Privacy Policy
Last updated: 30 July 2026
This policy explains how Big Ears AI handles personal data for platform users, clients, journalists, influencers, creators, professional contacts, and website visitors.
What this policy covers
This policy covers the Big Ears AI platform, the bigears.ai website, optional connected integrations, and related services.
We do not knowingly collect personal data from anyone under the age of 18. If we become aware that we have collected data from someone under 18, we will delete it.
We do not sell personal data.
Who is responsible for your data
The Service is currently operated by Samir James Shamsi, trading as Big Ears AI. Big Ears AI is the controller for the personal data described in this policy unless we process data on behalf of a client under that client's instructions.
When we process personal data on behalf of a client, such as Client Content, connected mailbox data, campaign materials, or client workspace data, we act as a processor and our processing is governed by our Data Processing Addendum or another data processing agreement with that client.
Big Ears AI is completing its corporate setup. If the operating entity responsible for the Service changes, we will update this policy and our legal documents. The Founder is responsible for data protection matters and can be reached at james@bigears.ai.
Big Ears AI completed its ICO data protection fee registration on 30 July 2026 and is awaiting ICO confirmation and public register listing. We will update this policy when the public register entry is available.
What data we collect and why
Account data
When a client or user signs up, we collect name, email address, company name, role, workspace membership, login details, and related account information. We use this to create accounts, manage access, provide support, communicate about the Service, and manage billing or subscriptions. Legal basis: contract performance and legitimate interests.
Client Content
Clients may upload press releases, brand documents, campaign materials, knowledge base content, organisation profiles, writing samples, contact lists, and other materials. We process this content to provide the Service for that client, including AI-assisted matching, drafting, reporting, and recommendations. Legal basis: contract performance and, where we act as processor, client instructions under the relevant agreement.
We do not use Client Content to train foundation models. We do not use one client's confidential content, connected mailbox data, campaign strategy, or uploaded materials to provide outputs or managed services for another client.
Public monitoring data
Our platform monitors publicly available news, public websites, podcasts, public social posts, company sources, and competitor activity. We may collect article headlines, links, source metadata, public author names and bylines, short excerpts where shown in the product, AI-generated summaries, public social post content, podcast metadata, and public engagement metrics.
We do not access content that is behind a login wall, paywall, or other restriction. Legal basis: legitimate interests in providing relevant PR, communications, and market intelligence to our clients.
Journalist, influencer, and creator data
We process professional information about journalists, influencers, creators, analysts, podcast hosts, newsletter authors, and similar professional contacts. This may include names, professional email addresses, publication or organisation, role, public author pages, public social handles, public bios, topics covered, public work, outreach history, engagement history within Big Ears AI, and suppression or opt-out status.
This information may come from public sources, client-provided information, direct interactions, platform activity, and contact discovery or verification services such as Hunter. Legal basis: legitimate interests in helping PR, communications, and marketing teams identify relevant professional contacts and carry out appropriate, targeted, human-reviewed outreach.
We do not knowingly collect special category data for this purpose. We do not sell journalist, influencer, or creator data. We require clients to honour opt-outs and not use the Service for spam, harassment, or unlawful outreach.
Connected mailbox data
Clients may choose to connect Gmail or Microsoft Outlook. Mailbox connection is optional and is not required for the core monitoring and intelligence features.
Where a mailbox is connected, we process the mailbox data necessary to provide the selected outreach features. This may include OAuth tokens, mailbox addresses and aliases, sender and recipient email addresses, subject lines, sent outreach, replies, message content for relevant outreach threads, timestamps, read or unread status, and engagement information.
We use this data to send user-approved outreach, sync replies, display outreach history, avoid duplicate follow-up, and improve draft outreach for that client workspace. We do not use one client's mailbox data to benefit another client.
Usage and website data
We collect information about how people use the platform and website, including pages visited, features used, device and browser information, referrer information, and session activity. Analytics and marketing technologies are only used where consent is required and has been obtained through our cookie controls.
Legal basis: consent where required for analytics or marketing technologies; legitimate interests for essential security, reliability, fraud prevention, and service operation.
