inzpyre inzpyre
  • How it works
  • Features
  • Story
  • Pricing
  • Waitlist
DE EN
Legal

Privacy Policy

Last updated: May 2026 · Scope: inzpyre app landing & inzpyre iOS app

The following notes give an overview of what happens to your personal data when you visit this website (the inzpyre app landing) or use the inzpyre iOS app. For inzpyre.me umbrella pages (blog, AI Disruption Score etc.) please see the privacy policy on inzpyre.me.

§ 01Controller

The controller for the data processing on this website is the operator of inzpyre.me. Name and contact details are in the Imprint (on inzpyre.me).

For any privacy-related request, an informal email to the contact address given there is sufficient.

§ 02Waitlist / Newsletter

To join our waitlist (= the inzpyre.me newsletter list) we need your email address. No other data is collected. You confirm your signup via double opt-in through a confirmation link sent after signup.

Purpose
Sending product updates (app launch, new features) and relevant content from the inzpyre.me ecosystem.
Legal basis
Art. 6(1)(a) GDPR (consent).
Retention
Until you revoke your consent. Unconfirmed signups are deleted after 30 days.
Revocation
At any time via the unsubscribe link in any email or informally via message to the controller. Revocation does not affect the lawfulness of processing before the revocation.
Processor
Supabase Inc., 970 Toa Payoh North, #07-04, Singapore 318992. Data is stored in the Supabase cloud. A data processing agreement under Art. 28 GDPR is in place.

§ 03Pageview analytics (no cookies, no IP)

For anonymous reach measurement, we record only the following per page view:

  • the path of the page (e.g. /, /en/, /en/privacy.html)
  • optional: the referrer (URL you came from)

Not collected: IP address, user agent, device ID, user ID or any other identifying data. No cookies are set. Re-identification is technically not possible.

Purpose
Rough reach analysis — to see which content is being used.
Legal basis
Art. 6(1)(f) GDPR (legitimate interest in anonymous reach analysis).
Retention
Maximum 12 months.
Processor
Supabase Inc. (see above).
Objection
You can disable JavaScript on this domain — no tracking request will be sent.

§ 04Google Fonts

For consistent typography we load the fonts Instrument Serif, Plus Jakarta Sans and JetBrains Mono from Google servers (fonts.googleapis.com, fonts.gstatic.com). Your IP address is transmitted to Google in the process.

Provider
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, USA).
Legal basis
Art. 6(1)(f) GDPR (legitimate interest in consistent typography and fast delivery).
US transfer
Google LLC is certified under the EU-US Data Privacy Framework (DPF). An adequacy decision by the EU Commission is in place.

If you prefer no data transfer to Google, you can block external fonts in your browser (e.g. with uBlock Origin or Privacy Badger). The page remains readable — a system font will be used as a fallback.

§ 05Hosting (Netlify)

This website is hosted by Netlify (Netlify Inc., 512 2nd Street, San Francisco, CA, USA). When you visit, Netlify technically processes server log data (IP address, user agent, timestamp, requested URL). Netlify typically deletes this data after 30 days.

Legal basis
Art. 6(1)(f) GDPR (legitimate interest in technically smooth and secure delivery of the website).
US transfer
Netlify Inc. is certified under the EU-US Data Privacy Framework (DPF).

§ 06inzpyre iOS app

If you use the inzpyre app, we process the data described below. The legal basis is your consent (Art. 6(1)(a) GDPR) and contract performance (Art. 6(1)(b) GDPR). Data is hosted on Supabase (EU region); AI processing is performed by Anthropic (Claude) and Voyage AI. We have data processing agreements (Art. 28 GDPR) with all processors; your data is not used to train third-party models.

6.1 · Account & authentication

On first sign-in we store your email address and a randomly generated account ID. Sign-in uses Magic-Link – we do not store any passwords. You may optionally provide a display name. Auth sessions live in the iOS Keychain on your device.

6.2 · Your thoughts, tags and topics

Content you capture (text, voice transcripts, optional images) is stored locally on your device (local-first) and synchronized with our database. Per entry we keep topic tags, creation and update timestamps, and – when available – the embeddings used for semantic search.

6.3 · To-dos and reminders

When you mark a thought as a to-do, we store a status tag (open / done) and – on completion – a done timestamp (done_at). Completed to-dos are automatically deleted after 12 days; before that you can delete them yourself or re-open them. Dates are detected on-device via NSDataDetector – the detection runs offline, with no cloud transfer. On request we schedule local reminder notifications for detected dates.

6.4 · AI features (premium only)

Premium features such as auto-classification, AI search, AI chat and the weekly digest send your query and a limited subset of your own thoughts to Anthropic (Claude API) and Voyage AI (embeddings) for processing. Free users do not send any content to these third parties.

6.5 · Shared groups and inzpyre shorts

If you share thoughts with a group, that content becomes visible to the group's members. You decide per entry whether it stays private or is shared – the default is private. If you subscribe to topics from the inzpyre-team feed, we store the subscribed topics per account; per displayed short we store whether you have seen, liked or saved it, in order to sort the feed sensibly.

6.6 · Push notifications

If you opt into push notifications, the APNs token Apple provides is transferred to our database. We use it solely to notify you about new inzpyre shorts on your subscribed topics, as well as reminders and briefings. Delivery happens via Apple Push Notification service.

6.7 · Face ID / Touch ID

You may optionally enable an app lock via Face ID, Touch ID or device passcode. The authentication happens entirely on your device – Apple does not return any biometric trait to us, only a success/failure signal.

6.8 · In-app purchases (Premium)

Premium is billed via StoreKit (Apple). We only learn from Apple whether a valid subscription is active; payment data stays with Apple. You can cancel any time via iPhone Settings → Apple ID → Subscriptions.

6.9 · Retention & deletion

You can delete your data yourself at any time. In your profile you'll find „Delete account and data" – this irreversibly removes all your thoughts, tags, subscriptions, tokens and account metadata. Completed to-dos are removed automatically after 12 days as described above.

§ 07Your rights

You have the following rights vis-à-vis us at any time:

  • Right of access to your stored data (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object to processing based on legitimate interest (Art. 21 GDPR)
  • Right to revoke consent with effect for the future (Art. 7(3) GDPR)

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). In Bavaria, the competent authority is: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany.

For requests regarding your rights, please contact the address given in the Imprint.

§ 08Changes to this policy

We update this privacy policy when new features, service providers or legal requirements make that necessary. The current version is always available here. The "Last updated" note at the top shows the date of the last change.

inzpyre inzpyre

System of Records. For thoughts.

Product

  • How it works
  • Features
  • Story
  • Pricing

Contact

  • Waitlist
  • Instagram
  • LinkedIn

Company

  • About
  • Imprint
  • Privacy
© 2026 inzpyre – System of Records. For thoughts.