Privacy Policy
Last updated: 14 September 2026
Ready Pip is operated by READY PIP LTD, company number 17265908, registered at 246 Coventry Road, Hinckley, United Kingdom, LE10 0NG. We are the controller of account, service administration and website visitor data described here. Contact privacy@readypip.com.
1. What this policy covers
This policy covers readypip.com, the Ready Pip web app and mobile app. Ready Pip helps a venue owner plan content, draft and approve single-image Instagram and Facebook Page posts, schedule publishing and understand performance. Google Calendar access is read-only. Review management, teams, advanced publishing formats and billing are not currently available. Connected platforms have their own privacy policies.
2. Information we process
- Account and venue details: your internal account identifier, name, email address and the venue details you supply. Google sign-in provides identity information to authenticate you; it does not by itself connect your Calendar or social accounts.
- Your content: chat messages and responses, uploaded photos, captions, brand information, drafts, approvals and scheduling preferences.
- Google Calendar: when separately authorised, calendar identifiers, names and events from the one calendar you select, used to plan content. Credentials are stored server-side. We do not edit your calendar.
- Instagram: the authorised professional account’s identifier and username, media and post records, publishing results, and audience and content insights such as reach and interactions.
- Facebook: the Pages you can manage and your Page tasks, the selected Page’s identifier and name, and publishing records. Instagram and Facebook use separate connections and access credentials.
- Service administration: report requests, email preferences, delivery status, support correspondence, authentication and operational records needed to run and protect the service.
- Optional web analytics: only after acceptance, page categories and selected actions such as signing in, setup, requesting a report, chatting and approving a post. These use a random analytics identifier, or your internal account UUID when signed in. They do not include message text, captions, photos, email addresses, Meta identifiers, access credentials, query strings or URL fragments. The receiving service necessarily handles connection information such as an IP address; we disable IP-based location enrichment in our events.
3. Purposes and legal bases
We use account, content and connected-platform data to provide the service you request, under our contract with you. You choose which platforms to connect and can disconnect them. We use legitimate interests to secure the service, diagnose failures and answer support requests, taking account of your rights. We use consent for optional analytics and optional email communications, and comply with legal obligations where applicable. Necessary service emails, such as account or security notices, are separate from optional communications.
We do not sell personal data or transfer Meta Platform Data to data brokers. We use Platform Data to deliver the authorised Ready Pip features, not for advertising or surveillance. Where you provide personal data about staff, customers or others, supply only what you are entitled to share and what is needed for the task. For venue personal data we process on your instructions, you determine the purpose and act as controller; we act as processor. Contact us for processing terms before uploading data that requires a separate agreement.
4. AI processing and stored history
Pip sends relevant messages, selected venue context, content and tool results to OpenRouter, which routes inference requests to selected model hosting providers. Our approved route uses Google Vertex AI as the inference provider. The current model is Gemini 3.8 Flash; the model version and the company hosting inference are separate choices. We may change models after checking their suitability and data handling, and update this policy when processing arrangements materially change.
Our routing requirements pin the approved provider, request zero data retention (ZDR) and deny provider data collection/training, with provider and model fallbacks disabled. If a compliant route is unavailable, the request must fail. OpenRouter prompt logging, input/output sharing and optional OpenRouter plugins are not part of this approved configuration.
These controls concern inference input and output. ZDR still involves transient processing and can include in-memory caching under OpenRouter’s ZDR rules. It does not mean that all Ready Pip data is never stored: we store conversations, drafts, approvals, reports and operational records to provide the product, and hosting and service providers process operational metadata. Backups are separate from inference processing. Credentials are not supplied to the model.
AI can make mistakes. You must review content before approving publication. We do not use Pip to make decisions about people with legal or similarly significant effects.
5. Providers and international processing
| Provider | Role |
|---|---|
| Supabase | Sign-in, database, access controls and uploaded-file storage |
| Railway | Application, backend and CMS hosting |
| Cloudflare | Marketing website hosting, content delivery and network protection |
| OpenRouter | AI request routing and inference service administration |
| Google / Google Vertex AI | Google sign-in and authorised Calendar access; separately, AI inference through OpenRouter |
| Meta Platforms | Authorised Instagram and Facebook connections, publishing and insights |
| PostHog | Optional analytics on the marketing website and web app, using our EU project |
| Pydantic Logfire | Backend operational traces for diagnosing failures and monitoring reliability |
| Notion | Handling information submitted to the website waitlist/free-report interest form |
| Resend | Service/report email delivery and delivery-status processing |
| Expo | Mobile application build and update delivery |
Providers receive the information needed for their role. An EU analytics project or a particular hosting region does not mean that every provider processes all information exclusively in the UK or EU. Processing and support may involve other countries. Applicable transfer arrangements depend on the provider and service, including adequacy arrangements or approved contractual safeguards where required. Contact us for information about the arrangements applicable to your data. We may also disclose data where the law requires it.
6. Analytics choices
The marketing site and web app offer equally accessible Accept analytics and Reject analytics controls. Essential sign-in and security storage is separate. Choosing either analytics option does not affect access to the app. The preference cookie lasts 180 days, shared between our production website and app subdomains. Local and preview sites use host-only preferences. If you accept, a separate random analytics identifier is stored for up to 180 days; this identifier is cleared when you withdraw consent.
Use Analytics preferences at the bottom of either web surface to change your choice. Withdrawal stops further analytics requests and clears local analytics identifiers; it does not automatically erase events already received. To request their deletion, contact us. Autocapture, session replay, heatmaps, surveys and automatic exception collection are not enabled by this integration. No optional PostHog analytics is added to the mobile app by this integration.
7. Retention and deletion
We retain account and venue records while needed to provide your account, content history and connected services. Operational records are kept according to their support, security and reliability purpose; we review continued need and remove or de-identify records that are no longer necessary. Optional analytics is retained according to the project’s configured retention and continued product-analysis need. You can ask us for the current periods.
For deletion requests we remove active service records and request relevant provider deletion, subject to identity checks and any lawful exceptions. Disconnected credentials are removed from Ready Pip; disconnection alone does not erase historical content or revoke the underlying grant at the provider. Backup copies expire according to the applicable backup lifecycle and are not used for ordinary service access. If a backup is restored, deletion requests must be reapplied. We may retain limited information to comply with law, resolve disputes or document the handling of your request, and explain any exception that applies.
See Data Deletion Instructions for how to request deletion and what happens to posts already published on your social accounts.
8. Security and your rights
We use encrypted connections, restricted access and server-side credential storage. No system is perfectly secure. We handle incidents and required notifications in accordance with applicable law.
You can ask to access, correct, delete, restrict or transfer your data, object to relevant processing, or withdraw consent. Email privacy@readypip.com. We normally respond within one month; if a lawful extension is needed, we will explain why within that period. You can complain to the Information Commissioner’s Office.
Ready Pip is a business service for adults, not directed at children under 18. We update this page when our practices change and notify users of significant changes through the service or email.