Privacy Policy

Last updated: 29th July 2026

This Privacy Policy outlines how we collect, use, protect, and share information about you when you use our media form, media channel, software, application, mobile website or mobile application related, linked, or otherwise connected thereto (collectively, the "Service") through access to and use of the machined.ai website (the "Website") operated by Sibu Ventures Ltd ("us", "we", "our" or “Sibu Ventures”). By accessing or using the Website and/or the Service, you agree to this Privacy Policy.

We value your privacy and strive to protect your personal data in compliance with global privacy standards, including the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and the California Consumer Privacy Act (CCPA).

Definitions

  • Personal Data: Information about an individual that can be identified from those data (or from those and other information either in our possession or likely to come into our possession).
  • Usage Data: Data collected automatically, generated by the use of the Service or from the Service infrastructure itself (e.g., the duration of a page visit).
  • Cookies and Similar Technologies: Cookies, localStorage, sessionStorage, and similar mechanisms used to store information on, or read information from, your device.
  • Data Controller: For the purposes of this Privacy Policy, we are the Data Controller of your Personal Data.
  • Data Processors (Service Providers): Any natural or legal person who processes the data on behalf of the Data Controller.
  • Data Subject (User): Any living individual who is using our Service and is the subject of Personal Data.

Data Controller

Sibu Ventures Ltd (“Sibu Ventures”, “we”, “us”, or “our”) is the Data Controller responsible for your personal data.

Registered Office: Suite A, 82 James Carter Road, Mildenhall, IP28 7DE, United Kingdom
Company Number: 14958943
Contact: privacy@machined.ai

Types of Data Collected

(a) Personal Information You Disclose to Us

We collect personal information that you voluntarily provide when you register, express interest in obtaining information, use our services, or contact us. This may include:

  • Contact Information: Name, business name, email address, website URL.
  • Credentials: Passwords, authentication data, and API keys.
  • Payment Information: Payment instrument details (e.g., credit card number). Payment data is processed by our payment provider Stripe and not stored on our servers.

(b) Information Automatically Collected

  • Usage Data: Includes your IP address, browser type and version, pages visited, date/time of visit, time spent on pages, and device identifiers.
  • Approximate Location Data: We do not request precise device-level location (GPS) or browser geolocation permissions. However, several of our service providers (including Intercom, PostHog, Sentry, and Vercel) automatically derive approximate location — typically country, region, and sometimes city — from your IP address. This is used to route customer support, generate aggregate analytics, diagnose errors, and detect abuse. Stripe additionally processes the full billing address you provide for payment and tax compliance purposes.

(c) Cookies and Similar Technologies

We do not use cookies or similar tracking technologies for advertising or cross-site profiling. What is stored on your device differs between our marketing website and the Machined application, and is limited to the following.

On our marketing website (machined.ai):

  • Affiliate attribution (Tolt): When a visitor arrives via an affiliate link containing an affiliate URL parameter, our affiliate provider Tolt records the referring affiliate using browser storage (localStorage and/or a first-party cookie) so that a future signup can be attributed to the correct affiliate. The Tolt script is loaded on every page of our marketing website. The identifier stored in your browser is personal data under UK and EU data protection law. You can block this by disabling third-party scripts or browser storage in your browser settings, without affecting your ability to use the Service.
  • Analytics (PostHog and Vercel Analytics): On our marketing website, analytics are configured not to store anything on your device — PostHog runs in cookieless mode and Vercel Analytics does not use cookies.
  • Testimonial widget (Senja): Our homepage embeds a third-party widget from Senja that displays customer testimonials. When the widget loads, Senja may set cookies or use similar storage in your browser. We do not control these cookies; please refer to Senja's Privacy Policy for details. You can block this by disabling third-party scripts or browser storage.

