Privacy Policy — DRAFT v0.3
Status: Working draft for collaborative editing and counsel review. Not legal advice. Do not publish. Effective date:
[EFFECTIVE DATE]· Version:privacy-v0.3-draft(v0.3: User Activity + personalization + marketing/product comms split + deidentified aggregates + rights structure — growth levers without training on library content) Companion: Terms of Service · Checklist: tos-checklist.md
Service: InspiMark at https://inspimark.com Controller / business: HWGA LLC Postal address: HWGA LLC Attn: Nicholas Losciuto 7483 Teasdale Ave Saint Louis, MO 63130 Contact:
- Privacy / data-subject requests: privacy@inspimark.com
- Support: support@inspimark.com
- Copyright / DMCA: copyright@inspimark.com
- Legal: legal@inspimark.com
This Privacy Notice explains how HWGA LLC (“InspiMark,” “we,” “us,” “our”) collects, uses, shares, stores, and secures information about you when you use our websites, applications, and related services (the “Services”), or when you otherwise interact with us. It also explains your choices.
It is written for a launch across the US, UK, EU/EEA, and Canada.
Overview
This notice covers:
- What information we collect
- How we use your information
- How we use cookies and similar technologies
- How we share your information
- How we store and secure information
- How long we retain information
- Communications preferences, changes, and deletion
- Payment processing (Paddle)
- Rights of US residents
- Rights of EEA/UK residents
- Other important information
Our Services may link to third-party sites or features (for example, OAuth login or embeds). Information those third parties collect is governed by their policies. We are not responsible for their practices.
1. What InspiMark is
InspiMark is a private personal library for content you choose to save—articles, PDFs and Office documents you upload, videos and posts, notes, tags, collections, transcripts, AI assistance about your library, and organizational views built from your saves.
v1 does not connect to Gmail or Outlook. If email-inbox integrations ship later, we will update this Policy and any required Limited Use disclosures.
2. What information we collect
We collect information when you provide it, when you use the Services, and (in limited cases) from other sources.
2.1 Contact and account information (you provide)
- Contact information: email address, and any other details you choose to give us (for example in support messages).
- User account information: password (hashed at rest), optional display name, subscription tier and status, and related account settings.
- Communications: messages you send to support@inspimark.com, privacy@inspimark.com, or through in-product support channels.
- Preferences and consents: cookie choices (implemented on the marketing site), terms-acceptance records (implemented — timestamp + version stored at signup), marketing opt-ins/opt-outs and personalization settings as those controls ship.
2.2 Content (your library)
If you save or upload materials, we collect the Content and data associated with it—for example URLs, files, notes, tags, collections, highlights, transcripts, and derivatives we generate for you (summaries, embeddings/search indexes, organizational structures). Content may include personal information depending on what you save.
If you use AI chat or similar interactive features, we also collect interactive inputs (prompts, questions, and related context you submit) needed to return a response to you (“Interactive Chat Information”).
2.3 User Activity Information (collected automatically)
When you use the Services we automatically collect User Activity Information, such as:
- Features and flows you use (for example save, search, chat, import, wiki/organization)
- Approximate access times, pages or screens viewed within the product, and navigation patterns
- How you found our marketing site (referrer, UTM parameters) when available
- Browser or app type, device type, operating system, language, and IP address
- Subscription and billing lifecycle events we receive from our merchant of record (e.g. plan changes, renewals)
- Diagnostic and security signals (errors, rate limits, authentication outcomes)
We use cookies and similar technologies as described in §4. We design product analytics so library item titles and viewing history are not sent to third-party advertising or analytics pixels in a way that would undermine §3.7.
2.4 Information from other sources
- Integrations you authorize (e.g. X, YouTube, Spotify): OAuth tokens, account identifiers, and content retrieved at your direction.
- Payment / merchant of record (Paddle): limited customer and subscription identifiers and status (not full card numbers).
- Optional partners (if we use them later): e.g. lead or affiliate partners, only as permitted by law—we will update this Policy if that becomes material.
