# Privacy Policy

**Last updated:** August 6, 2026

This Privacy Policy describes how Insula Labs (“we,” “us,” or “our”) collects, uses, stores, and deletes information when you use our website, accounts, and the applications and related services we operate (together, the “Services”).

We design the Services to keep your data private, secure, and honestly managed. As we add apps and change how features work, we may update this policy. Our goal stays the same: protect your information and not misuse it.

## 1. Who this covers

This policy applies to:

- Our website and account systems
- Our applications and any cloud features that sync or store settings and related data for those apps
- Authentication and device features that let you sign in and use the Services across your devices

We may expand the Services over time. This policy covers those offerings as we add them, unless a specific product publishes its own notice.

## 2. Information we collect

### Account and identity

When you create or use an account, we may store:

- Email address and name
- Authentication information (for example, a hashed password, or links to third-party sign-in providers you choose to connect)
- Basic account status needed to operate the account (such as whether the account is active)

### Service and device information

To run authentication, sessions, and app connectivity, we may store:

- Device registrations associated with your account
- Session and authentication tokens as needed to keep you signed in and secure
- Limited technical information required to operate and protect the Services

### App settings and secrets

You may choose to store with us settings and secret information used by our apps. That can include:

- Application settings and preferences
- Provider credentials such as LLM or other API keys
- Related secrets you supply so our apps can act on your behalf with third-party services

This app data is **encrypted** and **isolated per user**. It is stored so it can be used by the apps we provide for you—not shared with other users.

### Data that may stay on your devices

Some information may remain only on your devices (for example, local project files, local settings copies, or other on-device state) and is not uploaded to us unless you use sync, backup, or similar features that send that data to our Services.

## 3. How we use information

We use the information described above to:

- Provide, maintain, and improve the Services
- Authenticate you and manage your account and devices
- Sync and restore your settings and related app data across your devices when you enable those features
- Protect the security and integrity of the Services, including preventing abuse and unauthorized access
- Comply with law where required

We do **not** sell your personal information.

We do **not** use your provider API keys or other secrets you store as our own credentials, and we do not inspect them for unrelated product, marketing, or training purposes. Those secrets exist so *your* apps can use *your* providers under *your* accounts.

## 4. How we protect information

We take practical steps to protect your data, including:

- Encrypting sensitive cloud-stored settings and secrets at rest
- Isolating each user’s app data from other users
- Limiting access to what is needed to operate and secure the Services

No method of storage or transmission is perfectly secure. We work to keep systems private and secure, and we treat your secrets as confidential material for running your account—not as content for us to browse or reuse.

## 5. Sharing

We do not sell your personal information.

We may share information only:

- With infrastructure providers that help us run the Services (for hosting, storage, delivery, and similar operations), under obligations consistent with this policy
- When you direct us to (for example, connecting a third-party sign-in provider)
- If required by law, legal process, or to protect the rights, safety, or security of Insula Labs, our users, or the public
- In connection with a merger, acquisition, or similar transaction, subject to appropriate protections

Third-party providers you connect with your own API keys (such as LLM providers) process requests under *their* terms and policies when your apps call them using your credentials. That usage is between you and those providers.

## 6. Retention and deletion

While your account and data exist, we keep what is needed to provide the Services.

When you delete your data or delete your account through the Services:

- We delete your cloud-held data for that account **immediately**
- There is **no retention period**
- We do **not** keep copies to review, restore, or use later

Deletion is intended to be complete and final for data we store on your behalf in the Services.

Copies of data that remain on devices you still control (local files, local caches, or app data on those machines) are not automatically removed by our cloud deletion. You may remove those locally if you wish.

## 7. Your choices

Depending on the features available in the Services, you may be able to:

- View and update account and settings information in-product
- Enable or disable sync or backup of settings and secrets
- Manage connected sign-in providers and devices
- Delete your data or account, which permanently and immediately removes your cloud-stored data as described above

## 8. Children

The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact us and we will take appropriate steps to delete it.

## 9. Changes to this policy

We may update this Privacy Policy as we expand apps and services or change how data is managed. When we do, we will post the updated policy here and revise the “Last updated” date.

Material changes take effect when posted, or on a later date we specify. Continued use of the Services after an update means you accept the revised policy.

Our intent remains to handle data privately, securely, and honestly.

## 10. Contact

For privacy questions, contact Insula Labs at bosley@Insulalabs.com.