Within the Machined application (logged-in users):

  • Authentication and session cookies (Supabase): Strictly necessary first-party cookies that keep you signed in and secure your session.
  • Site access cookies: Where applicable, strictly necessary cookies are used to remember basic password access and to permit access during maintenance windows.
  • Product analytics (PostHog): Within the Machined application, PostHog sets first-party cookies and browser storage to measure feature usage and link activity to your account. If you would prefer we disable this for your account, contact privacy@machined.ai.
  • Abuse prevention (Fingerprint): We read technical characteristics of your browser and device to generate a device identifier, which is stored against your account. The identifier is read whenever you sign in, so that it stays current, but it is only acted upon when a new account is being created — see Automated Decision-Making below. It is used solely for this purpose, and only within the Machined application.

The session, authentication, and site-access cookies described above are first-party and strictly necessary for the Service to function. Because an ordinary visit to our marketing website does not store anything on your device, we do not display a cookie consent banner there. If you would like analytics storage disabled for your account, contact privacy@machined.ai.

How We Use Your Information

We process your personal data to:

  • Provide, maintain, and improve our Service
  • Notify you about updates and changes
  • Enable participation in interactive features
  • Provide customer care and support
  • Conduct analytics to improve performance
  • Monitor and prevent security or technical issues
  • Fulfil contractual obligations and process payments
  • Comply with legal requirements

Lawful Basis for Processing

Under both the UK GDPR and EU GDPR, we rely on one or more of the following lawful bases:

PurposeLawful Basis
Account registration and service deliveryPerformance of a contract (Art. 6(1)(b))
Marketing communicationsConsent (Art. 6(1)(a))
Publication of customer testimonialsConsent (Art. 6(1)(a)) where a testimonial is given to us directly; legitimate interests (Art. 6(1)(f)) where it is imported from a public post or review
Analytics and service improvementLegitimate interests (Art. 6(1)(f))
Legal and compliance obligationsLegal obligation (Art. 6(1)(c))
Fraud prevention and securityLegitimate interests (Art. 6(1)(f))

Administrative Access

We may access your personal data to:

  • Provide customer support and assistance. This includes responding to your inquiries, requests for technical support, and other customer support requests.
  • Investigate and respond to complaints or concerns. This includes investigating and responding to complaints or concerns about our Service, including complaints or concerns about the completenes or accuracy of the information we have collected about you.
  • Ensure compliance with our policies and legal requirements such as the GDPR and other data protection laws.
  • Protect our rights and property. This includes protecting our rights and property, including our intellectual property rights and our property rights.

This access is required for us to provide you the best possible service and to comply with our legal obligations. The access is limited to the minimum necessary to perform the tasks described above.

Data Sharing and Sub-Processors

We share personal data with the following third-party service providers acting as data processors. All processors have Data Processing Agreements in place and are required to handle your data in accordance with applicable data protection law.

We may also share your personal information in connection with a merger, acquisition, or sale of assets, or when disclosure is necessary to comply with law, protect rights, prevent fraud, or ensure safety.

Infrastructure & Hosting

ProviderPurposeData SharedLocationTransfer Mechanism
SupabaseDatabase & authenticationAccount data, content, usage dataEUSCCs
VercelApplication hostingRequest logs, IP addressesUSSCCs
RenderBackground job processing (worker tier)Job metadata, article/project identifiersUSSCCs
InngestBackground job orchestration (article and content cluster generation)User ID, project ID, article ID, keywords, titles, target audience, research settings, custom instructions, media settingsUSSCCs

Legacy Sub-Processors (Decommissioning)

As part of our recent platform migration, the following service is being decommissioned. We have stopped sending new data to it and are working to delete all residual data. Until that deletion is complete, the service remains a sub-processor for the data it still holds. We are targeting full deletion by the end of June 2026.

