Privacy Policy

Last Updated: September 2, 2026

Your notes are yours. Inksight uses your information to provide the scanning, editing, export, search, organization, and sync features you choose. We do not sell document content, use it for advertising, or permit it to be used to train AI models.

  • You stay in control: You can permanently delete your account and its entire document library at any time.
  • Your content stays out of analytics: Service telemetry does not include document images, text, filenames, names, or email addresses.
  • Advertising measurement is optional: The Google Ads tag is not loaded unless you allow it, and document content is never sent to Google Ads.
  • Human access is exceptional: Documents are not routinely browsed or reviewed. The single authorized operator may open an individual document only rarely to investigate a specific failure or support issue.

1. What Inksight Needs to Provide the Service

We process the information needed to provide, secure, and support the features you use:

  • Account Information: If you sign in, we collect your email address and basic profile information to sync your documents across devices.
  • Your library: We save the images you choose and the resulting digitized text so you can access, edit, and export them in your library.
  • Account and device identifiers: We process your account ID, app installation or device quota identifier, locale, timezone, notification token, and authentication-provider identifiers to secure accounts, enforce allowances, sync your library, and deliver notifications you enable.
  • Purchases and support: We receive subscription status, product, transaction, price, currency, and store information, plus information you send when requesting support. We do not receive your full card number.
  • Content-free service telemetry: We collect limited first-party product interactions, app version, platform, session timing, first-touch acquisition (the landing page and the channel a visit arrived from), and error details to operate, secure, support, and improve Inksight. This service telemetry is not used for advertising. Optional advertising attribution and conversion measurement is collected only after the choice described below.
  • Export-operation records: When a signed-in web user initiates a document export, we record the time, linked account and document identifiers, selected scope and page count, file format/extension, and that the browser download was initiated. We do not include document content, filenames, email addresses, acquisition data, or a browser measurement-session identifier in this record.

2. AI Processing You Request

To provide the best possible handwriting recognition and document service, Inksight uses leading cloud AI providers selected for quality and reliability:

  • Recognition: Your selected scan is sent through OpenRouter to Google Gemini to extract text and document structure.
  • Document organization: Extracted text may be sent through OpenRouter to Anthropic to create titles and organize documents.
  • Apple devices: The iPhone and iPad app asks for affirmative permission before the first scan is uploaded for this processing. You can review or withdraw that permission in Profile Settings; declining prevents cloud scanning and sends no selected document.
  • Training and retention safeguards: Inksight does not use your documents to train AI models and instructs OpenRouter not to route paid requests to providers that may train on request data. OpenRouter's optional prompt logging, external observability broadcasting, and input/output improvement program are disabled for Inksight. Recognition first uses compatible Zero Data Retention (ZDR) endpoints, so the model provider does not retain that content after processing. If both the primary and backup recognition routes cannot reach a ZDR endpoint because of provider availability, Inksight may retry the backup model through an endpoint that is not permitted to train on the request but may retain it for its documented operational or safety period. This narrow exception is used only to complete recognition you requested while ZDR routes are unavailable.

3. Permissions

Inksight asks for access only when you choose a feature that needs it:

  • Camera: Used when you choose to photograph a note inside the app.
  • Photo Library: Used when you choose an existing photo to import. Inksight does not browse your library.

4. Data Storage & Security

We take data security seriously:

  • Data is encrypted in transit and stored using cloud infrastructure with encryption at rest.
  • Document records use account-based authorization. New and migrated scan objects use private storage with short-lived signed access; older objects are moved from legacy storage when the owning account uses a compatible app.
  • Inksight's owner is the only person authorized to access document data. Documents are not browsed routinely. An individual document may be opened briefly and rarely to investigate a specific failure or support issue; most investigations use service metadata and logs without reading the text or viewing the image.

5. Processors That Help Deliver Inksight

We use the following processors and platform providers to deliver Inksight:

  • Supabase: authentication, database, private file storage, server functions, and first-party product events.
  • OpenRouter, Google Gemini, and Anthropic: handwriting recognition, titles, and document organization as described above.
  • RevenueCat, Apple, Google Play, and Stripe: purchases, entitlement status, checkout, and subscription support, depending on platform.
  • Apple and Google Sign-In: authentication when you choose the corresponding sign-in method.
  • Firebase/Google and Apple Push Notification service: app installation tokens and notification delivery. Firebase Analytics advertising measurement is disabled in the initial iOS release.
  • Vercel Web Analytics: cookie-free, aggregated audience statistics. Private document identifiers are removed from library URLs before an event is sent.
  • Google Ads: optional advertising attribution and conversion measurement only after you allow it as described below.

These providers may process data in countries other than your own. We use contractual, technical, and organizational safeguards intended to provide protection appropriate to the data and applicable law.

6. Cookies, Browser Storage, and Measurement

Inksight uses necessary cookies and browser storage to provide features you request, including authentication, account security, checkout continuity, language and privacy preferences, and restoring the document or plan you selected while moving between product screens. This storage is not used for advertising and cannot be disabled through the advertising-measurement choice without breaking those requested features.

When you initiate a signed-in web export, Inksight also creates the minimal export-operation record described above. We use it to deliver and support the requested export, investigate export reliability, and keep a cross-platform record of the format used. It is not used for advertising and is not controlled by the advertising measurement choice. “Download initiated” means the browser was handed the file; it does not prove that a file was saved, opened, or read.

