Last Updated: 11 July 2026
Welcome to Non-Exec.AI ("we," "our," or "us"). We are committed to protecting your privacy and ensuring that your personal information is handled in a safe and responsible manner. This Privacy Policy outlines how we collect, use, disclose, and safeguard your information when you visit our website www.non-exec.ai and use our AI-driven corporate governance services and platform.
Please read this Privacy Policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access the site.
We may collect information about you in a variety of ways when you interact with Non-Exec.AI. The information we may collect includes:
a. Personal Data
Personally identifiable information that you voluntarily give to us when registering with the site or when choosing to participate in various activities related to the site. This may include:
Lawful Basis: We process this Personal Data to fulfill our contract with you (service delivery) and for our legitimate interests (security and fraud prevention).
b. AI Interaction Data
When you use our AI tools, we process the inputs, prompts, and documents you submit to generate insights for your account and your use of the Service. This processing is limited to providing user-facing features within Non-Exec.AI. We do not use content you submit to train, develop, or improve generalized or non-personalized artificial intelligence or machine learning models.
c. Usage and Derivative Data
Information is processed from our website hosting, cloud and AI provider automatically when you access the site, such as your IP address, your browser type, your operating system, your access times, and the pages you have viewed directly before and after accessing the site.
d. Cookies and Tracking Technologies
We may use cookies, web beacons, tracking pixels, and other tracking technologies to help customize the Site and improve your experience.
e. Connected Calendar Data
If you choose to connect Google Calendar or Microsoft Outlook, we access calendar events read-only to display them in the Non-Exec.AI calendar view alongside your governance activities. For Google Calendar, this access uses the Google Calendar API under your authorization. We do not modify or delete events in your Google or Microsoft calendar.
Having accurate information about you permits us to provide you with a smooth, efficient, and customized experience. Specifically, we may use information collected about you via the site to:
We may share information we have collected about you in certain situations. Your information may be disclosed as follows:
We use administrative, technical, and physical security measures — including hosting our application infrastructure on an industry-leading, highly secure cloud platform and managing our data via a robust, encrypted cloud-based backend service — to help protect your personal information and sensitive corporate data. To ensure the highest level of performance, reliability, and security, our platform is hosted on globally recognized, secure cloud infrastructure. Furthermore, our application backend—including user authentication, real-time data syncing, and NoSQL database management—is powered by a highly secure, scalable cloud-based backend service provider. These environments utilize robust encryption and industry-standard security protocols to protect your data both at rest and in transit. While we have taken reasonable steps to secure the personal information you provide to us, please be aware that despite our efforts, no security measures are perfect or impenetrable, and no method of data transmission can be guaranteed against any interception or other type of misuse.
All data stored within our Google Cloud environment is encrypted both in transit and at rest. We rely on Google Cloud’s enterprise-grade security infrastructure, which complies with strict industry standards and certifications (such as ISO 27001 and SOC 2), to protect your personal and corporate data against unauthorized access, loss, or alteration.
We retain your personal and AI interaction data within our Google Cloud databases only for as long as necessary to fulfill the purposes outlined in this policy or to comply with legal obligations. Upon requesting deletion or account termination, your data will be securely purged from our active Google Cloud storage systems in accordance with Google's secure data deletion protocols.
If you disconnect Google Calendar or Microsoft Outlook in Settings, we stop further API access and remove imported external calendar events from our systems in accordance with our deletion practices. OAuth tokens are stored server-side and are not exposed to other users.
We do not knowingly solicit information from or market to children under the age of 18. If we learn that we have collected personal information from a child under age 18 without verification of parental consent, we will delete that information as quickly as possible.
Depending on your location (such as if you reside in the European Economic Area, UK, or California), you may have certain rights regarding your personal information, including the right to:
To exercise any of these rights, please contact us using the information provided below.
We may update this Privacy Policy from time to time in order to reflect, for example, changes to our practices or for other operational, legal, or regulatory reasons. We will alert you about any changes by updating the "Last Updated" date of this Privacy Policy. You are encouraged to periodically review this Privacy Policy to stay informed of updates.
To protect your personal information and ensure strict data isolation between users, our platform utilizes robust access controls within our Google Cloud and Firebase architecture. We employ multi-tenant security strategies to guarantee that you can only access your own data and files. This is enforced through the following mechanisms:
Because these protocols are enforced directly on our secure servers, they cannot be bypassed, ensuring your data remains completely invisible and inaccessible to other users.
9. AI Processing, Capabilities, and Transparency
We are committed to honest and transparent communication regarding our use of artificial intelligence (AI) and machine learning technologies. To ensure compliance with consumer protection standards and to prevent deceptive claims regarding AI capabilities, we expressly disclose the following regarding our AI-driven corporate governance tools (refer to Non-Exec.AI - Privacy Nutrition Label below):
10. Google API Services - Limited Use Disclosure
Non-Exec.AI Limited uses Google API Services, including the Google Calendar API, when you optionally connect a Google account to import calendar events into Non-Exec.AI. Access is read-only; we do not write to or change your Google Calendar}
Limited Use compliance: The use and transfer of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. Specifically:
features that are visible in the Non-Exec.AI application - for example, displaying imported calendar events alongside board and governance activities.}
11. Compliance Notes on GDPR and ISO / SOC
Non-Exec.AI Limited protects personal and corporate data on web, iOS, and Android.
