ConflictResolver
How it worksFAQSign in

ConflictResolver

Privacy Policy

Version 1.0Effective 23 September 2026

These production-ready templates may be refined after legal review.

ConflictResolver uses artificial intelligence to ask follow-up questions, understand different perspectives on a conflict, and create one shared Conflict Report. The person who starts a case needs an account. Invited participants use a secure personal link and do not need an account.

Each interview is private. Other participants are not shown the original private responses. The shared report may nevertheless describe a participant's perspective by name when relevant. The system is instructed not to reproduce private answers word for word, but to create an attributed synthesis.

AI processes interview content, and participants may use different languages. Report translations are language versions of the same report. A paid follow-up case may use shared report and relationship-history context from an earlier case, but old raw private responses are not used as material for the new case.

The case initiator can delete a case from the service. Paddle may retain payment and accounting records under its own legal obligations, and limited security or backup copies may remain temporarily with service providers. You have the rights provided by applicable data protection law.

1. Who we are

ConflictResolver is a service provided by What Would A+I Think Oy (Business ID 3583333-6), PL 91, 00391 Helsinki, Finland; ConflictResolver is the service's product name.

2. Scope

This Policy applies to the ConflictResolver website, accounts, conflict cases, private interviews, shared reports, translations, payments, notifications, and related support and security operations.

3. Controller

What Would A+I Think Oy is the controller for personal data processed to provide ConflictResolver. Paddle acts independently for parts of payment processing where its own terms and privacy notice apply.

4. User roles

The initiator creates an account, owns and pays for the case, chooses participants and the response deadline, and shares invitation links. Invited participants use personal secure links without an account or payment. All participants who complete their interview may access the resulting shared report.

5. Personal data we process

Depending on your role, we process account email, display name, chosen language, authentication identifiers, participant names, roles and age group, case title and type, conflict descriptions, interview questions and answers, participation status, invitation tokens, notification preferences and email, report content and translations, relationship history, payment references and technical records.

6. Account and sign-in

Only the initiator needs an account. Authentication is provided through a trusted cloud service provider and may include email/password or Google sign-in. The account profile stores a display name and language preference. The service asks an initiator to confirm they are at least 18; this is a declaration, not identity or age verification.

7. Case and participant data

We process the information needed to create and administer one case for 2–10 participants: relationship type, roles, names, age groups, status, deadline, payment status, and the information participants submit. A cryptographically random invitation token connects each invited participant to one participant record in one case.

8. Private interview content

Conflict descriptions, meanings, recognition choices and answers to follow-up questions are private interview content. They may include direct, emotional, angry, or sensitive language. We use this content to provide the interview, safety screening, analysis and report described here.

9. Private response and shared report

Other participants are not shown a participant's original private responses. The shared report is a new synthesis of the completed participants' material. The AI is instructed not to use direct private quotations or publish offensive wording word for word, while retaining relevant themes such as fear, threats, control, discrimination, distrust, unfair responsibility, deep anger, or thoughts of ending a relationship.

10. Attribution by name

The shared report is not anonymous. When useful for understanding the conflict, it may say, for example, “Kalle experiences…” or “Irma emphasises…”. Attribution must remain supported by the participant's material and must not put stronger claims into a person's mouth than the evidence supports.

11. Unfinished responses

Only completed participant responses are used to create a report. Incomplete responses are not included in the report. Their temporary interview state may remain in the case until it is completed, declined, closed, or deleted.

12. Languages and report translations

Participants may answer in different supported languages. The report is first generated in the service's base language and translated on request. Stored translations are language versions of the same report and may contain translation errors. The selected interface language does not determine a person's legal jurisdiction.

13. Use of artificial intelligence

These operations are routed through a trusted AI platform to a configured large language model. Requests are configured with provider storage disabled, but provider infrastructure and legally required records may still be subject to provider terms.

AI can make mistakes. Interpretations and interaction hypotheses are tentative, not verified facts or diagnoses. Human participants must assess the report critically, especially where safety, health, employment, or legal rights are involved.

