Privacy policy
- Version
- 1.5
- Effective
- 21 August 2026
- Last updated
- 21 August 2026
1. Controller and contact details
1.1 Tenor is operated by Tenor Research Ltd (“Tenor”, “we”, “us”), a company registered in England and Wales under company number 17385950, whose registered office is at High House, Ranworth Road, Blofield, NR13 4PJ. We are the controller of the personal data described in this policy.
1.2 Enquiries concerning data protection, and requests to exercise the rights set out in clause 22, should be addressed to privacy@readtenor.com.
1.3 We are not presently required to register with the Information Commissioner’s Office or to pay the data protection fee, on the basis that we have not begun trading. We will register, pay the fee and publish our registration number in this clause upon commencement of trading.
1.4 We have not appointed a Data Protection Officer. Our processing does not meet the criteria in Article 37 of the UK GDPR.
2. Scope
2.1 Tenor analyses comments published on UK political YouTube videos in order to identify the subjects under discussion and how opinion divides on each, and reports the results as population-level statistics. It does not construct profiles of individuals.
2.2 This policy addresses two categories of data subject and is divided accordingly:
- Part A applies where personal data is provided to us directly, by visiting this website, creating an account or joining the waitlist;
- Part B applies where personal data is obtained from YouTube because you commented on a UK political video, and was not provided to us by you;
- Part C applies where personal data is obtained because you posted publicly on X, and was not provided to us by you.
2.3 Clauses 22 to 27 apply to all three Parts.
Part A — Website, accounts and waitlist
3. Personal data collected
3.1 Account registration. Where you create an account using an email address and password, we collect your name, your email address and a password. The password is not stored as entered. Our authentication provider retains only a salted cryptographic hash of it, which we cannot read, recover or disclose.
3.2 Google sign-in. Where you sign in using Google, Google discloses to us your name, your email address, whether that address is verified, your Google account identifier and the URL of your profile image. We do not receive your password and receive no other element of your Google account, including your contacts, files or search history. This authorisation may be reviewed and revoked at any time from the connections settings of your Google account.
3.3 Server logs. Our hosting provider records technical information incident to serving this website, comprising IP address, browser type, pages requested and timestamps. This information is not used to identify you.
3.4 We do not collect your employer, job title, telephone number or postal address.
4. Accounts and dashboard access
4.1 Creating an account places you on our waitlist. It confers no entitlement to any reading, report, dataset or dashboard, and no charge is made for it.
4.2 Access to the client dashboard is enabled by us manually, for clients who have commissioned a reading, and is recorded as a single flag against the account. It cannot be self-granted, and creating an account does not commence any process towards it.
5. Cookies
5.1 On sign-in we set cookies which maintain your session between pages. These are strictly necessary for the provision of a service you have requested and are accordingly exempt from the consent requirement under regulation 6(4) of the Privacy and Electronic Communications (EC Directive) Regulations 2003. They are cleared on sign-out.
5.2 We do not use advertising cookies, analytics cookies or tracking pixels, and we do not disclose browsing data to advertisers or data brokers.
5.3 Should we introduce analytics, we will obtain your consent beforehand and amend this policy before doing so.
6. Purposes and lawful bases
| Purpose | Lawful basis |
|---|---|
| Creating and operating your account | Contract — Article 6(1)(b) |
| Notifying you once, when Tenor becomes available | Consent — Article 6(1)(a) |
| Verifying email addresses, maintaining account security and preventing misuse | Legitimate interests — Article 6(1)(f) |
| Enabling and administering dashboard access for clients | Contract — Article 6(1)(b) |
| Maintaining the security and operation of this website | Legitimate interests — Article 6(1)(f) |
6.1 The basis differs between the two functions of an account. Holding the account is performance of a contract you requested. Notifying you at launch rests on consent, which may be withdrawn under clause 9 without closing the account.
7. Use of contact details
7.1 We will use your email address to contact you regarding the availability of Tenor and regarding your account. We will not sell or rent your details, or disclose them to third parties for those parties’ own marketing purposes.
7.2 Creating an account is voluntary and is neither a statutory nor a contractual requirement. The sole consequence of not creating one is that we cannot notify you when Tenor becomes available. An account confers no entitlement to a reading, to particular pricing, or to any position in a queue. See our Terms and Conditions.
