This is a draft for review by a lawyer. It is not in effect and is not legal advice. Items in brackets need real details.

Privacy Policy

Last updated: [DATE]. See also the Terms of Service.

Who is responsible

[LEGAL ENTITY NAME], [REGISTERED ADDRESS], controls the personal data described here. For apps in a company workspace, the company decides what data its apps hold. [DRAFT: confirm controller and processor roles with counsel.]

What we collect when you sign up

Work email, organization name, whether you use Inhaus for yourself or your company, and a phone number if you choose to give one.

If you choose a paid plan: billing email and billing country. Card details go to Stripe, not to us.

What we collect when you use Inhaus

The apps you deploy: their code, versions, their own databases and files.

Secrets you set for an app, such as API keys. These are stored encrypted.

Access records: who opened, shared, deployed or exported an app, when, from which AI tool or browser, and the IP address.

Sign-in details from your company identity provider, such as your name, email and group membership.

Connection tokens that let your AI tool act on your behalf through the Inhaus connector.

How we use it

To run Inhaus: host your apps, check sign-in and permissions, and apply outbound data rules.

To run security checks on apps before they are shared.

To show workspace admins the access log for their workspace.

To bill paid plans and send service emails such as sign-in links and invites.

Phone number: optional. Used only to help set up your company workspace. Never used for marketing and never sold.

Who we share it with

Service providers that help us run Inhaus. [DRAFT: list final providers, for example hosting, database, sign-in, email and payments.]

We do not sell personal data. [DRAFT: confirm.]

We do not use your apps or their data to train AI models. [DRAFT: confirm.]

How long we keep it

[DRAFT: retention periods for account data, app data, access records and billing records.]

Cookies

Inhaus uses cookies needed to keep you signed in. [DRAFT: list any analytics cookies, or state that there are none.]

Your choices and rights

You can see, correct and delete your account details. Company workspace members can ask their admin, or us, for access to their data.

[DRAFT: add rights under the laws that apply, for example UAE PDPL, India DPDP Act, UK and EU GDPR.]

International transfers

[DRAFT: where data is stored and how transfers are protected.]

Changes

We will post changes here and email account owners about material changes.

Contact

[email protected] [DRAFT: set up once the domain is registered]