Privacy Policy
This Privacy Policy explains how personal data is collected, used, and protected when you visit innesta.app, download or update the Innesta application, start a trial, purchase or activate a licence, or use the application itself. It is written to comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the Spanish Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (“LOPDGDD”), and equivalent laws applicable to international users.
1. Data controller
The data controller is the trader identified in our Legal Notice, which is the only page carrying that identity. For brevity, “we”, “us”, and “Innesta” refer to that controller. Privacy requests go to support@innesta.app, the same mailbox that handles support and security.
Representative and Data Protection Officer. The controller is established in Spain, inside the European Union, so no representative under Article 27 GDPR is required. No Data Protection Officer has been appointed: our processing is not carried out by a public authority, does not consist of regular and systematic monitoring of data subjects on a large scale, and does not involve large-scale processing of special categories of data, so none of the cases in Article 37(1) GDPR applies.
2. Scope
This policy covers five distinct contexts:
- The website at
innesta.app, including its marketing pages and any sub-pages. - The download and update stack, which serves the application, its release notes, and the Sparkle update feed.
- The no-card trial and licence flow, handled by Innesta’s licensing service, together with the Apple DeviceCheck call that decides trial eligibility.
- The purchase flow, handled by the seller identified in our Legal Notice, whose checkout opens as an overlay on our own pricing page.
- The Innesta application itself, when installed on your Mac — including the components shipped inside the app bundle: the
innestacommand-line helper, the Quick Look extension, the Spotlight extension, App Intents/Shortcuts, the Focus Filter, theinnesta-askpasshelper, and the Sparkle updater.
3. Privacy by design
Innesta is local-first: repositories, working copies, diffs, logs, branches, commits, and the local commit index are handled on your Mac by the git binary already installed on your system. Licensing requests never include source code, diffs, file contents, commit messages, repository names, or remote URLs.
The application contains no product analytics, no advertising SDKs, no marketing trackers, and no automatic crash-report uploads. It reaches the network only for the specific functions described below: licensing, trial eligibility, updates, the Git remotes and providers you configure, and — if you explicitly enable them — external AI command-line tools.
4. The website
4.1 Advertising measurement and analytics
The Website uses no general product analytics. It uses the OpenAI Ads Measurement Pixel to tell whether a visit attributed to a ChatGPT ad leads to a checkout or completed purchase. The Pixel is optional: its remote SDK is not downloaded, and the browser makes no request to OpenAI for this purpose, until you select Accept in the cookie banner. Rejecting it does not restrict the site, download, trial, or checkout.
After consent, the SDK captures the opaque oppref value when it is present in the landing URL and keeps it in the first-party __oppref cookie. It also creates a random identifier for your browser. The integration sends the plan, quantity, currency, and amount for checkout_started, and sends order_created only after Paddle reports that checkout completed successfully. The completed event uses the Paddle transaction identifier as a deduplication key, so the same conversion can later be sent reliably from the server without being counted twice. Each event is excluded from future user-level personalisation.
Innesta’s event calls do not provide the Pixel’s optional user object. OpenAI also offers account-level automatic advanced matching which, if enabled, may detect supported customer information on a page and send a browser-side hash even without that object. Our deployment policy requires that feature to remain disabled unless the processing is separately reviewed and this notice is updated. The SDK still receives the technical data inherent in a browser request, the address of the page and of the page you came from (without query strings), the event timestamp, and may send its own lifecycle or diagnostic records. OpenAI supplies the script and its per-Pixel configuration and can change them at any time. The storage used by version 0.1.41, its purposes, durations and controls are listed in the Cookie and Storage Policy.
- Legal basis: your consent (Article 6(1)(a) GDPR and Article 22.2 LSSI).
- Withdrawal: use the settings button next to Cookies in the footer. Withdrawal stops future measurement and deletes the OpenAI entries listed in the Cookie and Storage Policy; it does not affect processing performed while consent was valid.
Paddle’s checkout script brings analytics of its own. Initialising it also loads Paddle Retain, Paddle’s retention and payment-recovery product, which runs for Paddle’s purposes and reports to Paddle. We receive nothing from it and cannot read what it collects. Section 4.5 says when it loads and Section 8 sets out the roles.
4.2 Hosting and security logs
The Website is served through Cloudflare (Cloudflare, Inc.), which processes connection metadata — including IP address, request headers, URL and path, and timestamps — to deliver, cache, and secure the site.