2.5 Website analytics (marketing site)
- Landing / marketing pages use analytics (including Google Analytics) only after consent, with reject-as-easy-as-accept; GPC/DNT signals are treated as a decline. (Implemented: consent banner on the landing page.)
- App / library shell: we do not load third-party marketing analytics on item-level library views in a way that would disclose personally identifiable viewing history to those vendors (VPPA-sensitive design goal).
- Details of cookie categories are in §4.
3. How we use your information
We use information about you for the purposes below. Where GDPR/UK GDPR applies, we rely on contract, legitimate interests, consent, or legal obligation as appropriate (counsel will map each purpose before publish).
3.1 To provide the Services (including personalization)
We use Contact, Account, Content, Interactive Chat Information, and User Activity Information to:
- Create and authenticate your account
- Host, index, search, sync, and display your library back to you
- Run AI-assisted features for you (transcription, summaries, embeddings, chat answers)
- Personalize and customize your experience—for example organizational suggestions, “related to your library” views, or default UI preferences derived from how you use InspiMark
Where we offer a personalization profile or non-essential personalized suggestions, we will provide a way to view, edit, or disable that personalization when the feature ships; core storage and search continue to work without it.
3.2 To communicate with you
- Transactional / service messages: verification, password reset, security alerts, billing/subscription notices, and support replies—needed to operate the account.
- Product / relationship messages: tips, feature announcements, and product news we believe relate to your use of InspiMark. You can opt out of these as described in §8.1.
- Promotional messages: offers or promotions (if we send them) only with consent or as otherwise allowed by law (including CASL for Canada). You can unsubscribe.
3.3 To maintain, monitor, and secure the Services
We use Account, Activity, Interactive Chat Information, and limited Content metadata to detect abuse, debug outages, enforce rate limits, investigate fraud or unauthorized access, and protect InspiMark, our users, and others.
3.4 To develop and improve InspiMark (without training on your library)
We use User Activity Information and aggregated diagnostics to understand which features help people build a useful library, improve reliability and UX, prioritize roadmap work, and measure marketing effectiveness (subject to cookie/consent rules).
We do not use your library Content or Interactive Chat Information to train foundation models or other AI models (ours or third parties’), except under a separate, optional program you can opt into if we ever offer one. When AI features call third-party model APIs, content is processed only to return results to you, under our vendor agreements.
3.5 Marketing and growth of InspiMark (not sale of your library)
We may use Contact Information and coarse User Activity Information (for example, whether you completed signup or activated a feature—not the substance of private library items) to:
- Understand funnels and improve onboarding
- Tell you about InspiMark plans, features, or events (with opt-out / consent as required)
- Measure campaigns on the marketing site
We do not sell your library content or build advertising profiles from what you save for third-party ads.
3.6 Legal and compliance
We use information as reasonably necessary to comply with law, legal process, or governmental requests; enforce our Terms and policies; and establish, exercise, or defend legal claims.
3.7 What we do not do with your library
- We do not sell your personal information or your library content.
- We do not use your library content to train AI models (default), as described in §3.4.
- We do not use your content for third-party advertising.
- We do not disclose personally identifiable video viewing history to third parties (including ad/analytics pixels) without required consent. Marketing tags must not leak titles/URLs with user identifiers.
3.8 Organizational / “Wiki” views
Features that organize your library by interest use content you saved to help you navigate it. They are not used to sell profiles or serve third-party ads. You can delete content or request account deletion to remove underlying data.
3.9 Deidentified and aggregated information
If we create deidentified or aggregated information that cannot reasonably be used to identify you, we may retain and use it for analytics, research, security, fraud prevention, and product improvement for any lawful purpose. We will not attempt to re-identify such data except as permitted by law (for example to test our deidentification).
