Privacy policy

Last updated · 2026-08-15

← back to inite.studio

This covers inite.studio — the product: signing in, running audits, connecting your own provider keys, and billing. The Idea TV channel at tv.inite.studio has its own policy for the public broadcast side.

Who controls your data

The data controller is inite LLC, a Wyoming limited liability company (filed 1 August 2025, Wyoming Secretary of State ID 2025-001735435), at 1621 Central Ave, Cheyenne, WY 82001, USA. Reach us at [email protected] for anything on this page, including the rights below.

We are based in the United States. If you are in the EEA, the UK or Switzerland, read "Where your data goes" before you sign up.

What we collect

  • Account identity. Sign-in is handled by our own identity service at auth.inite.ai. We store the account id and the email address it returns, so we can attach your audits and plan to you. We never see or store your password.
  • Session cookie. An httpOnly refresh-token cookie scoped to .inite.studio, so a sign-in here also signs you in on the channel. It is not readable by JavaScript and is not used for tracking.
  • What you audit. The idea text, documents and structured inputs you submit, plus the audit output. Your audits are private to your account. Nothing is published unless you explicitly publish it.
  • API keys you generate. Stored only as a salted, peppered hash — we cannot recover the key after it is shown to you once. Losing it means generating a new one.
  • Provider keys you bring (BYOK). Encrypted at rest with a key held outside the database. Used only to make the calls you asked for, on your behalf.
  • Usage counters. Per-month counts of audits, raw data calls and math calls, so quotas and billing work.
  • Server logs. IP, user-agent, referrer, path and a request id. Rolled over within 30 days.

What we do not do

  • We do not sell your data or your ideas.
  • We do not train models on your submissions.
  • We do not run third-party advertising trackers.
  • Our analytics is cookieless and collects no personal data — no cross-site profile is built, and there is nothing here to consent to on that front.

Processors we use

Running an audit means sending parts of your input to data and model providers. Which ones depends on what the audit needs:

  • Anthropic — the model that reads and reasons over your idea. When you supply your own key, the call is billed to you and made under your own agreement with them.
  • DataForSEO and Perplexity — search, SERP and research signals. Queries derived from your idea are sent; your identity is not.
  • Our billing service — handles subscriptions. Card details go to the payment processor, never to us.
  • Hosting and email — our own infrastructure and SMTP relay. Your address is not passed to a third-party marketing platform.

Why we are allowed to hold it

Under the GDPR, each thing above rests on one of these grounds:

  • Performing our contract with you — your account identity, session cookie, audits, API keys, BYOK provider keys and usage counters. Without these there is no service to deliver.
  • Our legitimate interests — server logs, rate-limit counters and abuse signals, to keep the service up and stop it being abused. We keep them short-lived and unlinked to audit content.
  • Legal obligation — billing records we are required to retain.

We do not rely on consent for any of the above, and we do not use your data for advertising or model training. Where we ever do ask for consent, you can withdraw it at any time without affecting what came before.

Where your data goes

inite LLC is in the United States, and the processors named above are too. Using the service therefore means your data is transferred out of the EEA, the UK or Switzerland to the US.

Each processor publishes its own data-processing terms, and those apply to the work it does for us. A formal, region-specific transfer mechanism is not yet in place for every one of them. We would rather say that than give you a blanket assurance — ask us about a named processor and we will tell you where it actually stands.

How long we keep it

  • Account and audits — while your account exists. Delete the account and the rows are marked deleted immediately and hard-deleted within 30 days.
  • Server logs — rolled over within 30 days.
  • Cached provider responses — up to 30 days, depending on the source; most are hours.
  • Usage counters and billing records — retained after account deletion only as long as tax and accounting rules require, then removed.
  • API key hashes and encrypted BYOK keys — deleted with the account.

Age

inite.studio is for adults working on a business idea. Do not use it if you are under 16, or under the age your country sets for agreeing to online services where that age is higher. We do not knowingly hold data about children, and we delete it if we find out we have.

Your rights

You can ask us at any time to:

  • Tell you what we hold about you, and give you a copy.
  • Correct it.
  • Delete your account and everything attached to it, including audits.
  • Export your audits in a portable format.
  • Restrict or object to processing we base on legitimate interests.

Email [email protected] and we will handle it within 30 days. There is no charge, and asking costs you nothing else.

If you are in the EEA, the UK or Switzerland and you think we have handled your data wrongly, you can complain to your national data-protection supervisory authority. We would rather you told us first, but that right is yours regardless.

Changes

We update the date above when this policy changes, and announce material changes by email to account holders.

See also our terms of service.

This document is published in English; translations are provided for convenience. Where the versions differ the English one is our reference — except where you are a consumer and the law of your country of residence says otherwise, in which case your language and your law win.