Askline
Legal Privacy Terms Back

Privacy

Privacy Policy

Last updated 18 August 2026. English is the binding language.

Who we are What we collect How we use it AI processing Who we share with Your rights

1. Who is responsible

This policy explains what personal data Askline collects, why, for how long, who else sees it, and what you can do about it. It covers this website and the Askline application. It does not cover third-party sites we link to, nor X itself — they have their own policies.

Yando Pte. Ltd. (“Yando”, “we”, “us”) is the controller of personal data processed through Askline.

Yando Pte. Ltd. UEN 202018750D · Accounting and Corporate Regulatory Authority, Singapore
68 Circular Road, Singapore 049422
hello@askline.app

Singapore’s Personal Data Protection Act 2012 (PDPA) is our home regime. Where the GDPR or UK GDPR applies to you, we honour those rights as well. If you live in a US state with its own privacy law, we honour the rights it gives you. This English text is the one that binds.

We have no establishment in the EU or the UK and have not designated a local representative. No data protection officer is required: we are not a public body, we do not monitor people on a large scale, and we do not process special-category data as a core activity. Privacy requests go to the address above. If that changes, we will name the representative or officer here.

2. What we collect

Account

Email address, a hashed password, an optional display name, your plan, and the date the account was created.

What you enter in the product

Your product description, who you sell to, competitors you name, reply tone, saved searches, and the drafts you edit. If you connect X, we store the tokens needed to post on your behalf.

Results we generate for you

Public posts we retrieve for a search, scores, reasons, and suggested replies. These sit in your inbox until you delete them or close the account.

Billing

Payments run through Stripe. Full card numbers never reach us. We keep Stripe customer and subscription identifiers, plan status, and invoice history needed to run the subscription and our books.

Technical logs

IP address (used to limit abuse on free searches), date and time, requested path, user agent, and error traces. They exist for security and debugging, not to profile you.

Support

What you write to us, and what we reply, kept so we can follow up and so we can prove what was agreed.

Cookies

Askline uses essential cookies to keep you signed in and to attach a search you run before creating an account. We also use Firebase Analytics (Google) to measure how the site and app are used — pages viewed, buttons used, and similar events. That measurement may set cookies or similar storage on your device. We do not use advertising cookies, and we do not sell the data.

We do not ask for private keys, seed phrases, or X credentials other than the official sign-in flow you start yourself.

3. Why we process it

  • To provide the service — create your account, run searches, show an inbox, send a reply you approved. Basis: performance of the contract.
  • To bill you — take payment, issue invoices, keep records the law requires. Basis: contract and legal obligation.
  • To keep the service safe — rate limits, fraud and abuse prevention. Basis: legitimate interest.
  • To understand usage — Firebase Analytics, so we can see which pages and features are used and improve the product. Basis: legitimate interest.
  • To answer support — the messages you send us. Basis: contract and legitimate interest.
  • To establish or defend a legal claim — Basis: legitimate interest.

We do not sell personal data. We do not use your content to train public models of our own. We do not make automated decisions that produce legal effects about you. Rankings in the inbox are scores of public posts you asked us to find, not a credit or employment assessment.

Service messages (invoices, security notices, changes to these documents) are part of the contract. Marketing mail goes out only if you opt in, and every such message carries an unsubscribe link.

4. Artificial intelligence (Grok API)

To rank conversations and draft replies, your brief, the public posts retrieved for that search, and any text you ask us to rewrite are sent to the Grok API provided by X.AI LLC (“xAI”), a Nevada company.

We only transmit the data strictly necessary for the model to process your request. All processing is carried out under this policy and applicable data-protection law. xAI processes this data solely on our behalf and under our contractual instructions, as a processor. Using search and draft features means you instruct us to send those inputs to xAI. The product cannot produce a ranked inbox or a draft without that step.

xAI’s consumer privacy policy does not govern API traffic processed on a customer’s behalf. That processing is subject to xAI’s enterprise terms and to our instructions. For reference:

  • xAI Privacy Policy
  • xAI Enterprise Terms of Service (API)
  • xAI Terms of Service

Outputs can be wrong, incomplete or unsuitable to send. You must review every draft before you use it.

5. Who else sees it

We use a short list of processors. Each acts on our instructions, for the purpose stated, and nothing more.

  • Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94103, United States — hosting, delivery, TLS, abuse filtering.
  • X.AI LLC (“xAI”) — generating scores and reply drafts, as described above.
  • Stripe Payments Singapore Pte. Ltd. / Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, United States — payments and invoicing. Card data stays on Stripe.
  • X Corp. — only if you connect your X account, and only to authenticate you and to publish a reply you chose to send.
  • Google Ireland Limited / Google LLC — (1) if you choose “Continue with Google”, to create or recognise your account from the email on that Google profile; (2) Firebase Analytics, to measure site and app usage (project askline-c2011, measurement ID G-30TQ75HXGC).

We may also disclose data if the law requires it — to a competent authority acting through the proper channel — or where it is necessary to establish or defend a legal claim. If the business is transferred, data may pass to the acquirer, still subject to this policy.

Askline is operated from Singapore. Some processors run international infrastructure, including in the United States. Where data protected by the GDPR leaves the EU/EEA, transfers rest on the European Commission’s standard contractual clauses (implementing decision 2021/914) where our processors provide them. For the UK GDPR, the same clauses apply together with the UK addendum where offered. Ask at hello@askline.app and we will send you a copy of the safeguards in place.

6. How long we keep it

  • Account and inbox: while the account is open, then up to 90 days after you close it, unless a longer legal retention applies.
  • Invoices and accounting records: 5 years, as required under the Singapore Companies Act and tax law.
  • Technical logs: 90 days.
  • Support mail: 24 months.

Data sent to the Grok API is retained under xAI’s retention rules for API traffic. Closing your Askline account deletes what we hold; it does not retroactively erase copies already processed by a processor under their legal duties.

Deleting your account does not delete the accounting records attached to it: we are required to keep those for the five years above, and we keep nothing beyond them.

7. Security

Below is what is actually in place. We list nothing else: a security claim in a privacy policy is a commitment.

  • connections are served over TLS, terminated at Cloudflare;
  • passwords are stored as salted hashes, never in clear text;
  • optional AI keys and X tokens are encrypted at rest;
  • no card data reaches us — payment is isolated at Stripe.

No system is invulnerable. If a breach is likely to put you at high risk, we will tell you and notify the authorities the law requires, including the Personal Data Protection Commission in Singapore (within 3 calendar days of establishing that the breach is notifiable) and, where GDPR applies, the competent European authority (within 72 hours of becoming aware of it).

8. Your rights

Subject to applicable law, you may ask to access, correct, delete, or export your data, to restrict or object to certain processing, and to withdraw consent where processing rests on consent. Write to hello@askline.app from the email on the account. We may ask for what is strictly necessary to confirm it is you. We answer within 30 days. If a request is genuinely complex we may take up to two further months, and we will tell you so within the first month.

You may also complain to:

  • Singapore — Personal Data Protection Commission (PDPC)
  • EU / EEA — the supervisory authority of the country where you live, work, or where the problem happened
  • United Kingdom — Information Commissioner’s Office (ICO)

9. Children

Askline is for people 18 or older. We do not knowingly collect data from children. If you believe a minor has an account, write to us and we will delete it.

10. Changes

The date at the top is the version in force. If a change materially affects your rights, we will email account holders and show a notice in the product at least 30 days before it takes effect. Minor corrections take effect on publication.

11. Contact

Privacy requests: hello@askline.app
Yando Pte. Ltd., 68 Circular Road, Singapore 049422

Askline
Legal Privacy Terms