Privacy Policy

How we collect, use, share and protect personal data across the MOTHER AI platform, websites and APIs.

Last updated: 26 July 2026 · Media Stream AI Limited, England & Wales

1. Who we are

Media Stream AI Limited (“MSAI”, “we”, “us”) is the data controller for personal data processed through the MOTHER AI platform, our websites, mobile apps and APIs (together, the “Services”). We are a company registered in England & Wales. Our registered contact for privacy matters is privacy@mediastreamai.com.

2. Scope & legal framework

This policy is issued under and interpreted in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR) 2003, and — where our processing falls within its territorial scope — the EU GDPR (Regulation (EU) 2016/679) and EU AI Act (Regulation (EU) 2024/1689).

3. Personal data we collect

CategoryExamples
Identity & contactname, email, organisation, role
Account & authenticationcredentials, session tokens, sign-in events
Usage & contentprompts, uploaded files, generated outputs, feature interactions
TechnicalIP address, device/browser, approximate location, diagnostics
Transactionaltoken balances, billing records (payment card data is handled by our PCI-DSS payment processor, not stored by us)
Special category / biometriconly where you explicitly provide it and consent (e.g. voice or face input to a capability demo); never used for identity surveillance without a lawful basis

4. Purposes & lawful bases

PurposeLawful basis (Art. 6 UK GDPR)
Providing and securing your accountPerformance of a contract
Operating AI models and returning resultsContract / legitimate interests
Personalisation and optional featuresConsent
Analytics, reliability and abuse preventionLegitimate interests
Billing and financial recordsContract / legal obligation
Legal compliance and fraud preventionLegal obligation

Where we rely on legitimate interests, we have carried out a balancing assessment; you may request a summary. Where we rely on consent, you may withdraw it at any time without affecting prior processing.

5. AI processing & automated decisions

MOTHER is an observe-and-advise system operated with a human in the loop. We do not subject you to solely-automated decisions that produce legal or similarly significant effects without the safeguards required by Article 22 UK GDPR. Model outputs are advisory and should be verified before being relied upon. We classify each system by risk under the EU AI Act and apply the transparency, logging, human-oversight and data-governance controls appropriate to that class (see our AI Act statement). We do not train foundation models on your private prompts or uploaded content except where you have explicitly opted in.

6. Sharing & processors

We share personal data only with vetted processors acting on our documented instructions under Article 28 data-processing agreements — for example cloud/hosting, payment processing, analytics and communications providers. We do not sell personal data. We may disclose data where required by law, court order, or to protect the rights, safety and security of users and the public.

7. International transfers

We host and process data within the UK/EEA wherever possible. Any transfer to a country without an adequacy decision is protected by the UK International Data Transfer Agreement (IDTA) or Addendum, or EU Standard Contractual Clauses (SCCs), together with a transfer risk assessment and supplementary technical measures.

8. Retention

We keep personal data only as long as necessary for the purposes above: account data for the life of your account and up to 12 months after inactivity; billing records for the period required by tax and company law (typically 6 years); security logs for a limited period. Content you delete is removed from active systems and purged from backups on our standard backup cycle.

9. Security

  • Encryption in transit (TLS 1.2+/1.3) and at rest (AES-256)
  • Role-based access control, least-privilege and audit logging
  • Segmented, UK-sovereign inference infrastructure; zero model-weight-extraction policy
  • Vulnerability management, penetration testing and incident response procedures

We notify the ICO (and, where required, you) of a qualifying personal-data breach within 72 hours of becoming aware of it.

10. Your rights

Under the UK/EU GDPR you have the right to be informed, and to access, rectify, erase, restrict, port and object to processing, and to withdraw consent. To exercise any right, email privacy@mediastreamai.com. We respond within one month (extendable by two months for complex requests) and do not charge a fee for a valid request. You may complain to the ICO (ico.org.uk) or your local EU supervisory authority.

11. Children

The Services are not directed at children under 16. We do not knowingly collect their personal data; if you believe a child has provided data, contact us and we will delete it.

12. Changes

We may update this policy as law and our Services evolve. Material changes will be signposted on this page, which always shows the current version and its effective date.