Privacy Policy
Last updated: 2 April 2026
Aldous is operated by The Product Bridge Ltd ("we", "us", "our"). This privacy policy explains how we collect, use, store, and protect your personal data when you use our website at askaldous.com and the Aldous application, including the web dashboard, WhatsApp integration, Chrome extension, and voice features (together, the "Service").
We believe privacy policies should be readable. We've kept the legalese to a minimum while making sure you know exactly what happens with your data.
1. Data controller
The Product Bridge Ltd is the data controller for personal data processed through the Service. If you have questions about how your data is handled, contact us at hello@theproductbridge.com.
2. What data we collect
We collect only what is necessary to provide the Service:
Account information
- • Name, email address, and profile picture from your Google account when you sign in via Google OAuth.
- • Email address if you sign in via magic link.
Data you provide
- • Contacts and companies — names, roles, notes, and relationship information you add or import.
- • Opportunities and actions — deals, tasks, and follow-ups you create or that the AI suggests and you approve.
- • Chat messages — conversations you have with Aldous via the web dashboard or WhatsApp.
- • Voice conversations — if you use the voice feature, your conversation is processed by our voice provider (ElevenLabs) in real time. We do not store audio recordings. Data you share during voice chats (contacts, notes, tasks) is saved to your account.
- • Profile and preferences — your business context, notification preferences, and onboarding information.
Data from connected services
- • Gmail — if you connect your Gmail, we access email metadata (sender, recipient, date, subject) to build relationship context. We also create draft emails in your account on your behalf. We do not read email body content. Drafts are always placed in your drafts folder for your review before sending.
- • WhatsApp — we process messages you send to and receive from the Aldous bot number. We do not access your private WhatsApp conversations.
- • Chrome extension — if you install the Chrome extension, it sends page data you explicitly capture (e.g. LinkedIn profiles, company pages) to your Aldous account. The extension does not track your browsing history.
Automatically collected data
- • Session cookies for authentication (see section 8).
- • Error reports and performance data via Sentry, which may include your IP address and browser information.
3. How we use your data
We use your data to:
- • Provide and improve the Service — powering AI-assisted relationship management, generating nudges and follow-up suggestions, and preparing you for meetings.
- • Authenticate your identity and maintain session security.
- • Send you notifications you have opted into (e.g. daily briefings, weekly kickoffs, nudges via WhatsApp or email).
- • Monitor and fix errors in the Service.
We do not use your data for advertising, profiling for third parties, or any purpose unrelated to providing the Service.
4. Legal basis for processing (GDPR)
- • Contract — processing your account data and the data you provide is necessary to deliver the Service you signed up for.
- • Consent — connecting Gmail, WhatsApp, or the Chrome extension is optional and requires your explicit action. You can disconnect at any time.
- • Legitimate interest — error monitoring and service improvement, balanced against your privacy rights.
5. Third-party services
We share data with the following third-party processors, solely to operate the Service:
| Provider | Purpose | Data shared |
|---|---|---|
| Anthropic (Claude) | AI agent processing | Your messages, contact data, and relationship context needed to generate responses |
| ElevenLabs | Voice conversations | Audio input/output during voice sessions (not stored) |
| OAuth authentication, Gmail integration | OAuth tokens, email metadata (if Gmail is connected) | |
| Meta (WhatsApp) | WhatsApp messaging | Messages to/from the Aldous bot number |
| Render | Infrastructure hosting | All Service data (hosted on their servers) |
| Sentry | Error monitoring | Error reports, IP address, browser info |
We do not sell, rent, or trade your data to any third party. We do not share data with advertisers.
6. AI and your data
Aldous uses AI (Anthropic's Claude) to power its relationship intelligence features. When you interact with the Service, relevant context from your account — including contacts, notes, and conversation history — is sent to the AI to generate responses.
- • Your data is never used to train AI models. Anthropic's API terms prohibit training on customer data.
- • Each user's data is completely isolated. The AI only sees data from your account, never data from other users.
- • Aldous will never send a message on your behalf without your explicit review. Email drafts go to your drafts folder. WhatsApp messages come from the Aldous bot, not your personal number.
7. Data security
We take the security of your data seriously:
- • Encryption in transit — all connections use TLS/HTTPS.
- • Encryption at rest — your database is encrypted. Sensitive credentials (e.g. Gmail OAuth tokens) are additionally encrypted with Fernet symmetric encryption.
- • Tenant isolation — every database query is scoped to your user ID. There is no mechanism for one user's data to be visible to another.
- • Session security — sessions are signed and validated on every request. API keys for the Chrome extension are hashed before storage.
8. Cookies
We use a single, essential cookie (aldous_session) to keep you signed in. It is a first-party, HTTP-only, secure cookie. We do not use advertising cookies, tracking pixels, or third-party analytics cookies.
9. Data retention
We retain your data for as long as your account is active. If you delete your account, all associated data — contacts, conversations, notes, actions, connected service tokens — is permanently deleted. We do not retain data after account deletion.
10. Your rights
Under GDPR and applicable data protection laws, you have the right to:
- • Access — request a copy of all data we hold about you.
- • Rectification — correct inaccurate data in your account.
- • Erasure — delete your account and all associated data.
- • Portability — export your data in a machine-readable format.
- • Withdraw consent — disconnect any integrated service (Gmail, WhatsApp, Chrome extension) at any time.
- • Lodge a complaint — you may contact the UK Information Commissioner's Office (ICO) at ico.org.uk if you believe your data rights have been violated.
To exercise any of these rights, email hello@theproductbridge.com. We will respond within 30 days.
11. International data transfers
Some of our third-party processors (Anthropic, ElevenLabs, Render, Sentry) are based in the United States. Where data is transferred outside the UK/EEA, we rely on appropriate safeguards including standard contractual clauses and the processors' own data protection commitments.
12. Children's privacy
Aldous is designed for business professionals. We do not knowingly collect data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
13. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you via email or an in-app notice. The "last updated" date at the top of this page reflects the most recent revision.
Contact
For any privacy-related questions or requests:
The Product Bridge Ltd
Email: hello@theproductbridge.com