Privacy Policy
Privacy Policy
Last updated: 2 October 2026
1. Introduction
objector.ai Limited ("objector.ai", "we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our planning application analysis platform.
2. Information We Collect
Account Information
Username (required for account identification)
Email address (required for communications and account recovery)
First and last name (required for personalisation)
Phone number and country code (required for SMS-only authentication)
Account preferences and settings
Planning Documents
Planning application documents you upload
Document metadata and extracted text content
Analysis results and generated reports
Application references and location data
Security and Usage Data
IP address and browser information
Login attempts and authentication events
Security events and session data
Platform usage patterns and preferences
Error logs and system performance data
SMS verification codes (temporary storage)
SMS authentication and verification status
Planning Analysis Records
We store application records, uploaded documents, extracted text and generated outputs linked to your account. These records can contain site addresses and other personal information. The current platform does not automatically create a separate anonymous planning-intelligence dataset when an analysis is purchased.
3. How We Use Your Information
We use your information to:
Provide planning document analysis services
Generate objection letters and supporting materials
Maintain your account and provide customer support
Process one-off Toolkit payments and other separately purchased platform features
Send service-related communications
Improve our platform and develop new features
Comply with legal obligations
Enforce platform usage limits and prevent misuse
Use stored analysis and service information for platform improvement and quality monitoring
Use of the platform is subject to our Terms of Service, including Acceptable Use and Indemnity clauses.
4. Information Sharing
We do not sell, trade, or rent your personal information. We may share information only in the following circumstances:
Service Providers: Third parties supporting platform operations include OpenAI and xAI/Grok for AI processing; SendGrid for email; Stripe for payments; Neon/PostgreSQL for database storage; Twilio for SMS; and Google Analytics/Tag Manager, Microsoft Clarity and Meta Pixel for optional tracking. Uploaded files may also be sent to VirusTotal for malware scanning, which can involve disclosure of file contents to that security service. Gemini is not used for processing your documents.
SMS Authentication: Your phone number is shared with Twilio solely for sending verification codes. Twilio complies with GDPR and operates under strict data protection agreements.
Legal Requirements: When required by law or to protect our rights
Business Transfers: In connection with mergers or acquisitions
Consent: With your explicit permission
SMS Data Processing (GDPR Compliance)
Phone numbers are processed on the lawful basis of legitimate interest for authentication. Sign-in SMS verification codes are stored temporarily and expire after ten minutes. Expiry does not mean the database record is immediately deleted.
5. Data Security
We implement appropriate security measures to protect your information:
Encrypted data transmission (HTTPS/TLS)
Secure database storage with access controls
Regular security audits and updates
Limited employee access on a need-to-know basis
6. Your Rights
You have the right to:
Access your personal information
Correct inaccurate data
Request deletion of your account and data
Export your data
Withdraw consent for processing
Lodge complaints with data protection authorities
If you are a consumer, you may also have the right to cancel paid services within 14 days of purchase under the Consumer Contracts Regulations 2013. See our Terms of Service for details.
Application records and generated outputs are linked to user accounts and can contain personal data. They are covered by the rights described above; payment does not automatically create a separate anonymous intelligence record.
7. Data Retention
We retain your information as long as necessary to provide our services, comply with legal obligations, resolve disputes, and enforce our agreements.
Unpaid and free analyses, application records and uploaded documents: normally removed after seven days from application creation.
Paid analyses, application records, uploaded documents and Toolkit outputs: normally removed after six months from payment verification.
Separately saved report and letter copies: normally removed after six months from creation. Inactive accounts: normally removed after two years of inactivity.
You may request account deletion at any time through your account settings.
8. Cookie Policy
Last Updated: 2 October 2026
What Are Cookies?
Cookies are small text files placed on your device when you visit our website. They help ensure functionality, remember preferences, and provide usage insights.
How We Use Cookies
Objector.ai uses cookies to:
Ensure proper functioning and security
Authenticate users and maintain login sessions
Protect against threats and fraud
Remember cookie preferences
Collect usage statistics and interaction information (with your consent)
Types of Cookies We Use
1. Essential Cookies (Always Active)
These are required for core functionality and include:
Session Cookie
Maintains login session
Duration: 24 hours for the login session, extended while the session remains active.
Security: HttpOnly, Secure, SameSite: 'lax'
Stored in PostgreSQL
CSRF Protection Cookie
Prevents CSRF attacks
Duration: 1 week
Security: Secure, SameSite: 'lax'
2. Analytics Cookies (Optional)
When analytics consent is granted, the platform activates Google Analytics 4 and Microsoft Clarity for usage measurement and interaction/session-recording information. This can include pages visited, device and browser information, general location and on-site interactions. Such data is not necessarily anonymous.
3. Advertising Cookies (Optional)
The platform uses Meta Pixel for advertising-related measurement and Google consent settings for advertising storage and personalisation. The current implementation also activates Meta Pixel when analytics consent is granted, rather than requiring the separate advertising preference. The separate advertising control therefore does not currently prevent every advertising-related tracker from activating.
Local Storage
We use browser localStorage to remember your cookie preferences. Preference changes are also sent to our server to record consent.
cookieConsent: Stores your analytics and advertising preferences as a structured browser-storage value; older 'all' or 'essential' preferences are also recognised.
Managing Your Preferences
On first visit, choose "Accept All" or "Essential Only"
Click "More" to customise your choices
Change preferences at any time via the Cookie Settings link in the footer
Blocking essential cookies may impact functionality
9. Data Controller
Company: objector.ai Limited
Registration Number: 16505692
Registered Address: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
10. Contact Us
For privacy-related questions or requests:
Email: support@objector.ai
Postal Address: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
11. Policy Updates
We may update this Privacy Policy periodically. Updates will be posted on our website and take effect upon publication. Continued use of the platform constitutes acceptance of the updated policy. For legal terms including limitation of liability, indemnity, and force majeure, please refer to our Terms of Service.
objector.ai Limited — Registered in England and Wales (Company No. 16505692)
Registered address: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