RecruitAffiliates.ai Start free

Legal

Privacy policy

Version 2. Last updated 28 September 2026.

The short version

  • RecruitAffiliates.ai helps businesses find creators and websites who might promote them, and email them from the business's own inbox.
  • We hold three kinds of data: yours as a customer, public data about creators, and the outreach our customers send. Section 2 says who's in charge of each.
  • We don't sell data. We don't train AI models on it. We don't read your inbox beyond the threads the service started.
  • Found through us and want it to stop? Go to app.recruitaffiliates.ai/creators/remove. No business using the service will see you or email you again.

1. Who is responsible

RecruitAffiliates.ai (recruitaffiliates.ai) is run by James Barkway, trading as RecruitAffiliates.ai, a sole trader established in England and Wales. It used to be called AffiliateRail Finder. AffiliateRail is run by the same person, and one sign-in works for both products. Office 4382, 182-184 High Street North, London, E6 2JA, United Kingdom. Contact support@recruitaffiliates.ai.

There's no data protection officer, because the business isn't required to appoint one. The address above reaches a person who can act.

2. Who decides what, for each kind of data

The law calls whoever decides why and how data is used the controller. A processor holds data for someone else, on their instructions. It tells you who to ask.

The dataWhat's in it, and where it sitsControllerCovered by
Your accountYour name, email, company, team, plan, invoices, sign-in and support emails. In our database and at Stripe.UsThis policy, sections 3 and 4
Discovery dataPublic data our scans gather and rank about creators and websites: names, links, public numbers, content titles, the affiliate links they use, and our fit score. Stored with the brand whose scan found it. Our public "who promotes" pages show a page link only.Us. We decide what to gather and how to rank itThis policy, section 5
The do-not-contact listA scrambled code for every address, channel or site that unsubscribed or asked to be removed. Shared across every customer and kept after any account closes.UsThis policy, section 5
Your outreachThe creators you save, the email addresses you reveal, your campaigns, the emails you send, the replies, your notes, your deals and your own do-not-contact list. Stored in your account.You. We're your processorThe data processing agreement, part of our terms

So if a business emailed you through us, that business decides who to email and what to say. We decide what our scans find and we keep the do-not-contact list.

3. What we collect about you, our customer, and why

WhatWhyLawful basis
Name, email, company, your websiteTo create your account, sign you in and reach you about itPerformance of a contract
Your brand details: competitors, keywords, country, your offerTo run the searches you ask for and write your emailsPerformance of a contract
Your plan, subscription and payment historyTo bill you and apply your plan's limitsPerformance of a contract
Billing address and card countryTo work out the right tax and keep the evidence tax law requiresLegal obligation
What you send us by emailTo answer youLegitimate interest in replying
Which page of this site sent you to the trial (from) and any campaign tags in the link you arrived onTo know which pages are worth keepingLegitimate interest in a working site
Which screens of the app get usedTo know what to fix. See section 7Legitimate interest in a working product
Recordings of app sessions, only if you said yes to analytics. Every typed field and email address is masked, and nothing is recorded on the signup, sign-in or billing pagesTo see where people get stuckConsent
Server logs: IP address, browser, the page requestedSecurity and keeping the service upLegitimate interest
Error reportsTo fix what broke. Personal data is stripped before a report is sentLegitimate interest

We never see your card number. Card details go straight into Stripe's own checkout. We get a confirmation, the last four digits and the card brand.

4. Signing in with Google

If you sign in with Google, Google tells us your name, your email address and your profile picture. That's all. It gives us no access to your Gmail, your Google Drive or YouTube. You can use an email address instead.

5. If we found you as a possible affiliate

RecruitAffiliates.ai looks for people who already make content in a business's field, on a blog, a podcast, a newsletter or their own website. If you publish that kind of content, you may be in a customer's results.

What we hold. Only what you or your site made public. Your site, channel or show name and link. Public numbers such as subscribers, views or estimated traffic. The title and link of each page, video or episode that matched a search, and when it came out. Which affiliate links appear on those pages. A score for how well you fit one business, based on your content, not on you as a person. And, if a customer asks for it, a contact email address and where it came from. We don't hold your age, home address, phone number, or anything about your health, beliefs or politics.

Where it comes from.

  • Websites: found through search results and traffic estimates from DataForSEO, then read from the site itself, including its contact page.
  • Podcasts: found through Podcast Index, then your show's public feed, including the owner address in it.
  • Hunter: a service that finds and checks work email addresses for a website's domain. We ask it only when a customer asks for your address. If we switch on Icypeas, which does the same job from France, it's asked the same way. Both are on our sub-processors page.

