Privacy policy
Effective 28 September 2026
whatisai.fyi collects only the information needed to operate the contact form, understand limited site activity and protect the service. It does not sell personal information or use behavioural advertising.
Information collected
- Contact messages: the name, email address, reason, message and page reference you submit.
- Reading events: a short, fixed list of first-party events, described below, used to learn which explainers and learning paths help readers.
- Security records: short-lived request and rate-limit information needed to protect public forms and APIs. Production proxy logs are configured to remove query strings, referrers, cookies and authorization headers.
Reading events, exactly
This site is open source, so anyone can read the code that records these events. Nothing is recorded if your browser sends Do Not Track or Global Privacy Control, or if it looks like a bot. Each event is one of these, and nothing else:
- Search: the words you searched for (lowercased, at most 120 characters), how many results appeared and which result you opened. Search words are deleted after 30 days.
- Pages opened: which category, explainer, deep dive or nearby term you opened.
- Learning path: whether you chose the “use” or “build” path, and which step or skill you opened.
- Explainer sections: which section of an explainer you scrolled to, such as “how it works” or “sources”.
- Links out: the number of a source you opened (for example source 3), or which company newsroom you opened from AI news. The link address itself is not recorded.
With each event the site stores the page address, the name of the website that sent you, the time, and a random ID kept in one first-party cookie so repeat visits are not counted twice. Only a keyed hash of that ID is stored. The site never stores your IP address, name, email, what you type into forms, or any other text. Events are deleted after 90 days and are never sold, shared or used for advertising.
Separately, the site counts page views with Umami, a self-hosted analytics tool that uses no cookies. It records the page, the website that sent you, and your browser, device type and country. It does not store your IP address, and it skips browsers that send Do Not Track. The counts stay on the site's own server.
How information is used
Information is used to respond to messages, measure aggregate interest, prevent abuse and keep the service reliable and secure. The site has no sign-in and no reader accounts. Email subscriptions are not available yet, so the site does not collect subscriber addresses.
Service providers
The service uses Supabase for application data, Cloudflare for DNS, edge security and private tunnelling, and a private container registry and hosting infrastructure for deployment. Each provider processes data under its own terms and privacy commitments.
Retention and deletion
Records are kept only for as long as they are needed for the purposes above, legal obligations and security. To request access, correction or deletion, email [email protected] or use the privacy contact form.
Security
Reasonable technical and organisational safeguards are used, including encrypted connections, restricted server credentials, origin and request validation, rate limits, database access controls and isolated production services. No Internet service can promise absolute security.
Children
The service is not directed to children under 13, and it does not knowingly collect their personal information.
Changes and contact
Material changes will be reflected on this page with a new effective date. Questions may be sent to [email protected].