Legal
Privacy Policy
What this website collects, what it does not, and what you can decide. We build systems that run on other people's data for a living, so it would be a poor advertisement to be vague about our own.
Last updated: 21 July 2026
01
Who is responsible
PlainAI is a brand of FaceCraft GmbH. FaceCraft GmbH is the controller for the personal data described here, which means it decides why and how that data is used.
FaceCraft GmbH, Grossmatte-Ost 24b, 6014 Luzern, Switzerland. Registered in the commercial register of the Canton of Lucerne, UID CHE-316.448.388.
Questions about anything on this page, and any request about your own data, go to hello@plainai.solutions or +41 78 671 17 96. We are not required to appoint a data protection officer and have not appointed one, so what you send reaches the people who run the company.
02
What this policy covers
This site, plainai.solutions, and the email correspondence that follows if you write to us. Other sites we link to publish their own policies, including thefacecraft.com.
Two laws apply to us at the same time. The Swiss Federal Act on Data Protection applies because we are a Swiss company. The GDPR applies because we offer our services to people in the EU. Where the two differ, we follow whichever gives you more.
03
What we collect
When you write to us. This site has no contact form. Every enquiry button opens your own email application, so nothing is submitted through the website and nothing is captured on the way. What we receive is what you chose to send: your name, your email address, and whatever is in the message. Mail addressed to us arrives at our hosting provider and is delivered on to Google Workspace, where we read and answer it. We keep that correspondence so we can answer it and so we are not asking you the same questions twice.
When you load a page. Our hosting provider records the ordinary data every web server records: the IP address the request came from, the browser and device type, which page was asked for, and when. This is what makes it possible to serve the page at all, and to notice an attack while it is happening.
When you accept analytics. If you accept in the cookie banner, Google Analytics and Microsoft Clarity record how the site is used: the pages you view, the city your IP address maps to, your device, browser and screen in detail, the link that brought you here, and, for Clarity, a replay of pointer movement, clicks and scrolling. Clarity runs in strict masking, so page text and anything typed into a field is masked in your browser and is never uploaded.
Google Analytics is configured to collect that location and device detail at its finer setting rather than the coarser one, which is worth saying plainly because we could have chosen less. It is also able to accept identifying details such as an email address where a site provides them. This site provides none: there is no form here to type anything into, so nothing of that kind is ever sent. If that changes, this page changes first.
If you refuse, neither tool sets a cookie and no session is recorded. Both keep running in a reduced, cookieless mode, and we would rather state that than let you find it out: Google Analytics sends a signal that a page was viewed with no identifier attached, and Clarity counts the page view under an identifier that lives and dies with that single page. Neither can join one page to the next, recognise a return visit, or build a profile of you.
Refusing therefore costs the journey through the site, the session replay and the heatmap. It does not cost the traffic count, which is why refusing here is a real option rather than a button that quietly breaks the measurement and makes us wish you had not used it.
05
Why we process it, and on what basis
The GDPR requires a named legal basis for each purpose. Swiss law asks the related question of whether the processing is justified. These are ours.
| Purpose | Legal basis |
|---|---|
| Answering your enquiry | Steps taken at your request before a contract, GDPR Art. 6(1)(b). |
| Keeping records of work we invoice | Legal obligation, GDPR Art. 6(1)(c), with the ten-year retention Swiss bookkeeping law requires under Art. 958f CO. |
| Serving and securing the website | Our legitimate interest in a site that stays up and is not abused, GDPR Art. 6(1)(f). |
| Counting page views with no cookie or identifier | Our legitimate interest in knowing roughly how many people visit, GDPR Art. 6(1)(f). |
| Analytics and session replay, with cookies | Your consent, GDPR Art. 6(1)(a). Nothing here happens until you accept, and you can withdraw at any time. |
06
Your choices about tracking
The banner appears before any analytics cookie is set. Refusing is a single click, offered as plainly as accepting, and the site behaves identically either way. The question is asked once and covers both tools, because both behave the same way when refused.
Your answer is remembered in your browser's local storage, not in a cookie and not against your IP address. It records only what you chose and when. We keep no copy of it, and because it never leaves your browser we cannot tell from it who you are.
The answer lasts six months. After that the banner asks again, which is the period the French supervisory authority treats as best practice and the shorter end of what regulators across the EEA accept. Clearing your browser storage also clears it, and the banner will simply ask again.
