engine.ly

Privacy Policy

Last updated 2026-09-10

Last updated: 10 September 2026

engine.ly (“engine.ly”, “we”, “us” or “our”) respects your privacy and is committed to protecting your personal information.

This Privacy Policy explains how we collect, use, store, share and protect information when you access or use engine.ly, including our website, applications, dashboards, AI-powered tools, development environments and related services (collectively, the “Services”).

By using the Services, you acknowledge the practices described in this Privacy Policy.

1. Who We Are

engine.ly provides online software and AI-powered tools that enable users to create, develop, manage and operate digital projects.

For the purposes of applicable data protection law, the data controller responsible for your personal information is:

engine.ly

Email: contact@engine.ly

Where we process personal information solely on behalf of a business customer under its instructions, that customer may act as the data controller and engine.ly may act as a data processor.

2. Information We Collect

The information we collect depends on how you use engine.ly.

2.1 Account Information

When you create or manage an account, we may collect information such as:

  • Name
  • Username
  • Email address
  • Profile information
  • Account preferences
  • Authentication information
  • Two-factor authentication settings
  • Organisation or workspace information
  • Account roles and permissions

Passwords are not stored by us in readable form and are protected using appropriate security measures.

2.2 Billing and Transaction Information

If you purchase a subscription, credits or another paid service, we may process:

  • Billing name
  • Billing address
  • Transaction amount
  • Subscription status
  • Payment status
  • Invoice and transaction identifiers
  • Tax-related information where required

Payments may be processed by third-party payment providers. We do not normally receive or store your complete payment card number.

2.3 Projects, Prompts and User Content

When you use engine.ly, you may provide, upload, create or generate:

  • AI prompts
  • Chat messages
  • Project instructions
  • Source code
  • Files and documents
  • Images and other media
  • Project configurations
  • Generated content
  • Application data
  • Deployment information
  • Workspace content
  • Feedback and support messages

We refer to this collectively as “User Content”.

You are responsible for ensuring that you have the necessary rights and permissions to upload, submit or process User Content through engine.ly.

You should not submit highly sensitive personal information through prompts, files or project content unless it is necessary and you are legally permitted to do so.

3. AI Services and Model Providers

engine.ly may use artificial intelligence models provided by us or by third-party AI providers to process requests and generate results.

When an AI feature is used, information such as your prompt, relevant project context, instructions, code or files may be transmitted to the model provider required to perform that request.

The specific information shared depends on the feature you use and the AI provider selected or configured.

Where engine.ly allows you to connect your own AI provider, API key or external account, those services may process information under their own terms and privacy policies.

We aim to transmit only the information reasonably necessary to perform the requested operation.

3.1 API Credentials

If the Services allow you to connect external providers using API keys, access tokens or similar credentials, we use appropriate technical measures designed to protect those credentials.

Credentials are used to provide the integrations you request and are not intended to be exposed to other users.

You remain responsible for your accounts, usage, charges and agreements with third-party providers.

4. Technical and Usage Information

When you access or use engine.ly, we may automatically collect certain technical information, including:

  • IP address
  • Browser type and version
  • Device type
  • Operating system
  • Language
  • Approximate location derived from IP address
  • Login timestamps
  • Pages and features accessed
  • Session information
  • Error logs
  • Security logs
  • Performance information
  • Referring URLs
  • Cookie and similar technology identifiers

We use this information to operate, protect, monitor, troubleshoot and improve the Services.

5. How We Use Your Information

5.1 Provide and Operate the Services

We may use your information to:

  • Create and maintain your account
  • Authenticate users
  • Operate workspaces and projects
  • Process AI requests
  • Generate requested content
  • Save project settings
  • Provide integrations
  • Process subscriptions and payments
  • Provide customer support
  • Maintain and improve platform functionality

5.2 Maintain Security

We may use information to:

  • Detect suspicious activity
  • Prevent fraud
  • Protect user accounts
  • Investigate abuse
  • Enforce access controls
  • Detect malicious activity
  • Maintain security and audit logs
  • Protect engine.ly, our systems and our users

5.3 Improve engine.ly

We may analyse technical and usage information to:

  • Diagnose errors
  • Monitor system performance
  • Improve reliability
  • Understand feature usage
  • Develop new functionality
  • Improve the user experience

Where appropriate, we may use aggregated or anonymised information that does not reasonably identify an individual.