Why, and our lawful basis. So a business whose product fits your audience can invite you into its affiliate program. Our lawful basis is legitimate interests (UK GDPR Article 6(1)(f)): yours in hearing about paid offers that match what you already publish, and ours and our customers' in making that offer. We've weighed that against your privacy. We use public data only. We prefer a business address, like hello@ or partners@, over a personal one when we find both. And you can stop it at any time, in one click.

Who sees it. The customers whose searches match you, each in their own account. We don't sell it and we don't publish it. Our public "who promotes" pages show a link to a public page only, never a name or an email address.

You're told at first contact. Every first email a customer sends through us carries a short notice they can't remove: who's writing and that they found you through RecruitAffiliates.ai, where your details came from, a link to see what we hold and where each piece came from, and a link to stop all email.

How long. Raw data from our providers is deleted after 90 days. We have paused YouTube API requests while the YouTube compliance review is open. Any YouTube API data is deleted after 29 days if it has not been refreshed, and it is deleted or refreshed within 30 calendar days (section 11). The rest stays while the customer whose scan found you keeps their account, and goes when you ask.

To be removed. Go to app.recruitaffiliates.ai/creators/remove and enter your email address, channel or site. No sign-in. We email you one link, and when you open it, no business using RecruitAffiliates.ai will see you or email you again. We keep only a scrambled code of your address or channel, so this holds for good. The unsubscribe link in any email sent through us does the same for that address. A confirmed request also deletes YouTube API data we hold about you within seven calendar days. Deleting data from RecruitAffiliates.ai does not delete anything from YouTube.

6. Your inbox

To send outreach from your own address, you connect your mailbox. The connection runs through Unipile, a French company that links mail accounts to software. You sign in on Unipile's page, not ours.

  • What we read. Only conversations RecruitAffiliates.ai started, or that you linked to an affiliate yourself. We never import your old mail and we don't look through the rest of your inbox.
  • Why Google or Microsoft still asks for read and send. Their permission screens don't offer "only these threads". The limit is in our software, and we explain each permission on the screen before you connect.
  • What we keep. The subject and body of synced messages, encrypted, for 30 days. Then they're deleted. The timeline keeps a line saying a message was there, so the history still makes sense.
  • What we send. Only emails you approved, in sequences you approved, with an unsubscribe line on each. We don't track opens or clicks.
  • Disconnecting. Remove the inbox in Settings, then Inboxes, at any time. You can also revoke access from your Google or Microsoft account. When your plan ends, we release the connection after 7 days.

Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We don't use mailbox content for advertising, don't sell it, don't let people read it except where you ask us to or the law requires, and don't use it to train AI models.

7. Cookies and what's in your browser

This site stores nothing and counts nothing until you answer the cookie card. Say no, and we still count the visit, with nothing stored on your device. Say yes, and our analytics (PostHog) keeps a cookie, so a visit here and a signup at app.recruitaffiliates.ai count as the same person. If you arrived on a RecruitAffiliates.ai affiliate's link, we also keep which affiliate sent you, but only after you say yes. The full list, with names and lifetimes, is on the cookie policy. Change your answer any time from Cookie choices in the footer.

8. AI

We use an AI model, Qwen, to sort websites our scans find, and to turn your website into a brand summary when you set up. We reach it through OpenRouter, a US company, which sends it to Alibaba Cloud International to run in Singapore or mainland China. We've switched off fallback to other hosts, and told OpenRouter to use no host that keeps or trains on what we send.

9. Who else sees data

The companies that process data for us are on the sub-processors page, with what each does, where, and the transfer safeguard. We give customers 30 days' notice before adding one.

Otherwise we share personal data only where the law requires it, or to defend a legal claim.

If you use AffiliateRail too, the same person runs it. When you choose to hand an agreed affiliate to AffiliateRail, we pass that affiliate's contact details and agreed terms across, because you asked us to. Nothing moves between the two unless you press that button.

10. Sending data outside the UK

Most of our providers process in the United States. Unipile and Hunter process in the EU, and DataForSEO in Estonia. Except for OpenRouter and the AI model below, each of those transfers relies on a mechanism UK law recognises: the UK International Data Transfer Addendum, the EU Standard Contractual Clauses with the UK Addendum, a certification under the UK Extension to the EU-US Data Privacy Framework, or UK adequacy regulations for the EU.

