Privacy Policy
Last updated: August 19, 2026
1. Who we are
Indash (“Indash”, “we”, “us”) is an AI marketing platform. This Privacy Policy explains what personal data we process, why, who we share it with, and what rights you have over it.
Indash acts as the controller of the data described in this policy. You can reach us at any time at privacy@indash.io.
2. Scope
This policy covers our website (indash.ai and its subdomains), the Indash application, our commercial communications and advertising campaigns, and the Indash MCP connector when you link it to an AI client. It does not cover third-party sites or services we link to, which are governed by their own policies.
3. Data we collect
a) Data you provide
- Contact and lead data: name, email, phone, company, and the content of messages you send us through forms, WhatsApp, email, or when booking a call.
- Account data: your email and identity provider data (for example, Google sign-in via Supabase Auth), workspace membership, and OAuth tokens issued to the clients you connect.
- Workspace content: products, brand kits, skills, creative strategies, briefs, comments, and the images/videos generated in the workspaces you grant access to.
- Generation inputs and outputs: prompts, reference images, and the media produced by the generation tools.
- Billing data: plan, credit consumption, and the data needed to process payments. Full card details are handled directly by our payment processor; Indash does not store them.
b) Data collected automatically
- Technical and usage data: IP address, device and browser type, operating system, language, pages viewed, referrer and campaign parameters (for example, utm_source or fbclid), and access timestamps.
- Cookies and similar identifiers: see section 4.
- Operational metadata: usage and billing events, timestamps, and tool-call telemetry needed to run and meter the service.
c) Data we receive from third parties
- Identity providers (for example, Google) when you sign in with them.
- Advertising and analytics platforms (for example, Meta), which report our ad performance to us in aggregate.
We do not request and do not want to receive special categories of personal data (health, ethnic origin, political opinions, biometric data, and so on). Please do not include them in the content you upload to the platform.
4. Cookies and tracking technologies
We use first- and third-party cookies, pixels, tags, and local storage technologies. We use them for three purposes:
- Strictly necessary: keeping you signed in, remembering preferences (such as the light/dark theme), and securing the service. The site does not work without them.
- Analytics: understanding in aggregate how the site is used so we can improve it. We use Vercel Analytics.
- Advertising and measurement: measuring how our ads perform and showing you relevant advertising. We use the Meta Pixel (Facebook/Instagram), which records page views and actions such as clicking a contact button or submitting a form, and associates them with your Meta account where one exists. Meta may use that data to attribute conversions, build custom and lookalike audiences, and for its own purposes under its Privacy Policy.
How to control them
- You can block or delete cookies in your browser settings. Blocking strictly necessary cookies may prevent you from using the service.
- You can adjust the ads you see on Meta from your ad preferences and limit the use of third-party data from the Accounts Center.
- You can opt out of interest-based advertising more broadly at optout.aboutads.info or youronlinechoices.com.
5. How we use the data
- Providing, maintaining, and improving the service.
- Authenticating you, managing your account, and scoping a connector to the workspace you select at the consent screen.
- Generating, storing, and delivering the creative output you request.
- Metering credit usage, invoicing, and collecting payment.
- Answering enquiries, scheduling calls, and providing support.
- Sending you service communications and, where you accept, marketing communications (you can unsubscribe at any time).
- Measuring, optimizing, and targeting our advertising, including remarketing.
- Preventing fraud and abuse, and complying with legal, accounting, and tax obligations.
6. Legal bases for processing
Where the GDPR or equivalent law applies, we process personal data on the following bases:
- Performance of a contract: to give you access to the service and bill for it.
- Legitimate interests: to secure and improve the service, prevent fraud, and carry out proportionate direct marketing.
- Consent: for non-essential cookies, interest-based advertising, and marketing communications where the law requires it. You can withdraw consent at any time.
- Legal obligation: to keep accounting records and respond to requests from competent authorities.
7. Who we share data with
We do not sell personal data. We share it only as needed to deliver the service, with:
- Infrastructure and hosting: Vercel (hosting and analytics) and Supabase (database, auth, and storage).
- AI model providers: Google (Gemini, Veo), OpenAI (gpt-image), and fal.ai (Kling, Seedance), which receive the prompt and reference images you submit to a generation tool for the sole purpose of producing the requested output.
- AI clients you connect: for example, Anthropic (Claude). The connected client receives the tool results for the workspace you authorized.
- Advertising and analytics: Meta Platforms, as described in sections 4 and 8.
- Payments: our payment processor, to handle subscriptions and charges.
- Third parties for legal or corporate reasons: competent authorities where the law requires it, and counterparties in a merger, acquisition, or restructuring, in which case we will notify you.
We do not use your data or your content to train third-party models beyond producing the output you request.
8. Advertising and remarketing
We promote Indash on third-party platforms, primarily Meta (Facebook and Instagram). To do so:
- The Meta Pixel installed on our site reports page views and the conversion actions described in section 4 to Meta.
- We may build custom audiences from those visits, and lookalike audiences derived from them, to show ads to people with comparable interests.
- We do not share your workspace content, your prompts, or the generated media with advertising platforms.
You can object to this processing using the controls in section 4 or by writing to privacy@indash.io.
9. International transfers
Indash works with providers located outside your country of residence, including the United States. When we transfer personal data from the European Economic Area, the United Kingdom, or other jurisdictions with transfer restrictions, we rely on recognized mechanisms such as the European Commission’s Standard Contractual Clauses or adequacy decisions.
10. Data retention
We retain personal data while your account is active and for as long as needed to fulfil the purposes in this policy, resolve disputes, and comply with legal obligations. Specifically:
- Workspace content and generated media are retained while the workspace is active.
- OAuth access tokens are short-lived; refresh tokens and authorization codes expire and are purged periodically. Revoking a connection invalidates its tokens immediately.
- Billing records are retained for the periods required by applicable accounting and tax rules.
11. Security
We apply reasonable technical and organizational measures to protect personal data: encryption in transit, per-workspace access control, credential isolation, and audit logging. No system is completely secure; if a breach affecting your data occurs, we will notify you as required by applicable law.
12. Your rights
Depending on your jurisdiction, you may have the right to access, rectify, erase, restrict, or object to the processing of your personal data, to request its portability, and to withdraw consent. You may also lodge a complaint with your local supervisory authority.
- Argentina: you may exercise your rights under Law 25.326 on the Protection of Personal Data and complain to the Agency for Access to Public Information (AAIP).
- EEA and United Kingdom: the rights under the GDPR and UK GDPR apply.
- California: we do not sell or share personal information as defined by the CCPA/CPRA. You may exercise your rights to know, delete, and correct without receiving discriminatory treatment.
To exercise them, write to privacy@indash.io. We will respond within the timeframes set by applicable law. We may ask for additional information to verify your identity.
13. Children
Indash is a business product and is not directed to anyone under 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with data, write to us and we will delete it.
14. Third-party links
Our site may link to third-party services (for example, WhatsApp, Calendly, or social networks). We do not control those services and are not responsible for their privacy practices; we recommend reviewing their policies.
15. Changes to this policy
We may update this policy. Changes are reflected in the “last updated” date and, where material, we will notify you by a reasonable means before they take effect.
16. Contact
Privacy questions, requests, or complaints: privacy@indash.io.