5.4 Communicate With You

We may send you:

  • Account notifications
  • Security alerts
  • Service announcements
  • Billing information
  • Support responses
  • Important changes to our Services or policies

Where permitted by law and where required with your consent, we may also send marketing communications. You may opt out of marketing communications at any time.

6. Lawful Bases for Processing

Where the UK GDPR, EU GDPR or other applicable data protection laws require a lawful basis for processing, we may rely on one or more of the following:

6.1 Contract

We process information where necessary to provide the Services you have requested or to take steps before entering into a contract with you.

This includes account management, subscriptions, projects, AI requests and requested platform functionality.

6.2 Legitimate Interests

We may process information where necessary for our legitimate business interests, provided those interests are not overridden by your rights.

These interests may include:

  • Protecting the Services
  • Preventing fraud and abuse
  • Improving reliability
  • Understanding product usage
  • Maintaining security
  • Developing new features
  • Operating and improving our business

6.3 Legal Obligation

We may process information where necessary to comply with applicable laws, regulations, court orders, taxation requirements or other legal obligations.

6.4 Consent

Where required, we rely on your consent, including for certain cookies, analytics technologies or marketing communications.

Where processing is based on consent, you may withdraw your consent at any time.

Withdrawal does not affect the lawfulness of processing carried out before your consent was withdrawn.

7. Cookies and Similar Technologies

engine.ly may use cookies, local storage and similar technologies to operate and improve the Services.

7.1 Essential Technologies

These may be required for functions such as:

  • Authentication
  • Session management
  • Security
  • CSRF protection
  • Language settings
  • Theme preferences
  • Account functionality

Essential technologies may be necessary for engine.ly to operate correctly.

7.2 Product Technologies

We may temporarily store information relating to application state, dashboards, workspace preferences, language preferences, themes and other functionality required to provide the Services.

7.3 Analytics Technologies

Where applicable and subject to consent requirements, analytics technologies may help us understand how people use engine.ly and improve our Services.

You can control non-essential cookies through our cookie controls where available and through your browser settings.

Please see our Cookie Policy for additional information.

8. When We Share Information

We do not sell your personal information.

We may share information with trusted service providers where necessary to operate engine.ly.

These providers may include:

  • Cloud hosting providers
  • Infrastructure providers
  • Database providers
  • AI model providers
  • Payment processors
  • Email delivery providers
  • Security providers
  • Monitoring and error-reporting providers
  • Analytics providers
  • Customer support systems

These providers may process information only as appropriate to provide their services and subject to applicable contractual and legal requirements.

We may also disclose information:

  • When required by law
  • In response to valid legal process
  • To investigate fraud, abuse or security incidents
  • To protect the rights, property or safety of engine.ly, our users or others
  • In connection with a merger, acquisition, financing, restructuring, reorganisation or sale of all or part of our business

9. Third-Party Integrations

engine.ly may allow you to connect third-party applications, services, repositories, APIs, AI providers, hosting platforms, deployment services or other external systems.

When you choose to connect a third-party service, information may be exchanged between engine.ly and that provider as required to perform the integration.

Third-party services operate independently from engine.ly and may process information according to their own privacy policies, terms and security practices.

We recommend reviewing the privacy practices of any third-party service you choose to connect.

10. International Data Transfers

Some of our infrastructure, suppliers, AI providers or service providers may operate outside the United Kingdom or European Economic Area.

Where applicable data protection law requires safeguards for international transfers, we take appropriate measures designed to protect personal information.

These measures may include:

  • UK International Data Transfer Agreements
  • UK Addendum to EU Standard Contractual Clauses
  • EU Standard Contractual Clauses
  • Adequacy regulations or adequacy decisions
  • Other legally recognised transfer mechanisms

11. Data Retention

We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, including providing the Services and satisfying legal, accounting, security and regulatory requirements.

Retention periods may vary depending on the type of information.

For example:

  • Account information may be retained while your account remains active.
  • Project information may remain stored until you delete it or your account, subject to applicable backup and retention processes.
  • Billing and transaction records may be retained where required by tax, accounting or financial regulations.
  • Security and technical logs may be retained for a limited period to investigate security incidents, prevent abuse and maintain system integrity.
  • Backup copies may remain temporarily after deletion until normal backup rotation is completed.

We may retain information for longer where necessary to establish, exercise or defend legal claims or where we are legally required to do so.