14. Shared relationship history and follow-up

A new follow-up is a separate paid case. It may use a shared-memory summary derived from an earlier shared report, including shared conflict patterns and recommendations. Old raw private responses are not retrieved as source material for the new case. Case-specific private derived memory is not used across cases.

15. Special categories of personal data

Conflict conversations may reveal health or mental-health information, sexuality, religion, political opinions, ethnicity, trade-union membership, or other specially protected data. Participants should share only what is relevant. Where applicable law requires explicit consent for this processing, we request it separately from Terms acceptance, Privacy acknowledgement, and report-attribution acknowledgement. Consent may be withdrawn for future processing, but withdrawal does not make earlier lawful processing unlawful and may prevent the service from completing the case.

16. Minors

ConflictResolver is normally for persons aged 18 or over. The only exception is an invited minor in a Parent & Child case started by that child's parent or other person with parental responsibility. A minor cannot initiate or pay for a case and cannot participate as a minor in Romantic Relationship, Friends, Family, Workplace, or Other cases.

The adult initiator must confirm parental responsibility and give permission for the child's participation. The child receives an age-appropriate explanation and must voluntarily confirm their own willingness to participate. Without this assent, the child does not participate. The guardian's permission does not give the guardian access to the child's raw private responses; the guardian sees only the shared report on the same basis as other report participants, and that report may attribute the child's perspective by name.

17. Payments and Paddle

Paddle is the Merchant of Record and processes checkout and payment details under its own terms and privacy notice. ConflictResolver receives and stores transaction identifiers, payment status, environment, amount, currency, time, participant count, and whether an access-code exemption was used. ConflictResolver does not receive or store full payment-card details.

18. Email

We use the initiator's account email for authentication and essential account communications. An invited participant may separately provide an email and opt in to a one-time report-ready notification; if delivery is available, that notice contains a link and no conflict content. We may also answer support or privacy requests sent to us.

19. Technical data and logs

Hosting, authentication, database, AI gateway, payment and security systems may process IP address, request time, device or browser information, route, identifiers, response status, error details and similar operational data. Application logs are used for security, delivery, debugging and fraud prevention and are designed to avoid unnecessary conflict content, although an error record may contain limited identifiers.

20. Cookies, local storage and analytics

The service uses essential browser storage for authentication sessions and local storage to remember the selected language. The application code reviewed for this version does not include advertising or behavioural analytics tools. Hosting and service providers may produce essential security and operational measurements. If non-essential tracking is introduced, we will update this Policy and request consent where required.

21. Why we use data

We use personal data to create and manage accounts and cases; authenticate users and invitation links; conduct private interviews; perform safety screening; generate, translate and deliver reports; support follow-ups; process payments and exemptions; send requested notifications; secure, maintain and improve service reliability; respond to requests; and comply with law.

23. Service providers

We use trusted cloud, database, authentication, and AI infrastructure providers to operate the service; Paddle for payments and Merchant-of-Record services; Google when you choose Google sign-in; and email and infrastructure providers when notifications are enabled. These providers process data under their own contractual and statutory obligations.

We provide information about the service's other infrastructure providers on request at privacy@conflictresolver.ai.

24. International transfers

Some providers or their subprocessors may process data outside your country, the EU/EEA, or the United Kingdom. Where required, transfers are supported by an adequacy decision, standard contractual clauses, the UK International Data Transfer Addendum, or another lawful safeguard. Contact us for available information about applicable safeguards.

25. Retention

Case content is kept while the case and related shared history remain active, unless the initiator deletes the case or law requires otherwise. Account data is kept while the account is active and as reasonably needed for security, disputes and legal obligations. Optional notification email remains with the participant record until changed, the case is deleted, or retention is no longer needed. Operational logs are kept only for limited periods set by us or our providers. Paddle may retain payment and accounting records under its own legal duties. Encrypted backup copies may persist until provider backup cycles overwrite them.

26. Case deletion

The initiator can permanently delete a case. Deletion removes from the active service the case record and content, participant records and invitation access, private answers, interview state, shared report, stored translations, and case-linked derived memory. If it is the final case in a relationship, the remaining relationship record and shared memory are also removed. A deleted case is no longer available as future AI context.

