DRAFT — not yet in effect. Pending counsel review.

Privacy Policy — DRAFT v0.3

Status: Working draft for collaborative editing and counsel review. Not legal advice. Do not publish. Effective date: [EFFECTIVE DATE] · Version: privacy-v0.3-draft (v0.3: User Activity + personalization + marketing/product comms split + deidentified aggregates + rights structure — growth levers without training on library content) Companion: Terms of Service · Checklist: tos-checklist.md

Service: InspiMark at https://inspimark.com Controller / business: HWGA LLC Postal address: HWGA LLC Attn: Nicholas Losciuto 7483 Teasdale Ave Saint Louis, MO 63130 Contact:

This Privacy Notice explains how HWGA LLC (“InspiMark,” “we,” “us,” “our”) collects, uses, shares, stores, and secures information about you when you use our websites, applications, and related services (the “Services”), or when you otherwise interact with us. It also explains your choices.

It is written for a launch across the US, UK, EU/EEA, and Canada.


Overview

This notice covers:

Our Services may link to third-party sites or features (for example, OAuth login or embeds). Information those third parties collect is governed by their policies. We are not responsible for their practices.


1. What InspiMark is

InspiMark is a private personal library for content you choose to save—articles, PDFs and Office documents you upload, videos and posts, notes, tags, collections, transcripts, AI assistance about your library, and organizational views built from your saves.

v1 does not connect to Gmail or Outlook. If email-inbox integrations ship later, we will update this Policy and any required Limited Use disclosures.


2. What information we collect

We collect information when you provide it, when you use the Services, and (in limited cases) from other sources.

2.1 Contact and account information (you provide)

2.2 Content (your library)

If you save or upload materials, we collect the Content and data associated with it—for example URLs, files, notes, tags, collections, highlights, transcripts, and derivatives we generate for you (summaries, embeddings/search indexes, organizational structures). Content may include personal information depending on what you save.

If you use AI chat or similar interactive features, we also collect interactive inputs (prompts, questions, and related context you submit) needed to return a response to you (“Interactive Chat Information”).

2.3 User Activity Information (collected automatically)

When you use the Services we automatically collect User Activity Information, such as:

We use cookies and similar technologies as described in §4. We design product analytics so library item titles and viewing history are not sent to third-party advertising or analytics pixels in a way that would undermine §3.7.

2.4 Information from other sources

2.5 Website analytics (marketing site)


3. How we use your information

We use information about you for the purposes below. Where GDPR/UK GDPR applies, we rely on contract, legitimate interests, consent, or legal obligation as appropriate (counsel will map each purpose before publish).

3.1 To provide the Services (including personalization)

We use Contact, Account, Content, Interactive Chat Information, and User Activity Information to:

Where we offer a personalization profile or non-essential personalized suggestions, we will provide a way to view, edit, or disable that personalization when the feature ships; core storage and search continue to work without it.

3.2 To communicate with you

3.3 To maintain, monitor, and secure the Services

We use Account, Activity, Interactive Chat Information, and limited Content metadata to detect abuse, debug outages, enforce rate limits, investigate fraud or unauthorized access, and protect InspiMark, our users, and others.

3.4 To develop and improve InspiMark (without training on your library)

We use User Activity Information and aggregated diagnostics to understand which features help people build a useful library, improve reliability and UX, prioritize roadmap work, and measure marketing effectiveness (subject to cookie/consent rules).

We do not use your library Content or Interactive Chat Information to train foundation models or other AI models (ours or third parties’), except under a separate, optional program you can opt into if we ever offer one. When AI features call third-party model APIs, content is processed only to return results to you, under our vendor agreements.

3.5 Marketing and growth of InspiMark (not sale of your library)

We may use Contact Information and coarse User Activity Information (for example, whether you completed signup or activated a feature—not the substance of private library items) to:

We do not sell your library content or build advertising profiles from what you save for third-party ads.

3.6 Legal and compliance

We use information as reasonably necessary to comply with law, legal process, or governmental requests; enforce our Terms and policies; and establish, exercise, or defend legal claims.

