Privacy Policy

Version 1.0, in force from 22 June 2026

This is version 1.0. Dark Orb is operated by DanTodd Ltd on an interim basis while Dark Orb Ltd is being formed; this policy will be reissued under Dark Orb Ltd once it is registered. The liability and AI wording and the per-subprocessor transfer mechanism remain under solicitor review and will be refined in a later version without reducing your rights.

Dark Orb is a business toolkit that composes websites and related outputs for small businesses. This policy explains what personal data we handle, why, and the rights you have over it.

Who we are

The data controller for the personal data described in this policy is DanTodd Ltd, 1 St. Hilaire Walk, Leeds, England, LS10 4FE, company number 15749189. DanTodd Ltd operates Dark Orb on an interim basis while Dark Orb Ltd is being formed. You can contact us about privacy or exercise your data rights at hello@danieltodd.uk. We have not appointed a Data Protection Officer: we are not required to at our current scale, and you can raise any data-protection matter with us at the same address.

A note on roles. For your account and your use of Dark Orb, we are the controller. For personal data that visitors submit to a website you have built with Dark Orb (for example, a contact form on your site), you are the controller and we act as your processor. The terms governing that processor relationship are set out in a separate Data Processing Agreement.

What data we collect, why, and our lawful basis

We practise data minimisation: we collect what the service needs to function and little else. There are no passwords, no marketing trackers, and no third-party analytics scripts.

Account data

When you create an account we store your email address, an internal user identifier (a random identifier, not derived from your email), and the date you joined. If you register a passkey, we store the public key and related metadata for that passkey. We never store passwords, and we never store passkey private keys (those stay on your device). Our lawful basis is performance of our contract with you.

Sign-in tokens

We use passwordless sign-in. A magic-link token expires after 15 minutes; a passkey challenge expires after 5 minutes. Both are single-use and deleted as soon as they are used. Our lawful basis is performance of our contract and our legitimate interest in account security.

Session cookie

When you are signed in we set one cookie, named session. It is strictly necessary to keep you signed in. It is marked HttpOnly and SameSite=Lax, is sent only over HTTPS in production, is signed so it cannot be tampered with, and expires after 30 days. It contains only your user identifier, your email, and an expiry timestamp. If you try Dark Orb without an account, we set one further strictly-necessary cookie, named demo_session, which holds a random identifier so your trial composition survives between requests; it expires after 24 hours. Both cookies are strictly necessary, so we do not show a cookie consent banner, and we use no analytics or advertising cookies. See our Cookie Notice for the full detail.

What you tell us to build

When you describe what you want Dark Orb to build, we store that description and what it produces (your website, and any logo you compose) so you can revise, undo, and restore earlier versions. We also store the business context you give us (for example your industry and location). To produce a site, your description is sent to our AI subprocessor and may be held in a short-lived cache for up to 24 hours. Our lawful basis is performance of our contract with you. If you try Dark Orb without an account, we keep that demo session for up to 7 days and delete it when you claim it into an account or when it expires.

Images

If you upload an image, we store it to provide it on your site. If you ask for a stock image, we fetch candidates from our stock-image subprocessors, screen them for suitability, and store the chosen image against your account. If you bring an existing logo for Dark Orb to draw from, we store it and send it to our AI subprocessor to read its visual character. Our lawful basis is performance of our contract with you.

Form submissions on the sites you build

When a visitor submits a form on a website you have built with Dark Orb (typically a name, email, and message, plus any custom fields), we store that submission so you can read it in your portal, and we email it to you through our email subprocessor to notify you that it has arrived. Submissions that carry an email address are also gathered into a customer record, so you can read everything one person has sent as a single thread. If you reply to a customer from your portal, your reply is delivered to them through our email subprocessor. If you ask a question about your customers, or for a summary of a thread, and answering needs interpretation, the relevant enquiry text is sent to our AI subprocessor; this happens only when you ask, never automatically. Beyond that, we do not send these submissions to any other third party or use them for our own purposes. We hold them on your behalf as your processor; you decide why they are collected and how long they are kept. The most recent 500 submissions per site are retained in the site inbox; customer records last for the life of your account.