ProviderStatusData Still HeldLocationTransfer Mechanism
Bubble.ioFrozen snapshot; no longer receiving updates; full deletion targeted by end of June 2026Full historic database from our previous platform as of the migration date, including account data, content, and usage data. The database is not synchronised with our current platform and is no longer used to deliver the Service.USSCCs

AI Processing

ProviderPurposeData SharedLocationTransfer Mechanism
AnthropicAI content generationKeywords, article briefs, generated contentUSSCCs
OpenAIAI content generation & embeddingsKeywords, article briefs, generated contentUSSCCs
Google (Gemini)AI content generationKeywords, article briefs, generated contentUSSCCs
OpenRouterAI routing fallback and BYOK pass-through (forwards requests to Anthropic, OpenAI, or Google Gemini)Keywords, article briefs, generated content, request metadataUSSCCs
PerplexityDeep research and grounded query responsesResearch queries and source URLsUSSCCs
Black Forest Labs (Flux)AI image generationImage prompts, generated imagesEU/USSCCs
LangfuseAI quality monitoring & service improvementAI prompts, generated outputs, model usage metadataEUSCCs

Note on AI processing: When you use Machined to generate content, your inputs (keywords, article briefs, brand voice settings, image prompts) and the resulting outputs are processed by the AI providers listed above solely to deliver the service. Anthropic, OpenAI, Google (Gemini), OpenRouter (which routes only to Anthropic, OpenAI, or Gemini), and Langfuse do not use your data to train their AI models under our agreements with them. Perplexity and Black Forest Labs may, under their respective terms, use submitted prompts and outputs to operate, secure, and improve their services, including model improvement; please see their privacy policies (Perplexity, Black Forest Labs) for details. We minimise the data we send to these providers to what is necessary to fulfil your request. Generated content is also monitored via Langfuse for service quality and improvement.

Payments & Communications

ProviderPurposeData SharedLocationTransfer Mechanism
Stripe (Stripe Payments Europe, Limited)Payment processingBilling information, transaction dataEU (Ireland)N/A
LoopsTransactional & marketing emailEmail address, name, account statusUSSCCs
IntercomCustomer supportName, email, support conversation dataUSSCCs

Analytics & Monitoring

ProviderPurposeData SharedLocationTransfer Mechanism
PostHogProduct analytics (signed-in app and marketing site)Pseudonymous user ID, workspace ID, role, plan, BYOK status, usage events, page views, IP-derived approximate locationEUSCCs
Vercel AnalyticsPrivacy-focused page-view analytics (marketing site and app)Page URLs, referrers, viewport, pseudonymous visitor signalsUSSCCs
SentryError monitoringError logs, stack traces, pseudonymous user identifiersUSSCCs
ChartMogulSubscription & revenue analytics (MRR, churn, retention) — ingests subscription data from StripeCustomer name, email, billing country, subscription plan, transaction and subscription event data (sourced from Stripe)EU (Germany)N/A

Fraud Prevention & Security

ProviderPurposeData SharedLocationTransfer Mechanism
FingerprintDevice identification for abuse prevention only (detecting duplicate or automated account creation)Device and browser attributes, visitor identifier, IP addressEU (Frankfurt, Germany)SCCs

Research & Search

ProviderPurposeData SharedLocationTransfer Mechanism
FirecrawlWeb research (user-initiated)URLs submitted for content researchUSSCCs
SerperSearch data (user-initiated)Keywords submitted for SERP analysisUSSCCs
DataForSEOKeyword data (user-initiated)Keywords submitted for volume/difficulty dataUSSCCs
Keywords EverywhereKeyword data fallback (user-initiated)Keywords submitted for volume/difficulty dataUSSCCs
ProAPIs / SerpsBotSERP data fallback (user-initiated)Keywords submitted for SERP analysisUSSCCs
YouTube Data API (Google)Video search (user-initiated)Search queries submitted for video discoveryUSSCCs

Stock Media

ProviderPurposeData SharedLocationTransfer Mechanism
UnsplashStock image search and retrieval (user-initiated)Search query termsUSSCCs
PexelsStock image search and retrieval (user-initiated)Search query termsUSSCCs

Affiliate & Referral

ProviderPurposeData SharedLocationTransfer Mechanism
ToltReferral attribution (script loaded on all marketing pages)Referral parameters, page-load events, browser storage identifiersUSSCCs

