Privacy Policy
What we collect, how we use it, how long we keep it, who we share it with, and your choices. US-only. CCPA addendum included.
Inscendo: Privacy Policy
Effective Date: June 26, 2026 Version: 1.7 (August 29, 2026 — § 4.1 adds Backblaze (off-site immutable backup storage, United States) to the Sub-Processor summary, posted before any customer data is stored with it; § 5 states that the ninety-day backup-retention window is a ceiling: any off-site backup copy we keep is written once, kept for a fixed period of no more than ninety (90) days, and cannot be deleted earlier by anyone, including us. No change to what we collect, how we use it, or how long we keep it; the retention window is confirmed, not extended. Version 1.6, August 23, 2026: § 2.11 adds an express statement that SMS consent is not shared with third parties, with a service-provider carve-out; § 2.1 scopes its no-marketing sentence to the account mobile number and cross-references § 2.11; § 10.1 conformed to § 2.11. No change to what we collect, how we use it, how long we keep it, or who it is disclosed to. Version 1.5, August 18, 2026: discloses SMS opt-in status and the phone number it attaches to: new § 2.11 paragraph with a stable anchor, § 5's surviving-record parenthetical now names the consented number and message category, and § 10.1 and § 10.5 updated so the Notice at Collection stays accurate. Version 1.4, August 9, 2026: scope bullet and § 1 describe Inscendo's operating domains generically rather than naming one; the Policy's coverage is unchanged and still reaches every Inscendo-operated site. Version 1.3, August 6, 2026: describes the information we collect from people who contact us, book a demo or consultation, or apply to our partner program without holding an account, and how long we keep it; new § 2.11, new § 3(h), § 5, § 10.1 and § 10.5 updated. Version 1.2, August 4, 2026: registration now offers an optional mobile number, and passkey sign-in is available; § 2.1, § 2.10, § 5 and § 10.1 updated to describe both accurately)
This Privacy Policy describes how Inscendo Automation Inc. ("Inscendo," "we," "us") collects, uses, and discloses personal information in connection with the Inscendo service (the "Service"). The Service is offered exclusively to U.S.-based businesses and is not directed to users outside the United States.
This Privacy Policy applies to:
- visitors of any Inscendo-operated marketing or product website, including any alternate front-door domain that routes to the Service, including people who contact us, request a demo or a consultation, or apply to our partner program without holding an account (§ 2.11);
- account holders and authorized users of the Service ("Subscribers" or "Customers"); and
- individuals whose information Subscribers submit to the Service in their own capacity as data controllers (covered separately in § 12 below: for those individuals, the Subscriber's privacy notice, not this Policy, is the controlling document).
If you are an end-user of a service or application built by a Subscriber on top of the Service, this Policy does not govern your relationship with that Subscriber. Please refer to that Subscriber's own privacy notice.
1. Trademark and Domain Notice
Each domain Inscendo operates is used solely as a network-infrastructure address on which the Service is hosted. The product offered through the Service is branded Inscendo. Inscendo is not affiliated with, sponsored by, or endorsed by any other company that may use a similar name. See the Trademark Notice at https://inscendoiq.com/legal/trademark.
2. Information We Collect
2.1 Account information
When you or your organization registers for the Service, we collect: name, business email, billing address, payment method (handled by Stripe, we receive a tokenized reference, not full card data), tenant/organization name, role, password (hashed), and any optional profile data you provide.
Mobile number (optional). Registration offers a mobile number field. Providing it is optional and you can complete registration and use the Service without it. Where you provide one, we store the number and, when you verify it, a one-time verification code in hashed form together with the time it was sent, the time it was verified, and a record of the send for rate-limiting and abuse-prevention purposes (which includes the number, the purpose of the message, and a hashed form of the requesting IP address). We use a mobile number you provide only to verify that the number is yours, to let you sign in or recover access by text where you have chosen that option, and to send service-related messages about your account. We do not use this account mobile number to send marketing or promotional text messages, and we do not sell or share it. Marketing text messages are sent only where you have separately opted in through a form (§ 2.11). You may remove it from your account at any time.
