Effective August 27, 2026 · https://bintu.ai
BINTU.ai (“we”, “our”, or “us”) is operated by Bintu Alkassoum. This policy explains what data we collect when you use https://bintu.ai to generate the AI Tool Kit, how we use it, and what rights you have over it. We collect the minimum data needed to provide our services and deliver your generated report. We do not sell your data.
Information you provide
Payment information
We never see or store your card details. All payments are processed by Stripe, under PCI-DSS compliance. Your card number never touches our systems.
From Stripe we keep only what we need to connect your payment to your report: the checkout session ID, the amount, and the email address and name you gave at checkout. Because payment now comes before the intake form, those two are the first things we hold — we use them to send you the link to finish your intake, and we fill them into the form for you so you do not have to type them twice. Both stay editable there. Card numbers, billing addresses, tax IDs and payment methods are never copied into our database.
Automatically collected data
We use standard server logs and may collect your IP address, browser type, and pages visited for security and debugging purposes.
We also load Google Analytics and a Google Ads conversion tag across the site. These set cookies and record which pages are visited and whether a visit led to a purchase, so we can understand how people find the Service and measure our advertising. They do not receive your intake answers or the contents of your generated report. We do not sell this data. You can block them with any standard ad or cookie blocker without affecting the Service.
We do not sell your personal information, and we never use the contents of your intake form or your report for advertising. Marketing email is strictly opt-in: buying a report does not subscribe you to anything. Under the Azure OpenAI terms, your data is not used to train Microsoft’s or OpenAI’s models.
We rely on trusted enterprise infrastructure to operate BINTU.ai securely:
Hosts this website. Standard server logs are collected by Vercel's infrastructure.
The sole AI model provider. Runs inside our own Azure tenancy and generates your report from your intake data. Under the Azure OpenAI terms, your prompts and outputs are not used to train or improve any Microsoft or OpenAI model, and are not shared with OpenAI.
Runs the web searches used to research the tools and vendors you name. Receives search queries about those tools, not your full intake form.
Stores your intake data and generated reports in a PostgreSQL database. Data is encrypted at rest.
Orchestrates the background jobs that generate your report, and carries progress events for the status page.
Processes payments. We never see or store your card details. Stripe is PCI-DSS Level 1 certified.
Delivers transactional emails, including your report delivery link.
Measures traffic to our marketing pages and whether a visit led to a purchase. Does not receive your intake data or your report.
Generated reports are stored indefinitely so you can return to them via your private link. If you would like your report and associated intake data permanently deleted, email us at hello@bintu.ai and we will execute a hard deletion within 7 days.
We may retain limited transaction records (via Stripe) and other operational records for legitimate business, accounting, tax, or legal compliance purposes.
This is the question we get asked most, so here is the direct answer. Your intake answers are sent to one AI provider: Microsoft Azure OpenAI, running in our own Azure tenancy in a region we control. They are not sent to OpenAI, Anthropic, Google, or any other model vendor.
Your data is not used to train any model. This is a contractual term of the Azure OpenAI service, not a setting we toggle: Microsoft does not use your prompts or outputs to train, retrain, or improve its models or OpenAI’s, and does not share them with OpenAI.
Microsoft may retain prompts and outputs for a short period (up to 30 days) solely to run automated abuse detection, as described in the Azure OpenAI documentation linked in our sub-processor list. That data is not used for training and is not available to us.
The web searches we run to research vendors are queries about the tools you named — not your answers, your finances, or your company’s internal context.
We use administrative and technical safeguards to protect your data. Your data is held in a managed PostgreSQL database, encrypted at rest, and reachable only through our server-side code — never directly from your browser.
There are no accounts and no passwords. Your report lives at a private link containing a long, randomly generated identifier that is not listed, indexed, or guessable. Treat that link as confidential: anyone who has it can view the report. If you believe your link has been shared beyond its intended audience, email us and we will remove the report.
Depending on your regulatory region (such as the EU/UK under GDPR, or California under CCPA), you may have the following rights regarding your personal and organizational data:
To exercise any of these rights, contact hello@bintu.ai.
We use essential browser storage (localStorage) to save your intake form progress, so you do not lose your answers if you refresh the page. That data stays in your browser and is used strictly to operate the Service.
We also load Google Analytics and a Google Ads conversion tag across the site, which set their own cookies to measure traffic and advertising performance. They record which pages are visited; they never receive your intake answers or the contents of your report. Blocking them with a cookie or ad blocker does not affect the Service.
We may update this policy from time to time as we launch new reports or change how the Service works. Material changes will be reflected with a new effective date at the top of this page. Continued use of the service after changes constitutes acceptance of the updated policy.
Questions about this privacy policy or your data? Reach us at hello@bintu.ai.