Privacy Policy

What we collect, and why.

We are a consulting firm, not an advertising business. We collect what we need to write you an accurate quote and nothing we can't justify. We do not sell your data, and we do not run advertising trackers on this site.

Last updated

1. Who we are

M Kiln AI is an AI integration consultancy based in Rochester, New York, serving small and medium businesses. For any privacy question, or to ask us to delete your data, email contact@mkilnai.com. A person reads that inbox, and we respond to privacy requests within the 30 days set out in section 8.

2. Information you give us

When you complete the free AI audit, we store the answers you typed and the contact details you submit:

Contact details
Your name, business name, and email address.
Your six answers
What your business does, your biggest weekly time sink, the software you use, your rough weekly volume, whether your work involves confidential material, and any AI tools you've tried. Stored verbatim, as you typed them.
The generated audit
The recommendations produced for you, kept alongside your answers so our quote matches what you were shown.

Please don't paste customer records, employee data, passwords, or anything confidential into the audit. It's a scoping conversation, not a secure channel. A general description of your workflow is all we need.

3. Information collected automatically

When you submit an audit, we also record technical and contextual details. We are listing all of them, because a policy that says "certain technical information" is telling you nothing:

IP address & location
Your IP address, and the approximate country, region, city, and postal area derived from it, plus the network operator or ISP. City-level at best — never a precise location.
Device & browser
Browser user agent, platform, device type, screen and window size, pixel ratio, language, and connection type.
Time zone
Your browser's time zone and UTC offset, so we call you during your working hours rather than ours.
How you arrived
The page URL, the referring site, any campaign tags in the link (utm_source and similar), and which button you used to start the audit.
Session timing
How long you spent on the page and on each question, and the total length of your answers. This tells us how much detail to expect in the follow-up — it is not behavioural profiling and is never shared.

This is collected at the moment you submit the audit — not as you browse. If you read the site and never start an audit, we don't record you at all.

4. Why we collect it

If you're in the UK or EU, our lawful bases are your consent (given by submitting the form) and our legitimate interest in responding to business enquiries and protecting the service from abuse.

5. Who else sees your data

We do not sell, rent, or trade personal information. Three third parties are involved in running this site:

Anthropic
Your six answers are sent to Anthropic's Claude API to generate the audit. They are processed to produce your result and are not used to train models on business API traffic. Describe your confidential material in general terms only — the audit is a scoping conversation, not a secure channel.
ipapi.co
Receives your IP address to return the approximate location and network operator. Nothing else about you is sent.
Google Fonts
The site's typefaces load from Google's servers, which means Google sees your IP address when the page loads. No cookie is set and we receive nothing back.

We may also disclose information if legally required to, or if necessary to protect our rights or someone's safety.

6. Cookies and local storage

This site sets no cookies and runs no advertising or analytics trackers. There is one piece of local storage: if your submission can't reach our server, it is held in your own browser under mkiln_pending_leads and sent when you next visit, so your audit isn't lost. It stays on your device until then, and clearing your browser data removes it.

7. Where it's stored, and for how long

Audit submissions are stored in a database on our web hosting, which is not publicly accessible, and copied to the email inbox where we receive new enquiries. Both are in the United States.

We keep enquiries that don't become projects for 24 months, then delete them. Records connected to actual client work are kept for seven years to meet tax and accounting obligations. You can ask us to delete yours sooner.

No transmission or storage system is perfectly secure. We use HTTPS throughout, keep the database outside the public web root, and never place API keys or credentials in the page you load — but we can't guarantee absolute security, and we won't pretend otherwise.

8. Your rights

Email contact@mkilnai.com and we will action any of the following, free of charge: get a copy of everything we hold on you; correct it; delete it; object to how we use it; or withdraw consent. We'll respond within 30 days and won't ask why.

California residents have these rights under the CCPA, including the right not to be discriminated against for exercising them. We have never sold or shared personal information for cross-context advertising, and we don't intend to. UK and EU residents have these rights under the UK GDPR and GDPR, and may complain to their supervisory authority — the ICO in the UK.

9. Children

This is a service for businesses. It is not directed at anyone under 16, and we don't knowingly collect their information. If you believe a child has submitted data, email us and we'll delete it.

10. Changes

If we change what we collect or who we share it with, we'll update the date at the top of this page. Material changes affecting people already in our records will be sent by email.

Questions

Anything unclear, or want your data removed? Email contact@mkilnai.com or call (680) 271-4201, Monday to Friday, 9AM–5PM ET.