8. Retention
8.1 Account details are retained for so long as the account subsists.
8.2 Where you close your account or request removal, the account record and waitlist entry are deleted within 30 days and removed from backups within 90 days. Should Tenor not launch, the waitlist will be deleted in its entirety.
9. Withdrawal of consent
9.1 Consent to launch notifications may be withdrawn at any time, without charge, by written request to privacy@readtenor.com. No reason need be given. Each email we send will also contain an unsubscribe facility.
9.2 Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and does not of itself delete your account. Deletion of the account must be requested separately.
10. Recipients
| Recipient | Data disclosed | Purpose |
|---|---|---|
| Supabase Inc. | Name, email address, password hash, access flag | Authentication and database services. Hosted in London (eu-west-2) |
| Vercel Inc. | Requests to this website, including IP address and session cookie in transit | Website hosting and delivery |
| Google LLC | The fact of sign-in, in exchange for name and email address | Only where you elect to sign in with Google |
| Zoho Corporation | Email address and the content of correspondence | Transmission of account and launch emails |
10.1 Each of the above acts as our processor on our documented instructions, save for Google LLC, which is an independent controller in respect of your Google account.
Part B — The Tenor polling service
This Part concerns individuals who have commented on UK political YouTube videos and who have had no dealings with Tenor. It is published in discharge of our obligations under Article 14 of the UK GDPR.
11. Source of the data
11.1 We process publicly visible comments on public YouTube videos, obtained through the official YouTube Data API v3 under Google’s developer terms, using an authenticated API key.
11.2 In respect of YouTube, we do not scrape, use unofficial endpoints or browser automation, or acquire third-party comment datasets. We do not access private or unlisted videos, or any material requiring account credentials. Clause 28 describes how material is obtained from X, which is different.
11.3 Because this service uses the YouTube Data API v3, we are bound by the YouTube Terms of Service, and you are referred to them. Google’s own handling of any data it receives, including the requests we make to the API, is governed by the Google Privacy Policy. Neither document is ours and neither is affected by this policy.
12. Data obtained
12.1 In respect of each comment we obtain the comment text; the public display name shown against it; the number of likes and replies it received; the date of publication; and the video and channel under which it appeared.
12.2 We do not obtain your email address, your real name, your subscriber list, your watch history, your location, or any other element of your Google account.
13. Processing operations
13.1 Pseudonymisation. On ingestion, the display name is converted to an irreversible identifier by means of a salted SHA-256 hash. The display name is not carried forward into analysis.
13.2 Classification. The comment is processed by an automated language model which records (a) the subjects the comment addresses; (b) whether it expresses support for, opposition to, or a neutral position on each; (c) the strength of that expression; and (d) a short statement of the basis on which those labels were assigned. Each label describes the comment. Labels are not combined across comments bearing the same identifier, and no overall position is calculated or held in respect of any individual.
13.3 No ideological placement. No comment and no individual is scored on a left-right, liberal-authoritarian or comparable ideological scale. That capability existed and was removed in August 2026, as recorded in clause 15.2.
13.4 Deletion of source material. On classification, the comment text, the display name and the video description are cleared. Clause 21 states the retention periods which apply in any event.
13.5 Aggregation. Labels are pooled across many thousands of comments to produce subject-level statistics, for example that 62% of comments addressing a given subject expressed opposition. Published output is statistical. We do not publish individual comments attributed to individual persons.
14. Purpose of the pseudonymous identifier
14.1 The identifier is used for one purpose: to prevent any one person being counted more than once within a tally.
14.2 Where the same person comments repeatedly on a subject, counting each comment would permit a single vocal individual to distort the result. The identifier enables us to cap each person’s contribution to any one subject at three comments, and to report the number of distinct persons on which a figure rests.
14.3 The identifier is not used for any other purpose. It is not used to track you, to build any picture of you, or to link you to any data outside the comment data.
15. Processing not undertaken
15.1 We do not:
- build a profile of you, or hold any accumulated political score against your identifier;
- infer your age or gender, whether from your username, your writing style or otherwise, including for internal purposes;
- infer your ethnicity, national origin, religion, sexual orientation, health or any other special category of personal data;
- take automated decisions producing legal effects concerning you or similarly significantly affecting you;
- attempt to identify or contact you, or to link your comments to any other account, dataset or platform;
- sell personal data.
