Privacy Policy

Last updated: February 24, 2026

Tooliverse (“we,” “us,” or “our”) operates the website tooliverse.ai (the “Platform”). This Privacy Policy explains how we collect, use, and protect your information when you use our Platform.

Tooliverse is operated by Francis Field as a sole trader based in the United Kingdom. We are committed to protecting your privacy in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable privacy laws.

Contact: For any privacy-related questions or requests, email us at privacy@tooliverse.ai.

1. What We Collect

We collect the following categories of information:

Information You Provide

  • Email address — when you sign up for our newsletter, join the Tooliverse 100 waitlist, or create an account
  • Account information — if you create an account, your name and email address
  • Interest preferences — if you optionally tell us which AI tool categories interest you

Information Collected Automatically

  • Browsing behaviour — pages visited, tools viewed, categories browsed, and search queries on our Platform
  • Device and browser information — browser type, operating system, screen resolution, and device type
  • Approximate location — derived from your IP address (country/region level, not precise)
  • Referral source — how you arrived at our Platform (e.g., search engine, social media, direct)
  • Server logs — our hosting provider (Vercel) automatically collects standard server logs including IP addresses, request times, and page URLs for security and operational purposes

Email Engagement Data

When you subscribe to our newsletter, our email service provider collects standard email analytics including whether you opened an email and which links you clicked. This helps us understand what content is most useful and improve the newsletter over time.

2. How We Use Your Information

We use your information for the following purposes:

  • Deliver our service — show you AI tool reviews, ratings, and recommendations
  • Send newsletters and updates — including AI tool recommendations, new tool alerts, and platform updates. Our newsletter may include clearly labelled sponsored content and affiliate recommendations.
  • Personalise your experience — recommend tools and content relevant to your interests, based on your browsing behaviour, saved tools, search queries, and any preferences you provide
  • Auto-segmentation — we automatically categorise users by inferred interests (e.g., if you frequently browse AI coding tools, we may tag your profile as having a coding interest). This helps us send you more relevant content and enables us to offer targeted advertising to our partners.
  • Support our business — Tooliverse is a free platform sustained through partnerships with AI tool companies. We use aggregate audience data (segment sizes, engagement rates, demographic breakdowns) to demonstrate audience quality to sponsors, advertisers, and affiliate partners.
  • Improve the Platform — analyse usage patterns to improve content, features, and user experience
  • Security and operations — prevent abuse, maintain Platform stability, and comply with legal obligations

3. Legal Basis for Processing

Under the UK GDPR, we process your personal data on the following legal bases:

  • Consent — for sending you marketing emails when you subscribe to our newsletter without creating an account (e.g., Tooliverse 100 waitlist). You can withdraw consent at any time by unsubscribing.
  • Soft opt-in (PECR Regulation 22(3)) — when you create an account, we will send you our newsletter and product updates as part of your service relationship. These communications relate to the AI tools discovery service you signed up for. You can opt out at any time via the unsubscribe link in every email or in your account settings.
  • Legitimate interest — for analysing browsing behaviour, auto-segmentation, generating aggregate audience insights for business purposes, improving our Platform, and maintaining security. We have assessed that these interests do not override your rights and freedoms, particularly because we only share aggregate data (never individual personal information) with partners.
  • Contract performance — for providing the service when you create an account
  • Legal obligation — where we are required to retain or disclose data by law

4. What We Share — and What We Don't

What partners and sponsors receive

We share aggregate audience data with sponsors, advertisers, and affiliate partners. This includes information such as: audience segment sizes (e.g., “800 subscribers interested in AI coding tools”), engagement rates, click-through rates, and demographic breakdowns (e.g., geographic distribution, device types).

This aggregate data helps our partners understand the value of our audience and serve you more relevant sponsored content.

What we never share

We never sell, rent, or share your individual personal information — such as your name, email address, or personal browsing history — with sponsors, advertisers, or any other third party for their own marketing purposes. Sponsors buy placement on our Platform and receive performance reports. They do not receive your contact details or individual data.

