Privacy Policy
LAST UPDATED · 21 July 2026
Social Machines AI ("Social Machines", "we", "us") is a frontier AI lab based in Singapore. This policy explains what personal data we collect when you visit socialmachines.ai, why we collect it, the legal bases we rely on, and the rights you have. We are the data controller for this website. Questions or requests: [email protected].
1. Scope
This policy covers our public marketing website only. It does not cover any separate products, apps, or services we may operate under their own terms, or third-party sites we link to.
2. Information we collect
Information you give us. The website has no user accounts and no payment processing. If you email us, we receive your email address and message. The newsletter field on the site is not yet operational and does not currently transmit or store any address.
Information collected automatically.
- Baseline analytics — we use Cloudflare Web Analytics, which is cookieless and does not track you across other websites. It records aggregate, non-identifying usage such as page views, referring site, and device/browser type.
- Product analytics (consent-based) — with your consent we use PostHog, hosted in the European Union, to understand how the site is used. This includes autocaptured interactions (clicks, page views), heatmaps, and session replay with all input fields masked. It sets cookies and a device identifier. It runs only after you accept our consent banner, which we show to every visitor regardless of location, and is never active in our admin area. If you decline or take no action, PostHog does not load.
- Hosting, security & performance — our host and CDN, Cloudflare, processes standard request data (IP address, user-agent, timestamps, requested URLs) to deliver the site, defend against abuse, and keep it reliable. Cloudflare also collects aggregate page-timing measurements (real user monitoring) so we can see how fast pages load.
Storage on your device. The site keeps a copy of its own published page content in your browser’s local storage (key sm_cms_published) so pages render immediately on repeat visits. That is site content, not personal data, and it never leaves your device. You can clear it any time via your browser’s site-data controls.
3. Cookies and similar technologies
We do not use advertising or cross-site tracking cookies. Baseline analytics and the site itself are cookieless. Cloudflare may set strictly necessary cookies for security and bot mitigation, and Cloudflare Access sets a session cookie for our internal admin area only (not for ordinary visitors).
Our product-analytics tool, PostHog, sets cookies and a device identifier — but only after you accept it. We present a consent banner to every visitor, regardless of country, and load nothing from PostHog until you accept; declining, or taking no action, means it never loads. You can withdraw consent at any time by clearing this site’s storage in your browser, which resets the choice.
4. Why we use your data and our legal bases (GDPR)
- Operate and secure the site — legitimate interests (Art. 6(1)(f)) and, for logs, legal obligation where applicable.
- Baseline aggregate usage to improve content — legitimate interests (Art. 6(1)(f)).
- Product analytics (PostHog), incl. session replay — your consent (Art. 6(1)(a)); we ask every visitor and do not run it otherwise.
- Respond to messages you send us — legitimate interests / steps at your request (Art. 6(1)(b)/(f)).
5. How we share data
We do not sell or rent personal data, and we do not share it with advertising networks. We rely on a small number of processors acting on our instructions:
- Cloudflare, Inc. — hosting, CDN, DNS, security, and cookieless web analytics.
- PostHog (EU region) — consent-based product analytics and session replay. Only receives data after you accept our consent banner.
Our webfonts are self-hosted from this domain rather than loaded from a font CDN, so no font provider (such as Google Fonts) ever receives your IP address. We load no advertising or social scripts. The only script served from outside this domain is Cloudflare’s cookieless performance beacon (static.cloudflareinsights.com). Our product analytics (PostHog, after your consent) is proxied through this domain and forwarded to PostHog’s EU infrastructure, so your browser communicates only with us; if your data is processed outside your region, appropriate transfer safeguards apply.
We may disclose data if required by law or to protect our rights, users, or the public.
6. International transfers
The site is served from Cloudflare’s global edge network, so data may be processed in countries outside your own, including outside the EEA/UK and Singapore. Where required, such transfers are covered by appropriate safeguards such as Standard Contractual Clauses.
7. Retention
Aggregate analytics are kept only as long as useful for understanding trends and then aged out. Security and CDN logs are short-lived and retained only as needed for reliability and abuse prevention. Emails you send us are kept for as long as needed to handle your request and meet legal obligations.
8. Your rights
EEA/UK (GDPR). You have the right to access, rectify, erase, restrict, or object to processing of your personal data, to data portability, and to withdraw consent at any time. You may also lodge a complaint with your local supervisory authority.
Singapore (PDPA). You may request access to and correction of personal data we hold about you, and withdraw consent for its collection, use, or disclosure.
California (CCPA/CPRA). You have the right to know, delete, and correct personal information, and to opt out of its "sale" or "sharing." We do not sell or share personal information as those terms are defined, and we will not discriminate against you for exercising your rights.
You can withdraw consent to product analytics at any time by declining the banner or clearing this site’s browser storage, which stops PostHog from loading. We do not sell or share personal information for cross-context behavioral advertising. To exercise any right, contact us at [email protected].
9. Children
The site is not directed to children and we do not knowingly collect data from anyone under 16 (or the minimum age in your jurisdiction). If you believe a child provided us data, contact us and we will delete it.
10. Security
We protect the site with HTTPS/HSTS, hardened HTTP security headers, restricted administrative access behind Cloudflare Access, and least-privilege infrastructure. No method of transmission or storage is perfectly secure, but we work to protect your data.
11. Changes to this policy
We may update this policy as the site evolves. Material changes will be reflected by the "Last updated" date above.
12. Contact
For any privacy question or request, email [email protected]. Social Machines AI, Singapore.