15.2 Tenor formerly had the capability to infer demographic attributes and to accumulate per-person ideological scores. That capability was removed from our systems in August 2026. Its removal is enforced by an automated test which fails the build if the retired functionality is reintroduced.
16. Status of pseudonymised data
16.1 We do not describe the hashed identifier as anonymous, and it should not be so understood. Pseudonymised data remains personal data under the UK GDPR.
16.2 The identifier cannot be mathematically decoded to recover a display name. A person holding both our secret salt and a correct guess at a display name could, however, confirm a match. We accordingly treat the salt as a protected secret and the identifier as personal data, with the protections that follow.
17. Lawful basis
17.1 We rely on legitimate interests under Article 6(1)(f) of the UK GDPR.
17.2 The interest pursued is the measurement and reporting of public opinion on political subjects, from material published in public by its authors.
17.3 Necessity. The analysis cannot be performed without processing the comments. Consent cannot be obtained from each commenter, as we hold no means of contacting them.
17.4 Balance. We process only material already public; we delete comment text and display names promptly under clause 21; we hold no profile of any individual; we publish only statistics; and we afford the right of objection at clause 22. We assess the impact on data subjects as minimal and the safeguards as proportionate.
18. Article 14 notice
18.1 Where personal data is not obtained from the data subject, Article 14 of the UK GDPR ordinarily requires that the data subject be notified directly. We are unable to do so: we hold no contact details for commenters and deliberately refrain from acquiring any. Contacting commenters individually would require the collection of substantially more personal data than the analysis itself requires.
18.2 We therefore rely on the exemption at Article 14(5)(b), and publish this policy openly and prominently as the notice required by that Article.
19. Recipients
| Recipient | Data disclosed | Purpose |
|---|---|---|
| Google LLC (YouTube Data API) | The requests we make | Source of the comments |
| Mistral AI SAS (France) | Comment text | Automated subject and stance labelling |
| Vercel Inc. | Website traffic data | Website hosting and delivery |
19.1 Comment text is disclosed to Mistral AI SAS, a French company, which operates the language model performing the classification. We use its paid API, under which comment text is not used to train any model. Mistral retains it for a limited abuse-monitoring period and then deletes it. It acts as our processor, on our instructions, under a data processing agreement.
19.2 We do not use free or consumer artificial intelligence services for this purpose. Certain of those services train their models on material submitted to them, and material used for training cannot subsequently be deleted, which would be incompatible with both the retention periods at clause 21 and the right to erasure at clause 22.
19.3 We do not disclose personal data to advertisers, data brokers, political parties or campaign organisations.
20. Anti-profiling controls
20.1 We do not attach any political characteristic to any named channel, creator or individual, and we publish no breakdown of opinion by any political characteristic of any person.
20.2 Nothing in Tenor’s published output identifies a comment, an author or an account. This is enforced by an automated test which fails the build in the event that any identifier appears in published output.
21. Retention
| Data | Retention |
|---|---|
| Comment text and display names | Cleared on classification; blanked in any event no later than 7 days after retrieval, and deleted no later than 30 days after retrieval, as required by YouTube’s developer terms |
| Pseudonymous identifiers and the per-comment labels described at clause 13.2 | Deleted no later than 30 days after retrieval of the comment to which they relate. Deletion of a comment cascades to every derived per-comment record of it |
| Aggregate statistics | Retained for up to 36 months. These are statistics and contain no personal data |
General
22. Your rights
22.1 Under the UK GDPR you have the right to be informed; to obtain access to the personal data we hold concerning you; to rectification; to erasure; to restriction of processing; to object to processing carried out on the basis of legitimate interests; to data portability; and to withdraw consent at any time where consent is the basis of processing.
22.2 No charge is made for exercising these rights. We will respond within one month of receipt.
22.3 We take no automated decision producing legal effects concerning you or similarly significantly affecting you. Holding an account does not alter this.
23. Exercising rights: account holders
23.1 Requests should be sent to privacy@readtenor.com from the address to which the account is registered.
23.2 Access. We will supply everything held against the account: name, email address, date of registration, and whether dashboard access is enabled. We cannot supply your password, as we do not hold it.
23.3 Erasure. We will delete both the authentication record and the account record. This is irreversible; a new account would be required in order to register again.
23.4 Rectification. We will amend the name or email address on notification of the correct particulars.
23.5 Deletion of a Tenor account does not affect your Google account. Where you signed in with Google, the authorisation may separately be revoked from the connections settings of that account.