3.7 What we do not do with your library

3.8 Organizational / “Wiki” views

Features that organize your library by interest use content you saved to help you navigate it. They are not used to sell profiles or serve third-party ads. You can delete content or request account deletion to remove underlying data.

3.9 Deidentified and aggregated information

If we create deidentified or aggregated information that cannot reasonably be used to identify you, we may retain and use it for analytics, research, security, fraud prevention, and product improvement for any lawful purpose. We will not attempt to re-identify such data except as permitted by law (for example to test our deidentification).


4. Cookies and similar technologies

We and certain service providers use cookies, pixels, local storage, and similar technologies.

CategoryPurposeTypical requirement
NecessaryLogin/session, security, load balancing, essential preferencesRequired for the Services
FunctionalityRemember choices (e.g. UI prefs, cookie banner choice)Often necessary or low-risk
AnalyticsUnderstand traffic and product usage (marketing site and, if enabled, coarse product analytics)Consent where required (EU/UK/ePrivacy)
Targeting / advertisingInterest-based ads for our products (if we enable them)Consent / opt-out as required; off by default until configured

You can withdraw or change cookie consent via Cookie preferences on the marketing site and browser settings. Disabling some cookies may limit features.

We honor Global Privacy Control (GPC) and similar universal opt-out signals as an opt-out of sale/sharing and targeted advertising where applicable law requires it — this is a legal obligation in several US states, not a voluntary commitment. (Today the marketing site treats GPC/DNT as an analytics decline; app-side opt-out plumbing is an engineering dependency before publish.)


5. How we share your information

We do not sell your personal information. (Under laws like the CCPA, "sale" includes exchanges for non-monetary consideration — our commitment covers those too.)

We may share information as follows:

  1. Service providers (processors). Hosting and storage (e.g. Amazon Web Services), transactional email (e.g. Amazon SES), AI/transcription APIs you invoke through the product, security and infrastructure vendors, and product or marketing analytics providers under written contracts that limit use to our instructions.
  2. Paddle, as merchant of record for paid plans. Paddle is the seller of the subscription and processes payment and tax data under its own terms and privacy notice—not as our subprocessor. We receive subscription status and limited identifiers back from Paddle.
  3. At your direction. Exports you download; OAuth integrations you connect; share links you create — a shared item or collection is viewable by anyone holding the link, without an InspiMark account, until it expires or you revoke it (see TOS §4.5); AI-agent access you enable — if you create a personal access token for the InspiMark MCP server, the external AI tool you give it to can read and add to your library on your behalf until you revoke the token; and any future collaboration features you explicitly use.
  4. Legal and safety. As reasonably necessary to comply with law, enforce agreements, or protect rights, safety, and integrity.
  5. Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality and this Policy’s principles.
  6. With your consent. Where you ask us to share or otherwise consent.

A living subprocessor / vendor list will be published at launch or provided on request to privacy@inspimark.com.


6. Storage, security, and international transfers

We are based in the United States and generally process information on infrastructure in the US (and other regions we configure with our providers).

If you use InspiMark from the EEA/UK or Canada, your information may be transferred to the US. Before marketing those regions we will implement appropriate transfer mechanisms (e.g. Data Privacy Framework certification and/or Standard Contractual Clauses, and Quebec Law 25 assessments where required).

We use commercially reasonable safeguards (HTTPS, hashed passwords, access controls, optional encryption of certain secrets at rest). No method is 100% secure. Protect your password and devices. Report concerns to support@inspimark.com (or privacy@inspimark.com for privacy-related security issues).


7. Retention

DataRetention
Account & library (live systems)Until you delete items or we complete account deletion
Soft-deleted library itemsUntil permanently removed from trash / purge
Account deletion (database and associated object-storage files we control)Within 30 days of a verified deletion request (see Terms §4.6)
Embeddings / indexes / transcriptsRemoved with associated content/account purge where implemented
Operational DB snapshots / backupsResidual copies may remain up to 90 days (or until snapshot expiry), then age out—config must enforce this before publish
Security / operator audit logs (not library body)As needed for security and compliance
User Activity logsOnly as long as reasonably needed for the purposes in §3 (shorter windows for raw logs where practical)
Paddle billing recordsHeld by Paddle per its policies and tax/legal needs
Deidentified / aggregated dataMay be retained as described in §3.9
Marketing consentsUntil withdrawn

8. Your choices: communications, access, deletion

8.1 Opt out of non-transactional communications

Use unsubscribe links in marketing or product-news emails, or email support@inspimark.com. We may still send transactional messages (security, billing, verification, password reset, essential service notices).