Audit and security logs

We keep minimised audit logs of security-relevant events, such as sign-in successes and failures, to protect accounts and investigate abuse. Sign-in success logs record only your internal identifier, not your email, and failure logs record a non-identifying reason. Our lawful basis is our legitimate interest in keeping the service secure.

Analytics

Our analytics are server-side, cookieless, and first-party. We do not set tracking cookies, do not assign persistent visitor identifiers, and do not send data to any third-party analytics product. Where an approximate location is derived, IP addresses are anonymised before storage. Raw events are kept for 30 days; aggregated counts that cannot identify a person are kept longer.

Payments

Dark Orb is provided without charge today, so we do not currently process any payment data. When paid subscriptions become available, payment will be handled by our payment subprocessor. We will not store full card details; we will store the information needed to manage your subscription, and we will update this policy before that processing begins.

Subprocessors

We use a small set of providers to deliver the service. Each processes data only on our instructions.

SubprocessorFunctionWhat is sharedLocation
CloudflareHosting, storage, server-side analytics, bot challengeAll service data is hosted on Cloudflare infrastructureGlobal edge
AnthropicAI composition, image screening, alt-text, logo analysis, answering questions you ask about your customersYour intent text and content to be composed; image descriptions; a logo you upload for logo composition; enquiry text when you ask about your customers or for a thread summaryUS / EU
OpenAIAI image generationImage-generation prompts derived from your composed contentUS
ResendSending magic-link sign-in emails; delivering new-submission notifications for the forms on the sites you build; delivering the replies you send to your customersRecipient email and sign-in link; for form notifications sent to you as the site owner, the visitor's submission content; and, for replies you send, the customer's email address and your messageUS
PexelsStock image searchSearch queryUS
Stripe (planned, when paid plans launch)Subscription billingBilling email, payment referenceUS / EU
Sentry (planned, when enabled)Error monitoringDiagnostic data, minimised of personal dataEU / US

The subprocessors listed above are the current set. Stripe and Sentry are listed as planned and are not yet in use. We will give notice before adding a new subprocessor that handles personal data, and we maintain a standalone Subprocessors page you can subscribe to for changes. Where personal data is transferred outside the UK, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses; the specific mechanism cited per subprocessor is being confirmed with our solicitor and does not change the safeguards you are entitled to.

How long we keep data

DataRetention
Account record and passkey credentialsLife of your account
Magic-link tokens / passkey challenges15 minutes / 5 minutes, single use
Session cookie30 days
Demo session cookie (no account)24 hours, refreshed on activity
Intent text and composed sitesLife of your account (version history you control)
Demo session content (no account)Up to 7 days
AI request cache / image search cacheUp to 24 hours / up to 7 days
Visitor form submissionsMost recent 500 per site in the site inbox, on your instruction; enquiries with an email address also join your customer records (life of your account)
Security and audit logsPer the Substrate Audit Log Policy (tiered)
Analytics raw events / aggregated counts30 days / retained (non-identifying)
Backups30 days

You can ask us to delete your account at any time by contacting us at hello@danieltodd.uk. When we action a deletion, we remove your account record and your sites, their versions, their form submissions, your customer records, and your business context. Site analytics are cookieless and are not linked to your identity; raw analytics events age out within 30 days. Backups age out within 30 days.

Your rights

Under UK GDPR you have the right to access your data, have inaccurate data corrected, have your data erased, restrict or object to certain processing, receive your data in a portable format, and withdraw consent where we rely on it. To exercise any of these, contact us at hello@danieltodd.uk. We will respond within one month. If a website visitor wants to exercise rights over data submitted to a site built with Dark Orb, that request goes to the business that owns the site, not to us. You also have the right to complain to the Information Commissioner's Office at ico.org.uk, though we would welcome the chance to resolve any concern first.

Security

Sign-in is passwordless, which removes the most common account-takeover risk. The session cookie is signed and tamper-evident. Access to your data is scoped to your account at the storage layer, not only at the surface.

Children

Dark Orb is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18.

Changes to this policy

We may update this policy as the service grows. When we make a material change we will update the version and date, and where appropriate we will notify you.

Version 1.0, in force from 22 June 2026.

← Back