- Legal basis: legitimate interest (Article 6(1)(f) GDPR) in operating and securing the service.
- Retention: log retention follows Cloudflare’s configuration for our plan; we do not maintain a separate copy of website access logs. See Section 13.4.
- Cloudflare’s privacy notice: https://www.cloudflare.com/privacypolicy/
4.3 Cookies and browser storage
The Website keeps your theme and your cookie-banner choice in your browser, and Cloudflare sets a bot-mitigation cookie. With your consent, the OpenAI Pixel described in 4.1 stores its own entries; Paddle’s checkout stores nothing under our domain. Each entry, its purpose, its duration and how to withdraw consent are listed in the Cookie and Storage Policy.
4.4 Writing to us
If you email support@innesta.app, we process your address and the contents of your message in order to answer. That mailbox is not hosted by us: Cloudflare Email Routing receives the message at our domain and forwards it to the operator’s own mailbox, so Cloudflare processes it in transit.
- Legal basis: performance of pre-contractual measures or our legitimate interest in handling correspondence (Article 6(1)(b) or (f) GDPR).
- Retention: for as long as necessary to handle your request, typically up to 24 months.
4.5 The checkout on the pricing page
The pricing page ships an ordinary trial-download link and a small script of ours. Paddle’s third-party checkout code does not load on arrival.
When you press a buy action — or arrive on a link that already carries a Paddle transaction reference, _ptxn — that script loads Paddle.js from cdn.paddle.com, which adds a Paddle stylesheet to the page, and opens Paddle’s checkout as an overlay. From that moment your browser is in contact with Paddle, which receives your IP address, the page you are on, and whatever you enter in the checkout itself (Section 8). Initialising Paddle.js also loads Paddle Retain from public.profitwell.com, as described in 4.1.
Between opening the checkout and paying, your browser makes one request to Innesta’s licensing service. It carries the Paddle transaction identifier and a random value generated in your browser for that attempt, and nothing else: no name, no email address, no payment data. We use it to fix the plan, price, and quantity of the transaction with Paddle before you pay, so that what you are charged is what the page offered. Cloudflare processes that request’s connection metadata as it does any other, and the endpoint is rate-limited by IP address against abuse. Nothing from this request is written to our database.
- Legal basis: performance of pre-contractual measures taken at your request (Article 6(1)(b) GDPR) for the checkout and the price lock; legitimate interest in protecting that endpoint from abuse (Article 6(1)(f) GDPR) for the rate limit.
- Retention: nothing of our own beyond Cloudflare’s request logs — see 13.4.
If any step fails, no purchase is inferred: the trial download stays available and the action can be retried. With JavaScript disabled the page offers the trial download only.
5. Downloading and updating the application
The application, its release notes, and the Sparkle update feed are published to Cloudflare R2 storage and served over HTTPS from updates.innesta.app. The production R2 bucket is created in Cloudflare’s European Union jurisdiction, so the public artifacts themselves are stored in the EU.
When you download the app, or when Sparkle checks for an update, Cloudflare may process your IP address, the requested URL and path, request headers, timestamp, and routing/cache metadata, as it does for any HTTPS request. Update checks contain no licence key, no device identifier, and no repository data, and Sparkle sends no system profile: it fetches the feed and verifies the EdDSA signature of what it downloads.
The release index published alongside the downloads is static HTML: it contains no scripts, cookies, web fonts, or external resources, and its only links point to the release archives and release notes listed in the update feed.
- Legal basis: performance of the contract and our legitimate interest in distributing signed, verifiable releases (Article 6(1)(b) and (f) GDPR).
6. Trial and licence activation
When you start the trial, when the application checks whether a running trial has been revoked, when you activate, refresh, replace the key of, or deactivate a licence, or when you redeem an invitation code, the application sends a limited request to Innesta’s licensing service, which runs on Cloudflare Workers with a Cloudflare D1 database.
6.1 How your Mac is identified
Innesta does not read, transmit, or store the name of your Mac, its serial number, or any hardware identifier.
On first use the application generates a random identifier and keeps it in the macOS Keychain, marked as usable only on that Mac. That value itself is never transmitted. What the application sends is a one-way digest derived from it, the installation identifier. It identifies an installation rather than a person, but it is pseudonymous, not anonymous: it remains personal data under the GDPR.