8.2 Change your information

Update profile/settings in-product when available, or email support@inspimark.com.

8.3 Export

While signed in, use in-product export tools (including JSON library export). For help or formats not yet automated, email support@inspimark.com—we aim to complete manual export help within 45 days.

8.4 Delete

Delete individual items in-product. Request account deletion by emailing privacy@inspimark.com from your account email (self-serve delete may ship later). We complete primary purge within 30 days of verification as described in the Terms. Some information may remain in backups for up to 90 days, or where law requires retention. Deidentified data may remain under §3.9.

8.5 Personalization and cookies

Disable non-essential personalization when the control is available. Manage cookies via the marketing-site preference UI and browser settings.


9. Payment processing

Paid plans are sold through Paddle as merchant of record. Card and tax details are collected by Paddle, not stored as full PANs on InspiMark servers. See Paddle’s checkout buyer terms and privacy notice, and our Terms §3.


10. Rights of US residents (CCPA and similar state laws)

If you are a resident of California, Colorado, or another US state with a comprehensive consumer privacy law, you may have rights to:

Categories we may collect (see §§2–3): identifiers (e.g. email, IP); customer records information; commercial information (subscription status); internet/network activity (User Activity Information); approximate geolocation derived from IP; audio/visual or document content you upload; inferences used only to personalize your library experience; account credentials (password is stored hashed).

Sources: you; your devices; integrations you connect; Paddle; service providers. Purposes: §3. Disclosure: service providers and parties in §5—not sold (for monetary or other valuable consideration).

Submit requests to privacy@inspimark.com. We will verify identity as reasonably necessary. Authorized agents may be required to provide proof of authority.

Working assumption at launch: CCPA “business” thresholds may not be met; we still aim for this structure. Re-test annually or at funding/growth events (see OPEN-QUESTIONS).


11. Rights of EEA and UK residents

If GDPR/UK GDPR applies, you may have rights to access, portability, rectification, erasure, restriction, objection, and withdrawal of consent (where processing is consent-based), and to lodge a complaint with a supervisory authority (or the UK ICO).

We will respond without undue delay and within one month (extendable as permitted). Contact privacy@inspimark.com. EU/UK representative: to be appointed before those markets are actively marketed; this notice will be updated with their contact details.

Lawful bases will be documented in our records of processing before launch (contract for core library; consent for non-essential cookies/marketing where required; legitimate interests for security and some product analytics, balanced against your rights).


12. AI-specific transparency

When you use AI chat or similar features, you interact with an AI system. Inputs may be sent to model-provider processors under contract to generate a response for you. Outputs can be wrong—verify important facts. See §3.4 regarding no training on your library by default.


13. Children

InspiMark is for users 16 and older. We do not knowingly collect personal information from anyone under 16. Contact us to delete if you believe we have.


14. Law enforcement

We review legal process carefully. Where permitted, we notify users of requests for their library content unless legally prohibited. Counsel will finalize our law-enforcement guidelines.


15. Changes

We may update this Privacy Notice. We will post the revised version with a new “Last modified” / effective date. For material changes we will provide a more prominent notice (in-app and/or email) as appropriate. If you disagree, stop using the Services and request deletion.


16. Contact

All privacy and DSR requests: privacy@inspimark.com Support: support@inspimark.com · Copyright / DMCA: copyright@inspimark.com · Legal: legal@inspimark.com Mail: HWGA LLC, Attn: Nicholas Losciuto, 7483 Teasdale Ave, Saint Louis, MO 63130

EU/UK representative / Quebec privacy officer: to be appointed before those market launches.