Privacy Policy

Last updated: April 2026

Who we are

SendPI is a communication intelligence tool that helps users understand how their messages will land before they send them. We are operated as a pilot program currently available to selected users in the United States.

What we collect

  • Account Information: name, email address when you create an account.
  • Usage Data: which features you use, how often, and the results (tone preferences, acceptance rates).
  • Anonymous Behavioral Metadata: communication patterns such as times of day you write most and relationship contexts.
  • Technical Data: IP address, browser type, device type, and session cookies necessary for authentication.
  • Consent Records: IP address, user agent, and electronic signature when you sign the pilot agreement.

What we do NOT collect

SendPI never collects or stores the actual content of your messages. When you type a message and SendPI analyzes it, that analysis happens through our AI service which does not retain your message text. The text of your messages is processed transiently and never stored in our database. This is a core design principle of SendPI, not just a policy.

Legal basis for processing (GDPR)

  • Consent: You explicitly consent to data processing through our Pilot Participation Agreement.
  • Contractual necessity: Processing required to provide the SendPI service you signed up for.
  • Legitimate interest: Product improvement, security, and abuse prevention.

How we use your data

  • Provide and personalize the SendPI service
  • Generate your communication progress insights
  • Improve the product based on aggregate usage patterns
  • Send product updates and feedback requests as part of the pilot
  • Generate your weekly PI Insights report
  • Ensure security and prevent abuse

Who we share data with

We do not sell, rent, or trade your personal data. We share data only with:

  • Cloud infrastructure providers (hosting, database) — minimum data required
  • AI service providers (for PI analysis) — message text processed transiently, not stored
  • Law enforcement — only when legally required

Your rights under GDPR (EU/EEA residents)

If you are located in the EU/EEA, you have the following rights under the General Data Protection Regulation:

  • Right of Access (Art. 15): Request a copy of all personal data we hold about you.
  • Right to Rectification (Art. 16): Correct inaccurate personal data.
  • Right to Erasure (Art. 17): Delete your account and all associated data at any time via Settings.
  • Right to Restrict Processing (Art. 18): Request we limit how we use your data.
  • Right to Data Portability (Art. 20): Download all your data in machine-readable JSON format from Settings.
  • Right to Object (Art. 21): Object to processing based on legitimate interest.
  • Right to Withdraw Consent: Withdraw consent at any time by deleting your account.

To exercise any of these rights, use the self-service options in your dashboard Settings, or email support@sendpi.ai. We will respond within 30 days.

Your rights under CCPA (California residents)

If you are a California resident, you have the following rights under the California Consumer Privacy Act:

  • Right to Know: Request details about the personal information we collect, use, and share.
  • Right to Delete: Request deletion of your personal information.
  • Right to Opt-Out of Sale: We do not sell your personal information. See our Do Not Sell page.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

To exercise these rights, email support@sendpi.ai or use account Settings. We verify your identity before processing requests.

Cookies

SendPI uses only strictly necessary cookies for authentication:

  • access_token — HTTP-only, Secure, session authentication (7 days)
  • refresh_token — HTTP-only, Secure, session refresh (30 days)

We do not use advertising, tracking, or analytics cookies. These cookies are essential for the service to function and cannot be disabled.

Data retention

We keep your data for as long as your account is active. When you delete your account, all your data is permanently and immediately deleted from all our systems. We do not retain deleted data.

Data transfers

Your data is processed and stored in the United States. If you are outside the US, by using SendPI you consent to this transfer. We implement appropriate safeguards including encryption in transit (TLS) and at rest.

Security

  • Passwords hashed with bcrypt (12 rounds)
  • HTTP-only, Secure cookies with SameSite protection
  • Security headers (HSTS, X-Frame-Options, CSP)
  • Rate limiting and brute force protection
  • Audit logging of all security-relevant actions
  • Three-tier access control (User, Admin, Support)

Children's privacy

SendPI is not intended for children under 16. We do not knowingly collect data from children under 16.

Changes to this policy

We may update this privacy policy. We will notify you by email of significant changes. The "Last updated" date at the top indicates the most recent revision.

Contact & Data Protection

For all privacy questions, data requests, or complaints: support@sendpi.ai

If you believe your privacy rights have been violated, you have the right to lodge a complaint with your local data protection authority.

SendPI uses strictly necessary cookies for authentication only. We do not use tracking, advertising, or analytics cookies. Read our Privacy Policy.