AI SpeedForce

Privacy policy

This policy explains what personal data AI SpeedForce collects through this website and during client projects, why, and what you can do about it.

Effective 22 September 2026 Last updated 24 September 2026 Version 1.9

Who we are

AI SpeedForce is not a company. It is the trading name of Poonam Devi, an individual who runs the business as a sole proprietor from India. When this policy says "we", "us" or "our", it means Poonam Devi, trading as AI SpeedForce.

We decide why and how the personal data described here is used. That makes us the Data Fiduciary under India's Digital Personal Data Protection Act 2023, and the controller under the EU and UK General Data Protection Regulation (GDPR). You, as the person the data is about, are the Data Principal under Indian law and the data subject under the GDPR.

What this policy covers

This policy covers personal data we handle when you:

  • visit aispeedforce.com;
  • send us an inquiry through the contact form, or arrange a call with us;
  • write to us by email; and
  • hire us for a project, where we may see material you share with us.

During a project we sometimes work inside your systems, and those systems can hold personal data about your own customers or staff. For that data you decide what happens to it and we act on your written instructions. You are the Data Fiduciary or controller, and we are your Data Processor or processor. The client confidentiality section and your project agreement cover how we handle it.

What we collect

Inquiry form and call bookings

When you use the contact form, or arrange a call with us, we collect:

  • your name;
  • the email address you give us, usually a work address;
  • your company name, if you provide it;
  • the type of work you are interested in; and
  • your message, which describes a task and may name the systems your business uses.

The form posts to a script on this website's own server. That script sends your inquiry to us as a single email. The email also records when it was sent, the IP address it came from and your browser's user agent string, which help us spot spam and tell whether an AI assistant sent it for you. No outside form service, CRM or tracking pixel is involved. The inquiry is also saved in the site's own database, so it can be answered from the site's admin area. It is kept and deleted on the same terms as the email, set out under how long we keep it.

Agent-readiness scanner

When you use the agent-readiness scan, we receive the website address you enter. We keep a log of every scan: the site scanned, the time, the score, your IP address, the country it points to, your browser's user agent string, the page that sent you, and your account if you ran the scan while signed in to app.aispeedforce.com. We use the log to see how the tool is used, to improve it, to follow up with signed-in users about their results, and to stop abuse. The log is kept for 90 days and then deleted. Separately, the report for a site is cached for ten minutes so a repeat scan is instant, and a one-way hash of your IP address is kept for up to an hour to enforce the rate limit. The requests to the scanned site come from our server, so that site does not see your IP address. Our scanner names itself in its requests and signs them with a published key (Web Bot Auth), so scanned sites can tell it apart from other bots; the signature carries no personal data.

Free accounts on app.aispeedforce.com

If you create a free account to see how to fix the gaps a scan finds, we store your name, email address, company if you give it, a one-way hash of your password (never the password itself), the time you agreed to our terms, and your sign-in times. We also store the sites you scan and their reports, which describe public websites. We send you only account emails: the link to confirm your address and, if you ask, a password reset link. We do not send marketing email.

Unconfirmed accounts are deleted after 7 days. A confirmed account is kept until you delete it from your account page, which removes the account, its sites and its reports at once. Sign-in attempts (IP address, email, time) are kept for 30 days to stop password guessing. The site owner can see accounts in the admin area and can open an account to help its user; every such access is logged and the log is kept for a year.

If you choose "Continue with Google", Google shares your name, your verified email address and basic profile details with us so we can create or sign in to your account. We do not receive your Google password.

Apps and AI agents you connect

You can let an app or an AI agent act for your account, for example to run scans or read your reports through our MCP server at https://aispeedforce.com/mcp. When you allow it, we store the app's registration (its name, website and return addresses, and the IP address it registered from), your consent and the permissions you granted, and records of the access tokens we issue. An agent that registers on your behalf also gives us the email address you asked it to use. Tokens expire (access after an hour, refresh after 30 days) and their records are deleted 30 days after expiry; sign-in codes after a day; an agent registration you never confirm after 7 days. You can disconnect any app or agent from your account at any time, which revokes its access at once.

Spam protection (Google reCAPTCHA)

Our forms and sign-in pages use Google reCAPTCHA to tell people from automated abuse. When you use a protected form, Google receives your IP address, information about your browser and device and how you interact with the page, and may set cookies. Google processes this under its own privacy policy (https://policies.google.com/privacy) and terms. Our legal basis is our legitimate interest in keeping the site and your accounts safe.

Email correspondence

If you write to us, we keep your email address, your message and anything you attach, along with our replies.

Server logs and IP address

Like every web server, ours records each request it receives. A log entry holds your IP address, the date and time, the page or file requested, the response status, the referring page if your browser sends one, and your browser's user agent string. We do not use these logs to profile you or to follow you across other sites.

