PurposeKit

Privacy Policy

Last updated: May 2026

Who runs this

PurposeKit is a personal project run by Steve Law. It is not a registered company. There are no paid plans, no commercial contracts, and no formal service-level commitments. This is an open experiment in building useful AI tools for the charity sector.

To get in touch, connect on LinkedIn. A LinkedIn message is the fastest way to reach Steve, and the one he answers — please use it in preference to email.

What data is collected

  • Your email address — for account creation and sign-in
  • If you choose to sign in with Microsoft or Google: your name, email address and profile picture link, which they pass to us. We get no access to your mailbox, files, calendar or contacts
  • If you register interest in the AI training: your email, and optionally your organisation and what your team needs. Used only to tell you when the training opens and to shape it — never shared, and removed on request to hello@purposekit.org
  • Usage metadata — which tools you used, token counts, approximate cost, and timestamps
  • Tool outputs — the text generated by AI tools, stored for up to one year

No payment card details are collected. Your data is not sold.

Where your data is stored

All account and usage data is stored in the European Union (Supabase, EU region). Personal data is not transferred outside the UK or EU/EEA.

AI processing

PurposeKit uses Anthropic's Claude API to generate tool outputs. When you submit a form, your input is sent to Anthropic's API. Anthropic does not use API inputs to train its models. Only metadata (token counts, response times) is logged by PurposeKit — not the content you entered.

See Anthropic's Privacy Policy for how they handle API data.

No guarantees

This is a personal project. There are no formal guarantees of data security, uptime, or continuity. Do not enter confidential, legally privileged, or personally sensitive information. Always consult your organisation's data policies before using any external tool with real data. Treat every input as potentially visible.

Data retention

  • Usage logs (token counts, costs): retained indefinitely for analytics
  • Tool outputs (generated text): deleted automatically after 1 year
  • Account data: retained until you request deletion
  • Login sessions: expire after 1 week

Your rights

You have the right to access, correct, or delete your data, and to lodge a complaint with the ICO at ico.org.uk. To request deletion, use the account settings page or contact via LinkedIn.

Analytics and error monitoring

PostHog (EU infrastructure) is used for product analytics and Sentry for error monitoring. Neither records the content of tool inputs.