Last updated 1 August 2026
Read our Terms of Service →Recover AI operates a failed-payment recovery platform for subscription businesses. This policy explains what personal data we handle, why, and what rights people have. For data about our own merchants we act as a controller. For data about a merchant's customers we act as a processor on that merchant's instructions.
Merchant account data: name, email address, company name, website, support and reply-to addresses, plan and credit balance, and authentication metadata.
Customer data supplied by merchants: customer email address, phone number (when provided by manual entry or CSV import), plan name, invoice amount, failure reason, retry count and payment status. We do not receive or store full card numbers, CVV codes or bank credentials.
Operational data: recovery sequence state, outreach attempts and their outcome, magic-link opens and uses, delivery events such as bounces and unsubscribes, and application logs.
Site data: basic analytics events on our marketing pages, including which hero variant was shown, page views and clicks.
Where GDPR applies, our legal bases are contract performance (providing the Service), legitimate interests (security, product improvement, recovering payments owed to our merchants) and legal obligation. Merchants are responsible for the lawful basis and consent for contacting their own customers.
We use a small set of vetted subprocessors, each bound by a data-processing agreement:
We do not sell personal data, and we never use your customer lists for our own marketing. We may disclose data where required by law or to protect our rights.
Our providers may process data outside your country, including in the United States and the EU. Where required, transfers are covered by Standard Contractual Clauses or an equivalent safeguard.
Merchants may request earlier deletion of specific customer records at any time.
Data is encrypted in transit with TLS and at rest by our infrastructure providers. Access is scoped per account using row-level security so one merchant cannot read another's data. Administrative access is restricted to the people who need it, secrets are held in a managed secret store, and magic links are single-purpose tokens that expire. No system is perfectly secure; we will notify affected merchants without undue delay if a breach affects their data.
Depending on where you live you may have the right to access, correct, delete, port or restrict the processing of your personal data, and to object to processing based on legitimate interests. To exercise these rights email privacy@recover-ai.tools. If you are the customer of a business that uses Recover AI, please contact that business first — we will forward your request to them and support them in responding. You also have the right to complain to your local data protection authority.
Every recovery email includes an unsubscribe link. When someone unsubscribes, or an address bounces or reports a complaint, we automatically stop the active recovery sequence for that recipient and send them nothing further. For SMS and WhatsApp, replying STOP opts the number out through our messaging provider, which blocks further messages to that number; we also stop the sequence at the next scheduled step. Transactional notices required to service an existing subscription may still be sent by the merchant directly.
We use strictly necessary cookies and local storage to keep you signed in and to remember which landing-page variant you saw. We do not use advertising cookies or cross-site trackers. You can clear this data at any time in your browser settings.
The Service is for businesses and is not directed to anyone under 18.
We will post any updates here and, for material changes, notify merchants by email. Questions: privacy@recover-ai.tools.
Recover AI is operated from the Kingdom of Saudi Arabia. Before launch, please add your registered legal entity name and address above, and have a qualified lawyer review this policy.