Embedded Content & Social Proof

ProviderPurposeData SharedLocationTransfer Mechanism
SenjaTestimonial display (embedded widget on our marketing website)Reviewer name, testimonial content (text, image, and/or video), optional profile metadata (job title, photo, company); IP address and widget interactions of website visitorsUK (provider); US (hosting)None in place — see note below

We use Senja to display customer testimonials on our marketing website via an embedded widget. The reviews shown come from two sources: posts and reviews that customers have published publicly on third-party platforms, which we import; and testimonials that customers have given to us directly, which we upload. Where a testimonial was given to us directly, we rely on that customer's consent to publish it, and they may withdraw it at any time. Where it was imported from a public post, we rely on our legitimate interests in promoting the Service. If you are the author of a review displayed on our website and would like it removed, email privacy@machined.ai and we will remove it from public display and request its deletion from Senja.

Transfers to Senja. Senja is provided by Senja Proof LTD, a company established in the United Kingdom, which hosts data on infrastructure located in the United States. We do not currently hold a data processing agreement or Standard Contractual Clauses with Senja, and the United States has not been recognised as providing an equivalent level of data protection. When the widget loads on our website, Senja receives your IP address and may set cookies or use similar storage technologies in your browser. For details, see Senja's Privacy Policy.

User-Connected Publishing Destinations

Where you choose to connect a third-party content management system (CMS) — such as WordPress or Webflow — Machined will, on your instruction, transmit articles, media, and metadata to that destination using the credentials you provide. These services are not our sub-processors; they are third-party services that you (or your organisation) directly contract with, and you remain the controller of any content published to them. We process the credentials and connection details you provide solely to authenticate with and publish to the destination you selected.

DestinationPurposeData Transmitted
WordPress (self-hosted or WordPress.com)Publishing articles and media to a user-connected WordPress siteArticle content, media files, metadata, user-supplied authentication credentials
WebflowPublishing articles and media to a user-connected Webflow siteArticle content, media files, metadata, user-supplied authentication credentials

Embedded media in published content. Articles published via Machined may contain references to third-party media (for example, YouTube videos). Once content is published to your CMS, the destination platform — not Machined — controls how that content is rendered to your site visitors. In particular, WordPress's built-in oEmbed feature will typically transform a YouTube URL into a standard youtube.com iframe at render time, which causes Google/YouTube to set cookies on your visitors' browsers when the page loads (not only on video play), regardless of any cookie posture Machined applies in its own preview. As the operator of the destination site, you are the controller for processing that takes place on your site, including any cookie or consent disclosures that may be required under UK PECR, EU ePrivacy, or other applicable rules. Machined does not control, and is not responsible for, embed rendering, cookies, or trackers set by third parties on your destination site.

Note on EU-hosted providers. Where a provider stores data in the EU but the provider itself is established outside it, we retain Standard Contractual Clauses to cover administrative and support access by that provider's non-EU entities. This is why some providers are listed with an EU location and SCCs rather than "N/A".

Copies of the relevant SCCs can be requested by emailing privacy@machined.ai

Payments

We may provide paid products and/or services within the Service. In that case, we use third-party services for payment processing (e.g. payment processors).

We will not store or collect your payment card details. That information is provided directly to our third-party payment processors whose use of your personal information is governed by their Privacy Policy.

These payment processors adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of payment information.

The payment processors we work with are: Stripe

Their Privacy Policy can be viewed at https://stripe.com/us/privacy

Retention of Data

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including:

  • Account data: Retained while your account is active and for up to 3 years after closure.
  • Payment records: Retained for 7 years to comply with tax and accounting laws.
  • Marketing data: Retained until consent is withdrawn, with inactive contacts reviewed after 2 years.
  • Device identifier (abuse prevention): Stored as part of your account record and retained for as long as your account exists, then deleted in line with the account data period above.
  • Records of refused signups: Where a signup is refused as a duplicate, we keep a record of the refusal — including a hashed email address, the device identifier, and the account it matched — so that we can review the decision if you contact us. These records are deleted automatically 30 days after the refusal.

