Privacy Policy
Last Updated: May 16, 2026
InnoSage LLC ("InnoSage," "we," "us," or "our") builds privacy-first writing, publishing, capture, and developer tools. This is the canonical company-wide Privacy Policy for InnoSage websites, apps, extensions, and services.
We keep one policy so users have one clear source of truth. Product-specific modules below explain privacy boundaries that apply only when you use those features.
If you have questions or want to exercise your privacy rights, contact us at team@innosage.net.
How This Policy Is Organized
The universal baseline applies across InnoSage. The product modules apply only when you use the listed product or feature.
| Area | What it covers |
|---|---|
| Universal baseline | Account data, contact/support data, billing, telemetry, providers, retention, security, rights, children, transfers, and policy changes. |
| InnoSage Draft | Local/offline storage, Google Drive sync, published pages, and Secret Share. |
| Draft browser extension | Browser or AI-chat capture into the user's configured Draft workspace. |
| AI and audio features | Remote processing boundaries for requested organize, transform, clip, and read-aloud actions. |
| Premium API and Gateway | API keys, hashed validation, subscription authorization, and rate-limit metadata. |
1. Universal Baseline
A. Information you provide
- Account information: When you sign in, we use Google Firebase Authentication and may receive your email address, name, profile photo, and Firebase user ID.
- Contact and support messages: If you use a contact form or email us, we receive your name, email address, message, and any details you choose to include.
- Billing information: If you buy a paid plan, Stripe processes your payment details. We store billing status metadata such as your Stripe customer ID, subscription status, plan, renewal period, and related timestamps. We do not store full card numbers.
- User content: Depending on the product feature you use, this may include documents, blocks, page metadata, published snapshots, encrypted Secret Share payloads, imported captures, audio/text feature inputs, comments, and task-toggle overlays.
B. Information collected automatically
- Basic device and usage data: Browser type, operating system, app route, feature interactions, error states, performance signals, and similar operational data.
- Product telemetry: Events such as button clicks, page views, storage mode, page counts, backup/recovery actions, and data-anomaly indicators.
- Local browser data: The apps may store preferences and operational state in
localStorage,IndexedDB, Cache Storage, or similar browser storage.
C. How we use information
- provide, secure, and maintain the services;
- authenticate users and prevent unauthorized access;
- save preferences and sync or restore data when you request it;
- process subscriptions, invoices, payment failures, and billing support;
- respond to support, contact, and privacy requests;
- debug errors, monitor reliability, and improve product quality;
- send important administrative notices, such as security, billing, or policy updates;
- comply with legal obligations and enforce our terms.
We do not sell your personal information.
D. Service providers
We use trusted service providers to operate InnoSage. Depending on what you use, these may include:
- Google Firebase and Google Cloud: authentication, Firestore data storage, server-side application hosting, and operational infrastructure.
- Stripe: checkout, payment processing, subscriptions, invoices, tax/payment metadata, and billing events.
- Cloudflare: Workers, Pages, R2 object storage, KV, Durable Objects, DNS/security services, gateway authorization, public publishing, and edge analytics through Zaraz.
- Microsoft Clarity or similar telemetry tooling: product analytics, session-quality signals, and debugging telemetry, configured to avoid collecting private document text.
- Google Drive APIs: user-authorized backup, restore, and sync transport.
- Email and support tools: receiving and responding to messages you send us.
We may also disclose information if required by law, to protect rights and safety, to investigate abuse, or as part of a merger, acquisition, financing, or sale of assets, subject to appropriate protections.
2. Product-Specific Modules
A. InnoSage Draft local/offline workspace
InnoSage Draft is local-first. By default, Draft content is stored in your browser or local workspace using local browser storage such as IndexedDB. This content does not leave your device merely because you write or edit it. Clearing browser data, switching browsers, or using another device may remove or hide this local content unless you have made a backup or sync copy.
B. Google Drive data sync
If you connect Google Drive, Draft uses your Drive as a user-owned backup and sync transport. Google Drive is not treated as InnoSage-owned primary content storage. We request Google API access only for the files and folders needed to support Draft backup, restore, and sync behavior.
