Legal
ANSI is built to help you decide things, which means you tell it what you are trying to work out. This policy explains what happens to that information — what reaches us, why we need it, who else is involved, how long it stays, and what you can ask us to do with it.
ANSI is a decision intelligence platform. People come to it with something they are trying to work out — whether a change matters to them, how two options compare, what a piece of news actually means for their work — and ANSI reads, checks and organises information to help them answer it.
That exchange only works if you tell ANSI what you are trying to decide. So the honest starting point for this policy is that using ANSI means sharing information with it, and you are entitled to know what happens next.
This policy covers ansi.com and the ANSI product. It explains the information involved, why each kind is needed, when other companies are part of the picture, how long information stays, how it is protected, and what you can ask us to do. It does not cover other websites we link to; those are governed by their own policies.
Throughout, personal information means information that identifies you or could reasonably be linked to you. Privacy laws around the world use different terms for that idea — personal data, personally identifiable information — and where a law that applies to you uses its own term, that term is what governs your situation.
The policy is written to be read rather than skimmed past. If something in it is unclear, that is worth telling us about; the contact route is at the end.
Information reaches ANSI in three ways: you hand it over deliberately, you produce it by using the product, and a small amount arrives automatically because that is how the web works. Each is described below.
Some information you provide on purpose. If you create an account, that includes the details needed to identify it and let you sign back into it — typically a name and an email address. If you write to us, it includes whatever you chose to write and the address we reply to.
This is the most straightforward category, and also the one you have the most direct control over: it exists because you typed it.
Using ANSI means telling it things. That includes the questions you ask, any content you paste or upload for it to work with, the domain you declare so results can be scored for your situation rather than in the abstract, the topics and entities you choose to follow, and the feedback you give on whether an answer was useful.
None of this is collected in the background — every item is something you deliberately submitted. But it is the most revealing category of information ANSI holds, because taken together it describes what you are working on. It gets its own section below.
A small amount of information arrives without anyone typing it. When your browser asks a web server for a page, the request itself carries technical details the server needs in order to answer: your IP address, so the response knows where to go; the type of browser and device you are using, so the page can be sent in a form that works; and the address of the page being requested. This is true of every website you visit, not just this one — it is the mechanism by which the web functions rather than a feature of ANSI.
Beyond that necessary minimum, ANSI uses cookies and similar technologies. Some are required for the service to run; others are optional and are not set unless you agree to them. The Cookie Policy names each one individually.
Information is used for the purposes below. Each one is a reason ANSI needs it, not a category we might expand into later.
This is the main one. When you ask ANSI something, the question has to be read, relevant material has to be gathered and checked, and a response has to be produced and sent back to you. Your account and settings determine what you can reach and how results are scored for you.
Running a service means routing requests to servers that can handle them, keeping the system available, and finding out what went wrong when something breaks. Log information is what makes a failure diagnosable after the fact rather than a mystery.
Any service that accepts input from the public is a target. Technical information — patterns of requests, addresses, timing — is what makes it possible to tell ordinary use apart from an attempt to abuse the service, take over an account, or overwhelm it.
When you write to us, we use what you sent and your contact details to reply, and to follow up if the matter needs it.
Understanding which parts of ANSI are used, and where people run into errors or dead ends, is how the product gets better. Optional analytics support this and are off until you turn them on.
Some uses are not discretionary. Where the law requires us to keep a record, respond to valid legal process, or act to protect people from harm, we do.
ANSI is an AI product, so the question of what happens to what you type into it deserves a proper answer rather than a sentence buried in a longer list. This section explains the mechanics.
Your question is read and interpreted — not just matched against keywords, but examined for what you are actually trying to establish. Relevant material is gathered, checked against sources, and organised into a response. That response is generated for your specific question rather than retrieved from a library of pre-written answers, which is why two similar questions can produce differently shaped results.
Producing a response involves processing your input. There is no version of an AI product where what you type is not read by the system you typed it into; the meaningful questions are what else happens to it, and who else sees it.
Some questions come with material attached — a document to summarise, a page to check, text to compare against something else. That content is processed for the purpose you submitted it for. Treat anything you upload the same way you would treat sending it to a colleague: submit what the task needs, and no more than that.
Working with ANSI produces things worth keeping — a signal you followed, a comparison you built, a question you want to return to. Those are associated with your account so you can find them again, which is the only reason they persist.
When you tell ANSI an answer was useful, wrong, or irrelevant, that judgement is attached to the response it refers to. Feedback is how a system that reasons under uncertainty finds out where it was overconfident.
Information is kept for as long as there is a reason to keep it, and no longer. What counts as a reason depends on what the information is:
Whether it is still needed to run the service. Account details are needed while the account exists; a saved comparison is needed while you might want to look at it again.