Passkeys. If you choose to create a passkey, the credential itself is generated and held on your own device. What we receive and store is the public half of that credential and the material needed to verify it: a credential identifier, the public key, a user handle, a signature counter, an authenticator model identifier, transport hints, whether the credential is backed up by your device platform, an optional label you set, and timestamps of creation and last use. We also keep a durable record of when a passkey was added or removed from your account, which survives deletion of the credential itself so the account's security history remains auditable. We never receive your fingerprint, face scan, device PIN, or any other biometric or knowledge factor — those stay on your device and are used by the device to unlock the credential locally. See § 2.10.
2.2 Service-usage information
We process activity associated with your account in two ways, with different retention.
- Operational and diagnostic telemetry, timestamps, IP address, browser and device characteristics, tool-invocation metadata, and security-relevant events, is retained on a rolling basis for up to thirty (30) days, except where extended retention is required for security investigation or legal hold. We apply automated secret-redaction to this telemetry.
- Your conversation history and agent session records, including the AI prompts you submit, the AI Outputs returned, the inputs and outputs of tool calls, the configurations you create (capsules, widgets, automations, skills), and web-page content the Browser Companion observes during a session, are stored as part of your tenant so the Service functions and you can review past activity. These records are retained for as long as your account is active and are deleted in accordance with the retention schedule in § 5, not on the thirty-day telemetry schedule.
Important: what these records contain and how we redact. Your conversation history and session records include the literal text of your prompts, the AI's responses, the inputs we send to and the outputs we receive from tool calls, and any web-page content the Browser Companion observes. We apply automated secret-redaction to strip credentials we can recognize (API keys, bearer tokens, database connection-string passwords). We do NOT apply automated redaction of other personal information. Names, email addresses, phone numbers, postal addresses, government identifiers, financial account numbers, free-text health information, and any other personal information present in your prompts or in pages the Companion observes will be stored in these records and may be accessible to authorized Inscendo personnel for security, debugging, and abuse-investigation purposes. If you process information about your own customers, employees, or end-users through the Service, you should not place sensitive personal information about those individuals in agent inputs unless you have accepted this retention and have a lawful basis for that processing under your own privacy notice.
2.3 Customer Configurations
The capsules, widgets, automations, skills, and code you build on the Service are stored in your tenant. We may access them as needed to operate the Service, support you, investigate AUP violations, or comply with law.
2.4 Browser Companion data
If you install the optional Inscendo Browser Companion Chrome extension, while it is attached to a tab we receive: the URL of the active tab, a snapshot of the tab's contents, screenshots, console-log messages, network-request metadata and bodies, and the results of JavaScript the agent evaluates. The extension's sensitive-field sensor automatically detaches the agent when password and payment-card fields are detected; this is a heuristic and is not a guarantee. The sensor detects standard password, one-time-code, and payment-card fields. Custom-built, non-standard, or programmatically-rendered input fields may NOT be detected. The Companion may attach to, observe, and transmit data from a page that contains your credentials, one-time codes, payment-card data, or other sensitive information before the sensor triggers, or if the sensor fails to recognize the field type. You should not rely on the sensor as a guarantee that sensitive data will be excluded from what is sent to Inscendo and to the AI model provider. Browser Companion data is transmitted to our servers and to our AI model provider for processing as part of providing the Service. See the Browser Companion Consent EULA for details.
2.5 Communications data
Where you configure outbound communications (SMS, email, voice, or chat) through providers you connect, we transmit message content and recipient identifiers through those providers on your behalf. The providers handle the underlying telecom delivery; we do not store message bodies beyond what is required to operate the Service and to honor your retention configuration.
2.6 Inferred and derived data
We generate inferred and derived data about Service usage, including embeddings, similarity scores, billing and usage metrics, and aggregated analytics.
2.7 Cookies and similar technologies
We use cookies and similar technologies for: authentication, security, fraud prevention, load balancing, preference storage, and analytics. We use the analytics providers listed in our Sub-Processor List. We do not "sell" or "share" personal information for cross-context behavioral advertising (see § 3.1 and § 10.2); because there is no sale or sharing to opt out of, no action is required to give effect to a Global Privacy Control (GPC) or similar browser opt-out signal, and we do not currently process such signals automatically. We do not display a GDPR-style consent banner because the Service is not directed to EEA / UK / CH residents.