4. Cookies and similar technologies
We and certain service providers use cookies, pixels, local storage, and similar technologies.
| Category | Purpose | Typical requirement |
|---|---|---|
| Necessary | Login/session, security, load balancing, essential preferences | Required for the Services |
| Functionality | Remember choices (e.g. UI prefs, cookie banner choice) | Often necessary or low-risk |
| Analytics | Understand traffic and product usage (marketing site and, if enabled, coarse product analytics) | Consent where required (EU/UK/ePrivacy) |
| Targeting / advertising | Interest-based ads for our products (if we enable them) | Consent / opt-out as required; off by default until configured |
You can withdraw or change cookie consent via Cookie preferences on the marketing site and browser settings. Disabling some cookies may limit features.
We honor Global Privacy Control (GPC) and similar universal opt-out signals as an opt-out of sale/sharing and targeted advertising where applicable law requires it — this is a legal obligation in several US states, not a voluntary commitment. (Today the marketing site treats GPC/DNT as an analytics decline; app-side opt-out plumbing is an engineering dependency before publish.)
5. How we share your information
We do not sell your personal information. (Under laws like the CCPA, "sale" includes exchanges for non-monetary consideration — our commitment covers those too.)
We may share information as follows:
- Service providers (processors). Hosting and storage (e.g. Amazon Web Services), transactional email (e.g. Amazon SES), AI/transcription APIs you invoke through the product, security and infrastructure vendors, and product or marketing analytics providers under written contracts that limit use to our instructions.
- Paddle, as merchant of record for paid plans. Paddle is the seller of the subscription and processes payment and tax data under its own terms and privacy notice—not as our subprocessor. We receive subscription status and limited identifiers back from Paddle.
- At your direction. Exports you download; OAuth integrations you connect; share links you create — a shared item or collection is viewable by anyone holding the link, without an InspiMark account, until it expires or you revoke it (see TOS §4.5); AI-agent access you enable — if you create a personal access token for the InspiMark MCP server, the external AI tool you give it to can read and add to your library on your behalf until you revoke the token; and any future collaboration features you explicitly use.
- Legal and safety. As reasonably necessary to comply with law, enforce agreements, or protect rights, safety, and integrity.
- Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality and this Policy’s principles.
- With your consent. Where you ask us to share or otherwise consent.
A living subprocessor / vendor list will be published at launch or provided on request to privacy@inspimark.com.
6. Storage, security, and international transfers
We are based in the United States and generally process information on infrastructure in the US (and other regions we configure with our providers).
If you use InspiMark from the EEA/UK or Canada, your information may be transferred to the US. Before marketing those regions we will implement appropriate transfer mechanisms (e.g. Data Privacy Framework certification and/or Standard Contractual Clauses, and Quebec Law 25 assessments where required).
We use commercially reasonable safeguards (HTTPS, hashed passwords, access controls, optional encryption of certain secrets at rest). No method is 100% secure. Protect your password and devices. Report concerns to support@inspimark.com (or privacy@inspimark.com for privacy-related security issues).
7. Retention
| Data | Retention |
|---|---|
| Account & library (live systems) | Until you delete items or we complete account deletion |
| Soft-deleted library items | Until permanently removed from trash / purge |
| Account deletion (database and associated object-storage files we control) | Within 30 days of a verified deletion request (see Terms §4.6) |
| Embeddings / indexes / transcripts | Removed with associated content/account purge where implemented |
| Operational DB snapshots / backups | Residual copies may remain up to 90 days (or until snapshot expiry), then age out—config must enforce this before publish |
| Security / operator audit logs (not library body) | As needed for security and compliance |
| User Activity logs | Only as long as reasonably needed for the purposes in §3 (shorter windows for raw logs where practical) |
| Paddle billing records | Held by Paddle per its policies and tax/legal needs |
| Deidentified / aggregated data | May be retained as described in §3.9 |
| Marketing consents | Until withdrawn |
8. Your choices: communications, access, deletion
8.1 Opt out of non-transactional communications
Use unsubscribe links in marketing or product-news emails, or email support@inspimark.com. We may still send transactional messages (security, billing, verification, password reset, essential service notices).