Analytics

If you accept analytics cookies in the banner, the site loads Google Analytics 4 from Google, directly or through Google Tag Manager, which we use only to load Google Analytics. It records the pages you view, how you arrived, your device and browser type and your approximate location, derived from your IP address. We use it only to understand which pages are useful. Before you choose, and if you decline, the Google tag still loads with every kind of consent denied: it sets no cookies, and Google receives only cookieless signals that a page was viewed, which, like any web request, include your IP address and browser details. Google may use these to estimate visits in aggregate. If you accept, full Google Analytics runs with cookies. You can change your choice in the cookie policy. Our legal basis is your consent.

Client project material

If you hire us, you may share documents, data samples, example tasks, system access, credentials and other material so we can do the work. Some of it may contain personal data. We only use it as described in client confidentiality below.

What we do not ask for

We do not ask for sensitive personal data through this website. That includes passwords to personal accounts, bank, card or other payment details, health information and biometric data. Please do not put them in the contact form.

Why we use it, and our legal bases

We use personal data only for the purposes below. Each purpose has a legal basis under Indian law and under the GDPR.

PurposeData usedBasis under Indian lawBasis under the GDPR
Replying to your inquiry and discussing a possible projectInquiry and email dataYou gave the data voluntarily for this purpose (DPDP Act, section 7(a)), or your consentSteps taken at your request before a contract (Article 6(1)(b))
Delivering a project we have agreed with youContact details, correspondence, project materialYour consent and our contract with youPerformance of a contract (Article 6(1)(b))
Providing your free account and its scan reportsAccount details, sites scanned, reportsYour consent, given when you create the accountPerformance of a contract with you (Article 6(1)(b))
Running the agent-readiness scanner, understanding its use and limiting abuseThe address you enter, the scan log (IP address, country, browser, referring page, account if signed in)You gave the data voluntarily for this purpose (DPDP Act, section 7(a))Our legitimate interest in a working, fairly shared free tool (Article 6(1)(f))
Invoicing, accounts and tax recordsName, company, billing details, correspondenceCompliance with Indian law (DPDP Act, section 7)Legal obligation (Article 6(1)(c))
Keeping the website running and secure, and investigating abuseServer logs and IP addressYour consent, given by using the site, and legitimate uses permitted by lawOur legitimate interest in a secure, working site (Article 6(1)(f))
Establishing or defending legal claimsAny of the above, only as neededLegitimate uses permitted by lawLegitimate interest (Article 6(1)(f))

Where we rely on your consent, you can withdraw it at any time by writing to us. Withdrawing consent does not affect anything we did before you withdrew it. We may not be able to carry on a project without the data it needs.

We do not sell personal data, use it for advertising, or add you to a mailing list.

Indian law that applies

We handle personal data in line with the Digital Personal Data Protection Act 2023 and the rules made under it, to the extent they are in force. We also follow the Information Technology Act 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011, known as the SPDI Rules, to the extent they apply.

Under the SPDI Rules, "sensitive personal data or information" includes passwords, financial information, health information and biometric data. We do not collect it through this website. If a client shares it with us during a project, we handle it only under that project's written agreement and only for that project.

Who we share it with

We share personal data only with service providers who help us run the business or deliver a project. They process it on our instructions. The types of provider are:

  • Hosting. The server that runs this website and the contact form, including its server logs.
  • Email. The services that carry and store our email, including inquiries from the contact form, account emails from app.aispeedforce.com, and the outgoing mail (SMTP) provider we use to send them.
  • Analytics. Google Analytics 4, provided by Google, only if you accept analytics cookies. Google may process this data outside India, including in the United States.
  • Google reCAPTCHA. Spam protection on our forms, only while it is switched on.
  • Google sign-in. Only when you choose "Continue with Google".
  • AI model and API providers. During a project, the AI systems we build send data to the model and API providers chosen for that project.

The providers used on a project, including the AI model and API providers, are named in that project's agreement. Many are accounts you open and pay for yourself, as the terms explain.

We may also disclose personal data where Indian law or a lawful order requires it, or where we need to protect our legal rights.

Client confidentiality

During a project we may see your data, your systems and data about your customers. We treat all of it as confidential.

  • We use client data only to deliver the engagement it was shared for. We do not use it for anything else, and we do not use it for another client.
  • We access only the systems and data the task needs, using the access you grant. You can revoke that access at any time.
  • You own the code, prompts, tools and eval cases we build for you. Ownership passes to you on full payment, as set out in the terms.
  • At the end of the engagement we return or delete your data, as your project agreement says, unless the law requires us to keep a record.

AI systems keep records of what they did, such as run traces and logs. These records can contain personal data from your systems. They are kept in accounts you control, or handled as your project agreement sets out.

International transfers

We are based in India, so personal data we receive is handled in India. Some of our service providers, and the AI model and API providers on a project, may store or process data in other countries.

If you are in the EU or the UK, sending your data to us in India is an international transfer. We rely on it being necessary to answer your inquiry or deliver the contract you asked for. Where a project involves ongoing transfers, we agree suitable safeguards with you, such as standard contractual clauses, in the project agreement.