2.8 Information from third parties
We may receive limited information from third parties: payment processors (Stripe, payment confirmation, dispute notices), authentication providers (where you sign in via OAuth), enterprise integrations you authorize, threat-intelligence and fraud-prevention vendors, and our AI model provider's safety-monitoring systems.
2.9 Billing and usage data
When you fund your account, we collect and retain: wallet purchase history, transaction amounts and dates, tokenized payment-method references received from Stripe (we do not receive or store full card data), refund and chargeback records, and per-tenant aggregate token-consumption metrics organized by date and by AI model. Billing data is retained for the period required by U.S. tax, accounting, and recordkeeping law (typically seven years) and is not subject to the rolling thirty-day log retention described in § 2.2.
2.10 What we do not knowingly collect
- Personal information of any individual under 18.
- Personal data of any individual located in the European Economic Area, the United Kingdom, Switzerland, China, Russia, Brazil, or any jurisdiction whose data-protection law would impose extraterritorial obligations on us.
- Protected Health Information regulated under HIPAA (we do not currently offer a BAA).
- Cardholder Data subject to PCI-DSS (Stripe handles card data; we receive tokens).
- Biometric identifiers regulated under BIPA, CUBI, or analogous law. This remains true where you sign in with a passkey. A passkey is unlocked on your own device by whatever method that device uses, which may be a fingerprint or face scan. That check happens entirely on the device and its result is not transmitted to us. We receive only a public key and the non-biometric metadata listed in § 2.1, from which no biometric identifier can be derived.
- Sensitive Personal Information as defined under applicable U.S. state privacy law.
If we become aware that we have inadvertently collected information of any of these categories, we will delete it as soon as reasonably practicable.
2.11 Enquiry, consultation, demo, and partner intake information
This section describes information you give us before, or without ever, holding an account: when you use a contact form on our website, request a product demonstration, book an Inscendo IQ Expert consultation, or complete a partner or distributor intake form.
What we collect. Your name, work email address, company, and role; a phone number if you choose to give one; what you tell us about your business, the systems you use today, and what you are trying to solve; your answers to any structured questions the form asks; which meeting you booked and when; and the identifier in a personalized link you followed, where the form was sent to you individually, so we can attach your answers to the right conversation.
Records of agreements you accept. Where a form asks you to acknowledge an agreement, such as our Mutual Confidentiality and Non-Disclosure Agreement, we record that you acknowledged it, the version and effective date of the document, a cryptographic fingerprint of the exact text that was displayed to you, and the time of your acknowledgment. We keep the fingerprint so that we can later show what you were shown, not merely that you agreed.
Why we collect it. To respond to what you asked, to prepare for and hold the meeting you booked, to keep a record of the conversation, and to evaluate a potential partnership (§ 3(h)).
Where it is held. In our own systems, including a workspace we operate for ourselves on the Service, which is how we run our own sales and partner pipeline. We disclose it to the Sub-Processors listed in our Sub-Processor List who help us operate those systems, and to nobody else. We do not Sell or Share it (§ 3.1, § 10.2).
SMS opt-in status. Where a form includes SMS consent checkboxes, we also record which category or categories of text messages you consented to receive and when. SMS consent is not shared with third parties. We do not sell, rent, or share your SMS opt-in status or the phone number you provided for SMS with any third party or affiliate for that party's own purposes, including marketing or SMS/text marketing purposes. The only recipients are the service providers that transmit or process these messages on our behalf, under contracts limiting them to that purpose (§ 4.1). This SMS opt-in status, and the phone number associated with it, are used only to operate our SMS program as described in the Terms of Service. The categories, the messages each one covers, and how to stop them are set out in § 9A of the Terms of Service at https://inscendoiq.com/legal/terms#sms-terms.
Marketing is separate. Any invitation to receive occasional updates from us is a separate, unticked choice. Declining it has no effect on whether we respond to you, prepare for your meeting, or consider your partnership application.
