Privacy Policy

Ash, Virtual BA ash.businessanalyststoolkit.com

Last updated: April 2026

About this policy

This Privacy Policy explains how Ash, Virtual BA, operated by Sam Cordes, collects, uses, stores, and protects your personal information when you use our service at businessanalyststoolkit.com. By registering for or using Ash, you agree to the practices described in this policy.

Who we are

Ash is a free AI-powered business analysis knowledge tool operated by Sam Cordes, based in Coffs Harbour, New South Wales, Australia. We can be contacted at sam@businessanalyststoolkit.com.

What information we collect

When you register for Ash, we collect the following personal information:

If you register using email and password, we collect your first name, last name, and email address.

If you register or sign in using Google Sign-In, we collect your name and email address from your Google account. We request only the minimum information necessary to create and manage your account. We do not access your Google contacts, Gmail, Google Drive, calendar, or any other Google account data beyond your basic profile and email address.

When you use the Ash chat feature, we collect your chat messages and the responses generated by the AI. We also collect token usage data to manage your monthly usage allowance.

We collect standard technical information including your IP address, browser type, and pages visited, for security and service improvement purposes.

How we use your information

We use the information we collect solely to provide and improve the Ash service. Specifically we use it to:

Create and manage your user account. Authenticate your identity when you log in, including via Google Sign-In. Provide you with access to the Ash glossary and AI chat features. Track your monthly token usage against your plan limit. Send you transactional emails such as your welcome email and support responses. Improve the accuracy, relevance, and quality of Ash’s responses over time.

We do not use your information for advertising. We do not sell your personal information to any third party. We do not use your Google user data for any purpose other than providing and improving Ash’s functionality as described above.

Google user data

Our use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, we use Google user data only to authenticate your identity and create your Ash account. We do not transfer your Google user data to third parties except as necessary to operate the service, as described in the Third Parties section below. We do not use Google user data to serve advertisements. We do not allow humans to read your Google user data unless you have given explicit permission, it is necessary for security purposes, or we are required to do so by law.

Third parties

We share your information with third parties only where necessary to operate the service:

Anthropic provides the AI model that powers Ash’s chat responses. Your chat messages are processed by Anthropic’s API to generate responses. Anthropic’s privacy policy is available at anthropic.com/privacy.

Make.com is the automation platform that routes chat requests between our WordPress site and the Anthropic API. Your messages pass through Make.com’s infrastructure as part of this process.

WordPress and our hosting provider store your account data and usage records securely on servers located in Australia or the European Union.

We do not share your information with any other third parties. We do not sell, transfer, or disclose your Google user data to third parties for reasons other than providing or improving Ash’s functionality.

Data protection and security

We take reasonable and appropriate steps to protect your personal information against unauthorised access, use, disclosure, alteration, or destruction. These steps include:

All data transmitted between your browser and our service is encrypted using HTTPS. Passwords are stored using industry standard hashing. Access to user data is restricted to Sam Cordes and authorised service providers operating under confidentiality obligations. We regularly review our data collection, storage, and processing practices.

Data retention and deletion

We retain your account information for as long as your account remains active or as needed to provide you with the service.

We retain your chat history and token usage records for a period of 12 months, after which they are deleted.

If you delete your account, we will delete your personal information within 30 days, except where we are required to retain it by law.

You may request deletion of your account and personal information at any time by emailing sam@businessanalyststoolkit.com. We will confirm deletion within 30 days of your request.

Your rights

Under the Australian Privacy Act 1988 and the Privacy Principles, you have the right to:

Access the personal information we hold about you. Request correction of inaccurate or incomplete information. Request deletion of your personal information. Withdraw consent to our processing of your information at any time. Lodge a complaint with the Office of the Australian Information Commissioner at oaic.gov.au if you believe we have handled your information incorrectly.

To exercise any of these rights, contact us at sam@businessanalyststoolkit.com.

Cookies

Ash uses cookies and similar technologies to maintain your login session and remember your preferences. We do not use cookies for advertising or cross-site tracking. You can control cookies through your browser settings, however disabling cookies may prevent you from logging in to the service.

Children

Ash is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

Changes to this policy

We may update this Privacy Policy from time to time. When we make changes, we will update the date at the top of this page and notify registered users by email. Your continued use of Ash after any changes constitutes your acceptance of the updated policy.

Contact

If you have any questions about this Privacy Policy or how we handle your personal information, please contact:

Sam Cordes Ash, Virtual BA sam@businessanalyststoolkit.com, businessanalyststoolkit.com