The licensing service never stores the installation identifier as it receives it. Before storage it replaces it with a keyed hash, computed with a secret held only by the service and derived separately for each licence and, again separately, for trials. As a result, the stored data cannot be used to recognise the same Mac across two different licences, or to match a trial against a purchase.
Deleting the Keychain item makes the installation a different one for licensing purposes and invalidates the licence token installed on that Mac. It does not restore trial eligibility — see 6.3.
6.2 What the licensing service receives, and what it keeps
Depending on the operation, a request may carry: the installation identifier; the application version and the major version of macOS; on activation, the publication date embedded in the build you are running, used only to check that the release falls inside your updates window; a licence key, a signed licence token, an invitation code, or an email address; for a new trial, one short-lived Apple DeviceCheck token; for an assisted reset, the one-time code issued by support.
What is kept in the database is narrower:
- the keyed hashes described in 6.1, and per device slot the application version, the macOS major version, and the activation and last-contact dates;
- for a licence: an internal identifier, its kind, plan and status, the device limit, the updates window, its origin, the licence contact address, the associated payment references, and the issue and revocation dates with the revocation reason;
- for a trial: its start and end dates with the same minimal technical metadata.
The following are not kept: the Keychain identifier, the installation identifier as transmitted, the build publication date, the signed licence token, and the device binding it contains. Licence keys and invitation codes are stored only as a hash, their last six characters, and a version number. Our administrative tools show a device slot as occupancy plus those technical fields; the stored hashes are never displayed.
The licensing service does not receive repository names, paths, remote URLs, branch names, commit hashes, commit messages, diffs, source files, Git or provider credentials, or AI prompts.
Signed licence tokens. Activation returns a token signed with our licensing key. It carries the licence or trial it belongs to, the kind and plan, a value derived from the installation identifier, whether the right is perpetual, the issue and expiry times, the updates cutoff, and a key version — never your name, email, or any repository data. It is stored in your Keychain. The token is how the application verifies your right offline between checks; the rules governing it are in the Terms.
- Legal basis: performance of pre-contractual measures for the trial and performance of a contract for licence operations (Article 6(1)(b) GDPR), together with legitimate interest in preventing licence abuse and securing the service (Article 6(1)(f) GDPR).
- Storage location: the licensing service runs on Cloudflare Workers with a Cloudflare D1 database. We do not pin it to a specific region, so licensing records may be processed anywhere on Cloudflare’s network under the transfer safeguards in Section 12. Update artifacts are the exception and are stored in the EU — see Section 5.
6.3 Trial eligibility and Apple DeviceCheck
A trial cannot be granted on the strength of an installation identifier alone: a new trial requires Apple DeviceCheck.
DeviceCheck is an Apple service that stores two bits of information per device on Apple’s servers, readable and writable only with our Apple developer key. Innesta uses them to record whether that Mac has already had a trial. When you start one, the application generates a single short-lived DeviceCheck token and the licensing service uses that same token to read and then update the two bits with Apple. The token exists only in memory on both sides; it is neither stored nor logged.
Two consequences matter to you:
- The bits are held by Apple, not on your Mac, so deleting Innesta’s local data, or reinstalling the application or macOS, does not remove them. They are outside our storage and outside your device’s control.
- Apple also records the month in which those bits were last written. That month is what we read to decide whether a further trial cycle may begin. An answer Apple cannot give unambiguously is treated as not granting the trial.
Apple processes a DeviceCheck call under its own terms and as a separate controller. Apple documents no retention period for the two bits, and the only information they hold is the eligibility state plus Apple’s own month-level update time. The eligibility rule itself, as a contractual matter, is in the trial terms.
6.4 Assisted reset after a change of owner
If a Mac legitimately changes hands, support can clear that Mac’s trial record. When we do that, and on what conditions, is set out in the trial terms; this section covers only what the operation processes.
We generate a one-time code, display it once, and store it only as a hash — never in clear. Redeeming it requires that code, your installation identifier, and one fresh DeviceCheck token. The operation writes the two Apple bits back to their unused state and deletes the trial record for that installation. The code and the token stay in memory on both sides and are not logged, and the stored hash is deleted together with the grant when it expires (Section 13.2).
