Privacy Policy

Last updated: 2 June 2026 · Version 0.1-draft

DRAFT — awaiting UK solicitor review. This is a structural scaffold with grounded placeholder copy. Every legal-effect decision is marked <!-- SOLICITOR: ... -->. Do not treat as final or publish-announce until a qualified UK solicitor has reviewed and the frontmatter status is PUBLISHED.

1. Who we are

FirstWeek ("we", "us") provides guidance for people in the UK facing redundancy. We are the data controller for the personal data described below.

2. What personal data we collect

3. Why we collect it — lawful basis (UK GDPR Art. 6)

4. How we use it

To run the service, send your magic-link, generate and display your action plan, process payments, prevent abuse, debug crashes, and improve the product.

5. Who we share it with

We use the following processors. Each has its own privacy notice.

Processor Purpose Region
Supabase Auth + database (your account/questionnaire/report data) EU (London eu-west-2 per DEPLOY.md)
Stripe Payments + fraud/3DS UK/EU
DeepSeek AI chat (fallback) — PII stripped before sending (sanitizeAiProfile) API: api.deepseek.com
Moonshot (Kimi) AI chat (primary) — PII stripped before sending (sanitizeAiProfile) API: api.moonshot.ai (default in app/api/chat/route.js)
PostHog Product analytics + session replay (input masking on) EU (eu.i.posthog.com default in components/PostHogProvider.jsx)
Vercel Hosting + CDN US
Upstash Rate-limit store (hashed IP/user key only) eu-west-1 (documented in CLAUDE_CODE_FIX_P0_SEQUENTIAL_PROMPT.md)

We do not sell your personal data.

6. International transfers

Some processors are outside the UK (notably the AI providers in China and Vercel in the US).

7. How long we keep it

8. Your rights

You can ask to access, correct, erase, port, restrict, or object to processing of your data, and withdraw consent. To exercise any right, email privacy@firstweek.co.uk. You can also complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.

9. Children

The service is intended for adults.

10. Cookies and tracking

11. Contact

Data protection enquiries: privacy@firstweek.co.uk (see §1; inbox monitoring not verified in-repo) .

12. Changes to this policy

We will update the version and effective_date above for any material change and notify users .

Need help? ACAS: 0300 123 1100