fifteen hands
How it works Pricing Sign inStart free trial

Privacy policy

Last updated 7 September 2026. Written to be read, not skimmed past. If anything here is unclear, write to hello@fifteenhands.com.

Who we are

Fifteen Hands is operated by the people named in the footer, who is the data controller for the personal data described here. Contact: hello@fifteenhands.com.

The short version

  • We store what you put in: your account, your business's messages, tasks, files, drawer and log.
  • We send the parts a specialist needs to OpenAI to generate its reply. We never send direct messages between the two people in a business.
  • We don't sell data, we don't run advertising, and we don't use analytics trackers. One cookie, for signing in.
  • You can ask for a copy of your data or have it deleted at any time.

What we collect

Your account

Your name, email address and a hashed password (we cannot read the password). When you sign in we record the time and count sign-ins so we can spot problems. Optional: a Telegram chat id if you link Telegram, and browser push subscriptions if you turn on notifications.

Your business's content

Everything your business puts into Fifteen Hands: messages, tasks and their history, comments, the business brief, drawer facts and uploaded files, log entries, and the settings you choose (time zone, rhythm times, specialist descriptions).

Technical data

Our server logs record the IP address and the time of requests for security and to rate-limit sign-in attempts. Logs are kept for a short period and are not linked to your content. We record the size of each AI request (token counts, model, duration), never its text, to understand costs.

What we don't collect

No analytics or advertising trackers, no fingerprinting, no third-party cookies. We don't read your business's content except when you ask us to help with a problem, or where the law requires it.

How we use it

  • To run the service: show your messages and tasks, send briefings and nudges, deliver notifications you asked for.
  • To generate specialist replies, task capture and briefs with an AI model (see below).
  • To email you about your account: invitations, password resets, and, when your trial or subscription changes, what happens next. No marketing newsletters unless you ask for one.
  • To keep the service safe: rate limiting, abuse prevention, backups.

The legal bases under the GDPR are the contract with you (running the service you signed up for), our legitimate interest in keeping it secure and improving it, and your consent where you turn optional things on (push, Telegram).

AI processing

Specialist replies, task capture from chat, the onboarding brief and ideas are generated by models from OpenAI, called through OpenAI's API. To do that we send the model what it needs for that request: the relevant conversation, your business brief, open tasks, drawer facts, recent log entries and, if you attach one, the file. OpenAI processes that data under its API terms, which state that API data is not used to train its models; OpenAI may retain it for up to 30 days for abuse monitoring. Direct messages between the two people in a business are never sent to a model.

Requests are built to be small, and specialists only see channels they have been given access to. If you would rather not have any AI processing, you can leave the AI off in Settings: chat, tasks and the daily rhythm keep working without it.

Who else sees it (sub-processors)

ServiceWhat forWhat they get
DigitalOceanHosting the application and databaseEverything, stored on our server
OpenAIAI replies, capture, briefs, the mapThe content of the request, as described above
StripeCard payments, only if you subscribeYour name, email, billing address and card, entered on Stripe's pages; we keep only Stripe's customer and subscription ids
BrevoSending invitation and password-reset emailsYour email address and the email's text
TelegramNotifications, only if you link itThe notification text and your chat id
Apple, Google, Mozilla push servicesPhone and desktop push, only if you turn it onThe notification text, encrypted to your device

No one else. We don't share, rent or sell personal data.

Where it is stored, and for how long

Your data is stored on our server hosted by DigitalOcean, with daily backups kept for seven days. We keep it for as long as your business exists in Fifteen Hands. When you delete your account or ask us to delete a business we remove it within 30 days; backups roll over within a further seven days. Server logs are kept for up to 90 days.

Security

Everything travels over HTTPS. Passwords are stored as salted hashes. Each business's data is isolated from every other business at the database level. Access to the server is limited to the people who run Fifteen Hands. No system is perfectly secure; if we learn of a breach affecting your data we will tell you without undue delay.

Your rights

You can ask us to show you the personal data we hold about you, correct it, delete it, give you a copy in a usable format, or stop processing it in a certain way. Most of this you can do yourself in Settings; for the rest, email hello@fifteenhands.com and we will answer within 30 days. If you are in the EU or UK you can also complain to your data-protection authority.

Cookies

One cookie, set when you sign in, so the app knows it's you. It expires after 90 days or when you sign out. The public pages of this site set no cookies.

Children

Fifteen Hands is for running a business and is not intended for anyone under 16.

Changes

If we change this policy in a way that matters we will say so inside the app and update the date at the top. Continuing to use Fifteen Hands after that means you accept the change.

fifteen hands

Made by two people who run a business exactly this size.

How it worksPricingStart free trialSign in
PrivacyTermshello@fifteenhands.com
© 2026 Fifteen Hands. Fifteen Hands is not affiliated with OpenAI, Slack or Telegram.