Please do not send us sensitive information. These forms ask only the questions above. Do not include government identification numbers, dates of birth, health information, payment card or bank details, credentials, or information about protected characteristics, in a form, a message, or a screen share. See § 2.10 and, for consultations, the Mutual NDA at https://inscendoiq.com/legal/mutual-nda.
How long we keep it. See § 5.
3. How We Use Information
We use information for:
(a) Service operation: providing, maintaining, supporting, securing, and billing the Service; processing your prompts and tool calls; transmitting outbound communications you authorize; routing data to and from third-party integrations you configure;
(b) Service improvement: analyzing aggregated, de-identified usage to improve features, performance, and reliability;
(c) Security and abuse prevention: detecting and investigating suspected violations of the Acceptable Use Policy or AI Code of Conduct, fraud prevention, and incident response. This may include automated log analysis and limited human review of logs;
(d) Communications: sending account, transactional, and Service notifications, and (with separate consent) marketing communications;
(e) Compliance and legal: complying with applicable law, responding to lawful requests from authorities, enforcing our agreements, and exercising or defending legal claims;
(f) AI provider operation: transmitting prompts, configurations, and Browser Companion data to our AI model provider under that provider's commercial terms;
(g) Aggregate analytics: creating aggregated, anonymized, or de-identified data, which we may use, retain, and share for any lawful purpose (including benchmarking and research). Such data is not reasonably linkable to you.
(h) Enquiries, demonstrations, consultations, and partner discussions: responding to what you ask us; preparing for, holding, and following up on a meeting you booked; keeping a record of that conversation; evaluating a potential partner or distributor relationship; and retaining proof of any agreement you acknowledged in the course of it (§ 2.11).
3.1 What we will not do
- We will not Sell or Share (in the CCPA sense, including for cross-context behavioral advertising) your personal information.
- We will not use Customer Data, prompts, or AI Output to train, fine-tune, or evaluate generalized or "foundation" AI models. We do not offer an in-product "training" setting because such training does not occur; if we ever introduce a program that uses your data to improve AI models, it will be optional and presented to you separately for your express agreement. Our AI model provider's commercial-tier agreement with us prohibits training on data sent through our API.
- We will not use account contact information for unrelated marketing without separate, unbundled consent.
4. Disclosures
4.1 Sub-Processors and service providers
We disclose information to sub-processors/service providers who process information on our behalf under contracts that limit their use to the purposes we specify. The current Sub-Processor List is at https://inscendoiq.com/trust/subprocessors and includes: our AI model and embedding providers, Microsoft Azure, Backblaze (off-site immutable backup storage, United States), our transactional email providers, Stripe, Cloudflare, GitHub, and GoDaddy.
4.2 To Customers (B2B context)
If you are an authorized user, your activity is visible to your organization's administrators. If you use the Service through a third party that has invited you, that third party may receive your activity data.
4.3 Legal requirements
We may disclose information when required by law or when we believe in good faith that disclosure is necessary to (a) comply with legal process, (b) protect Inscendo's or others' rights, property, or safety, (c) investigate fraud or AUP violations, or (d) defend against legal claims.
4.4 Business transactions
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction. We will use reasonable efforts to notify customers and to require the receiving party to honor commitments materially equivalent to this Policy.
4.5 With your direction
We disclose information to third parties when you direct us to (e.g., when you configure an integration, install a capsule, or invite a collaborator).
4.6 Aggregated and de-identified data
We may share aggregated or de-identified data freely.
5. Retention
We retain personal information for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Specifically:
- Account information: for the life of the account plus a reasonable post-termination wind-down period.
- A mobile number you provide: for the life of the account, or until you remove it, whichever is first. One-time verification codes are stored hashed and expire shortly after they are sent; the send record kept for rate-limiting and abuse prevention (§ 2.1) is retained on a rolling basis for up to thirty (30) days.
- Passkey credentials: for as long as the passkey exists on your account. Deleting a passkey deletes the stored public key and its metadata. The record that a passkey was added or removed is retained with the account's security history so that history stays complete.
- Operational and diagnostic telemetry logs: up to thirty (30) days.