Singapore and China. We use OpenRouter to send requests to Qwen models run by Alibaba Cloud International, which may process them in Singapore or mainland China. Neither country has a UK or EU adequacy decision, which is the official finding that a country protects data well enough. Alibaba states it does not use this data to train models. We rely on OpenRouter's contractual data-protection commitments; we do not currently hold a signed data processing agreement with Standard Contractual Clauses for this transfer. To limit the risk, we keep what goes there small: public web text and your own website's text. No email addresses, mailbox content or payment data ever go there.

Which mechanism applies to which provider is on the sub-processors page.

11. RecruitAffiliates.ai and YouTube

Current status. We have paused YouTube API requests while the YouTube compliance review is open. If YouTube discovery is made available again, RecruitAffiliates.ai will use YouTube API Services under the YouTube Terms of Service, and Google's handling of data is covered by the Google Privacy Policy.

  • What we would read. Public information only: a channel's name, link, description and country, its subscriber count and how many videos and views it has, and the title, description, view count, length and publish date of the videos that matched your search.
  • What we never touch. We never ask for access to your Google or YouTube account for this. We read nothing private, and we never upload, comment, like or subscribe. You can sign in with Google if you like, but that only tells us your name, email address and profile picture. It gives us no access to YouTube.
  • How we would use it. To show it only to people in your organization, with links back to the channel and videos on YouTube.
  • No score or ranking from YouTube data. We do not calculate, store or display a score, ranking, activity measure or other derived metric from YouTube API data.
  • Who else sees it. While requests are paused, no YouTube API data is sent to another service. We don't sell YouTube data, show it to anyone outside your organization, or use it to train an AI model.
  • How long we keep it. We refresh YouTube API data only by fetching it again. If it is not refreshed, we delete all YouTube API data after 29 days. That includes channel IDs and links, names, numbers, video titles, descriptions and API-derived metadata. We keep only a scrambled suppression code if you asked us not to contact you again.
  • Revoking access. We hold no access to your Google account for YouTube, so there's nothing to revoke there. You can review and remove any app that has access to your Google account at Google's security settings page. That includes a Gmail inbox you connected for outreach.
  • Deleting it now. Use the remove page, or email support@recruitaffiliates.ai. We delete the YouTube API data we hold within seven calendar days. This does not delete your channel or videos from YouTube.

12. How long we keep it

WhatHow longWhy
Your account and its outreach dataWhile the account exists. When you ask us to delete it, we finish within 30 daysSo you can come back to your results
A finished trial or a cancelled planKept read-only until you ask us to delete itA trial ending never deletes anything
Raw data from our discovery providers90 daysEnough to rebuild a result, then gone
YouTube API data29 days unless refreshed, see section 11YouTube's developer policies
Synced email subjects and bodies30 daysLong enough to read and answer a reply
Your mailbox connectionReleased 7 days after your plan ends, or at once when you disconnect itA short grace period if you renew
Unsubscribes and removal requestsFor good, as a scrambled code onlySo a person who said no is never emailed again
Database backups7 days, then overwrittenTo recover from a failure
Invoices and payment records5 years after the 31 January filing deadline for that tax yearHMRC record keeping
Tax location evidence10 yearsEU VAT One Stop Shop rules
Support emails3 yearsLong enough for a billing dispute
Error reports90 daysFixing things

13. Your rights, and how to use them

You can ask for a copy of your data, or ask us to correct it, delete it, restrict or object to how it's used, or hand it to someone else in a machine-readable form. Where consent was the basis, you can withdraw it. You can object to direct marketing at any time, and we'll always stop.

We reply within one month, and it's free.

About an email a business sent you. That business is the controller of its outreach. If you ask us about it, we'll tell you which business it was and pass your request to them, so they can answer too. We still stop all email to you through us straight away if you ask.

Some records survive a deletion request because the law requires them, like invoices, or because deleting them would undo your request, like the do-not-contact code. We tell you which, and why.

You can complain to the Information Commissioner's Office at ico.org.uk. We'd rather you told us first, but you don't have to.

14. If there's a breach

If a breach is likely to put your rights at risk, we tell you without undue delay, and we tell the ICO within 72 hours where the law requires it. Where your outreach data is involved, the data processing agreement says what we tell you and how fast: within 48 hours of finding out.

15. Children

RecruitAffiliates.ai is for businesses and isn't for anyone under 16. Our customers must not contact anyone who is, or appears to be, under 18. We don't knowingly hold data about children. If you think we do, use the remove page or tell us, and we'll delete it.

16. Changes

Changes are posted here with a new date at the top. For anything material, we email customers first.