Suggestion Box Ai

    Suggestion Box AiBack to Home

    Terms of Use & Privacy Policy

    Last updated: August 21, 2026

    Automatic Agreement

    By creating an account on Suggestion Box Ai, you automatically agree to be bound by these Terms of Use and the Privacy Policy below. If you do not agree, do not create an account or use the service. Continued use of the service constitutes ongoing acceptance of these terms.

    1. Introduction

    Suggestion Box Ai ("we", "us", "our") provides an identity-protected messaging platform that enables members of an organization to send messages to their administrator without revealing personal identity information. These Terms of Use ("Terms") and Privacy Policy govern your access to and use of the Suggestion Box Ai website, applications, and services (collectively, the "Service").

    2. Eligibility & Account Creation

    You must be at least 16 years old to create an account. By registering, you confirm that the information you provide is accurate and that you are authorized to act on behalf of any organization you administer. Creating an account constitutes automatic and binding agreement to these Terms and the Privacy Policy.

    3. Acceptable Use

    You agree not to use the Service to:

    • Harass, threaten, defame, or harm any individual or group.
    • Submit unlawful, fraudulent, deceptive, or misleading content.
    • Attempt to identify, deanonymize, surveil, or retaliate against any sender.
    • Interfere with the security, integrity, or availability of the Service.
    • Reverse engineer, scrape, or otherwise misuse the platform.
    • Violate any applicable law, regulation, or third-party right.

    Organizations remain solely responsible for lawful use, follow-up, internal procedures, and compliance with employment and labor laws in their jurisdiction.

    4. Subscription & Billing

    Paid plans are billed in advance through our payment processor (Stripe). A 30-day trial may be offered to new accounts. You may cancel at any time; cancellations take effect at the end of the current billing period. Fees are non-refundable except where required by law.

    5. Privacy Policy

    5.1 Data We Collect

    • Account data: email, organization name, hashed password.
    • Billing data: processed by Stripe; we do not store card details.
    • Messages: end-to-end encrypted content; we cannot read message bodies.
    • Technical data: minimal logs (IP, timestamp) for security and rate limiting only.

    5.2 How We Use Data

    We use data only to operate, secure, and improve the Service; to process payments; to send essential transactional emails; and to comply with legal obligations. We do not sell your data and do not use it for advertising.

    5.3 Identity Protection

    Messages submitted through the Identity Protected channel are not linked to a member's personal identity in our database. Senders may voluntarily disclose their identity within the message body; we cannot prevent or detect such disclosures.

    5.4 Encryption & Security

    Messages are encrypted client-side using AES-GCM via the Web Crypto API. Encryption keys are stored locally in the administrator's browser and are not transmitted to our servers. We employ Row-Level Security, rate limiting, and strict access controls. For a full description of our security measures, see our Security Policy.

    5.5 Data Retention

    Account data is retained for as long as your account is active. Messages are retained until manually deleted by the administrator. Upon account deletion, all associated data is permanently removed within 30 days, except where retention is required by law.

    5.6 Your Rights (GDPR, UK GDPR, CCPA)

    You have the right to:

    • Access the personal data we hold about you.
    • Rectify inaccurate or incomplete data.
    • Erase your data ("right to be forgotten").
    • Restrict or object to certain processing.
    • Data portability — receive your data in a machine-readable format.
    • Withdraw consent at any time.
    • Lodge a complaint with your local data protection authority.

    To exercise these rights, email team@suggestion-box.ai. We respond within 30 days.

    5.7 Sub-processors

    We rely on a limited set of vetted sub-processors: Supabase (database & auth hosting), Stripe (payments), and Resend (transactional email). Each is bound by data processing agreements consistent with applicable law.

    5.8 Data Residency (Ireland, EU)

    All account data, encrypted message records, and attachments are stored and processed in Ireland (European Union), within an EU data centre region operated by our infrastructure sub-processor. Choosing EU residency gives you concrete advantages:

    • GDPR by default — your data sits under one of the world's strongest privacy regimes, with enforceable rights and supervisory oversight.
    • No onward transfer required — data stays inside the EEA for normal operation, so no reliance on ad-hoc cross-border mechanisms.
    • Strong legal protection — Irish and EU law require lawful process before any authority can compel disclosure; we do not grant bulk or standing access to any government.
    • Resilience and security — EU-certified data centres with encryption at rest, encryption in transit, redundancy, and independent audit standards.
    • Neutral jurisdiction — hosting outside your own country reduces the risk of local interference with sensitive whistleblowing and suggestion data.

    Where a transfer outside the EEA is unavoidable (for example, payment processing or transactional email), we rely on Standard Contractual Clauses or another lawful transfer mechanism, and only the minimum data necessary is transferred.

    5.9 Local Compliance & Country-of-Use Statistics

    To help organizations meet local data-protection obligations in their country of use — including registration and annual reporting with national regulators such as Uganda's Personal Data Protection Office (PDPO) under the Data Protection and Privacy Act, 2019 — we record and make available aggregate message-volume statistics only. These statistics may be stored and retained in the organization's country of use for filing purposes.

    What is recorded for compliance reporting:

    • Counts of messages received over a reporting period.
    • Counts by category (for example suggestions, ideas, complaints, safeguarding reports).
    • Counts per organization account and platform totals.
    • Date of first and most recent activity in the reporting window.

    What is never recorded, exported, or accessible: we do not read, log, record, copy, transcribe, or export the actual content of any message or reply exchanged between users and administrators. Message bodies are encrypted client-side and are not readable by us, and no message content, attachment, sender identity, IP address, or device identifier is ever included in compliance statistics, exports, or reports. Compliance outputs contain numbers only.

    Advantages of this approach: organizations can satisfy local registration and annual reporting duties, demonstrate accountability to their regulator, and evidence responsible processing volumes — all without any loss of confidentiality for the people who speak up.

    5.10 International Transfers

    Where data is transferred outside your region, we rely on Standard Contractual Clauses or other lawful transfer mechanisms.

    5.11 Cookies

    We use only strictly necessary cookies and local storage required for authentication and encryption key management. We do not use tracking or advertising cookies.

    6. Intellectual Property

    All software, branding, and content provided by Suggestion Box Ai are owned by Zetu Africa Ltd and our software licensors equally and protected by intellectual property laws within the Jurisdiction of the user. You retain all ownership of content you submit through the Service.

    7. Disclaimers

    The Service is provided "as is" and "as available" without warranties of any kind. We do not guarantee that the Service will be uninterrupted, error-free, or completely secure. suggestionbox.ai supports responsible safe communication, not surveillance, or misuse. This service gives instant access to unfiltered feedback for team / operational high-performance.

    8. Limitation of Liability

    To the maximum extent permitted by law, Suggestion Box Ai shall not be liable for any indirect, incidental, special, consequential, or punitive damages, or any loss of profits or revenues, arising from your use of the Service. Our total liability shall not exceed the amount you paid us in the 12 months preceding the claim.

    9. Termination

    We may suspend or terminate your account if you breach these Terms. You may delete your account at any time from your account settings, which will permanently remove your data as described in Section 5.5.

    10. Changes to These Terms

    We may update these Terms from time to time. Material changes will be communicated by email or in-app notice at least 14 days before taking effect. Continued use after changes take effect constitutes acceptance.

    11. Governing Law

    These Terms are governed by the laws of the jurisdiction in which Suggestion Box Ai is established, without regard to conflict-of-law principles. Disputes shall be resolved in the competent courts of that jurisdiction, subject to any mandatory consumer rights.

    12. Contact

    Questions about these Terms or our privacy practices? Contact us at team@suggestion-box.ai.