Who is responsible
Inked (“we”, “us”) operates inked.top from Shanghai. For personal data processed through the site, Inked is the data controller. Privacy requests go to hello@inked.top. If we appoint a processor or a representative in another region, we will name them here.
This policy is written for a product that is still in early public use. Where a feature described below is not yet live (for example a production magic-link server), we still describe the intended processing so you can decide before you submit an email or a URL.
What we collect
We collect only what we need to run a memo, secure the service, and remember your session if you sign in.
Account data
If you request a magic link: email address, sign-in timestamps, and which reports are tied to that address. We do not store a password.
Research inputs
The URL, product text, or PDF you submit, plus derived company identifiers (domain, product name) needed to assemble the memo.
Usage data
Pages viewed, analyze starts and cancels, export events, approximate region from IP, browser type, and error logs. This is operational, not a marketing dossier.
Communications
Emails you send to hello@inked.top, including any attachments you choose to include in a support thread.
We do not ask for government ID, payment-card PAN, health data, or biometric templates. Do not upload materials that contain those things. If a pitch deck you drop includes personal data of third parties, you are responsible for having a lawful basis to share it with us.
How we use information
We use personal data to:
- Run and return a 360° memo from the inputs you provide.
- Send a magic link and keep you signed in on that device.
- Enforce the two-free-memo limit and prevent abuse (rate limits, fraud).
- Debug failures, measure reliability, and improve section quality.
- Respond to your emails and legal requests.
- Comply with law, or defend a claim, when we have no reasonable alternative.
Legal bases we rely on, where a regime such as the GDPR applies: contract (delivering the memo you asked for), legitimate interests (securing the site, understanding which sections fail), consent (optional cookies, if we ever add non-essential ones), and legal obligation.
We do not sell personal data. We do not use your email to build a third-party advertising profile. We do not train a public generative model on the contents of your uploaded decks in a way that would publish those decks to other customers.
Public research sources
A memo is assembled from public signals: websites, archived pages, pricing, social and developer traces, press, and disclosed funding. Those sources are about companies, not about you. We may cache excerpts long enough to generate and display the report.
If you analyze a company you do not control, you are asking us to read information that is already public. That is the product. It is not a request for us to access private systems, employee emails, or data behind authentication.
Confidence labels
Source tables mark confidence as high, medium, or low so you can discount a number. They are not a warranty that the underlying publisher was correct.
Cookies and local storage
We use strictly necessary cookies or local storage to remember a signed-in session and to prevent replay of a magic link. We may use a first-party analytics cookie to count analyze starts; if we do, it will not be shared with an advertising network.
You can block cookies in the browser. The analyze form still works without an account. Sign-in will not persist if you block the session cookie.
How long we keep it
Research inputs and generated memos tied to an account are kept for 24 months after your last sign-in, then deleted or irreversibly aggregated, unless you ask us to delete sooner. Anonymous, unauthenticated runs may be kept only as server logs for 90 days.
Support emails are kept for 36 months. Security logs that are not tied to a memo are kept for 12 months. We may retain a narrower record if we must meet a legal hold.
Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or export personal data, to object to certain processing, and to withdraw consent. You may also complain to a supervisory authority.
Email hello@inked.top with the subject “Privacy request”. Tell us the email you used and what you want done. We may need to verify that you control that address. We will not charge a fee for a reasonable request. We will not retaliate for exercising a privacy right.
California residents: we do not sell or share personal information as those words are used in the CPRA for cross-context behavioral advertising. You may still request know, delete, and correct.
International transfers
Inked is operated from China and may use processors in other regions. If we transfer personal data out of a jurisdiction that requires safeguards, we will use a recognized mechanism (for example standard contractual clauses) or another lawful basis. By using the service from outside China you understand that your data may be processed where we and our processors operate.
Security
We use TLS in transit, access control on production hosts, and least-privilege credentials for email and logs. No method of transmission is perfectly secure. If we become aware of a breach that is likely to affect your rights, we will notify you and, where required, the relevant authority, without undue delay.
Children
Inked is a professional research tool. It is not directed at anyone under 16. We do not knowingly collect their data. If you believe we have, write to us and we will delete it.
Changes to this policy
We will update the “Last updated” date when we change this policy. Material changes — a new purpose, a new category of personal data, or a new class of recipient — will be announced on this page and, if we have your email, sent to that address.
Need a copy of your data, or a deletion?
Write hello@inked.top with the address you used to sign in. We treat that as a formal privacy request.
Email hello@inked.top