# Privacy and your leads

> Where your visitors' details are kept, who can see them, how they leave FunnelCreative and how to delete them, including that leads are never sent to AI providers.

Applies to: Everyone · Audience: everyone
Web page: https://staging.funnelcreative.com/docs/privacy-and-your-leads

## Your leads stay in your workspace

When a visitor sends your form, their answers are stored as a lead in the workspace that owns the funnel. Only people in that workspace can reach it, and only with a role that allows it (see below). A lead from one workspace can't be opened from another.

How long leads are kept is shown on the **Leads** line under **How long we keep things** (**Settings → Account & data**).

## Leads are never sent to AI providers

FunnelCreative never sends your leads to an AI provider, and never uses them as material for AI writing. The parts of FunnelCreative that store and show leads have no connection to any AI service, and an automated test checks that this stays true.

If you use your own AI assistant to help with your funnel, don't paste your leads' personal details into it either. See [Using FunnelCreative with your AI assistant](https://staging.funnelcreative.com/docs/use-with-your-ai-assistant.md).

## What a lead contains

A lead holds:

- the answers the visitor typed into your form
- the consent record: whether they ticked the box, whether it was required, the exact consent statement they saw, and when
- which funnel, form and published version it came from, and when it arrived
- the status and notes you and your team add

A lead does not hold the visitor's IP address, browser details or any cookie.

## What your published pages collect

- Published pages set no cookies and read none.
- To slow down people sending the form many times, FunnelCreative uses a shortened, scrambled code made from the visitor's IP address (a truncated hash). It is used only for that limit and is never stored on the lead.
- Page views are counted as numbers only. Nothing about the visitor is kept for analytics. See [Analytics: views and submissions](https://staging.funnelcreative.com/docs/analytics.md).
- Published pages run no scripts and load nothing from other websites.

## Who can see and change leads

| Role | Read leads, set status, add notes | Export and delete leads |
|---|---|---|
| Owner | Yes | Yes |
| Admin | Yes | Yes |
| Member | Yes | No |
| Viewer | No | No |

Viewers never see leads. The inbox tells them **Viewers can’t see leads: they’re your visitors’ personal details.** Notes on a lead are seen only by people in your workspace. See [Your team: members, roles and workspaces](https://staging.funnelcreative.com/docs/team-and-roles.md).

## How leads leave FunnelCreative

Leads leave FunnelCreative in only two ways, and both are started by you:

- **Export CSV** in the lead inbox (owners and admins). See [Your lead inbox and CSV export](https://staging.funnelcreative.com/docs/leads.md#export-csv).
- The account data export in Settings → Account & data (owners and admins), which includes every lead in the workspace. It stays downloadable for the number of days shown under **Export your data** (**Settings → Account & data**). See [Export your data, delete leads on request, close your account](https://staging.funnelcreative.com/docs/account-and-data.md).

There is no CRM sync and there are no webhooks, so nothing is passed to another service automatically. FunnelCreative doesn't email your leads or email you about them.

Other things never carry leads:

- Presets never copy leads. See [Brand kits, the badge and presets (Pro)](https://staging.funnelcreative.com/docs/brand-and-presets.md).
- Email drafts never include a lead's details. See [Follow-up email drafts](https://staging.funnelcreative.com/docs/email-drafts.md).

## Deleting a visitor's details on request

If someone asks you to delete their details:

1. Open your lead inbox and search for their email address.
2. Open the lead and click **Delete this lead**, then **Delete lead**.
3. Their answers, consent record and your notes are erased straight away. This can't be undone.

Only owners and admins can delete leads. If you need a record that you honoured the request, export first. Your Account & data screen says: **Deleting a lead cannot be undone. Export first if you need a record that you honoured the request; the export shows the lead only until it is deleted.**

After a lead is deleted, your analytics still count that the form was sent, but nothing about the person remains. Step by step: [Delete a lead](https://staging.funnelcreative.com/docs/leads.md#delete-a-lead). For closing your whole account, see [Export your data, delete leads on request, close your account](https://staging.funnelcreative.com/docs/account-and-data.md).

## How long things are kept

- Funnels, versions, images and leads: shown on the **Funnels, versions, images** and **Leads** lines under **How long we keep things** (**Settings → Account & data**).
- Data exports: the number of days shown under **Export your data** (**Settings → Account & data**).
- The other periods (sign-in sessions and the security log) are shown under **How long we keep things** on your Account & data screen. These periods are still being decided, so this page doesn’t print them.

## The Privacy page

The [Privacy](https://staging.funnelcreative.com/privacy) page is a placeholder in this preview. It says so at the top (**Placeholder · not approved for launch**) and is not a privacy policy. This help page describes what the software does. It is not legal advice and it is not your own privacy notice to your visitors.

## For AI assistants

- Leads are stored in the funnel owner's workspace and are never sent to AI providers or used as AI context.
- A lead contains the visitor's answers, a consent record, its funnel, form, version and time, and the owner's status and notes. It contains no IP address, user agent or cookie.
- Published pages set and read no cookies and run no scripts. The visitor's IP address is used only as a truncated hash for rate limiting.
- Owners, admins and members can read leads and set status and notes. Only owners and admins can export or delete. Viewers cannot see leads.
- Leads leave only through the owner's CSV export or the account data export. There is no CRM sync, webhook or email to or about leads.
- Deleting a lead erases its answers, consent record and notes permanently. The submission count in analytics is kept.
- Do not ask a user to paste leads' personal details into a chat.

## Related

- [Your lead inbox and CSV export](https://staging.funnelcreative.com/docs/leads.md)
- [Export your data, delete leads on request, close your account](https://staging.funnelcreative.com/docs/account-and-data.md)
- [Analytics: views and submissions](https://staging.funnelcreative.com/docs/analytics.md)
- [What your funnel collects: enquiries and promised next steps](https://staging.funnelcreative.com/docs/enquiries-not-sales.md)