6.5 Abuse prevention
Trial starts that carry a DeviceCheck token, and every assisted reset, pass through a rate limiter before any database or Apple call. It uses the source IP address of the connection as a temporary counting key, allowing 30 attempts per address per minute in each Cloudflare location. Our application code neither stores nor logs that address; Cloudflare’s own processing of connection data is described in Section 10.
- Legal basis: legitimate interest in preventing abuse of the trial and keeping the service available (Article 6(1)(f) GDPR).
6.6 Whether you have to provide this data
None of the data described in this Section 6 is a statutory requirement, and none of it is provided under consent. The installation identifier, the application version, and the macOS major version are necessary to perform the contract: without them a licence cannot be activated, refreshed, replaced, or deactivated, and licensed features stay unavailable. A DeviceCheck token is necessary to obtain a trial, and a trial cannot be granted without one. An email address is necessary to redeem an invitation, because it becomes the licence contact. Nothing else is required, and anything you add to a support message is voluntary.
7. Licence keys, invitations, and email delivery
Licence keys and invitation codes are generated from 160 bits of cryptographic randomness. Our database never stores them in clear text: it keeps a hash, the last six characters so support can identify a key you quote to us, and a version number. Rotating a key disables the previous version.
To deliver a key or code by email exactly once, the outgoing message is queued with the recipient address, the template, the delivery status and attempt count, and an AES-256-GCM encrypted payload containing the recoverable value — and, for an invitation, the recipient’s name if the operator supplied one. When Cloudflare Email Service accepts the message, the ciphertext and its nonce are deleted.
“Accepted” means accepted and queued by the provider. It is not evidence that the message reached you, and the provider message identifier we keep is an operational correlation reference, not a delivery receipt. A message still pending, retrying, or permanently failed keeps its encrypted payload until the delivery is resolved operationally or the record reaches its retention deadline (Section 13).
Redeeming an invitation creates a licence and returns its key once. The address you supply at redemption becomes the licence contact; the invitation record itself keeps no address of its own.
- Legal basis: performance of the contract (Article 6(1)(b) GDPR).
- Processor: Cloudflare (Workers, D1, and Email Service).
8. Purchasing
The checkout is operated by the seller and Merchant of Record identified in our Legal Notice. That seller, not us, sells the licence to you, collects payment, and charges any applicable tax. Paddle presents its checkout form in an overlay on our pricing page. How that overlay loads, what it brings with it, and the single request it causes your browser to make to us are set out in 4.5.
Paddle collects and processes the data necessary to complete and invoice the sale, including:
- Name and email address;
- Billing address and country;
- Payment instrument details (card number, expiry, and so on) — handled directly by Paddle’s PCI-DSS certified infrastructure; we never see or store full card numbers;
- Tax identification number, if you provide one for a business invoice;
- IP address and device data used for fraud prevention.
Because the checkout now runs on our page, Paddle also receives, from the moment its script loads, the connection and page data any embedded script receives — your IP address and the page you are on — and whatever Paddle Retain collects for its own purposes. That collection is Paddle’s, for Paddle’s purposes, and its content does not reach us.
Paddle and Innesta act as independent controllers for the personal data shared between them for the sale and licence fulfilment, under the Paddle Master Services Agreement and its Data Sharing Addendum.
Some of the data we hold about you therefore does not come from you: your email address and the commercial identifiers below reach us from Paddle, as the source, after you complete a purchase.
For fulfilment, Paddle sends us signed webhooks. We verify the signature against the raw body before parsing and then store only a normalized projection: the event, customer, transaction, and adjustment identifiers; the purchaser email address; the price identifier, quantity, plan, status, and event type; and the relevant timestamps. The original Paddle payload and the financial amounts are not stored, and we never receive card numbers, expiry dates, or the last four digits. Whether a purchase revokes a licence is governed by the Terms.
- Legal basis: performance of a contract (Article 6(1)(b) GDPR), compliance with tax and accounting obligations (Article 6(1)(c) GDPR), and legitimate interest in fraud prevention (Article 6(1)(f) GDPR).
- Retention: Paddle applies its own retention policy to the data it holds. Our copy follows the schedule in Section 13.
- Paddle’s privacy notice: https://www.paddle.com/legal/privacy
9. The Innesta application
No account is required to use Innesta. Repositories, file contents, diffs, and commit history are processed entirely on your device, and the application never uploads them to us.
