BINTU.aiBINTU.aiGet your plan
Legal

Privacy Policy

Effective August 27, 2026 · https://bintu.ai

Overview

BINTU.ai (“we”, “our”, or “us”) is operated by Bintu Alkassoum. This policy explains what data we collect when you use https://bintu.ai to generate the AI Tool Kit, how we use it, and what rights you have over it. We collect the minimum data needed to provide our services and deliver your generated report. We do not sell your data.

What we collect

Information you provide

  • Organizational ContextRole, org size, departments, budget context, industry, and regulatory regions. Used to personalize your generated report. Stored with your record.
  • Tool & Workflow DataThe AI tools you use, costs, workflows, and business goals. The core input for your analysis. Stored with your record.
  • Email addressCollected at checkout, and confirmed on the intake form. Used to send your finished report, to send you the link to finish your intake, to reach you if something goes wrong with your order, and to send your payment receipt.
  • Your nameThe name you enter at checkout. Used to address your report and our emails to you, and to tell your order apart from another with the same company name. You can change the name on the intake form.
  • Marketing consentOnly if you tick the opt-in box. We store your choice, the date, and the exact wording you agreed to. Leaving the box unticked means we never email you anything but your order.

Payment information

We never see or store your card details. All payments are processed by Stripe, under PCI-DSS compliance. Your card number never touches our systems.

From Stripe we keep only what we need to connect your payment to your report: the checkout session ID, the amount, and the email address and name you gave at checkout. Because payment now comes before the intake form, those two are the first things we hold — we use them to send you the link to finish your intake, and we fill them into the form for you so you do not have to type them twice. Both stay editable there. Card numbers, billing addresses, tax IDs and payment methods are never copied into our database.

Automatically collected data

We use standard server logs and may collect your IP address, browser type, and pages visited for security and debugging purposes.

We also load Google Analytics and a Google Ads conversion tag across the site. These set cookies and record which pages are visited and whether a visit led to a purchase, so we can understand how people find the Service and measure our advertising. They do not receive your intake answers or the contents of your generated report. We do not sell this data. You can block them with any standard ad or cookie blocker without affecting the Service.

How we use your data

  • 01Generate your personalized report using enterprise LLM APIs.
  • 02Run web searches on the tools and vendors you name, to ground the report in current public information.
  • 03Store your report in our database so you can return to its delivery page.
  • 04Send you a transactional email with a link to finish your intake form after you pay, and fill your name and email into that form so you do not have to type them twice.
  • 05Send you a transactional delivery email containing your report link, and contact you if something goes wrong with your order.
  • 06Render your report as a downloadable PDF in your own browser.
  • 07Improve our internal audit methodology and proprietary database using anonymized, aggregated trend data.
  • 08Send you AI guidance and product updates — only if you ticked the opt-in box on the intake form. Every one of those emails has an unsubscribe link, and unsubscribing never affects your report.

We do not sell your personal information, and we never use the contents of your intake form or your report for advertising. Marketing email is strictly opt-in: buying a report does not subscribe you to anything. Under the Azure OpenAI terms, your data is not used to train Microsoft’s or OpenAI’s models.

Third-party services (Sub-processors)

We rely on trusted enterprise infrastructure to operate BINTU.ai securely:

Hosts this website. Standard server logs are collected by Vercel's infrastructure.

Microsoft Azure OpenAIPrivacy policy ↗

The sole AI model provider. Runs inside our own Azure tenancy and generates your report from your intake data. Under the Azure OpenAI terms, your prompts and outputs are not used to train or improve any Microsoft or OpenAI model, and are not shared with OpenAI.

Runs the web searches used to research the tools and vendors you name. Receives search queries about those tools, not your full intake form.

Stores your intake data and generated reports in a PostgreSQL database. Data is encrypted at rest.

Orchestrates the background jobs that generate your report, and carries progress events for the status page.

Processes payments. We never see or store your card details. Stripe is PCI-DSS Level 1 certified.

Delivers transactional emails, including your report delivery link.

Google (Analytics & Ads)Privacy policy ↗

Measures traffic to our marketing pages and whether a visit led to a purchase. Does not receive your intake data or your report.

Data retention

Generated reports are stored indefinitely so you can return to them via your private link. If you would like your report and associated intake data permanently deleted, email us at hello@bintu.ai and we will execute a hard deletion within 7 days.

We may retain limited transaction records (via Stripe) and other operational records for legitimate business, accounting, tax, or legal compliance purposes.

What happens to your intake answers

This is the question we get asked most, so here is the direct answer. Your intake answers are sent to one AI provider: Microsoft Azure OpenAI, running in our own Azure tenancy in a region we control. They are not sent to OpenAI, Anthropic, Google, or any other model vendor.

Your data is not used to train any model. This is a contractual term of the Azure OpenAI service, not a setting we toggle: Microsoft does not use your prompts or outputs to train, retrain, or improve its models or OpenAI’s, and does not share them with OpenAI.

Microsoft may retain prompts and outputs for a short period (up to 30 days) solely to run automated abuse detection, as described in the Azure OpenAI documentation linked in our sub-processor list. That data is not used for training and is not available to us.

The web searches we run to research vendors are queries about the tools you named — not your answers, your finances, or your company’s internal context.

Security and confidentiality

We use administrative and technical safeguards to protect your data. Your data is held in a managed PostgreSQL database, encrypted at rest, and reachable only through our server-side code — never directly from your browser.

There are no accounts and no passwords. Your report lives at a private link containing a long, randomly generated identifier that is not listed, indexed, or guessable. Treat that link as confidential: anyone who has it can view the report. If you believe your link has been shared beyond its intended audience, email us and we will remove the report.

Your rights

Depending on your regulatory region (such as the EU/UK under GDPR, or California under CCPA), you may have the following rights regarding your personal and organizational data:

  • AccessRequest a copy of the data we hold about you.
  • DeletionRequest that we permanently delete your report and intake data.
  • CorrectionRequest that we correct inaccurate data.
  • PortabilityRequest your data in a machine-readable format.

To exercise any of these rights, contact hello@bintu.ai.

Cookies & Local Storage

We use essential browser storage (localStorage) to save your intake form progress, so you do not lose your answers if you refresh the page. That data stays in your browser and is used strictly to operate the Service.

We also load Google Analytics and a Google Ads conversion tag across the site, which set their own cookies to measure traffic and advertising performance. They record which pages are visited; they never receive your intake answers or the contents of your report. Blocking them with a cookie or ad blocker does not affect the Service.

Changes to this policy

We may update this policy from time to time as we launch new reports or change how the Service works. Material changes will be reflected with a new effective date at the top of this page. Continued use of the service after changes constitutes acceptance of the updated policy.

Contact

Questions about this privacy policy or your data? Reach us at hello@bintu.ai.