12. Account, Project and Content Deletion

Where supported by the Services, you may delete projects, generated content or your account through your account settings.

Deletion from active systems may not always result in immediate removal from backup systems.

Information may also be retained where we have a legal obligation or another legitimate legal reason to retain it.

13. Security

We use technical and organisational safeguards designed to protect personal information against unauthorised access, alteration, disclosure, loss, misuse or destruction.

Depending on the relevant system, measures may include:

  • Encryption
  • Secure authentication
  • Password hashing
  • Access controls
  • Role-based permissions
  • Two-factor authentication
  • Environment and workspace isolation
  • Secure credential storage
  • Network protections
  • Security logging and monitoring
  • Software and security updates
  • Backup and recovery procedures

No online service, transmission method or method of electronic storage can be guaranteed to be completely secure.

Users are responsible for maintaining the confidentiality of their account credentials and securing devices used to access engine.ly.

If you believe your account, API credentials or information has been compromised, contact us immediately at contact@engine.ly.

14. Your Data Protection Rights

Depending on where you live and applicable law, you may have the following rights.

14.1 Right of Access

You may request a copy of the personal information we hold about you.

14.2 Right to Rectification

You may request correction of inaccurate or incomplete information.

14.3 Right to Erasure

You may request deletion of your personal information in certain circumstances.

14.4 Right to Restrict Processing

You may request that we restrict how certain information is processed.

14.5 Right to Data Portability

Where applicable, you may request certain personal information in a structured, commonly used and machine-readable format.

14.6 Right to Object

You may object to certain processing based on legitimate interests or processing for direct marketing purposes.

14.7 Right to Withdraw Consent

Where processing relies on consent, you may withdraw that consent at any time.

14.8 Automated Decision-Making

Where applicable, you may have rights relating to decisions made solely by automated means that produce legal or similarly significant effects.

engine.ly's generative AI features produce automated outputs, but these tools are not intended to make legally significant decisions about users solely through automated processing unless explicitly stated otherwise.

To exercise your privacy rights, contact:

contact@engine.ly

We may need to verify your identity before completing certain requests.

15. Complaints

If you are located in the United Kingdom and believe your personal information has been handled improperly, you have the right to complain to the UK Information Commissioner's Office (ICO).

You may also have the right to complain to the relevant data protection authority in the country where you live or work.

We encourage you to contact us first at contact@engine.ly so that we have an opportunity to address your concerns.

16. Children's Privacy

engine.ly is not intended for children below the minimum age required to consent to use of an online service under applicable law unless the Service explicitly states otherwise.

We do not knowingly seek to collect personal information from children in violation of applicable law.

If you believe that a child has provided personal information to engine.ly without appropriate authorisation, contact us at contact@engine.ly so that we can investigate and take appropriate action.

17. Business Customers and End Users

Customers may use engine.ly to create applications, websites, software or other digital services that independently collect personal information from their own users.

In those circumstances, the engine.ly customer is generally responsible for determining:

  • What information their application collects
  • Why that information is collected
  • The lawful basis for processing
  • What privacy notices must be provided to their users
  • How data protection requests are handled
  • How long information is retained
  • Whether additional legal or regulatory requirements apply

Use of engine.ly does not automatically make a customer's application, website or business compliant with privacy or data protection law.

18. User Responsibility for Generated Applications

engine.ly enables users to create and configure digital products, applications and websites.

You are responsible for ensuring that anything you create, publish, deploy or operate using engine.ly complies with applicable laws, regulations and privacy requirements.

This includes responsibility for providing appropriate privacy notices, cookie controls, consent mechanisms and data handling procedures where required.

19. Links to Other Websites and Services

Our Services may contain links to websites or services operated by third parties.

We are not responsible for the privacy practices, security, availability or content of third-party websites or services.

You should review their privacy policies before providing personal information.

20. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes to our Services, technology, service providers, business practices or legal and regulatory requirements.

When we make material changes, we may provide notice through engine.ly, your account, email or another appropriate method.

The “Last updated” date at the top of this Privacy Policy indicates when it was most recently revised.

21. Contact Us

If you have questions, concerns or requests relating to this Privacy Policy or how engine.ly processes personal information, contact us:

engine.ly

Email: contact@engine.ly

For security-related matters, please also see our Security page.

contact@engine.ly