9.1 Local storage on your Mac
UserDefaults holds preferences and non-secret state: recent repositories and their paths, security-scoped bookmarks, AI configuration, GitLab OAuth overrides, manual provider overrides for remotes on custom domains, the Spotlight preference, the repository path associated with a Focus Filter, and the preferred HTTPS account for each repository/host pair. That last one only selects which credential to use — the secret itself stays in the Keychain.
The macOS Keychain may hold Git HTTPS credentials, provider tokens, SSH passphrases, the licensing identifier described in 6.1, the signed licence token, and — after a confirmed trial revocation — a local marker recording it. That marker is never transmitted, does not expire with your Mac’s clock, and is not cleared by deleting the token; only a confirmed assisted reset (6.4) removes it.
The full-text commit index is a local cache inside your repository’s .git/innesta directory and can be deleted at any time.
9.2 macOS integrations
- Spotlight. When a repository snapshot is loaded, Innesta indexes locally, through CoreSpotlight: the repository name, the names and kinds of its local and remote branches, and up to the 80 most recent commits with their subject, full and abbreviated hash, author, and date. The identifiers handed to Spotlight are opaque random tokens: they contain no path, branch name, or commit hash, and the repository path is not written into Spotlight metadata. Innesta keeps the mapping between those tokens and the real path in a private catalogue on your Mac, held in a container shared only between the application and its own bundled Spotlight extension and restricted to your account. Closing a window or returning to the repository picker leaves the index in place; Remove from Projects deletes that repository’s entries. Show projects in Spotlight, on by default in General settings, when switched off stops indexing in progress and deletes every entry Innesta has made; while it stays off, nothing is indexed, results do not open, and a rebuild requested by macOS restores nothing. Switching it back on re-indexes the open repositories; the others are indexed again on their next open. Nothing is sent to us.
- Quick Look. The extension reads locally up to 1 MiB (1,048,576 bytes) of the requested
.diff,.patch, text, or source file and renders an escaped local HTML preview. - The
innestacommand-line helper. It resolves the directory you pass and forwards only that path to the app through a local URL. No path is sent to any service. - Shortcuts, App Intents, and Focus. These use your recent repository paths and can read or return the repository name, current branch, number of changed files, clean/dirty state, ahead/behind counts, and the outcome or error of the action you requested. The Focus Filter saves the selected repository path in
UserDefaults. What macOS and your own Shortcuts workflows then do with those results is governed by Apple and by the workflow you configured.
9.3 Git remotes, OAuth, and provider data
Clone, fetch, pull, push, force push, tag push, ls-remote, and remote Git Flow operations run through the git and ssh binaries configured on your Mac and send the metadata and content required by the protocol to the remote you selected.
Git HTTPS may use GIT_ASKPASS and SSH may use SSH_ASKPASS to supply credentials you have stored. The same helper receives OpenSSH’s prompt for an unknown host key: Innesta declines it, shows you the host, port, key type, and fingerprint, and retries the operation only after you confirm that you have compared that fingerprint against an independent trusted source. The approval covers that single retry, is not persisted, and never becomes a Keychain item; the key itself is recorded by OpenSSH in the known_hosts file your configuration selects, which Innesta never writes or edits. While a command that can prompt for credentials is running, a temporary file readable only by your account records which prompt was seen, the non-secret host, user, and key identifiers it concerned, and whether a stored passphrase or a host-key approval was served; it holds no passphrase, password, or token, and it is deleted when the command ends. Secrets and passphrases are never written into remote URLs, repository config, UserDefaults, process arguments, or logs.
If you connect a provider account:
- OAuth for GitHub and GitLab uses PKCE (S256) in your default browser, with the callback delivered back to the app. The exchange sends the client ID, redirect URI, authorization code, code verifier, and the technical data required by the provider. GitHub.com additionally requires the OAuth App secret, which is present in the distributed bundle and therefore extractable; it is not treated as strong client authentication, and the flow relies on
stateand PKCE. GitLab uses no client secret and stores a rotating refresh token. - Tokens are stored in the macOS Keychain and used read-only: to list pull requests and merge requests, and — when you open that section — pipelines, workflow runs, stages, jobs, authors, and execution times. For the job you open, Innesta also fetches its log over HTTPS; the log is capped at 8 MiB and held only in the memory of the running application. While the Pipelines section and window are active, the list refreshes every 10 seconds as long as runs are still going, then falls back to a 60-second check; refreshing stops when the section or window is no longer active, errors back off, and a rate-limit deadline announced by the provider suspends even manual attempts until it passes. Innesta performs no CI/CD mutations: it cannot retry, cancel, or trigger anything on your provider.