24. Exercising rights: commenters
24.1 As we hold no display names, we cannot search our records by name. We can, however, search for the identifier derived from a name.
24.2 Send to privacy@readtenor.com the YouTube display name or channel handle under which you commented. We will apply the same hash to it, search for the resulting identifier, and inform you what is held against it. You may then request erasure or object to further processing.
24.3 Deletion of your comment on YouTube does not of itself remove derived labels already held by us. A separate request should be made to us.
24.4 Where you object or request erasure, we will remove your data from our analysis. We cannot withdraw statistics already published, which contain no personal data and cannot be reverse-engineered to identify any individual contribution.
25. International transfers
25.1 Account data remains in the United Kingdom. Our database and authentication services are hosted in London (eu-west-2), a region selected so that account details do not leave the United Kingdom.
25.2 Comment text does not leave Europe. Classification is performed by Mistral AI SAS on European infrastructure. A European provider was selected so that the comments analysed are not transferred outside the UK and EU.
25.3 Two transfers to the United States are disclosed:
(a) Where you sign in with Google, the exchange involves Google LLC in the United States. That transfer is made under Google’s standard contractual clauses together with the UK International Data Transfer Addendum. Signing in with email and password avoids it.
(b) Where you correspond with us by email, the correspondence is held by Zoho Corporation, whose servers for our account are in the United States. That transfer is made under Zoho’s standard contractual clauses together with the UK International Data Transfer Addendum. It affects correspondence only, and neither account data nor comment data.
26. Complaints
26.1 Complaints concerning our handling of personal data should in the first instance be addressed to privacy@readtenor.com.
26.2 You have the right to complain to the Information Commissioner’s Office at any time, without first referring the matter to us:
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113 — ico.org.uk/make-a-complaint
27. Amendment
27.1 Where we change our processing of personal data, we will amend this policy and revise the version number and effective date above.
27.2 Material changes — a new category of data, a new purpose or a new recipient — will be published on this website before taking effect, and notified by email to waitlist members where we hold a relevant address.
27.3 We will not reintroduce individual profiling, demographic inference or special-category inference otherwise than by publishing that change clearly and in advance.
Part C — Readings from X
This Part concerns individuals who have posted publicly on X (formerly Twitter) and who have had no dealings with Tenor. It is published in discharge of our obligations under Article 14 of the UK GDPR. Part B, which concerns YouTube, does not apply to this material, and this Part does not apply to that.
28. Source of the data
28.1 We process posts published publicly on X.
28.2 We do not obtain this material from X. We are not party to X’s developer agreement, we hold no X API credentials, and we have no relationship with X Corp. We obtain it from twitterapi.io, an independent third-party service which supplies X post data on a per-request basis.
28.3 We state this plainly because the distinction matters to you. The material we hold about you did not reach us through a route X operates or controls, and X has no record of our having obtained it. Neither X’s terms of service nor X’s privacy policy is ours, and nothing in this policy affects them.
28.4 We process only posts that were publicly visible at the time we collected them. We do not access protected accounts, direct messages, or any material requiring account credentials, and we do not log in to X.
28.5 We do not collect reposts of another person’s post. Where a post was deleted before we collected it, we did not collect it; where it is deleted afterwards, see clause 34.7.
29. Data obtained
29.1 In respect of each post we obtain the text of the post; the public display name shown against it; the number of likes and replies it received; the date of publication; whether it was a reply, and to what conversation.
29.2 Our supplier also returns, and we discard at the point of ingestion without recording them: follower counts, verified status, account creation dates, view counts, and any location associated with the account. This is enforced in our own code and is covered by an automated test.
29.3 We do not obtain your email address, your real name, your followers, your private posts, or any other element of your X account.
30. Processing operations
30.1 The operations described at clauses 13.1 to 13.5 apply to this material in the same terms: pseudonymisation of the display name by salted SHA-256 hash on ingestion; automated classification recording the subjects addressed, the position expressed, its strength and a short statement of the basis for those labels; deletion of the post text after classification; and aggregation into subject-level statistics.
30.2 The limitations at clause 15 apply in the same terms. In particular we do not build a profile of you, hold any accumulated political score against your identifier, infer your age, gender, ethnicity, religion or any other special category of personal data, attempt to identify or contact you, or link your posts to any other account or dataset.
