Privacy Policy
Last updated: 10 September 2026
The short version: we collect what you give us through the contact form and newsletter sign-up, nothing more. It is stored in London, used only to reply to you and to send the writing you asked for, and never sold. Analytics runs only if you say yes.
1.Who We Are
White Rabbit Foundry Limited (“WRF”, “we”, “us”, “our”) is a product studio and consulting company. This policy covers the website at https://www.whiterabbitfoundry.com (the “Site”), including the contact form and newsletter sign-up on it.
We are registered in England and Wales under company number 15222598. Our registered office is at 86-90 Paul Street, London EC2A 4NE, United Kingdom.
We act as a data controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy explains what we collect, why, how long we keep it, and what you can do about it.
Our products have their own policies, because they process different data for different reasons: Emily and Clean Rabbit.
For any question about this policy, or to exercise any of the rights in it, write to hello@whiterabbitfoundry.com. We have not appointed a Data Protection Officer, as we are not required to; data protection questions go to the same address and are handled by us directly.
2.What We Collect and Why
When you contact us
The contact form asks for your name, email address, what your message is about and the message itself. Company name is optional. We use this to reply to you and, if it leads to work, to carry out that work. The lawful basis is our legitimate interest in responding to people who contact us and, where a contract follows, taking steps at your request before entering into it.
We also record the date and time of the message and the browser identification string your device sent, which help us tell real enquiries from automated ones. We do not store your IP address with your enquiry.
To prepare a useful reply, we may look up publicly available information about your company (for example its website) and summarise it for our team using Google’s Gemini model, running inside our own Google Cloud project in London. The summary is stored with your enquiry, is only ever read by us, and is deleted with it. The lawful basis is our legitimate interest in responding well to business enquiries.
When you subscribe to our newsletter
The sign-up form asks only for your email address. We record it together with the time you subscribed and which page you subscribed from, as evidence of your consent. The lawful basis is consent, which you give by submitting the form and can withdraw at any time using the unsubscribe link in every email, or by writing to us.
Our newsletter essays are published on Substack. When you subscribe on the Site we also register your email address with our Substack publication, so that new posts reach you as they are published. Substack is a separate service with its own privacy policy, and you can unsubscribe from it independently using the link in any Substack email.
We use the first part of your email address only to address the welcome email to you by name where it looks like one. We do not store that guess.
When we email you
Emails we send, whether a newsletter or an automatic message such as a welcome or an acknowledgement, are delivered by Mailgun and contain a tiny image and rewritten links that let Mailgun tell us whether the email was opened and which links were followed. We use this, in aggregate, to see which emails are worth sending and, per person, to spot addresses that never receive our mail. The lawful basis is our legitimate interest in running our mailing list well. Most mail clients let you block remote images, which stops the open tracking; the emails read fine without them. The records are kept by Mailgun for up to thirty days and by us as totals only.
When you browse the Site
The Site is served from Google Cloud. Like any web server, it records standard technical logs (the address requested, the time, the response, your IP address and browser identification string) for security and to diagnose faults. These logs are kept for 30 days.
With your consent, and only with it, we use Google Analytics to count page views and understand which pages are useful, and we may use marketing cookies to measure our advertising on other platforms. Each category is a separate choice. See the cookie policy for details. If you choose “essential only”, nothing is sent to Google or to any advertising platform.
When you play the crossword
Opening the crossword sets a cookie containing a random identifier, so that the letters you have entered and the puzzles you have finished can be found again when you come back. It holds nothing about you. The identifier, your letters, the time you have spent and the puzzles you have completed or skipped are stored in our Google Cloud project in London and deleted twelve months after your last visit. The lawful basis is our legitimate interest in running the game; you can start afresh at any time using the link on the page, or by clearing your cookies.
If you choose to enter your email address on the crossword page, we tie that address to your progress so it can follow you to another device, and we send you a one-off email containing a private link that opens your record on the device you use it on. We do this on the basis of the request you make by entering the address. That email is not a newsletter and does not subscribe you to anything; the newsletter remains a separate choice, offered with a tick box or a button, and handled as described above. If an address you enter already belongs to another record, we do not transfer that record on the say-so of whoever typed it; we email the link to the address instead.