You can change your mind sooner using the cookie settings link in the footer of every page. Withdrawing stops future collection and tells Clarity to erase the cookies it set. It cannot undo what was collected while consent was in place, which is the reason the banner comes before the tracking rather than after it.
Your browser can also block or delete cookies itself, and Google publishes a browser add-on that opts you out of Google Analytics everywhere. Both work regardless of anything we do.
07
Who else is involved
Three companies are involved in running this site and answering your mail. We keep the list short deliberately, because every processor is another place your data exists.
Hostinger hosts the website and receives mail sent to our addresses, then delivers it on to Google Workspace. They process what passes through the server on our instructions and nothing else.
Google appears twice, and the two are worth separating. Google Workspace is where we actually run the business: the email you send us, the calendar we book you into, and the documents and notes we write about the work. Google Analytics 4 is the measurement on this website, and we have enabled Google's advertising features, which lets Google use signed-in Google users' data to report on demographics and to recognise the same person across devices. That is a genuine widening of what Google can infer, and it is why the measurement sits behind consent while your email does not: answering a message you sent us needs no permission beyond your having sent it.
Microsoft provides Clarity. Microsoft is not only acting on our instructions here: it also uses Clarity data for its own purposes, including product improvement, security, and advertising through Microsoft Advertising. What Microsoft does with it is governed by the Microsoft Privacy Statement, which is linked at the end of this policy.
08
Where your data is processed
The website and the mail server that first receives your message are hosted in the European Union.
Beyond that, Google and Microsoft may process data outside Switzerland and the EEA, including in the United States. That applies to the analytics on this site, and it applies to the correspondence held in Google Workspace. Both companies are certified under the EU-US Data Privacy Framework and its Swiss-US counterpart, and both rely on the European Commission's Standard Contractual Clauses in addition. Those are the mechanisms the law provides for transfers of this kind.
If that matters to you, say so in your first message and we will keep the exchange to email alone rather than filing it anywhere else.
09
How long we keep it
| What | How long |
|---|---|
| Email correspondence | For as long as we are working together, then ten years from the end of the business relationship, which is the retention Swiss law requires for business records. |
| Google Analytics | User and event level data is deleted after 14 months. Aggregate reporting totals are kept beyond that and cannot be traced to a person. |
| Clarity session recordings | 30 days. Recordings we mark as favourites, and a random sample Clarity keeps for benchmarking, are held up to nine months. |
| Clarity heatmaps | Up to nine months. |
| Server logs | A short period set by our hosting provider, for security and troubleshooting only. |
10
Your rights
You can ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, ask us to restrict what we do with it, object to processing we base on legitimate interest, and ask for it in a portable form. Where we rely on your consent, you can withdraw it at any time, and doing so does not make what came before unlawful.
Write to hello@plainai.solutions. We answer within 30 days. If we cannot identify you from the request we will ask, because handing your data to someone who merely claims to be you would be the worse failure.
If you think we have got it wrong, you can complain to a regulator without going through us first. In Switzerland that is the Federal Data Protection and Information Commissioner. In the EU it is the supervisory authority where you live, work, or where the problem happened.
11
Automated decisions and AI
We make no automated decisions about you that produce legal effects or anything similarly significant. Nothing here decides whether you are a lead, scores you, or ranks you.
The AI agents we build are built for clients and run in the clients' own accounts. They are not connected to this website. Nothing you do here is used to train a model, ours or anyone else's, and nothing you send us is fed into a public AI service.
12
How we protect it
The site is served only over HTTPS and instructs browsers to refuse an unencrypted connection to it. It sets the usual protective response headers, refuses to be embedded in another site's frame, and ships no third-party code beyond the two analytics tools named above.
Access to correspondence is limited to the people who need it, which at our size is a small and specific number of people. We take no card details and store no payment data: invoices are paid by bank transfer.
13
Children
This site sells business services and is not directed at children. We do not knowingly collect data about anyone under 16. If you believe a child has sent us personal data, write to us and we will delete it.
14
Changes to this policy
We will update this page when what we do changes, and the date at the top will say when. We are currently building a booking flow and a client record system; when they go live, this policy will be extended to describe them before they collect anything, not afterwards.
If a change materially affects how we use data you have already given us, we will ask again rather than rely on this page having quietly changed.
Microsoft’s own handling of Clarity data is described in the Microsoft Privacy Statement, and Google’s in the Google Privacy Policy. Our contract terms are on the Terms & Conditions page. Anything unclear here is worth an email to hello@plainai.solutions.