Legal
Privacy Policy
Last updated August 15, 2026
This Privacy Policy explains how Inokta collects, uses, shares, and protects personal information when you use inokta.ai and related services (the Service).
Inokta is an early-stage service operated from Ontario, Canada. Questions or privacy requests can be sent to [email protected].
1. Information we collect
We collect information in the following categories:
- Account information: your Google account identifier, name, email address, avatar, sign-in records, and account settings.
- Your Content: files, source material, prompts, chat messages, notes, modules, entities, relationships, tags, context logs, and other material you submit or create.
- Usage and technical information: actions in the Service, feature and allowance usage, model and agent run records, token counts, estimated provider cost, timestamps, error records, browser and device information, IP address, session identifiers, and security events.
- Collaboration information: vault membership, invitations, roles, organization membership, edit locks, and activity needed to coordinate shared work.
- Billing information: subscription status, Stripe customer and subscription identifiers, billing period, and payment status. Stripe receives and processes your payment method details; we do not store your full card number.
- Communications: support requests, feedback, and other messages you send us.
Your Content may contain personal, confidential, or sensitive information. We process that material only to provide the Service and as otherwise described here. You are responsible for deciding what to upload and for having a lawful basis to process information about other people.
2. How we collect information
We receive information:
- directly from you when you sign in, upload sources, create or edit material, use Alice, share a vault, subscribe, or contact us;
- from Google when you use Google sign-in;
- from collaborators when they share a vault or organization with your registered account;
- automatically from the application and its security, logging, and usage systems; and
- from service providers such as Stripe when they report subscription or payment status.
We do not sell personal information or use it for third-party targeted advertising.
3. How we use information
We use personal information to:
- authenticate accounts and keep sessions secure;
- store, display, search, parse, encrypt, and organize Your Content;
- create embeddings, entities, modules, relationships, world models, and AI-assisted responses;
- provide sharing, permissions, collaboration, revision, and audit features;
- operate subscriptions, beta grants, usage allowances, rate limits, and abuse safeguards;
- monitor reliability, troubleshoot errors, measure provider cost, and improve product performance;
- respond to support requests and communicate material service or policy changes;
- prevent fraud, misuse, unauthorized access, and security incidents; and
- comply with legal obligations and enforce our Terms.
We use model and feature telemetry to understand whether Inokta is working and to control cost. We do not need to include the text of your private documents in ordinary product analytics.
4. AI and document processing
When you use extraction, embeddings, world-building, or Alice, relevant parts of Your Content and instructions may be sent to AI and processing providers to perform the requested feature. This can include source text, tables, images or rendered pages, prompts, retrieved excerpts, and the context required to create an output.
We use commercial API or infrastructure arrangements for these operations. Provider handling is governed by our agreements and the provider's applicable privacy and security terms. Do not submit information that you are not authorized to send to these providers.
AI outputs and intermediate records may be stored in your vault, chat history, modules, relationship records, source references, and run telemetry so the Service can remain inspectable and persistent.
5. Service providers
We use service providers to operate the Service. Current core categories include:
- Google for account sign-in;
- Supabase for authentication, database, and file storage infrastructure;
- OpenAI and other configured AI providers for language models and embeddings;
- Modal and document-processing infrastructure for extraction and OCR;
- Stripe for checkout, subscriptions, invoices, and the customer portal;
- hosting, vector database, cache, queue, logging, and delivery providers used to run the application.
Providers may process information only for the services they supply to us, subject to their contracts and applicable law. This list may change as our infrastructure develops.
6. Sharing and collaboration
When you share a vault or join an organization, authorized users can access information according to the role and permissions shown in the Service. This can include account identity, vault content, sources, modules, world-model objects, and collaboration activity.
Do not share a vault with someone who should not see its contents. Removing access stops future access through Inokta but cannot recall information another user was permitted to export or copy.
Chat sessions are scoped to their author under the current launch contract unless the product expressly shows otherwise.
7. Other disclosures
We may disclose information:
- when you direct us to share it;
- to service providers described above;
- to comply with law, legal process, or a valid government request;
- to protect the rights, safety, and security of users, Inokta, providers, or the public;
- to investigate fraud, abuse, or a violation of our Terms; or
- as part of a financing, reorganization, acquisition, sale, or transfer of the business, subject to appropriate confidentiality protections.
8. Cookies and sessions
We use cookies and similar browser storage that are necessary for authentication, session continuity, security, interface preferences, and first-run notices. We do not currently use third-party advertising cookies.
You can block cookies in your browser, but authentication and core workspace features may stop working.
9. Retention and deletion
We retain account information and Your Content while your account is active or as needed to provide the Service. Different records may have different retention periods:
- active vault content remains until you or an authorized owner deletes it;
- billing and transaction records may be retained for accounting, tax, fraud, and legal obligations;
- security and operational logs are retained for a limited period appropriate to troubleshooting and protection;
- backups and deleted records may persist temporarily before scheduled removal; and
- content shared with another user may remain in copies they were permitted to keep.
You may request account deletion by emailing [email protected]. We may retain limited information where required by law or reasonably necessary for security, dispute resolution, or enforcing agreements.
10. Security
We use administrative, technical, and organizational measures intended to protect information, including authenticated access, scoped permissions, encryption for stored source files, bounded service credentials, and security logging.
No system is perfectly secure. You are responsible for protecting your Google account and for using appropriate care when uploading or sharing sensitive material. Tell us promptly at [email protected] if you believe your account or data has been compromised.
11. International processing
Inokta is operated from Canada, while service providers may process or store information in Canada, the United States, or other countries. Those countries may have privacy laws different from where you live. By using the Service, you understand that information may be transferred internationally as needed to provide it.
12. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of personal information, or to object to or restrict certain processing. You may also withdraw consent where consent is the legal basis for processing.
You can update some account and workspace information directly in the Service. For other requests, email [email protected] from the address associated with your account. We may need to verify your identity before completing a request. Some rights are subject to legal exceptions.
You may stop using AI-assisted features by not starting those actions, but some core world-model functionality depends on automated processing.
13. Children
The Service is not directed to children under 18, and we do not knowingly create accounts for them. If you believe a child has provided personal information, contact us so we can investigate and delete it where appropriate.
14. Changes and contact
We may update this Policy as the Service and our providers change. We will update the date above and provide additional notice for material changes where reasonable.
Privacy questions and requests: [email protected]