InnoSage's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including Limited Use requirements. We do not sell Google Workspace API data, and we do not use Google Drive content to train generalized AI or machine-learning models.
C. Public publishing
When you publish a page, you intentionally create a public or shareable snapshot. Published snapshots, published Markdown artifacts, public comments, task-toggle overlays, and related metadata may be stored and served through Cloudflare Workers and Cloudflare R2. Anyone with the published URL may be able to view that content unless the feature explicitly says otherwise.
D. Secret Share
Secret Share is separate from ordinary public publishing. Secret Share content is encrypted in the browser before upload using WebCrypto. Depending on your settings, decryption may require a password or a key fragment in the URL. Secret Share records may include expiration and burn-after-read controls. We store the encrypted payload and operational metadata needed to serve and enforce the share, but we should not receive plaintext Secret Share content through the Secret Share storage endpoint.
E. Draft browser extension
The InnoSage Draft browser extension helps capture web or AI-chat content into your Draft workspace. Captured content is sent from the extension to your configured Draft app/workspace flow. The extension itself is designed not to use third-party analytics, tracking pixels, or InnoSage-owned external storage buffers for captured content.
F. AI and audio features
Some InnoSage features may help organize, transform, read aloud, clip, or process content. When a feature needs a remote service, only the data needed to perform that requested action should be sent. We do not sell your content, and we do not use your private Draft or Google Drive content to train generalized AI models.
If a feature uses a third-party AI, speech, or infrastructure provider, that provider may process the submitted content solely to provide the requested feature. Product UI should make remote processing clear where it materially changes the privacy boundary.
G. Premium API keys and Gateway
If you generate an InnoSage API key, we show the full key once, store a non-secret prefix for display, and store a hashed form for validation. InnoSage Gateway may process API-key validation results, premium feature names, subscription authorization results, rate-limit counters, and remaining quota to enforce plan access and abuse controls.
3. Retention
- Account records: kept while your account is active or as needed for security, billing, legal, or operational reasons.
- Contact submissions: kept as long as needed to respond and maintain business records.
- Billing records: retained as required for accounting, tax, fraud prevention, dispute handling, and Stripe synchronization.
- API key metadata: key prefixes, hashes, creation timestamps, usage metadata, and rate-limit counters may be retained while the key or subscription is active and for a reasonable period afterward.
- Local Draft content: controlled by your browser or local device unless you export, sync, publish, or share it.
- Google Drive sync data: controlled by your Google Drive account. You can manage or delete those files in Google Drive.
- Published content: retained until you unpublish, delete it where supported, or ask us to remove it, subject to backups, caches, abuse prevention, and legal obligations.
- Secret Share records: retained until expiration, burn-after-read consumption, deletion, or operational cleanup, subject to cache and backup limits.
- Telemetry and logs: retained for a limited period appropriate for security, debugging, reliability, and product analytics.
4. Security
We use technical and organizational measures intended to protect information, including authentication, access controls, encryption in transit, provider-managed storage security, hashed API-key validation, and client-side encryption for Secret Share payloads. No system is perfectly secure, and you are responsible for protecting your account, devices, browser profile, API keys, passwords, and share URLs.
5. Your Choices And Rights
Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to certain processing of your personal information. You can also:
- delete local Draft content from your browser or device;
- remove Google Drive sync files from your Google Drive;
- revoke Google permissions through your Google account;
- cancel or manage subscriptions through the available billing/support flow;
- rotate or delete API keys where supported;
- unpublish or remove shared content where supported;
- contact us for account deletion or privacy requests.
6. Children
The services are not intended for children under 13, and we do not knowingly collect personal information from children under 13.
7. International Transfers
InnoSage is based in the United States, and our providers may process information in the United States and other countries. By using the services, you understand that information may be transferred to and processed outside your country of residence.
8. Changes
We may update this Privacy Policy from time to time. The "Last Updated" date shows when the policy was last revised. If changes are material, we will take reasonable steps to notify users through the services or another appropriate channel.