Your documents, and the trust of the people who read them, are yours. Here is exactly how we protect both.
Last updated: 24th July 2026
ReadProspects is operated by ReadProspects Technologies Nigeria (RC 9702396), registered at 325 Enugu Road, FCDA, Bwari, Abuja, Nigeria.
This policy explains how we handle personal data across readprospects.com and app.readprospects.com. Our document delivery service at relaydocuments.com has its own notice, which readers see when they open a document.
For all privacy matters, contact privacy@readprospects.com.
If you hold an account with us, we collect what we need to run your account and process what you upload. If someone shared a document with you and you opened it, we recorded how you read it on behalf of the person who sent it. Section 6 explains that.
We use AI to answer readers' questions and to analyse how documents are read. Document content and reader questions are sent to our AI provider. Section 8 covers this, and section 9 covers the fact that our verdict feature profiles individual readers. Those two sections matter most.
We do not sell personal data. We do not use it to train AI models.
We handle two different kinds of personal data, and our legal responsibility differs for each.
Because we design the analytics and AI features that operate on reader data, a supervisory authority may treat us as a joint controller for some of it. We accept that possibility and have written this policy to describe that processing openly rather than hide behind the processor label.
Under the Nigeria Data Protection Act 2023 and the GDPR where it applies, every use of personal data needs a lawful basis. Ours are:
| Purpose | Legal basis |
|---|---|
| Creating and running your account | Performance of a contract with you |
| Providing document, reader and verdict features | Performance of a contract |
| Billing and collecting payment | Performance of a contract |
| Security, abuse prevention, rate limiting | Legitimate interests |
| Product improvement and diagnostics | Legitimate interests |
| Service announcements and support | Performance of a contract |
| Marketing emails | Consent, withdrawable at any time |
| Meeting legal, tax and regulatory duties | Legal obligation |
Where we rely on legitimate interests, we have weighed those against your rights and concluded they do not override them. You can ask us for that assessment.
This is the part of our service most likely to affect someone who never signed up with us, so we describe it plainly.
When you share a document, we process the recipient's name and email address as supplied by you, and we record how they read it: when they opened it, which pages they viewed and for how long, whether they returned to a page, any questions they typed into the document, and whether they forwarded it and to whom. Our hosting and database providers also log the reader's IP address as part of normal operation.
We store the full conversation between a reader and the document's AI companion. In the sender's dashboard, senders see the questions asked but not the AI's answers. If a sender has configured Slack or webhook alerts, both the question and the AI's answer are delivered to their chosen destination at the moment the question is asked.
If a reader forwards a document, we record the name and email of each colleague they send it to, because the reader entered those details in order to send it. Those colleagues can ask us to erase them, and we have a specific tool to do so.
Your obligations as the sender. By sharing a document, you confirm that you have a lawful basis to provide us with that person's details, and that you will tell them their engagement with the document is recorded and analysed where the law requires it. The reader has no relationship with us, so only you can tell them. You indemnify us against claims arising from a failure to do so, as set out in our Terms.
We use the following providers. Each processes personal data on our behalf under contractual terms.
| Provider | What they do | Where |
|---|---|---|
| Supabase | Database, file storage, authentication | United States |
| Vercel | Application hosting and delivery | United States and global edge |
| Anthropic | AI processing of document content and reader questions | United States |
| Resend | Sending emails to you and to your recipients | United States |
| GitHub | Source code hosting (no customer personal data) | United States |
| Paystack | Payment processing (not yet active) | Nigeria |
We will update this list before adding a new provider that processes personal data.
We want to be specific here, because it is the processing least visible to the people affected by it.
What is sent. When a reader asks a question, we send the document's extracted text and their question to Anthropic to generate an answer. When a document is an image or a scanned PDF, the image itself is sent to Anthropic so that its text can be read. When you run a verdict, we send the document text together with that reader's behavioural signals, meaning opens, page dwell, re-reads, questions and forwards, and the reader's name and organization.
What comes back. An answer for the reader, or an assessment for you of what the reader appears to be thinking and what you might do next.
What does not happen. Anthropic does not use this data to train their models. We do not use your documents or reader data to train any model. We do not sell this data.
Its limits. AI output is generated text. It can be wrong, and a verdict is an inference from limited behavioural evidence, not a fact about a person. It should not be the sole basis for a consequential decision about anyone.
Our verdict feature analyses an identified individual's behaviour and produces an assessment of their intent and likely next step. Under data protection law this is profiling, and we describe it as such rather than call it analytics.
The profiling is not fully automated decision-making with legal or similarly significant effects, because a person, the sender, reads the assessment and decides what to do. Readers retain the right to object to profiling and to ask for erasure, as set out in section 12.
Your data and your readers' data are transferred outside Nigeria, principally to the United States, because our infrastructure providers are based there.
For transfers from Nigeria we rely on the safeguards permitted under the Nigeria Data Protection Act 2023, including contractual protections with each provider. For transfers of data originating in the European Economic Area or United Kingdom, we rely on Standard Contractual Clauses or an equivalent approved mechanism with each provider.
Data is encrypted in transit and at rest. Document files are served through short-lived signed links rather than public URLs. Profile photos are stored in a public bucket and are accessible to anyone holding the link. Row-level database security separates one customer's data from another's, and the reader conversation transcript is restricted so that account holders cannot query it directly.
Administrative access to customer data is restricted to authorised personnel. Every administrative action that changes or deletes data is recorded in an audit log. Administrative read access is not currently logged.
No system is perfectly secure. If a breach occurs that is likely to result in risk to affected individuals, we will notify the Nigeria Data Protection Commission within 72 hours where required, and affected individuals without undue delay.
Retention. We keep your account data for as long as your account is open. Documents and their associated reader data remain until you delete them or close your account. Deleting a document removes its recipients, their signals, their conversations and the underlying file. Closing your account removes your documents, their files, your profile photo and all associated reader data. After closure we retain limited records where we must for legal, tax or accounting reasons.
Compliance records. Where we erase someone's data on request, we retain a minimal record of the request and the action taken, including the identifier used to make it, as evidence that we honoured it. Audit records of administrative actions are kept as a security control.
Your rights. Subject to legal limits, you may ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, provide it in a portable format, or withdraw consent where consent is the basis. You will not be treated less favourably for exercising any of these.
If you are a reader, not an account holder, you have the same rights. The person who sent you the document is the controller of your data, so contacting them is usually fastest, but you may write to us at privacy@readprospects.com and we will act on your request, including erasing everything we hold about your reading of a document. If you were named as a colleague when someone forwarded a document, you may ask us to erase you, and we will remove your name and address from those records.
We respond within 30 days.
Complaints. You may complain to the Nigeria Data Protection Commission at ndpc.gov.ng. If you are in the European Economic Area or the United Kingdom, you may complain to your local supervisory authority.
The service is not intended for anyone under 18, and we do not knowingly collect their data. If you believe a child has provided us with personal data, contact us and we will delete it.
We will post any change here and update the date above. If a change materially affects your rights, we will tell you directly before it takes effect.
ReadProspects Technologies Nigeria (RC 9702396), 325 Enugu Road, FCDA, Bwari, Abuja, Nigeria.
Email privacy@readprospects.com for any privacy question or to exercise a right.