Effective 5 September 2026
FirstAsk (FirstAsk, Hyderabad, India) is the controller of the personal data described here. Contact: support@firstask.ai.
Account data (name, email, timezone, password hash, consent time and IP), organisation and billing status (payment details are held by Stripe, not us), the profiles and channels you configure, your activity in the portal (leads viewed, feedback, pipeline states, notes), email delivery events (delivered, opened, clicked, bounced, complained), and technical logs (IP, user agent, request ids). Product analytics (PostHog) and error reporting (Sentry) are pseudonymous.
To provide the service you signed up for (contract): matching, digests, alerts, billing. To keep it secure and improve it (legitimate interest): logs, analytics, feedback-driven matching. Marketing email only with consent; digests are part of the service and stop the moment you turn them off or unsubscribe (one click, honoured within seconds).
We process a limited amount of personal data about people who publish requests publicly: the username or name shown on the post, the public content of the post, and any contact detail the poster themselves included in it. We index this under legitimate interest — connecting people who publicly asked for a service with people who provide it — and we have documented a Legitimate Interest Assessment. We do not build profiles, do not enrich with third-party data, do not sell contact details, and never email posters. Posts are stored as excerpts and summaries with a link to the original; raw source payloads are archived after 180 days; leads expire per source and are removed from the portal after 90 days.
Access, correction, deletion, restriction, portability and objection, as applicable under GDPR, UK GDPR, India's DPDP Act and similar laws. Subscribers can export and delete from account settings. If you posted something we indexed and want it removed, email support@firstask.ai with the link: we remove the lead, add your handle to an ingestion-time denylist so it is not re-collected, and confirm completion.
Google Cloud (hosting, database, AI qualification — US region), Amazon Web Services SES (email, US East), Stripe (payments), DataForSEO (search results), Apify and its vendor actors where enabled (collection), PostHog (analytics), Sentry (errors). Transfers outside your jurisdiction rely on standard contractual clauses or equivalent safeguards under each processor's DPA.
Account data for the life of the account plus 30 days; billing records as tax law requires (Stripe); email events 90 days; logs 30 days; database backups within a 7-day point-in-time window.
A session cookie and a refresh cookie (strictly necessary) on the portal; a theme preference; PostHog analytics identifiers when enabled. The marketing site sets no cookies without consent.
We will notify subscribers by email of material changes.