← Back to Strive Private AI
// legal · privacy

Privacy Policy

Last updated: 13 May 2026 · Version 2.0

The short version. We process no Customer Data. Your prompts, documents, and AI-generated responses never leave your device. The only personal data we collect is what you give us directly when you sign up for an account or contact us — your email and your name.

1. Who we are

This Privacy Policy describes how StriveTech AI Limited ("we", "us", "our") handles personal data in connection with the Strive Private AI desktop application, our website at striveprivate.ai, and related services (collectively, the "Service").

Registered office: 4500 Parkway, Solent Business Park, Whiteley, Fareham PO15 7AZ, United Kingdom
Contact: info@strivetech-ai.com
ICO registration: Pending — will be published here once issued

We are the data controller for any personal data described in section 3 below. We are not the data controller for any data you process using the Strive Private AI application (see section 2).

2. Customer Data — what we do not collect

Strive Private AI is an entirely on-device application. We have no technical means to access, retrieve, or recover any of the following:

Together, the categories above are referred to in our Terms of Service as "Customer Data." Customer Data is processed exclusively on your device, under your sole control. Even at your request, we cannot retrieve Customer Data — there is no copy of it on our infrastructure.

Because we do not process Customer Data, we are not a data processor in respect of it under UK GDPR Article 28. No Data Processing Agreement (DPA) is required for Customer Data — we cannot reasonably offer the contractual commitments of a DPA in respect of data we never see.

Why this matters. If you are an enterprise procurement reviewer, the most common compliance question — "where is our data going?" — has the simplest possible answer for Strive Private AI: nowhere it isn't already.

3. Account Data — what we do collect

When you create an account, request information, or otherwise interact with us, we collect the following limited personal data:

DataSourceRequired?Why
Email addressYou provide itYesAccount identification, password reset, transactional emails (license keys, security notices)
NameYou provide itOptionalPersonalisation in emails and the portal interface
Company name & roleYou provide itOptionalSales context, lead qualification
Password (hashed)You set itYesAuthentication. We never store plain-text passwords or have visibility of them.
IP addressAuto-loggedYesSecurity, fraud prevention, rate limiting
Browser & device infoAuto-loggedYesSecurity, session management, debugging
Sign-up & login timestampsAuto-loggedYesAccount management, security audit
Marketing preferenceYou choose at sign-upOptionalTo send (or not send) product update emails

4. Why we process Account Data — lawful basis

Under UK GDPR Article 6, we rely on the following lawful bases:

Transactional emails (e.g. confirming a license, notifying you of security incidents that affect your account) are sent regardless of marketing preference because they are necessary to perform the contract.

5. Sub-processors

We use the following third-party providers to operate the Service. Each is contractually bound to UK GDPR-compliant data handling, and each is, where applicable, certified under SOC 2 and/or ISO 27001.

ProviderPurposeData processedLocation
Clerk, Inc.Authentication, user account managementEmail, name, password hash, IP, session dataUSA (SCCs in place)
HubSpot, Inc.CRM, marketing communicationsEmail, name, company, lead activityUSA / EU (SCCs in place)
Vercel, Inc.Website hosting, edge functionsIP, request logs (no PII content)Global edge network (SCCs in place)
Microsoft 365Email (inbound & outbound)Email content of correspondence with usUK / EU

For transfers outside the UK and EEA, we rely on the UK International Data Transfer Agreement (IDTA) or the European Commission's Standard Contractual Clauses (SCCs), supplemented by the technical and organisational measures published by each provider.

6. Cookies and similar technologies

Our website uses a small number of cookies, all of which are strictly necessary for the Service to function:

We do not use analytics, advertising, or tracking cookies. There is no Google Analytics, no Meta Pixel, no third-party advertising network, no behavioural ad targeting. You may block cookies in your browser settings; this will prevent you from logging in but will not otherwise impair the website.

7. Your rights under UK GDPR

You have the following rights in respect of personal data we hold about you:

To exercise any of these rights, email info@strivetech-ai.com with the subject "Privacy request." We respond within 30 days as required by law.

You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.

8. Data retention

9. Security

We implement industry-standard technical and organisational measures:

For the security of the Strive Private AI application itself (the on-device software), see our Security & Compliance page.

10. International transfers

Some of our sub-processors (Clerk, HubSpot, Vercel) are located in the United States. Personal data transferred outside the UK is protected by:

Each sub-processor also publishes its own technical safeguards (encryption, access controls, etc.) which supplement the contractual protection.

11. Children

The Service is not directed to children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes — anything that meaningfully expands what we collect or how we use it — will be communicated to registered users by email at least 30 days before they take effect. The "Last updated" date at the top reflects the most recent revision.

13. Contact

For any privacy enquiry, data subject request, or to report a concern: