Privacy Policy
Last updated: 29 December 2025
Who We Are
Experiment OS is operated by Another Web is Possible (AWIP), a UK-based company. We are committed to protecting your privacy and handling your data responsibly.
This privacy policy explains how we collect, use, and protect your personal information when you use our service.
What Data We Collect
We collect the following types of data:
- Account information: Email address, name (first and last name), and password (hashed and encrypted)
- OAuth profile data: When you sign in with Google, GitHub, or LinkedIn, we receive your email address and name from the provider
- Usage data: We collect anonymised analytics data through Vercel Analytics (no personal information, cookieless)
- Authentication data: Session cookies required for you to stay logged in
Why We Collect This Data
We collect your data to:
- Create and manage your account
- Authenticate you when you sign in
- Provide the service you signed up for
- Understand how our service is used (through anonymised analytics)
- Communicate with you about your account if necessary
Legal Basis for Processing
Under UK GDPR, we process your data based on:
- Contract performance: We need your data to provide the service you agreed to when you signed up
- Legitimate interests: We use anonymised analytics to improve our service (this does not identify you personally)
How We Store Data
Your data is stored securely in Supabase, a UK/EU-hosted database service. Supabase is GDPR compliant and uses encryption to protect your data.
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction.
Cookies
We use only essential cookies:
- Authentication cookies: Required for you to stay logged in. These are session cookies that expire when you close your browser or sign out.
- No marketing cookies: We do not use tracking cookies, marketing cookies, or any other non-essential cookies.
Analytics
We use Vercel Analytics, which is privacy-focused and cookieless. It does not collect personal information or use tracking cookies. The analytics data is anonymised and cannot be used to identify you.
Third-Party Services
We use the following third-party services:
- Supabase: For database storage and authentication (GDPR compliant, UK/EU hosted)
- Vercel: For hosting and analytics (GDPR compliant, cookieless analytics)
- OAuth providers (Google, GitHub, LinkedIn): For social authentication. When you sign in with these services, they share your email and name with us. We recommend reviewing their privacy policies.
We do not sell or share your data with third parties for marketing purposes. We only share data with the services necessary to provide our platform to you.
Your Rights Under UK GDPR
You have the following rights:
- Right of access: You can request a copy of the personal data we hold about you
- Right to rectification: You can ask us to correct inaccurate or incomplete data
- Right to erasure: You can request that we delete your personal data (see below)
- Right to data portability: You can request a copy of your data in a machine-readable format
- Right to object: You can object to processing based on legitimate interests (though this may affect our ability to provide the service)
- Right to withdraw consent: If we process your data based on consent, you can withdraw it at any time
To exercise any of these rights, please contact us at privacy@anotherweb.is. We will respond within one month.
Data Retention
We retain your data for as long as:
- Your account is active
- We need it to provide the service to you
- We are legally required to keep it
If you delete your account, we will delete your personal data within 30 days, unless we are required by law to retain it for longer.
Requesting Data Deletion
You can request deletion of your account and data at any time by:
- Contacting us at privacy@anotherweb.is
- Or by using the account deletion feature in your account settings (if available)
We will delete your data within 30 days of your request, subject to any legal requirements to retain certain information.
Updates to This Policy
We may update this privacy policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Last updated" date. We encourage you to review this policy periodically.
Contact Us
If you have questions about this privacy policy or how we handle your data, please contact us:
Email: privacy@anotherweb.is