Legal and compliance processing
We may process and retain personal data to comply with legal obligations, respond to lawful requests, enforce agreements, manage disputes, exercise or defend legal claims, prevent misuse, and protect the Service. Legal basis: legal obligation and legitimate interests.
How we handle third-party content
We monitor and summarise publicly available content from news websites, public social platforms, podcasts, company sources, and similar public sources.
We do not redistribute, republish, or display full article bodies to clients as a clippings service. We generate summaries and link back to original sources so users can read the source material on the publisher's website.
We honour publisher and platform opt-out mechanisms where technically supported, including robots.txt and recognised AI bot signals where they apply to a source we would otherwise process.
If you are a publisher, rights holder, platform, journalist, influencer, or creator with a concern, contact james@bigears.ai.
Automated decision-making and profiling
Big Ears AI uses artificial intelligence to score and rank content, suggest contacts, generate summaries, draft content, and make recommendations. This involves profiling in the sense that we analyse information to assess relevance to a client's workspace or campaign.
These automated processes support human users. They do not make decisions on behalf of individuals, do not produce legal effects for individuals, and do not similarly significantly affect individuals. Clients are responsible for reviewing and approving outreach before it is sent.
Cookies and similar technologies
We use essential cookies and similar technologies for login sessions, security, preference storage, and service operation. Analytics and marketing cookies, pixels, scripts, or similar technologies are used only where they are enabled and consented to through our cookie controls.
You can change cookie preferences through the cookie settings link in the platform or cookie banner.
Who we share data with
We use service providers, subprocessors, data sources, and optional integrations to operate the Service. We do not share personal data with third parties for their own marketing.
A fuller list is available on our Subprocessors and Data Sources page.
International data transfers
Some providers process personal data outside the UK. Where required, transfers are protected by an adequacy decision, the UK Extension to the EU-US Data Privacy Framework, the UK International Data Transfer Agreement, standard contractual clauses, or equivalent safeguards.
How long we keep data
Account and platform data
Kept while the account or client workspace is active. After cancellation or pilot end, we generally delete active client data within 90 days unless retention is required for legal, regulatory, security, dispute, or compliance reasons.
Journalist, influencer, and creator data
Kept for as long as the information remains relevant and accurate. We review contact records at least every 12 months and remove or suppress records where required. Individuals can request deletion or object at any time by emailing james@bigears.ai.
Connected mailbox data
Kept while the mailbox remains connected and the account or workspace is active, unless deleted earlier through client settings, client instruction, or an applicable rights request. After disconnection, we stop new mailbox syncing.
Backups
Encrypted backups may take up to 90 days to be fully purged, depending on provider backup cycles.
Your rights
Under UK data protection law, you may have rights to access, correct, delete, restrict, or receive a copy of your data, object to processing based on legitimate interests, and withdraw consent where processing is based on consent.
Where we process your data based on legitimate interests, you have the right to object. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or unless we need the data for legal claims.
To exercise rights, contact james@bigears.ai. We aim to respond within 30 days.
If you are a journalist, influencer, or creator
If you do not want Big Ears AI to hold or surface your professional contact information, email james@bigears.ai. We will remove your active contact record where required and add you to a suppression list so that you are not re-added.
Data protection complaints
If you have a concern about how we handle personal data, email james@bigears.ai with the subject line "Data protection complaint". We will acknowledge receipt within 30 days and respond without undue delay.
You also have the right to complain to the Information Commissioner's Office at ico.org.uk.
Security
We use technical and organisational measures designed to protect personal data, including encryption in transit, provider-managed encryption at rest, workspace separation, access controls, logging, monitoring, and incident response processes. More detail is available on our Security page.
If Big Ears AI ceases trading
If Big Ears AI ceases to operate, we will notify users and affected clients where appropriate, provide a reasonable export period, and then securely delete personal data from active systems unless retention is legally required. Encrypted backups may take up to 90 days to be fully purged.
Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify account holders by email or in-app notice where appropriate. The latest version is always available on our website.
Contact
Samir James Shamsi, trading as Big Ears AI.
Email: james@bigears.ai