Privacy Policy
This Privacy Policy explains how Inuberry, Inc. ("we", "us") collects, uses, and discloses personal data when you use Inuberry.
1. Data we collect
- Account data: name, email, password hash, profile photo, organization membership.
- Customer Data: records you create in the product (contacts, deals, invoices, employees, etc.).
- Billing data: handled by Stripe; we store a customer ID and subscription metadata but not card numbers.
- Usage data: logs, IP, device, browser, page events used for security, debugging, and product analytics.
- AI prompts: prompts and tool calls executed by your agents.
2. How we use data
- To provide, secure, and improve the Service.
- To process payments and prevent fraud.
- To send transactional emails (receipts, invoices, security alerts).
- To respond to support requests.
- To comply with legal obligations.
We do not sell personal data. We do not use Customer Data to train foundation AI models.
3. Legal bases (GDPR)
We process personal data on the basis of contract performance, legitimate interests (security, product analytics), legal obligation, and consent where required.
4. Subprocessors
We use the following subprocessors to deliver the Service:
- Supabase / Lovable Cloud — application hosting, database, auth, storage.
- Stripe — payment processing.
- Resend — transactional email.
- OpenAI and/or Anthropic — AI model inference (per-organization key).
- Sentry — error monitoring (when enabled).
Current subprocessor list is updated as we add vendors.
5. International transfers
Data may be processed in the United States, the European Union, and other regions where our subprocessors operate. We rely on Standard Contractual Clauses or equivalent safeguards for cross-border transfers.
6. Retention
We retain Customer Data while your Workspace is active and for up to 30 days after deletion to allow recovery, after which it is permanently removed from primary systems. Backups are rotated within 90 days.
7. Your rights
Depending on your jurisdiction, you may have the right to access, correct, delete, port, or restrict processing of your personal data, and to object or withdraw consent. You can exercise most rights directly inside the Service or by emailing privacy@inuberry.com.
8. Security
We use encryption in transit (TLS) and at rest, row-level security on all multi-tenant tables, leaked-password protection, and least-privilege access for our team. See our Security page.
9. Children
The Service is not directed at children under 16. Do not use it if you are below that age.
10. Cookies
We use strictly necessary cookies for authentication and CSRF protection, and optional analytics cookies when you consent. See the cookie banner shown on first visit.
11. Contact
Privacy enquiries: privacy@inuberry.com. Data Protection Officer: dpo@inuberry.com.
This page is maintained by Inuberry, Inc. and should be reviewed by qualified legal counsel before public launch.
Inuberry, Inc. · [Update address in src/lib/legal-config.ts] · support@inuberry.com