We will not transfer personal data to a country the Government of India has restricted under the DPDP Act.

How long we keep it

We keep personal data only as long as we need it for the purpose it was collected for, or as long as the law requires.

  • Inquiries that do not become a project: kept while we discuss the work with you, then deleted when it is clear the conversation has ended, unless you ask us to keep it.
  • Client correspondence, contracts and invoices: kept for as long as Indian tax and accounting law requires.
  • Client project material: kept during the engagement, then returned or deleted as your project agreement says.
  • Connected apps and agents: until you disconnect them; token records 30 days after expiry; unconfirmed agent registrations after 7 days.
  • Scan log: deleted after 90 days. Cached reports and rate-limit hashes: within an hour.
  • Free accounts: unconfirmed accounts after 7 days; confirmed accounts, their sites and reports when you delete the account; sign-in attempts after 30 days; logs of admin access to an account after one year.
  • Server logs: kept for a limited period for security and troubleshooting, then rotated out and deleted.

You can ask us to delete your data sooner. See your rights.

How we protect it

We take reasonable steps to protect personal data from loss, misuse and unauthorized access. They include:

  • serving the whole website over encrypted HTTPS connections;
  • limiting access to inquiries and client material to what the work needs;
  • asking for the narrowest access a task needs on a client's systems, using credentials the client can revoke;
  • keeping write actions behind human approval by default in the AI systems we build; and
  • deleting data we no longer need.

No system is fully secure. If a personal data breach affects you, we will tell you and the authorities required by law, without undue delay.

Your rights

Under India's DPDP Act 2023

As a Data Principal you have the right to:

  • get a summary of the personal data we hold about you and how we use it, and the identities of those we have shared it with;
  • have your personal data corrected, completed, updated or erased;
  • withdraw consent you have given;
  • have a grievance about our handling of your data answered; and
  • nominate another person to exercise your rights if you die or become unable to.

If you are not satisfied with our answer to a grievance, you can complain to the Data Protection Board of India.

Under the EU and UK GDPR

If you are in the EU or the UK, you have the right to:

  • access your personal data and get a copy of it;
  • have inaccurate data corrected;
  • have your data erased;
  • restrict how we use your data;
  • receive your data in a portable format;
  • object to our use of your data where we rely on legitimate interests;
  • withdraw consent at any time; and
  • complain to the data protection authority in the country where you live or work. In the UK this is the Information Commissioner's Office.

How to exercise your rights

Email support@aispeedforce.com and say which right you want to use. We may ask you to confirm your identity before we act, so we do not hand your data to someone else.

We respond within 30 days. Using your rights is free. If a request is clearly unfounded or excessive, we will tell you why we cannot act on it.

If your request is about data in a client's systems, where we act as a processor, we will pass it to that client and help them answer it.

Children's data

Our services are for businesses. This website is not directed at anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has sent us personal data, contact us and we will delete it.

Cookies

This website sets analytics cookies only if you accept them. See what we collect.

If you use the theme button, your browser saves your light or dark choice on your device. It is never sent to us. The cookie policy explains this in detail.

Changes to this policy

When we change this policy, we publish the new version on this page and update the "Last updated" date and the version history. If a change materially affects how we use personal data we already hold, we will also tell current clients by email before it takes effect.

Grievance Officer

Under India's DPDP Act 2023 and the Information Technology Act 2000 and its rules, you can raise a grievance about how we handle your personal data. Our Grievance Officer is:

We acknowledge a grievance and give a full response within 30 days of receiving it.

Read this policy with our terms of service, refund and cancellation policy, cookie policy and disclaimer.

Contact

AI SpeedForce is run by Poonam Devi as a sole proprietor. Questions about this document, or any of our policies, go to:

Effective date: 22 September 2026
Last updated: 24 September 2026

Version history

VersionDateChange
1.022 September 2026First published version.
1.122 September 2026Cookie and privacy policies: added the light or dark theme choice saved in your browser.
1.222 September 2026Privacy policy: the inquiry email also records the time, IP address and user agent of the submission.
1.322 September 2026Privacy policy and disclaimer: added the agent-readiness scanner.
1.422 September 2026Disclaimer: platform logos are trademarks of their owners.
1.523 September 2026Privacy and cookie policies: inquiries are also stored in the site database; analytics wording applies automatically if Google Analytics is switched on.
1.623 September 2026Privacy, cookie and terms: free accounts on app.aispeedforce.com, what they store and for how long, and the rules for the free tools.
1.723 September 2026Privacy policy: the agent-readiness scan now keeps a 90-day log of each scan, including IP address, country and browser.
1.823 September 2026Privacy policy: apps and AI agents you connect (OAuth and MCP), signed scanner requests; reCAPTCHA and Google sign-in wording applies automatically when those are switched on.
1.924 September 2026Privacy and cookie policies: wording for Google consent mode (advanced or basic), applied automatically from the analytics setting.
AI SpeedForce
Start a project Log in