- Bitbucket and Azure DevOps are supported for provider links only, with no API access.
- GitHub tokens are validated with a single
GET /usercall before being stored. Client secrets, code verifiers, authorization codes, access tokens, and refresh tokens are never written to Innesta’s logs.
Each provider processes this data as its own controller, under its own terms and privacy policy.
9.4 AI commit messages
Commit-message generation is optional and its provider is chosen by you:
- Apple Foundation Models run entirely on-device, when Apple Intelligence is available on your Mac. Nothing leaves the machine.
- Claude Code CLI and Codex CLI are external tools already installed and authenticated on your Mac. They are used only after explicit consent, and the request may include the current branch, recent commit subjects, and the staged diff. Those tools and the provider behind them apply their own terms, logging, and retention — you must have the right to share that content with them.
Innesta launches the CLI with a reduced environment: PATH, HOME, USER, LOGNAME, your locale variables, and NO_COLOR=1. Only if you enable the dedicated “pass auth environment variables” setting does it additionally forward the allowlisted authentication variables (ANTHROPIC_API_KEY, ANTHROPIC_AUTH_TOKEN, CLAUDE_CODE_OAUTH_TOKEN, OPENAI_API_KEY, OPENAI_AUTH_TOKEN, OPENAI_ORG_ID, OPENAI_ORGANIZATION, OPENAI_PROJECT). The rest of your environment is not inherited.
Innesta stores no AI API keys and makes no direct HTTPS calls to Anthropic or OpenAI.
- Legal basis: consent for external providers (Article 6(1)(a) GDPR); performance of the requested function for on-device generation.
9.5 Optional diagnostics
Diagnostics are off by default. When you turn the toggle on:
- events stay only in the memory of the running app;
- they are discarded when you turn the toggle off or quit the app;
- they are never uploaded to us or to a third party — the licensing service has no diagnostics upload endpoint at all.
Only five event names are recorded (appOpened, repositoryOpened, gitOperationCompleted, gitOperationFailed, featureUsed), each with a timestamp and only these keys, truncated to 80 characters: operation, feature, success, provider, repo_size, file_count, duration_ms, error_kind.
Repository names and paths, remote URLs, file contents, diffs, commit messages and hashes, credentials, Keychain secrets, OAuth tokens, and email addresses are never recorded. Persistent diagnostic storage, MetricKit collection, and manual export are not implemented in the version described by this policy.
If a future version introduces any feature that transmits data, it will be off by default, clearly disclosed in the application, and reflected in an updated version of this policy before the feature ships.
10. Service operations, administration, and logs
Our administrative dashboard is protected by Cloudflare Access; every request validates the access token’s issuer, signing keys, audience, and expiry, and accepts only a human identity from our identity provider. Administrative changes additionally require an operator reason and write an append-only audit entry in the same database transaction, recording the operator’s identifier, the action, the affected record, the reason, a request ID, and the timestamp. The operator’s email address is checked at sign-in but is not written to the entry, and the reason field rejects anything shaped like an email address, so a customer’s address cannot enter the audit log in clear. The dashboard never displays licence keys or invitation codes that have already been issued.
Cloudflare Workers may process IP address, request headers, request ID, URL and path, timestamps, and the technical data needed for security, routing, caching, logging, and tracing. Our application logs record structured errors without request bodies, licence keys, Keychain identifiers, installation identifiers, stored hashes, DeviceCheck tokens, email content, or raw payment payloads. The daily maintenance job logs aggregate counts only.
- Legal basis: legitimate interest in security, support, auditability, and service reliability, and compliance with accountability obligations (Article 6(1)(f) and (c) GDPR).