Deletion may not erase records independently retained by Paddle for payment or accounting, limited security records, legal-hold material, or encrypted backup copies before the provider's normal overwrite cycle. We do not promise that nothing remains anywhere immediately.

27. Account deletion

There is currently no self-service account-deletion control. An account holder may request account deletion at privacy@conflictresolver.ai. We will verify the request, explain any data that must be retained, and act under applicable law. Deleting an account may require cases to be deleted or closed first.

28. Withdrawing consent

You may withdraw an optional consent for future processing by contacting us or using an available opt-out control. An invited participant may decline before completing their interview. Withdrawal may make it impossible to continue or complete a case. We keep separate records for Terms acceptance, Privacy acknowledgement, report-attribution acknowledgement, special-category consent, guardian consent, and minor assent where applicable.

29. Security

We use access controls, server-side authorization checks, personal high-entropy invitation tokens, encrypted network connections, managed infrastructure and limited privileged access. No online service can guarantee absolute security. Anyone with an invitation link may be able to act as that participant, so links must be kept confidential.

30. Your rights

Depending on applicable law, you may have rights to access, correct, delete, restrict or object to processing, receive portable data, withdraw consent, and complain to a supervisory authority. Rights may be limited by other people's rights, legal obligations, security, or the nature of a shared report. Contact privacy@conflictresolver.ai. We may need to verify identity or control of an invitation link.

31. Automated decision-making

ConflictResolver uses automated AI analysis, but it does not make decisions that produce legal effects or similarly significant effects about users within the meaning of GDPR Article 22. It does not decide fault, custody, employment status, discipline, entitlement, or legal rights.

32. Marketing communications

The current service does not use case content for marketing and does not send marketing messages based on private interview content. If optional marketing communications are introduced, they will have a separate legal basis and opt-out mechanism.

33. Changes to this Policy

We may update this Policy when the service, providers, or law changes. We show the version and effective date. A material change may require a new acknowledgement; purely typographical changes or translations that do not change meaning do not.

34. Supervisory authorities

You may complain to the Finnish Data Protection Ombudsman or the competent data protection authority where you live or work, or where an alleged infringement occurred. UK residents may contact the Information Commissioner's Office. Other regional appendices below identify additional avenues where applicable.

35. Contact

Controller: What Would A+I Think Oy, Business ID 3583333-6, PL 91, 00391 Helsinki, Finland. Privacy requests: privacy@conflictresolver.ai. General support: support@conflictresolver.ai.

36. Version and effective date

Privacy Policy version 1.0. Effective 23 September 2026.

37. Jurisdiction-specific provisions

These appendices supplement the common Policy. They are not selected by interface language, and all remain part of this document.

A. European Union / European Economic Area

The GDPR applies where its territorial scope is met. What Would A+I Think Oy is established in Finland. Data subjects have the GDPR rights described above and may complain to the Finnish Data Protection Ombudsman or another competent EEA authority. Consumer and child-data rules of the user's country may also apply.

B. United Kingdom

Where UK law applies, references to GDPR include the UK GDPR and Data Protection Act 2018 as appropriate. UK residents may complain to the Information Commissioner's Office. Applicable UK consumer protections remain unaffected.

C. United States

United States privacy rights vary by state and may depend on statutory thresholds and exemptions. We do not treat this appendix as a claim that every state law applies. Where an applicable law grants access, correction, deletion, portability, opt-out or appeal rights, requests may be sent to privacy@conflictresolver.ai. We do not sell personal information or share it for cross-context behavioural advertising in the application described by this version. California residents may request the categories and specific pieces of personal information covered by an applicable California law, subject to verification and statutory exceptions.

D. Canada

Where PIPEDA or applicable provincial privacy law applies, we process personal information for identified and appropriate purposes, use consent where required, and provide access and correction rights subject to legal exceptions. Complaints may be directed to us first and then to the competent federal or provincial privacy regulator.

E. Australia

Where the Privacy Act 1988 and Australian Privacy Principles apply, users may request access or correction and complain to us. If unresolved, a complaint may be made to the Office of the Australian Information Commissioner. Applicability may depend on statutory thresholds and circumstances.