- Conversation history, agent session records, Customer Data, and Customer Configurations: retained for the life of the account; on termination, per the MSA: thirty (30)-day post-termination retention, then deletion subject to backup-retention windows of up to ninety (90) additional days and to legal holds. Ninety days is a ceiling, not an estimate: any off-site backup copy we keep is written once, is kept for a fixed period of no more than ninety (90) days from the date it is written, and cannot be deleted earlier by anyone, including us.
- Billing records: as required by tax and accounting law (typically seven years).
- Marketing-consent records: as required to demonstrate compliance.
- Enquiry, consultation, demo, and partner intake records (§ 2.11): twenty-four (24) months from our last contact with you, after which they are deleted on a recurring schedule. If the enquiry becomes an account, the resulting account information is retained under the account line above instead. If you ask us to delete an enquiry sooner, we will.
- Records that you acknowledged an agreement (the document, its version, the fingerprint of the text shown, the time, and, for an SMS consent, the phone number it was given for and which category or categories of messages it covered): retained for as long as we may need to demonstrate that acknowledgment and to enforce or defend that agreement. This deliberately outlasts both the twenty-four-month enquiry window above and the account itself, because a confidentiality obligation survives the relationship that created it. It is the one category we keep after an account is deleted.
Even after you request deletion, we may retain limited information for as long as necessary to comply with law, satisfy tax and recordkeeping obligations, resolve disputes, prevent fraud and abuse, enforce our agreements, and honor legal holds.
6. Security
We maintain administrative, technical, and physical safeguards described in our Master Subscription Agreement and Data Processing Addendum, including encryption in transit and at rest, logical separation of tenants, access controls, regular platform and dependency updates, and incident-response procedures. Logical separation reduces but does not eliminate cross-tenant risk, and no security program eliminates all risk. You are responsible for credential security and for using available controls.
7. Your Choices
You may:
- Update or correct your account information via in-product settings or by contacting
support@inscendoiq.com. - Delete your account by contacting
support@inscendoiq.com. - Export your Customer Data by requesting it at
support@inscendoiq.com, and via any in-product export tools we make available. - Opt out of marketing communications via the unsubscribe link in any marketing email.
- Configure the Browser Companion: pause it, detach it from a tab, or uninstall it from Chrome.
- Rely on our standing policy that we do not use your data to train foundation AI models (see § 3.1); there is no toggle to set because such training does not occur.
8. Children
The Service is for businesses and is not directed to users under 18. We do not knowingly collect information from anyone under 18. If we learn we have collected information from anyone under 18, we will delete it. Do not use the Service if you are under 18. Customer is contractually prohibited from collecting information from individuals under 18 through the Service (MSA § 3.2(h); AUP § 1.7(e)).
9. Geographic Scope
The Service is intended only for businesses and individuals located in the United States. We do not target, market, advertise, or solicit users outside the United States. If you are located in the EEA, the United Kingdom, Switzerland, China, Russia, Brazil, or any other jurisdiction whose data-protection law would impose extraterritorial obligations on us, please do not use the Service. We use, and/or reserve the right to use, technical measures (including edge-based geographic restrictions) to limit access from outside the United States, and we reserve the right to terminate any account that violates the U.S.-only eligibility requirement.
10. California Privacy Notice
This section is provided to address the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and applicable regulations (collectively "CCPA"), and applies to California consumers irrespective of whether Inscendo would be a covered "Business" by reference to revenue and consumer thresholds. Definitions in this § 10 follow the CCPA.