Service providers

We use the following third-party services to operate the Platform. These providers process data on our behalf under data processing agreements:

  • Supabase (database and authentication) — stores account data, tool data, and search functionality. Servers in the United States.
  • Vercel (hosting and analytics) — hosts the Platform and provides cookieless web analytics. Servers in the United States.
  • Email service provider — processes newsletter delivery, including email engagement tracking (opens, clicks). Provider details available on request.
  • Google Gemini API — processes search queries to generate embeddings for our semantic search feature. Queries are sent without personal identifiers.

5. International Data Transfers

Tooliverse is operated from the United Kingdom. Some of our service providers (Supabase, Vercel, Google) are based in the United States. Where your data is transferred outside the UK, we rely on appropriate safeguards including the UK's adequacy decisions and standard contractual clauses to ensure your data receives equivalent protection.

6. How We Handle Review Data

Tooliverse generates Consensus Scores by aggregating publicly available user reviews and opinions from across the web, including online forums, community discussion platforms, video review channels, software review sites, and app store listings. We use AI systems to extract structured data from these publicly posted reviews and generate editorial summaries.

This process involves publicly posted opinions — not private user data from our Platform. If you have posted a public review that appears in our aggregated data and you would like it excluded, please contact us.

7. Cookies and Tracking Technologies

Our approach to cookies and tracking is as follows:

  • Essential cookies — used for authentication (if you have an account) and basic Platform functionality. These do not require consent under UK GDPR.
  • Analytics — we use Vercel Web Analytics, which is cookieless and does not track you across websites. It provides us with aggregate site performance data only.
  • Email tracking — our newsletter emails may contain standard tracking pixels and link tracking to measure engagement. You can disable image loading in your email client to opt out of open tracking.
  • No third-party advertising or retargeting cookies — we do not use Meta Pixel or any advertising or retargeting cookies. We do not track you across websites.

If we introduce additional cookies or tracking technologies in the future (such as for behavioural analytics), we will update this policy and implement a cookie consent mechanism where required by law.

8. Your Rights

Under UK GDPR and Data Protection Act 2018

If you are in the UK or EEA, you have the right to:

  • Access your personal data
  • Rectify inaccurate personal data
  • Erase your personal data (“right to be forgotten”)
  • Restrict processing of your personal data
  • Data portability — receive your data in a structured, machine-readable format
  • Object to processing based on legitimate interest, including profiling and auto-segmentation
  • Withdraw consent at any time for consent-based processing (e.g., marketing emails)

To exercise any of these rights, email privacy@tooliverse.ai. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

Under the California Consumer Privacy Act (CCPA)

If you are a California resident, you have the right to:

  • Know what personal information we collect and how we use it
  • Delete your personal information
  • Opt out of the sale or sharing of personal information
  • Non-discrimination for exercising your privacy rights

We do not sell your personal information as defined under the CCPA. We share aggregate, de-identified data with business partners, which does not constitute a “sale” under the CCPA.

Email marketing (CAN-SPAM / UK PECR)

Every marketing email we send includes an unsubscribe link. We honour unsubscribe requests within 48 hours. You can also email privacy@tooliverse.ai to be removed from all marketing lists.

9. Data Retention

  • Account data — retained for as long as your account is active. Deleted within 30 days of account deletion request.
  • Email subscriber data — retained until you unsubscribe. After unsubscribing, your email is removed from active lists within 48 hours. We may retain a hashed record of your email for suppression purposes (to ensure we don't re-subscribe you) for up to 12 months.
  • Server logs — retained by our hosting provider for up to 30 days.
  • Aggregate analytics — retained indefinitely in de-identified form.

10. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including encrypted data transmission (HTTPS), access controls on our database, and secure authentication for user accounts. While no system is completely secure, we are committed to protecting your data to the highest reasonable standard.

11. Children's Privacy

Tooliverse is not directed at children under 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us at privacy@tooliverse.ai and we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will post the updated policy on this page with a revised “Last updated” date. For material changes that affect how we use your personal data, we will notify newsletter subscribers by email.

13. Contact

If you have any questions about this Privacy Policy or wish to exercise your data rights:

  • Email: privacy@tooliverse.ai
  • Postal address: St Johns Innovation Centre, Cowley Road, Cambridge, England, CB4 0WS

Data protection authority: Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Website: ico.org.uk.