first.
5. International transfers
consensor is run from Australia and uses providers in other countries, mainly the United States. When personal data leaves the EU, UK or another region with transfer rules, we protect it with Standard Contractual Clauses (or the UK equivalent), and rely on the EU–US Data Privacy Framework where a provider participates in it. Copies of the safeguards we rely on are available on request.
6. Your rights
Wherever you live, you can:
- See what we hold about you (Account → My data).
- Export it in a machine-readable format.
- Correct anything that's wrong.
- Delete your account and all your data in one click (Account → Delete). Everything is erased from live systems within 7 days, and from backups within 30.
- Withdraw consent for the timing data at any time, with no effect on anything else.
- Object to processing based on legitimate interest.
- Complain to a privacy regulator: in Australia, the OAIC (oaic.gov.au); in the EU, your local data protection authority; in the UK, the ICO; in California, the CPPA.
We don't charge for any of this, and we respond within 30 days (usually much sooner). California residents: we don't sell or share personal information as those terms are defined under the CCPA/CPRA, and we don't use sensitive personal information to infer characteristics about you.
7. Cookies
We use only the cookies needed to keep you signed in and keep the service secure. No advertising, tracking or third-party analytics cookies. We measure site traffic with Cloudflare Web Analytics, which doesn't use cookies or track you across sites. That's why there's no cookie banner.
8. Security
- Encryption in transit (TLS 1.2+) and at rest.
- Each person's stored outputs are isolated; one user can't reach another's data, and this is tested before every release.
- Access to production systems is limited, protected by two-factor authentication, and logged.
- Every privacy commitment in this policy has an automated test that must pass before a release goes out.
No system is perfectly secure. If a breach affects your data, we'll tell you and the relevant regulators as the law requires (within 72 hours under GDPR where it applies).
9. Children
consensor is for people 18 and over. We don't knowingly collect data from anyone younger. If you believe a child has signed up, contact privacy@consensor.io and we'll delete the account.
10. Automated decisions
consensor doesn't make decisions about you that have legal or similarly significant effects. HOURGLASS decides automatically whether a job may run. If it refuses one, you can ask us why at privacy@consensor.io.
11. Changes to this policy
If we change this policy in a way that matters, we'll email active users at least 14 days before it takes effect and show the change on this page. Earlier versions are kept at consensor.io/privacy/history.
12. Contact
Privacy questions or requests: privacy@consensor.io
Post: Bluelabs Pty Ltd, [REGISTERED ADDRESS, AUSTRALIA]
EU/UK representative: [NAME AND ADDRESS, ONCE APPOINTED]
consensor · built by Bluelabs Pty Ltd · protected by HOURGLASS