30.3 The purpose of the pseudonymous identifier is as stated at clause 14: to cap the number of posts any one person contributes to a single tally, so that one person posting repeatedly cannot distort a result. It is used for nothing else.
30.4 The identifier is specific to a single reading. It is derived using a random value generated for that reading alone, and that value is destroyed when the reading is complete. Two readings therefore produce unrelated identifiers for the same person, and we cannot link your posts across readings even if we wished to. Once a reading is finished, the identifiers in its working data cannot be connected to any account by us or by anyone else.
30.5 This is a deliberate limit on our own capability rather than a description of our intentions, and it is enforced in our software and covered by automated tests.
30.6 Clause 16 applies: we do not describe the hashed identifier as anonymous, and pseudonymised data remains personal data.
31. Lawful basis
31.1 We rely on our legitimate interests under Article 6(1)(f) of the UK GDPR, namely the conduct of opinion research on matters of public interest.
31.2 Our assessment of that basis, including the balancing exercise, is recorded in a Legitimate Interests Assessment. A copy is available on request to privacy@readtenor.com.
31.3 You have the right to object to this processing at any time under Article 21(1). Clause 35 explains how, and what happens when you do.
32. Article 14 notice
32.1 We did not obtain this data from you, and Article 14 requires that we tell you so.
32.2 We do not contact posters individually. Doing so would require us to identify and approach a large number of people who have had no dealings with us, using data we do not hold and would have to obtain for that purpose alone, which would be both disproportionate under Article 14(5)(b) and more intrusive than the processing it announced. This published notice is how we discharge the obligation instead.
32.3 The categories of data, the purposes, the lawful basis, the recipients, the retention periods and your rights are set out at clauses 29, 30, 31, 33, 34 and 35 respectively.
33. Recipients
33.1 The processor table at clause 19 applies. In addition, in respect of this material only:
| Recipient | Data disclosed | Purpose |
|---|---|---|
| twitterapi.io | The searches we run | The source of the posts |
| Mistral AI SAS (France) | The text of a post | Automated classification. Post text does not leave Europe |
33.2 We do not sell personal data and we do not share it for any purpose other than those described.
34. Retention
34.1 Post text, display names and per-post classifications are deleted no later than 30 days after collection, and the text and display name are cleared as soon as the post has been classified.
34.2 That 30-day period applies to the material we use to produce a reading. It is our own commitment, not one imposed on us: the equivalent limit in Part B is required by Google’s developer terms, and no such requirement applies here. We have adopted it deliberately, because the case for holding the working data behind a finished reading does not improve with time. Clause 34.4 describes the one thing we do keep for longer, and why.
34.3 Subject-level statistics, which are counts and percentages carrying no identifier and no text, are retained for up to 36 months.
34.4 A small number of posts are kept for longer, as a research set. To measure whether our classification is accurate we need examples that have been checked by a person, and those examples have to outlive the reading they came from or the measurement cannot be repeated. We rely for this on the provisions for research and statistical purposes in Article 89 of the UK GDPR and Part 6 of Schedule 2 to the Data Protection Act 2018.
34.5 Material held in that research set:
- carries no identifier of any kind for the person who wrote it. The hashed identifier described at clause 30 is not merely omitted from it, it is removed, so nothing in the set groups posts by author or connects one to any account;
- is used only to measure and improve our classification;
- is never used to make any decision about, or take any measure in respect of, any person whose words appear in it;
- never appears in any client report or published output.
34.6 If you object under clause 35, your posts are excluded from the research set as well as from future readings.
34.7 If you delete your post, we will already be deleting our copy. We do not re-check X for deletions, because doing so would require us to keep a record of which posts we had collected in order to look them up, which would defeat clause 34.1. Within 30 days our copy is gone regardless of what you do.
35. Objecting, and exercising your rights
35.1 The rights at clause 22 apply to this material.
35.2 To object to the processing of your posts, or to make any other request, write to privacy@readtenor.com with the X handle the posts were published under. We will apply the same hashing function to it, which is the only way we can find your data, and we will act on the request.
35.3 We will honour an objection permanently, by adding the derived identifier to a suppression list so that your posts are excluded from future readings. That list holds the hash and nothing else.
35.4 Deletion of your post on X does not of itself remove derived statistics already produced, because those carry no identifier and cannot be traced back to any individual. Clause 34.3 states how long they are held.