Security and Data Handling
Last updated: 30 July 2026
This page summarises how Big Ears AI protects client data, account data, public-source data, and optional integration data.
Client data separation
Each client workspace is separated from other client workspaces. Client Content, connected mailbox data, campaign materials, organisation profiles, uploaded documents, and confidential strategy information are not shared across clients.
Big Ears AI does not use one client's confidential data to benefit another client, train another client's workspace, or support another client's managed services.
Data protection governance
Big Ears AI completed its ICO data protection fee registration on 30 July 2026 and is awaiting ICO confirmation and public register listing. This registration is a UK data protection fee requirement and is not an ICO certification or approval of the Service.
Data protection, privacy, and security questions can be sent to james@bigears.ai.
Managed services
Where Big Ears AI provides optional managed services, we use the relevant client's data only for that client's agreed services. Managed service access is limited to authorised personnel who need access to perform the agreed work.
We do not use confidential client information to compete with agency clients, pitch to their customers, or build campaigns for another client.
Access controls
Access to client data is limited to authorised users and personnel with a business need. Users must use individual accounts and may not share credentials.
Administrative access is restricted and reviewed periodically. Where internal access is required for support, debugging, account management, or managed services, access should be limited to the minimum data and time needed.
Encryption and storage
Data is encrypted in transit using TLS. Data stored in core systems is encrypted at rest by our infrastructure providers. Client files, account data, and application data are stored in managed cloud services with access controls and security protections.
Logging and monitoring
We use logging and monitoring to detect errors, maintain service reliability, investigate security issues, and protect the platform. Logs should be configured to avoid storing unnecessary personal data or confidential client content.
AI processing
Big Ears AI uses AI providers disclosed on our AI Data Processing and Subprocessors pages. Current product features may use OpenAI, Anthropic, and Google AI services for summaries, recommendations, relevance scores, drafts, content generation, and media generation. We send only the data reasonably needed for the requested feature.
We do not opt in to provider model-improvement programmes for Client Content, and we do not allow Client Content to be used for provider foundation model training under our commercial/API arrangements. More detail is available on our AI Data Processing page.
Connected mailboxes
Mailbox connection is optional. If a client connects Gmail or Outlook, Big Ears AI processes mailbox data needed to send outreach, sync replies, display outreach history, and support the requested mailbox features.
Clients can disconnect connected mailboxes. After disconnection, Big Ears AI stops new syncing and retains or deletes existing mailbox data according to the client's settings, our retention schedule, and legal requirements.
Retention and deletion
Client data
Account and platform data is generally retained while the account is active. After cancellation or pilot end, Big Ears AI aims to delete client data from active systems within 90 days, unless retention is required for legal, regulatory, dispute, security, or compliance purposes.
Backups
Encrypted backups may take up to 90 days to be fully purged depending on provider backup cycles.
Incident response
If we become aware of a personal data breach affecting client data, we will investigate, contain, and assess the incident. Where required, we will notify affected clients without undue delay and provide reasonable assistance with regulatory or individual notifications.
Where Big Ears AI acts as controller and a breach is likely to result in a risk to individuals, we will notify the Information Commissioner's Office within the required timeframe.
Client controls
- request deletion or export of workspace data;
- disconnect mailbox integrations;
- suppress specific journalist, influencer, or creator contacts;
- restrict managed service access;
- ask for subprocessor and AI provider information;
- enter into a Data Processing Addendum.
Contact
Security and privacy questions can be sent to james@bigears.ai.