Who is responsible for your data
Whip Smart Technologies Ltd (company number 17341039), trading as Octopus Assembly, is the controller for the personal data described here. Our registered office is Suite A, 82 James Carter Road, Mildenhall, United Kingdom, IP28 7DE. Contact us at support@octopusassembly.com. We are registered with the ICO (registration ZC231758). We have not appointed a data protection officer.
What we collect, why and the legal basis
Idea and planning information: the goal and other answers you enter to obtain an AI-generated assessment or plan. We use this to take steps at your request before a contract and, after purchase, to perform our contract with you. The application sends the goal text to OpenAI only when you ask for the idea-read; it does not intentionally store that input in its fulfilment database.
Order, access and delivery information: when you buy, we receive your email address, selected product, Stripe checkout-session reference, payment status, a hash of the private access token, access-link creation, expiry, recovery and delivery-event times. We use this to perform the contract, prevent duplicate delivery and recover access. We do not store the access token itself after it has been issued.
Support and complaint information: your name (if provided), email address, message and our correspondence. We use this to answer you, deal with a complaint and protect our legitimate interests in running and defending the service.
Payment and tax information: when you buy, we receive the payment and transaction details made available by Stripe. We use this to perform the contract and comply with accounting, tax and fraud-prevention obligations. We do not receive or store full payment-card details.
Technical and browser information: browser storage used by the product, and limited technical information processed by the site host and third-party services. See “browser storage, cookies and scripts” below. We use necessary technical information to operate and secure the service; where consent is required for storage/access technology, we rely on consent.
Our legal bases
Depending on the activity, our lawful basis is: taking steps at your request before a contract or performing a contract (idea-read, order, delivery and recovery); compliance with a legal obligation (tax and accounting records); legitimate interests (support, security, fraud prevention and defending legal claims, balanced against your rights); or consent (non-essential storage/access technologies and any optional activity for which we ask). You can withdraw consent at any time, but that will not affect earlier processing.
OpenAI and your idea text
When you use the AI idea-read feature, the text you enter is sent from our application to OpenAI’s API to generate the requested response. OpenAI is a recipient used to provide that feature. Please do not enter passwords, API keys, payment-card data, special-category personal data, confidential information or personal data about someone else. We do not intentionally attach your name or email to that API request, but free-text answers can themselves contain personal data. We do not intentionally retain the input or generated assessment in our fulfilment database; it is held in your browser unless you clear it. Provider and hosting logs may still exist under their own retention arrangements. OpenAI’s handling is also governed by its privacy policy and applicable business/API terms.
Stripe, Resend and email
Stripe: Stripe processes payment-card and checkout data as its own payment-service provider. We receive the order information Stripe makes available to us, including payment status, customer email, selected product and transaction reference, but not your full card details. See Stripe’s privacy policy.
Resend: for a product that is available to buy, Resend sends the private delivery and recovery email. It receives the purchaser’s email address, product label and private access-link message for that purpose.
Support email: if you email us, your address, message and our correspondence are handled by our email provider. We use this information to answer and manage your query. Do not include passwords, API keys, payment-card details, special-category data or other sensitive information.
Browser storage, cookies and scripts
Factory Builder uses browser local storage to retain your questionnaire answers, generated assessment, planning signals and checklist state on your device so that related screens can use them. This storage remains on your device unless a feature sends selected text to OpenAI or you submit a form. You can remove it through your browser controls; clearing it may remove your saved plan and checklist state. A private paid-product access link expires after 30 days and is sent separately by email after verified payment.
The site is hosted on Replit using Google cloud infrastructure. The host sets a first-party cookie named GAESA for 30 days to maintain infrastructure session affinity and route requests to an application instance. It is not used by Whip Smart Technologies for advertising or customer profiling. Replit also injects its deployment-analytics script into the live HTML; our Content Security Policy blocks that external script from executing on this site. If either behaviour changes, we will reassess this notice and any consent requirement before relying on the changed deployment.
Hosting, recipients and international transfers
Our intended launch recipients are Replit (hosting), Stripe (payment), Resend (delivery and recovery email) and our email provider (support replies). OpenAI is also a recipient only if the optional idea-read API is enabled. Each may process data from the UK or elsewhere. Where a provider receives personal data outside the UK and no UK adequacy regulation applies, we use a UK-recognised transfer safeguard, such as the UK International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, together with any required transfer-risk assessment. You may request information about the applicable safeguard by emailing support@octopusassembly.com.
How long we keep data
Browser local storage remains until you clear it. Private access links expire after 30 days, after which the related entitlement row is deleted by scheduled maintenance. Pseudonymous recovery-rate-limit records are deleted after 24 hours and minimal delivery-event records after 90 days. We retain support and complaint correspondence for 24 months after closure, and order-confirmation and exact contract records for six years, or longer only where law or a live dispute requires it. Stripe retains payment and VAT transaction records under its applicable configuration and terms.
Your rights and complaints
Subject to the UK GDPR, you may ask us for access to, correction or deletion of your personal data; restriction of processing; portability; or to object to processing based on legitimate interests. You may withdraw consent at any time. Contact support@octopusassembly.com to exercise a right. You can complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint. We may need to verify your identity before acting on a request.
Children and automated processing
Factory Builder is not designed for children. Do not use it if you are under 18. The AI idea-read generates recommendations from the information you enter. It is not a decision that produces legal or similarly significant effects, and you should not rely on it as professional advice or solely automated decision-making about you.