Inksight records limited first-party product and service events in Supabase, including actions such as upload, scan, preview, checkout, copy, and export, together with account, document, page, platform, session, and limited error fields where relevant. We use these records to operate and support the requested service, diagnose failures, understand the product funnel, and improve reliability. We do not include document images, document text, filenames, names, or email addresses in these event properties, and this telemetry is not used for advertising.

Vercel Web Analytics records cookie-free, anonymized page-view and audience statistics. Vercel derives a visitor hash that resets after 24 hours and provides aggregated reporting rather than cross-site or long-term visitor profiles. Inksight removes private document identifiers from library URLs before sending these events. This audience measurement and the first-party service telemetry above remain enabled when advertising measurement is declined.

We store a first-touch acquisition record in session storage, which normally lasts until the browser tab or session ends. It records the landing path, the channel a visit arrived from, campaign parameters, and the referring host — the site domain only, never the third-party page path or its query string. This is first-party measurement of our own pages, used to understand which pages and channels bring people to Inksight, and it remains enabled when advertising measurement is declined. Google click identifiers such as GCLID, GBRAID, or WBRAID are advertising data: they are added to this record only if you choose Allow advertising measurement, and are removed if you later withdraw it.

The Google Ads tag is not loaded before you allow advertising measurement. If you allow it, Google can receive the ad visit and two defined outcomes: a successful scan followed by copy or export, and a completed web subscription purchase. Purchase events include the order value, currency, and a random checkout-attempt identifier used to prevent duplicate counting. Enhanced conversions, advertising personalization, and Google Analytics storage are disabled, and document content is never sent to Google Ads.

Your advertising-measurement choice is saved in local storage so the banner does not keep returning. You can decline advertising measurement without losing Inksight functionality, and you can withdraw or grant permission at any time. Changing your choice does not affect processing that occurred lawfully before the change.

Open all privacy choices

7. Google Drive Exports

When you choose to create a Google Doc or Google Sheet, Inksight asks you to connect a Google account and grant the drive.file permission. This permission is limited to Google Drive files that Inksight creates for you or that you explicitly open with Inksight; it does not give Inksight access to browse all of the files in your Drive.

  • Information accessed: We use basic Google account information to establish the connection, and Google returns limited metadata such as the identifier, name, type, and editor link for the file you asked Inksight to create.
  • How it is used: Inksight generates the requested export on your device and uploads it directly from your device to Google Drive solely to create the Google Doc or Google Sheet you requested.
  • Storage and retention: Inksight's backend does not receive or store your Google access token or copies of your Google Drive files. The temporary export file on your device is deleted after the upload attempt. The resulting file remains in your Google Drive until you delete it there.
  • Sharing: We do not sell Google user data, use it for advertising, use it to train AI models, or share it with third parties. Data is sent to Google only at your direction to provide the export.
  • Your control: You can revoke Inksight's Google access at any time from your Google Account's third-party connections page. Revoking access does not delete files already created in your Drive; you can delete those files directly in Google Drive.

Inksight's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

8. Your Rights & Account Deletion

You can permanently delete your account and all associated account and document data at any time. You can do so through either of these methods:

  • In-App Deletion: Go to Account > Profile Settings and select "Delete Account". The app rechecks account ownership, removes and verifies your stored files, deletes linked processor customer data, erases direct internal identifiers, and then deletes the authentication account.
  • Manual Request: If you cannot access the app, you can email us at inksight.notes.app@gmail.com with the subject line "Account Deletion Request". We will verify the request and begin deletion without undue delay.

Removing an individual document from your active library may archive it so it can be recovered. This is a reversible library feature, not a limit on your privacy rights: choosing Delete Accountpermanently removes your entire document library together with your account data.

Permanent deletion: Upon account deletion, we permanently remove your email address, profile metadata, all uploaded images of notes, all transcribed text, notification tokens, local per-account search data, and processor customer profiles associated with your account. Deleting an account does not cancel an App Store subscription; manage or cancel it at Apple subscriptions.

Data Retention: Active document and profile data is removed through the deletion workflow. Infrastructure providers may retain encrypted backup copies for their limited backup lifecycle. Transaction facts may be retained when required for accounting, fraud prevention, disputes, or legal compliance, but Inksight removes the direct account and RevenueCat customer identifiers from its retained transaction ledger.

9. Free Web Tool (Handwriting to Text)

Our web tools at https://www.inksight-app.com/handwriting-to-text let you prepare up to ten free pages before choosing a plan:

  • Your work is saved for the features you choose. Uploaded images, extracted text, edits, and document metadata are kept in your Supabase-backed library so previews, exports, recovery, and cross-device access work. You can permanently delete the entire library at any time by deleting the account.
  • No raw IP addresses. To prevent repeated anonymous free batches, we store only a one-way salted hash derived from the network IP address — never the raw address — alongside daily free-page and locked-preview counters.
  • No email is required for the first upload. We create an anonymous technical session. If you sign in from that browser session, its documents and free-page usage move to your account.
  • Allowance decisions are server-side. Account, page-credit, subscription, and anonymous network ledgers determine whether a page is available. Locked transcription text is not returned to the browser until the page is unlocked.

10. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at:

inksight.notes.app@gmail.com