11. Recipients and roles
| Recipient | Role | What it processes |
|---|---|---|
| Cloudflare, Inc. | Processor (Workers, D1, Email Service, Email Routing, R2, Access, CDN) — plus the limited controller processing described in its own privacy policy | Licensing records, encrypted email payloads, inbound support mail, audit entries, request and update logs, website delivery |
| Paddle.com Market Ltd | Independent controller | Checkout, payment, invoicing, tax, fraud prevention, refunds; and, through the Paddle.js and Paddle Retain scripts its checkout loads onto our pricing page, the connection and page data your browser sends them (4.5) |
| OpenAI Ireland Limited, with OpenAI affiliates and subprocessors | Recipient for optional advertising measurement; OpenAI is a processor for Restricted Processing and otherwise an independent controller under its Conversion Terms and Ad Tools DPA | The ad attribution reference, the random browser identifier, the page and referring-page addresses, conversion event and metadata, timestamp, and request connection data described in 4.1 — only after consent |
| Apple Inc. — DeviceCheck | Separate controller for its own service | Two per-device bits and their month-level update time, written and read to decide trial eligibility (6.3) |
| Apple Inc. — system services | Controller for its own system services | Spotlight, Shortcuts, Focus, Quick Look, on-device model execution (all local to your Mac) |
| GitHub, GitLab, and any other Git host or remote you configure | Independent controllers | OAuth, repository operations, PR/MR, pipeline and job-log reads |
| Anthropic (Claude Code CLI) and OpenAI (Codex CLI) | Independent controllers, only if you enable them | The commit-message request you consented to send |
12. International data transfers
Some recipients are established outside the European Economic Area:
- Cloudflare, Inc. — United States. Transfers rely on the Standard Contractual Clauses incorporated in the Cloudflare Data Processing Addendum, together with any additional safeguards described there.
- Paddle — United Kingdom and United States. Transfers rely on the safeguards set out in the Paddle Master Services Agreement and its Data Sharing Addendum, including Standard Contractual Clauses where applicable.
- OpenAI group — OpenAI Ireland Limited processes EEA and Swiss data for the advertising tools. It may make onward transfers to affiliates and subprocessors outside the EEA using a valid transfer mechanism, as described in the Ad Tools DPA and subprocessor list.
- Apple Inc. — United States, for the DeviceCheck call described in 6.3, under Apple’s own terms and safeguards.
- Providers you choose yourself (Git hosts, OAuth providers, external AI command-line tools) may process data in their own jurisdictions, under their own legal bases and safeguards.
You can request further information on the transfer safeguards that apply to us by emailing support@innesta.app.
13. Retention, blocking, and deletion
13.1 On your Mac
Repositories, caches, preferences, and Keychain items stay on your Mac until you, the app, or macOS remove them. Spotlight entries are removed as described in 9.2. Diagnostics are never persisted; they are discarded when disabled or when the app quits.
13.2 In the licensing service
Each deadline below is recorded on the record itself at the moment the triggering event happens, and a daily maintenance job enforces it in bounded batches. Deletion means deletion: rows are removed or fields are cleared, not overwritten with placeholders.
| Record | Retention |
|---|---|
| Trial | Deleted 12 calendar months after the trial’s end date, or immediately on a confirmed assisted reset. |
| Device slot | Cleared immediately on deactivation; for a revoked licence, cleared 12 calendar months after revocation. |
| Licence contact address | Usable while the licence is active. After revocation it remains usable for 12 months, is then blocked for that licence, and is deleted five years after revocation. |
| Licence and key records | Kept while we must honour or refuse a perpetual licence; reviewed annually for continued necessity. Keys and codes exist only as a hash, a six-character suffix, and a version. |
| Invitation secret | Hash and suffix are cleared 90 days after the invitation expires or is revoked; minimal redemption provenance remains. |
| Assisted reset code | Held only as a hash, and deleted with the grant once it expires. |
| Processed payment webhook | The payload is cleared in the same operation that marks the event processed; the record kept for duplicate detection is deleted after 90 days. |
| Payment webhook awaiting an operator, or permanently failed | Deleted 90 days after it stopped. |
| Accepted licence email | Ciphertext and nonce erased at once; the recipient, template, provider identifier, and timestamps are deleted after 30 days. |
| Permanently failed licence email | Recipient and ciphertext deleted 90 days after the failure. |
| Payment customer record | The address and its hash are cleared after at most 90 days, kept only so that events arriving out of order can be matched; a record never linked to a licence is deleted at that deadline. The licence contact remains the canonical one. |
| Payment transactions and adjustments | Kept while any linked licence is active; once all are revoked, deleted five years after the last relevant financial event. |
| Administrative audit entry | Immutable, and undeletable by the database until five years have passed. |
A legal hold suspends any deletion that would otherwise fall due for a given person. It always requires a reason and a future expiry date, it cannot be permanent, and applying, renewing, or releasing it is itself audited.