8.2 Change your information
Update profile/settings in-product when available, or email support@inspimark.com.
8.3 Export
While signed in, use in-product export tools (including JSON library export). For help or formats not yet automated, email support@inspimark.com—we aim to complete manual export help within 45 days.
8.4 Delete
Delete individual items in-product. Request account deletion by emailing privacy@inspimark.com from your account email (self-serve delete may ship later). We complete primary purge within 30 days of verification as described in the Terms. Some information may remain in backups for up to 90 days, or where law requires retention. Deidentified data may remain under §3.9.
8.5 Personalization and cookies
Disable non-essential personalization when the control is available. Manage cookies via the marketing-site preference UI and browser settings.
9. Payment processing
Paid plans are sold through Paddle as merchant of record. Card and tax details are collected by Paddle, not stored as full PANs on InspiMark servers. See Paddle’s checkout buyer terms and privacy notice, and our Terms §3.
10. Rights of US residents (CCPA and similar state laws)
If you are a resident of California, Colorado, or another US state with a comprehensive consumer privacy law, you may have rights to:
- Know / access categories and specific pieces of personal information we collected
- Delete personal information (subject to exceptions)
- Correct inaccurate personal information
- Opt out of “sale” or “sharing” for cross-context behavioral advertising (we do not sell; if our practices ever constitute “sharing,” we will provide opt-out including GPC where required)
- Limit use of sensitive personal information where applicable
- Appeal a denied request
- Non-discrimination for exercising rights
Categories we may collect (see §§2–3): identifiers (e.g. email, IP); customer records information; commercial information (subscription status); internet/network activity (User Activity Information); approximate geolocation derived from IP; audio/visual or document content you upload; inferences used only to personalize your library experience; account credentials (password is stored hashed).
Sources: you; your devices; integrations you connect; Paddle; service providers. Purposes: §3. Disclosure: service providers and parties in §5—not sold (for monetary or other valuable consideration).
Submit requests to privacy@inspimark.com. We will verify identity as reasonably necessary. Authorized agents may be required to provide proof of authority.
Working assumption at launch: CCPA “business” thresholds may not be met; we still aim for this structure. Re-test annually or at funding/growth events (see OPEN-QUESTIONS).
11. Rights of EEA and UK residents
If GDPR/UK GDPR applies, you may have rights to access, portability, rectification, erasure, restriction, objection, and withdrawal of consent (where processing is consent-based), and to lodge a complaint with a supervisory authority (or the UK ICO).
We will respond without undue delay and within one month (extendable as permitted). Contact privacy@inspimark.com. EU/UK representative: to be appointed before those markets are actively marketed; this notice will be updated with their contact details.
Lawful bases will be documented in our records of processing before launch (contract for core library; consent for non-essential cookies/marketing where required; legitimate interests for security and some product analytics, balanced against your rights).
12. AI-specific transparency
When you use AI chat or similar features, you interact with an AI system. Inputs may be sent to model-provider processors under contract to generate a response for you. Outputs can be wrong—verify important facts. See §3.4 regarding no training on your library by default.
13. Children
InspiMark is for users 16 and older. We do not knowingly collect personal information from anyone under 16. Contact us to delete if you believe we have.
14. Law enforcement
We review legal process carefully. Where permitted, we notify users of requests for their library content unless legally prohibited. Counsel will finalize our law-enforcement guidelines.
15. Changes
We may update this Privacy Notice. We will post the revised version with a new “Last modified” / effective date. For material changes we will provide a more prominent notice (in-app and/or email) as appropriate. If you disagree, stop using the Services and request deletion.
16. Contact
All privacy and DSR requests: privacy@inspimark.com Support: support@inspimark.com · Copyright / DMCA: copyright@inspimark.com · Legal: legal@inspimark.com Mail: HWGA LLC, Attn: Nicholas Losciuto, 7483 Teasdale Ave, Saint Louis, MO 63130
EU/UK representative / Quebec privacy officer: to be appointed before those market launches.