Where the GDPR and UK GDPR apply, we process data lawfully, honour access, correction, deletion, and related rights, and use safeguards for international transfers - including Google Cloud's Data Processing Addendum, Standard Contractual Clauses, and the EU-US Data Privacy Framework. California residents and others may have additional privacy rights described in Section 6 of this policy; we do not sell personal information.
Data is hosted on Google Cloud Platform and Firebase, which meet standards including ISO 27001 and SOC 2; we encrypt data in transit and at rest and enforce per-user access controls. Google's certifications cover infrastructure; Non-Exec.AI Limited does not claim independent SOC 2 or ISO 27001 certification unless agreed in writing.
Security standards (ISO 27001 / SOC 2). ISO 27001 is an international information-security management standard; SOC 2 is an independent auditor’s report on a service provider’s security and related controls. Non-Exec.AI hosts data on Google Cloud Platform and Firebase, which maintain certifications and reports including ISO 27001 and SOC 2 for applicable infrastructure. We encrypt data in transit and at rest and enforce per-user access controls. Those Google certifications cover the underlying infrastructure; Non-Exec.AI Limited does not claim an independent ISO 27001 or SOC 2 certification unless agreed in writing.
If you have questions or comments about this Privacy Policy, including questions about Google Calendar connection, OAuth, this Limited Use disclosure, or this Privacy Policy, please contact us at:
Non-Exec.AI - Privacy Nutrition Label (for Privacy Policy)
============================================================
Applies to: www.non-exec.ai, app.non-exec.ai, and Non-Exec.AI on Google Play and Apple App Store
Full policy: https://www.non-exec.ai/privacy-policy
This summary gives an at-a-glance view of what data we collect, how we use it,
and what we do NOT collect. It supplements our Privacy Policy and reflects the
same practices described there.
AT A GLANCE
-----------
Ads We do not show ads or sell your data to advertisers.
Tracking We do not track you across other companies' apps or websites.
Encryption Data is encrypted in transit and at rest on Google Cloud.
Deletion Delete your account in-app (My Profile -> Account) or contact us.
Children Our service is not directed at anyone under 18.
DATA LINKED TO YOU
------------------
We collect the following when you use Non-Exec.AI. It is linked to your account
and used to provide and secure the service - NOT for third-party advertising.
CONTACT INFORMATION
Name When you register or sign in Account setup, profile
Email address Required for an account Sign-in, communications, billing
Phone number Optional (profile) Profile preferences
Other profile Optional - job title, timezone, Personalise your experience
location (city/region text),
notification settings
USER CONTENT YOU PROVIDE
Photos & videos Uploads, profile photos, video links Analysis and transcription
Documents & files PDFs, spreadsheets, Word files, etc. AI-assisted risk analysis
Audio Audio uploads Transcription and analysis
Company & board Financial data, reports, notes Governance and risk features
you enter
AI interactions Prompts, chat, documents to AI tools Generate insights (Policy 1b)
Calendar events Only if you connect Google, Outlook, Portfolio calendar (read-only)
or Apple Calendar
IDENTIFIERS & ACCOUNT DATA
User ID When you sign in Secure access across devices
Device / app IDs Automatically (security checks) Fraud prevention - NOT for ads
PURCHASES
Purchase history When you subscribe Manage subscription
Payment cards: Processed by Stripe, PayPal, Apple Pay, or Google Pay.
Non-Exec.AI does NOT store full card numbers.
DIAGNOSTICS & SECURITY
Diagnostic data Automatically Platform protection (App Check,
authenticated server logs)
USAGE & TECHNICAL DATA (WEB)
Usage data When you access web or app Operate and secure the service
(IP, browser/device type, OS, (Privacy Policy Section 1c)
access times)
Cookies When you use our website Sessions and site operation
(Privacy Policy Section 1d)
DATA USED TO TRACK YOU
----------------------
NONE.
We do not link your data with third-party data for advertising or share it with
data brokers for cross-app tracking.
DATA WE DO NOT COLLECT
----------------------
- Precise or approximate GPS location
- Contacts or address book
- SMS or in-app messages from other apps
- Health or fitness data
- Web browsing history outside our service
- Advertising identifiers for targeted ads (we do not run ads)
WHO WE SHARE DATA WITH
----------------------
We share data only with service providers under contract. We do NOT sell personal data.
Google Cloud / Firebase / Vertex AI (Gemini) Hosting, auth, storage, AI
Stripe, PayPal Subscription payments
Google Calendar, Microsoft Outlook, Apple Read-only calendar - only if you connect
Apple, Google, Microsoft, LinkedIn Sign-in - where available on your platform
Google Cloud acts as our service provider / data processor. See Section 3 of our
Privacy Policy for GDPR and international transfer safeguards.
YOUR CHOICES & RIGHTS
---------------------
Optional data Phone, profile fields, calendar, uploads - unless a feature needs them
Calendar Connect or disconnect anytime in Settings
Account deletion In-app or contact us (Policy Section 4)
Privacy rights Access, correct, delete, restrict, port - Policy Section 6
Contact:
PLATFORM NOTES
--------------
Practices are consistent across web, Android, and iOS. Sign-in and calendar
options differ by platform (e.g. Sign in with Apple on iOS, Google on Android).
Google Play and Apple App Store may show platform-specific summaries that align
with this label.
We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.