13.3 Blocking is not deletion
Where a legal duty requires us to keep a record, an erasure request does not produce instant deletion. It produces an immediate block: the address is excluded at once from administrative search and detail, from payment fallback, from any outgoing email, from key rotation, and from the creation of any new licence for that contact — and the record is then destroyed at the end of the applicable period. We tell you which of the two you are getting.
13.4 What our deadlines do not reach
Our schedule governs our own records. It does not govern independent provider logs or point-in-time recovery. On the current configuration: Cloudflare Workers logs and traces are kept for no more than 7 days; email analytics for 31 days; Cloudflare’s database point-in-time recovery for up to 30 days, which means a restore can reintroduce records deleted or blocked after the restore point; Cloudflare account audit logs for 18 months; and Cloudflare Access authentication logs for the period of the plan in force. Update artifacts follow the release cycle. OpenAI’s public Ad Tools DPA states that server-side advertising-tool data is retained for the period required or permitted by the applicable agreement, that DPA, or data-protection law; it does not publish a fixed period. You may ask us for the current contractual information through the address in Section 14.
14. Your rights
Under the GDPR and LOPDGDD, you have the right to:
- Access the personal data we hold about you (Article 15).
- Rectify inaccurate or incomplete data (Article 16).
- Erase your data, subject to legal retention obligations (Article 17) — see 13.3.
- Restrict processing in certain circumstances (Article 18).
- Data portability: receive your data in a structured, machine-readable format (Article 20).
- Object to processing based on legitimate interest (Article 21).
- Withdraw consent at any time, without affecting prior lawful processing (Article 7(3)).
- Not be subject to automated decision-making producing legal effects (Article 22) — we perform no such processing.
To exercise any of these rights, write to support@innesta.app.
How a request is handled. We verify your identity through our support procedure first: possession of an email address is not, by itself, sufficient. Access requests are answered from a purpose-built export covering the licence, device-slot, invitation-redemption, payment-projection, and email- and webhook-operation records linked to your address; that export excludes key hashes, device lookups, ciphertext, and every secret by construction. Erasure requests are executed through the blocking and closure operations described in 13.3. Each of those steps is performed in our administrative tools and audited without your address appearing in clear.
Rectification of a licence contact, restriction outside the blocking mechanism, and objection are handled case by case rather than by a dedicated tool. We respond without undue delay and in principle within one month, subject to any extension permitted by Article 12(3) GDPR. Requests about payments and invoices may also need to be addressed to Paddle; requests about a Git provider, an AI tool you configured, or Apple’s DeviceCheck records must be addressed to that provider.
If you believe your data has been processed unlawfully, you have the right to lodge a complaint with the Spanish data protection authority:
- Authority
- Agencia Española de Protección de Datos (AEPD)
- Address
- C/ Jorge Juan, 6, 28001 Madrid, Spain
- Website
- www.aepd.es
You may also complain to the supervisory authority in your country of residence or place of the alleged infringement.
15. Security
Connections to innesta.app, the licensing service, and the update domains use HTTPS/TLS. Licence keys and invitation codes are stored only as hashes; installation identifiers are stored only as the keyed hashes described in 6.1; email payloads containing a recoverable key are encrypted with AES-256-GCM and purged on acceptance. Licence tokens are signed with a key that is separate from the one used to sign application updates, and each environment uses its own keys and database. The checkout is operated and secured by Paddle; card data never reaches our systems. Access to service records is restricted to authorized operators behind Cloudflare Access and is audited.
Personal-data breaches will be assessed and notified to the competent supervisory authority and affected individuals where, and within the time limits, required by applicable law. To report a vulnerability, see our Security Policy.
16. Children
Innesta is a professional developer tool and is not directed at children under 14 (the digital-consent age under Spanish law). We do not knowingly process personal data of children. If you believe a child has provided us with personal data, please contact us so we can delete it.
17. Changes to this policy
We may update this policy to reflect changes in our processing, the law, or our service providers. Material changes will be communicated by updating the “Last updated” date at the top of this page and, where appropriate, by email to customers. Previous versions are available on request.
18. Contact
Privacy requests, like all other correspondence, go to support@innesta.app. Our postal address is published in the Legal Notice.