Methos lets founders (“customers”) run short AI-led conversations with their users (“respondents”). This policy explains what happens to the data of both.
1. Who is responsible
- If you answered an interview, the founder or company that shared the link (named on the first screen of the conversation) is the controller of your data. Methos processes it on their behalf, as a processor under article 28 of the GDPR.
- If you have a Methos account, Methos (run by Eduardo García Ruiz, edu@getmethos.com) is the controller of your account and billing data.
2. Data about respondents
- The conversation: the messages you write and the interviewer's replies.
- Your email, if you choose to leave it at the end (to get your result, a copy of your answers or the results), or if the founder invited you by email. Founders on some plans can connect their Stripe account so that, when you cancel a subscription with them, we email you an invitation on their behalf, using the name and email they hold. You get one invitation per interview (or per cancellation) and no follow-ups.
- An AI-generated summary of the conversation for the founder: your answers to their questions, the main problems you mentioned, a short profile and a suggested next step. Only the founder who ran the interview can see it.
- Your result, when the conversation is a diagnostic: an AI-generated reading of your situation based only on what you said. You can see it at the end of the conversation and through a private link that works for 30 days, and download it as a PDF. The founder sees the same result and a short brief on how to follow up with you.
- Your permission to be contacted, if you tick the box at the end. It is optional, unticked by default, and separate from getting your result. Without it, the founder should not contact you about their product.
- The link you came from (for example “x” or “blog”), so the founder knows which channels work.
- Technical data: dates, the state of the conversation and your IP address, used for security and to limit abuse.
If the founder publishes a results page, it only shows counts and quotes the founder approved one by one. It never shows names or emails, and emails, links, phone numbers and @handles inside quotes are hidden automatically.
3. Data about customers (founders)
- Account data: email and name (sign-in is handled by Clerk).
- What you add to the Service: your product's public website, which we read to write your product brief and growth plan; diagnostics and interviews; documents and notes; brand settings.
- Billing data, handled by Stripe. We never see or store your full card number.
- Usage data about how the website is used (Google Analytics, if enabled).
4. Why and on what legal basis
- Running the conversation and summarising it for the founder: on behalf of the founder, who decides the legal basis (usually their legitimate interest in understanding their users, or your consent). You choose to start the conversation and can stop at any time.
- Emailing you your result, a copy of your answers or the results: your consent, when you leave your email and ask for it.
- The founder contacting you about their product: your consent, only if you tick the box. You can withdraw it at any time by telling the founder or writing to us.
- Providing the Service to customers and billing them: performance of the contract (article 6.1.b GDPR) and legal obligations for invoicing.
- Security and abuse prevention: our legitimate interest.
We don't sell personal data, and we don't use conversations to train our own AI models.
5. Automated summaries
Conversations are summarised by AI to help the founder read them. The summary has no legal or similarly significant effect on you; any decision is taken by the founder.
6. Sub-processors
| Provider | Purpose |
|---|---|
| Anthropic | AI models (the conversation and the summaries) |
| OpenRouter | Routing to AI models |
| Neon | Database (PostgreSQL) |
| Vercel | Hosting and file storage |
| Clerk | Sign-in for customers |
| Resend | |
| Upstash | Cache, rate limiting and queues |
| Stripe | Payments (customers only) |
| Google Analytics | Website analytics |
Some of these providers are in the United States. Transfers rely on the EU Standard Contractual Clauses or other safeguards under article 46 GDPR.
7. How long we keep it
Respondent data is kept while the founder keeps the interview. Founders can delete a response, an interview or their whole account at any time, and the related data is deleted with it. Invoices are kept as long as tax law requires.
8. Your rights
You can ask to access, correct or delete your data, object to or restrict its processing, and ask for a portable copy. If you answered an interview, you can ask the founder who shared it, or write to us and we will pass it on and help them respond. Write to edu@getmethos.com; we answer within one month.
You can also complain to the Spanish Data Protection Agency (AEPD) or the authority in your country.
Privacy policy · version 2.0 · edu@getmethos.com