The puzzles themselves are generated by Google’s Gemini model on Vertex AI, in our own Google Cloud project, from a theme we supply. Nothing about you, your letters or your address is sent to the model.
Automated abuse protection
To stop automated scripts flooding the forms, we count submissions per network address for a short period. The address is stored only as a one-way hash that expires within 20 minutes, and it is never linked to your enquiry or subscription.
3.What We Do Not Collect
- We do not buy, rent or scrape contact lists. Everyone on our list put themselves there.
- We do not follow you around the web: email opens and clicks are measured, as described above, but nothing else about your browsing is.
- We do not set advertising cookies or social media pixels unless you have accepted marketing cookies, and none are in use today.
- We do not sell personal data, and we never will.
4.Where Your Data Lives and Who Handles It
Enquiries and subscriptions are stored in Google Cloud Firestore in the London (europe-west2) region, in a project owned and administered by us. Emails are sent through Mailgun’s European region. Our own correspondence uses Microsoft 365. Each of these providers acts as a processor under a written contract and is bound to use the data only on our instructions.
| Provider | Purpose | Location |
|---|---|---|
| Google Cloud (Cloud Run, Firestore, Cloud Logging) | Hosting the Site, storing enquiries, subscriptions and crossword progress, server logs | London, UK |
| Google Cloud Vertex AI (Gemini) | Writing a short briefing on business enquiries, and setting crossword puzzles | London, UK (occasionally routed globally when the London endpoint is busy; no personal data is sent for the crossword) |
| Google Analytics | Page view statistics, only with your consent | EU and US, under Google’s UK and EU data transfer terms |
| Mailgun (Sinch) | Sending welcome emails, confirmations and newsletters, and measuring opens and clicks | European Union |
| Substack | Publishing and delivering newsletter essays | United States, under Substack’s standard contractual clauses |
| Microsoft 365 | Reading and replying to your messages | UK and EU |
Where a provider handles data outside the UK, the transfer is covered by the UK International Data Transfer Addendum or an adequacy decision, as applicable.
We share personal data with nobody else, except where the law requires it or to protect our rights, and we would tell you if we could.
5.How Long We Keep It
- Enquiries: for as long as the conversation is live and then up to 24 months, so we can pick up where we left off if you come back. If work follows, the records relating to that work are kept for six years after it ends, as required for accounting and limitation purposes.
- Newsletter subscriptions: until you unsubscribe. When you do, we keep your address on a suppression record so that we do not email you again by mistake. Ask us and we will delete it entirely.
- Crossword progress: twelve months after your last visit, then deleted automatically, together with any email address you tied to it. Ask us and we will delete it sooner.
- Server logs: 30 days.
- Analytics data: Google Analytics is configured to keep user-level data for 2 months. Aggregated statistics do not identify anyone and are kept indefinitely.
6.Your Rights
Under UK GDPR you have the right to:
- ask for a copy of the personal data we hold about you;
- have inaccurate data corrected;
- have your data deleted, where we no longer have a reason to keep it;
- restrict or object to our processing, including objecting to any direct marketing at any time;
- receive your data in a portable format;
- withdraw consent at any time, without affecting anything done before you withdrew it.
To exercise any of these, email hello@whiterabbitfoundry.com. We will respond within one month and will not charge you. We may ask you to confirm your identity first, so that we do not hand your data to someone else.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office (helpline 0303 123 1113). We would be grateful for the chance to put things right first.
7.Security
The Site is served over HTTPS only. Data at rest in Firestore is encrypted by Google, and access to it is restricted to named accounts protected by multi-factor authentication. Secrets such as API keys are held in Google Secret Manager, never in code. Unsubscribe links are cryptographically signed so that nobody can unsubscribe someone else.
No system is perfectly secure. If we ever became aware of a breach affecting your data we would tell you and the ICO without undue delay, as the law requires.
8.Children
The Site is for businesses and the people who work in them. It is not directed at children under 16, and we do not knowingly collect data from them. If you believe a child has given us personal data, write to hello@whiterabbitfoundry.com and we will delete it.
9.Changes to This Policy
We will update this policy when the way we handle data changes, and the date at the top will change with it. Where a change is significant and you are on our newsletter, we will tell you by email.