Whether it is needed to keep the service safe. Some technical records have to outlive the moment they describe in order to be useful in investigating abuse.
Whether the law requires it. Certain records must be retained for a set period regardless of whether we would otherwise keep them.
Whether it is needed to resolve something outstanding — a dispute, an unresolved support matter, or an enforcement question.
Backups. Systems are backed up so that data can be restored after a failure. Information removed from a live system persists in backups until those backups age out on their own cycle, which is why deletion is rarely instantaneous anywhere.
When none of those reasons applies any more, information is deleted or stripped of the details that connect it to a person.
Protecting information is a combination of technical measures, controls on who inside an organisation can reach what, and practices for noticing and responding when something looks wrong. All three matter; a strong measure in one area does not compensate for a gap in another.
This policy does not enumerate the specific technologies, tools or configurations in use. That is deliberate, for two reasons. A published list of defences is also a map for anyone trying to get past them. And a specific security claim should be independently verifiable before it appears on a public page, because a claim that turns out to be inaccurate is worse than no claim at all.
What can be stated plainly is this: no method of transmitting or storing information is completely secure, and any service that tells you otherwise is overstating its position. Where a security incident affects your personal information and the law requires notification, you will be told.
A privacy policy that only describes what a company does is half a document. This section is about what you can do.
You can ask what personal information is associated with you and ask us to correct anything that is wrong. If you hold an account, some of this is directly visible and editable by you; anything that is not, you can ask for.
You can ask us to delete personal information, including by closing your account. Two things are worth knowing before you do. Deletion is subject to the retention reasons above — where the law requires a record to be kept, it will be. And information already removed from live systems can persist in backups until those cycle out.
You can ask for a copy of the personal information we hold about you. Tell us what you are looking for and we will explain what we are able to provide and in what form.
Messages that are part of the service — a security alert, a notice about your account, a reply to something you asked — continue for as long as your account is open, because a service that cannot contact you about your own account is not operating safely. Anything promotional is separate and optional.
Optional cookies are not set until you agree to them, and you can change that decision at any time. Withdrawing agreement is as straightforward as giving it. The Cookie Policy covers this in detail.
Making a request. Any of the above can be requested through the contact route at the end of this policy. We may need to confirm your identity first — otherwise anyone could ask for a copy of your information — and if we do, we will tell you exactly what is needed rather than refusing without explanation.
Depending on where you live, you may have legal rights over your personal information in addition to the choices described above. Privacy laws differ considerably between countries and, in the United States, between states, so which rights apply to you depends on where you are.
The rights most commonly granted are the ability to ask what information an organisation holds about you and obtain a copy; to have inaccurate information corrected; to have information deleted; to receive it in a portable format; and, in some places, to object to or restrict certain uses, or to withdraw agreement you previously gave.
Most of these rights come with exceptions written into the law that grants them — a deletion request does not override a legal obligation to retain a record, for instance. Rather than list which rights apply to which readers, the practical route is simpler: tell us what you want to do, and we will tell you what we are able to do and why.
Privacy requirements are not the same everywhere. The protections that apply to you, the rights you can exercise, and the obligations placed on organisations handling your information all depend on the country — and sometimes the state or province — you are in.
Using an online service also usually means information crosses a border at some point, because the servers involved are rarely in the same place as the person using them. Where that happens, the protections available in your own country may differ from those where the information is processed.
If you have a question about how this policy applies where you live, ask us. That is a better use of your time than working it out from a page written for everybody.
Cookies are small files a website asks your browser to store, so that it can recognise the browser on a later visit. ANSI uses a small number of them. Some are necessary for the service to function — keeping you signed in, protecting your account, remembering the cookie choices you have already made. The rest are optional and are not set unless you agree.
The detail lives in the Cookie Policy. It lists every cookie by name, with who sets it, how long it lasts, what it does, and how to switch the optional ones off. It is maintained separately from this policy and updated whenever the cookies in use change. Read the Cookie Policy.
This policy will change — because practices develop, because the product grows, and because the law that governs both moves. The date at the top of the page always reflects the most recent update, so you can tell at a glance whether you are reading the current version.
Where a change materially affects how personal information is handled, we will give notice of it rather than relying on a silent edit. Continuing to use ANSI after a change takes effect means the updated policy is the one that applies.
Questions about this policy, requests about your personal information, and anything you think we have got wrong can all be sent through the contact page on ansi.com, and a person will reply.
If you are getting in touch to exercise a right or make a request, it helps to say what you are asking for and roughly when you used ANSI. That is usually enough for us to find the relevant information and tell you what we can do.