10.1 Categories collected (last 12 months)
| Category (Cal. Civ. Code § 1798.140) | Collected? | Source | Disclosed for a business purpose to |
|---|---|---|---|
| Identifiers (name, email, IP, account ID, optional mobile number, a phone number you give us on a form, SMS opt-in status, passkey credential identifier and public key) | Yes | You / your employer / you as a website visitor, prospect, or prospective partner (§ 2.11) | Sub-Processors |
| Customer records (Cal. Civ. Code § 1798.80) | Yes | You / your employer / you as a website visitor, prospect, or prospective partner (§ 2.11) | Sub-Processors |
| Commercial information (transactions; what you tell us about the systems you use and what you are trying to solve) | Yes | You / your employer / you as a prospect or prospective partner (§ 2.11) | Sub-Processors |
| Internet/electronic activity | Yes | Your interactions | Sub-Processors |
| Geolocation (IP-derived, coarse) | Yes | Your interactions | Sub-Processors |
| Audio, electronic, visual (browser screenshots, voice via integrations) | Limited | Your use of the Browser Companion or voice integrations | Sub-Processors |
| Professional / employment information (job title, role, size of the team you manage) | Yes | You / you as a prospect or prospective partner (§ 2.11) | Sub-Processors |
| Inferences | Yes | Derived | Sub-Processors |
| Sensitive Personal Information | No (Service is contractually prohibited from processing) | — | — |
Phone number and SMS opt-in status. Where a form offers SMS consent (§ 2.11), the Identifiers we collect include the phone number you give and a record of which category or categories of text messages you consented to and when. Both are collected from you, are used only to operate our SMS program, and are not Sold or Shared and not disclosed to any third party or affiliate for that party's own purposes, including marketing or SMS/text marketing purposes (§ 10.2).
10.2 Sales / Sharing
We do not Sell or Share personal information for cross-context behavioral advertising or any other purpose. Because we do not Sell or Share, there is nothing for a Global Privacy Control signal to opt out of; we do not currently process such signals automatically.
10.3 Your rights
California consumers have the right to:
- Know what personal information we have collected, used, disclosed, and (if applicable) sold or shared.
- Delete personal information, subject to legal exceptions.
- Correct inaccurate personal information.
- Limit use of Sensitive Personal Information (we do not process SPI).
- Opt out of Sale and Sharing, not applicable, because we do not Sell or Share personal information.
- Non-discrimination for exercising privacy rights.
10.4 How to exercise
Submit a request via support@inscendoiq.com. We will verify identity using reasonable means proportionate to the request. We will respond within forty-five (45) days, with one extension where permitted. Authorized agents are accepted with written authorization and verification.
10.5 Notice at Collection
The categories above are collected for the purposes set out in § 3 of this Policy. We retain each category as set out in § 5. Sensitive Personal Information is not knowingly collected.
This notice is given at or before collection on every form that collects personal information, including the contact, demonstration, consultation, and partner intake forms described in § 2.11. Those forms collect Identifiers, Customer records, Commercial information, and Professional / employment information; they are collected for the purpose in § 3(h); they are retained for twenty-four (24) months from our last contact with you, except for a record that you acknowledged an agreement, which is retained for as long as that agreement may need to be demonstrated or enforced (§ 5). Where a form offers SMS consent, the Identifiers collected also include the phone number you give and your SMS opt-in status, both retained as set out in § 5. They are not Sold or Shared.
11. Other State Privacy Notices
Residents of Texas, Virginia, Colorado, Connecticut, Utah, Oregon, Montana, Iowa, Indiana, Tennessee, Delaware, New Hampshire, New Jersey, Maryland, Minnesota, Rhode Island, Kentucky, and other U.S. states with comprehensive privacy laws may have rights to access, delete, correct, port, and opt out of certain processing under their state law. Submit requests via support@inscendoiq.com. We will respond consistent with the timelines set by each applicable state law. Texas-resident requests are handled under the Texas Data Privacy and Security Act.
12. Privacy of End-User Data Submitted by Subscribers
When a Subscriber uses the Service to process the personal information of its own customers, employees, contractors, or other end-users, the Subscriber, not Inscendo, is the controller / Business with respect to that information. Inscendo acts as the Service Provider / Processor / Sub-Processor under the Data Processing Addendum.
This Privacy Policy does not apply to such end-users' personal information. End-users should refer to the relevant Subscriber's own privacy notice. Inscendo is not in a position to respond to data-subject rights requests from end-users; please direct such requests to the Subscriber that controls your data.
13. Changes to this Policy
We may update this Policy from time to time. Material changes will be communicated by posting the updated Policy and, where required by law, notifying you. The "Effective Date" at the top reflects the most recent revision.
14. Contact
- Privacy and security incidents:
support@inscendoiq.com - Mail: Inscendo Automation Inc., 24900 Pitkin Rd, Ste 210, Spring, TX 77386, USA, Attn: Privacy
[End of Privacy Policy]