International Data Transfers

Your personal data may be transferred to and processed in countries outside the UK or EEA.

We ensure appropriate safeguards are in place, including:

  • The UK International Data Transfer Addendum (IDTA), or
  • The EU Standard Contractual Clauses (SCCs).

The UK has been recognised by the European Commission as providing an adequate level of protection (Commission Implementing Decision (EU) 2021/1772), so transfers from the EEA to the UK are permitted without additional safeguards.

Copies of relevant safeguards may be requested at privacy@machined.ai.

Your Privacy Rights

Depending on your location, you have the following rights regarding your personal data:

  • Access: Request a copy of the data we hold about you.
  • Rectification: Request correction of inaccurate or incomplete data.
  • Erasure (“Right to be Forgotten”): Request deletion of your personal data.
  • Restriction: Request limited processing of your data.
  • Data Portability: Receive your data in a structured, commonly used format.
  • Objection: Object to processing based on legitimate interests or direct marketing.
  • Withdrawal of Consent: Withdraw consent at any time (without affecting prior processing).

To exercise any of these rights, email us at privacy@machined.ai. We will respond within 30 days as required under the GDPR.

You also have the right to lodge a complaint:

  • UK residents: With the Information Commissioner’s Office (ICO) – https://www.ico.org.uk
  • EEA residents: With your local data protection authority.

EU Representative

Machined has appointed a representative in the European Union to act as our contact point for supervisory authorities and data subjects in the EU.

This representative will handle any GDPR-related inquiries or data subject requests concerning our processing of personal data of individuals located in the European Economic Area (EEA).

The representative is: Data Privacy and Security Services Ltd (Trading as Data Privacy Services)

The representative's contact details are: info@dataprivacyservices.co.uk

CCPA Privacy Rights (California Residents)

Under the California Consumer Privacy Act (CCPA), California residents have the right to:

  • Know the categories of personal information we collect and how it is used
  • Request deletion of personal information
  • Opt out of the sale or sharing of personal information (we do not sell personal data)
  • Receive equal service and price even if privacy rights are exercised

Requests can be made by emailing privacy@machined.ai.

Children’s Privacy

Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe a child has provided us with data, contact us immediately at privacy@machined.ai, and we will delete it promptly.

Security of Data

We use industry-standard security measures to protect your personal data. However, no online transmission or storage system is completely secure, and we cannot guarantee absolute security.

Automated Decision-Making

We use automated checks to detect fraudulent or abusive use of the Service, including the creation of multiple accounts to obtain repeated free trials. These checks assess signals such as device and browser characteristics, a visitor identifier generated by our fraud-prevention provider Fingerprint, and your IP address, in order to identify signups that appear to duplicate an existing or previous account.

Where a new signup is identified as coming from a device already associated with an existing account, it is refused automatically, without human involvement at the point the decision is made. Your signup will not complete and you will not have an account. This check applies only when a new account is created.

If you believe a decision was made in error, you have the right to obtain human intervention, to express your point of view, and to contest the decision. Contact us at support@machined.ai and a member of our team will review the flagged account together with any information you provide, and will reverse the decision where the flag was incorrect. We consider that this decision does not produce legal effects concerning you or similarly significantly affect you, as it concerns the creation of an additional account rather than access to an existing account or to any essential service; we provide the safeguards described above regardless. Separately, our payment provider Stripe operates its own automated fraud screening on card payments, which may decline a transaction; that screening is described in Stripe's own privacy policy.

Our Service may contain links to third-party websites. We are not responsible for their content or privacy practices. Please review their privacy policies before providing any personal information.

Changes to This Privacy Policy

We may update this Privacy Policy periodically. Any changes will be posted on this page with an updated “Last Updated” date. Continued use of our Service after such updates constitutes your acceptance of the new terms.

Contact Us

For any questions about this Privacy Policy or your personal data, please contact us:

  • Email: privacy@machined.ai
  • Address: Sibu Ventures Ltd, Suite A, 82 James Carter Road, Mildenhall, IP28 7DE, United Kingdom