Ask direct questions about your own reporting — your thresholds, your dates, what you file and when.

Sign up free →

WHY REGISTER

Ask these pages about your own company.

  • answers with paragraph citations
  • your dates, from your year end
  • your company record, kept
Sign up free

Free · no card

Everything on this site stays open without an account.

ASK ABOUT YOUR OWN REPORTING

Ask direct questions about your own reporting — your thresholds, your dates, what you file and when.

Sign up free

Free · one email · already registered? Log in

Everything on this site stays open without an account.

Privacy

What we hold about you

In plain English, because you should be able to check it.

Everything on this site stays open without an account; this page is about what happens when you make one.

Who we are

Fractional Quest Ltd, company no. 17322105, 71–75 Shelton Street, London WC2H 9JQ. We are the data controller for everything on this page. If you want to ask us anything about it, or exercise any of the rights below, write to us at that address.

Which sites this covers

This policy covers your account, and it covers every site in the UK SRS cluster: uksrs.org.uk, sustainabilityreportingstandards.co.uk, srsreport.co.uk, srsreport.com, uksrsreport.co.uk, uksrs.finance, secr.quest, srs.credit, srs.green and carbon.legal. There is one account and it lives here; the other nine have no sign-in of their own, and their own privacy pages describe the analytics on that site and link back to this page for everything else.

Signing in on this site does not sign you in on the others. No cookie of ours crosses a domain, which is why a reader who is signed in here still sees the way in on the rest.

If you never sign in

We hold nothing about you. Every page of this site is open without an account, and it stays that way. We use analytics on the public site to count page views; the cookie banner asks first, and declining is the default-safe choice and costs you nothing.

If you do sign in, this is the whole list

This is not a summary. It is the same list the delete button works from — every store this product keeps member data in, with what it holds. If something is not here, we do not have it.

member_object
Your company record — the company you confirmed, its number, your headcount, turnover, balance sheet, year end and anything else you have told us or tapped to confirm.
member_object_changelog
The history of those figures: what each one was before you changed it, and when. It is an audit trail, so you can always see what you told us and when you corrected it.
conversation_message
Your conversations with the assistant — your messages and its replies, kept so a conversation carries on where you left it.
pinned_artefact
Anything you kept from a conversation into your working file.
plan_task_status
Your plan board: which cards are on it, where you moved each one, the dates you set, who you assigned it to and your notes.
plan_card_event
The history of that board — every move, so the board can show you how the work has gone.
tender_document
The TEXT of any tender you uploaded, and its page numbers. We never keep the PDF itself.
tender_requirement
What we extracted from that tender — the requirements, the quotes and where each one sits against your record.
member_profile
Your name, what you asked us to call you, and your photo if you uploaded one.
member_thread
Your threads — the separate conversations you have going, and their titles.
thread_hidden
Which threads you dismissed, so they stay out of your list.
conversation_recovery
A reply that was still being written when something interrupted it, so it is not lost when you come back.
copilot_thread_run
The run behind a reply — the steps taken to answer you, kept so a conversation can be replayed where it left off rather than started again.
plan_card_checkpoint
How far through a plan card you are.
channel_identity
The link between your Slack user and your account, if your organisation connected one, so a question asked in a channel is answered as you.
organisation_member
Which organisations you belong to, and your role in each.
organisation_join_request
Any request you made to join an organisation, and whether it was decided.
user_active_organisation
Which of your organisations you were last working in.
zep graph (words + tapped facts)
A memory of what you have said, held by Zep, our memory provider, so the assistant recalls it in a later conversation. Your words and the values you confirmed go there. The text of a tender does not, and the PDF never existed to send.
neon_auth.user
Your sign-in: your email address, whether it is verified, and how you sign in — with a password, or with Google.

Who else sees it

The processors, and what goes to each. Zep holds the memory graph above — your words and the values you confirmed. The Vercel AI Gateway carries your message to the model that answers it; we do not retain the content of that call. Logfire receives traces of what the product did — how long a step took, which tool ran — with message content switched off (include_content=False), so your words are not in them. Neon hosts the database and the sign-in.

When the assistant searches the web — which it does to find a company or a published source — the words of that search go to Exa or Tavily, the search providers we use. If the search repeats a question you asked, your words are in it. If your organisation has connected Slack, we hold the link between your Slack user and your account so a question asked in a channel is answered as you; that link is in the list above and is deleted with everything else.

We also look your company up on the Companies House public registerwhen you search for it. That sends your company’s name or number to a public government service. It sends nothing about you.

We send one kind of email: the message that verifies your address when you make an account. Nothing is sold, and nothing you say trains a model.

How long, and what “delete” means

We keep it until you delete it. There is no clock and no expiry.

Delete everything we hold about you, under Settings, removes every store in the list above — including the change history, which is an audit trail and is deleted with the rest rather than kept. It leaves your sign-in, so signing in again gives you an empty account. Delete account, also under Settings, does all of that and then removes the sign-in too. Both require typing DELETE, and neither can be undone.

One honest detail about the memory. When you tell the assistant something, it reaches the memory graph within a few seconds and takes a few minutes — around seven, measured — to be processed into something it can recall. That means a thing you have just said may not come back for a little while. It also means that if you delete your data during that window, the deletion is done first and completely: we erase the memory graph before anything else, and if that cannot be confirmed we stop and delete nothing.

What outlives your account, and for how long

Two things are not deleted when you are, and this page would be dishonest if it left them out of the list above without saying so. Each is kept for a stated period, and the period is enforced by the code that writes it: adding a row retires the expired ones. A period nothing enforces is a sentence, not a period.

api_request_log
If your organisation uses the API, a line per request: which key, which endpoint, when, and the IP address it came from. It is how we can tell a key has been abused or leaked. Kept: 90 days from the request, then the row is deleted.
organisation_invite
An invitation someone sent to a colleague's email address. It belongs to the organisation rather than to the person who sent it, so it survives them leaving — revoking a pending invite because somebody else deleted their account would take away a third party's access. Kept: An accepted invite is kept as the record of how that person joined. One nobody answered is deleted 90 days after it was sent; a revoked one, 30 days after it was revoked.

Your rights

To see it. Settings → Privacy → Export as JSON gives you everything we hold, immediately, in the same shape our own API serves.

To correct it. Every figure on your company record is editable, and changing one keeps the old value in the history rather than overwriting it.

To delete it. The two buttons above. You do not have to ask us.

To object, to restrict, or to take it elsewhere. The export is your data in a machine-readable file. For anything else, write to us at the address above and we will answer.

To complain. The Information Commissioner’s Office regulates us: ico.org.uk. We would rather you told us first.

Cookies

The public site sets analytics cookies only if you accept them, and works the same if you decline. Declining is not a preference we record and ignore.

Precisely what happens before you answer. Google Analytics does load, with Google Consent Mode set to denied: it stores nothing on your device and sends no identifier, but it does make a request, which means Google sees your IP address as it would for any file our pages fetch. Nothing is written, nothing is joined to you, and no profile is built. Any tag that cannot be held back that way is not loaded at all until you accept — which is why the visitor tracker we used to run has been removed rather than deferred.

Signing in sets a session cookie. That one is not optional, because it is what keeps you signed in, and it is the only cookie we set without asking.

Book a free consultation