Privacy Policy
Last updated: March 2026
1. Introduction
Inspiration Index ("we," "us," or "our") is an unincorporated business operating out of Canada. This Privacy Policy explains how we collect, use, share, and protect personal information when you use our website and services (the "Service").
We are subject to Canada's federal privacy legislation (PIPEDA) and, where applicable, the General Data Protection Regulation (GDPR) for users in the European Economic Area. By using the Service, you acknowledge the practices described in this policy.
If you have questions or requests relating to your personal data, contact us at legal@m.inspirationindex.app.
2. Data We Collect
2.1 Account Information
When you create an account, we collect:
Email address — used to identify your account and send transactional communications.
Name (first, last, and display name) — sourced from your Google profile or entered at registration.
Profile avatar — a URL and cached copy of your Google profile picture, or none if you registered with email.
Authentication provider data — if you sign in with Google, we store your Google user ID and the raw OAuth profile response (including name, email, and profile picture URL) returned by Google at the time of login.
Password hash — if you register with email and password, we store a one-way hash of your password. We never store your password in plaintext.
2.2 Search Queries & Usage Data
When you use our AI-powered search, we store:
Your raw search query — the exact text you typed, stored as entered.
Normalized and transformed versions of your query — used for deduplication and to generate AI embeddings.
Search results and metadata — the ranked results returned and execution details including token usage and cost.
Quota usage counters — daily, monthly, and overage search counts tied to your account or device identifier.
Search query logs are accessible to Inspiration Index administrators for debugging and service improvement. Please avoid entering sensitive personal information into the search field.
2.3 Billing Data
For paid subscribers, we store your Lemon Squeezy subscription ID, plan variant, billing status, and renewal dates. We do not store payment card details — these are handled entirely by Lemon Squeezy as our merchant of record.
2.4 Collections & Saved Items
We store the names of collections you create and the items you save to them.
2.5 Feedback
If you submit feedback through the Service, we store your message, the page URL where feedback was submitted, your name and email address (if you are logged in), and a timestamp.
2.6 Anonymous Usage Data
For users who are not logged in, we track search quota usage using a device identifier generated from your browser and a hashed version of your IP address (one-way SHA-256 hash — your raw IP address is never stored). This is used solely to enforce the anonymous search quota.
2.7 Cookies & Session Data
We use the following cookies and browser storage:
Session cookie — authenticates your logged-in session. Stored server-side and referenced by a token in your browser. Expires when your session ends or is invalidated. Essential.
Preferences cookie — stores your UI preferences (color theme, device view, sidebar width). Contains no personal data. Essential.
Analytics identifier (Silo) — a first-party identifier set by our internal analytics system to track usage sessions and associate events across page views. When you are logged in, this identifier is linked to your user account. Non-essential.
_ga, _ga_* (Google Analytics) — set by Google Analytics (GA4) to distinguish users and maintain session state for usage analytics. Non-essential. Expire after 2 years.
_gcl_au (Google Ads) — set by Google Ads to store and track ad conversion events, allowing us to measure the effectiveness of our advertising campaigns. Non-essential. Expires after 90 days.
Non-essential cookies are only set with your consent. You can manage your cookie preferences at any time via our Cookie Policy.
2.8 Event & Behavioural Data
We use an internal analytics system called Silo to collect event-level data about how the Service is used. This includes:
Pages visited and navigation patterns.
Feature interactions — such as searches performed, filters applied, items saved, and collections created.
Device type, browser, and general technical context.
When you are logged in, events are associated with your user ID. Silo is self-hosted on our own infrastructure — this data is not sent to or shared with any third party.
3. How We Use Your Data
We use the data we collect to:
Operate and maintain the Service, including authenticating your account and displaying your collections.
Power the AI search feature — processing your queries through third-party AI models to return relevant design results.
Enforce search quotas and calculate overage billing.
Process subscription payments and sync billing status via Lemon Squeezy webhooks.
Debug and improve AI search quality — search logs are reviewed by administrators.
Analyse usage patterns and improve the Service using event data collected by our internal analytics system.
Measure the performance and attribution of our advertising campaigns via Google Ads conversion tracking.
Respond to feedback you submit and forward it to our internal team.
Send transactional emails — such as team member invitations. We do not send marketing emails.
Comply with applicable legal obligations.
4. Data Sharing & Third-Party Services
We do not sell your personal data. We share data only with the following third parties, and only to the extent necessary to operate the Service:
Lemon Squeezy — our merchant of record for billing. Handles subscription creation, payment processing, and invoicing. Receives your payment and subscription information. Subject to Lemon Squeezy's own privacy policy.
Google — used for two purposes: (1) Google OAuth, which authenticates your account and provides your profile data at login; and (2) Google Gemini AI models, which receive your search queries and screenshot images to power AI search and reranking. Subject to Google's privacy policy.
OpenAI — receives a normalized version of your search query to generate text embeddings used in AI search. Subject to OpenAI's privacy policy.
Cohere — receives content for vision embedding as part of AI search processing. Subject to Cohere's privacy policy.
Google Fonts — the Service loads fonts from fonts.googleapis.com. This means your browser makes a request to Google's servers, which may include your IP address. Subject to Google's privacy policy.
Google Tag Manager — we use GTM to manage and deploy analytics and advertising tags on the Service. GTM itself does not collect personal data, but it loads the tags described below. Non-essential tags are only loaded after you have given consent. Subject to Google's privacy policy.
Google Analytics (GA4) — receives usage and behavioural data (pages visited, events, device info) to help us understand how the Service is used. Sets _ga and _ga_* cookies. Only loaded with your consent. Subject to Google's privacy policy.
Google Ads — we run search advertising campaigns via Google Ads. Conversion tracking measures whether users who clicked an ad subsequently completed an action on the Service (e.g. signing up or subscribing). Sets the _gcl_au cookie. Only loaded with your consent. Subject to Google's privacy policy.
Internal email gateway — when you submit feedback, your feedback message, name, email address, and the page URL are forwarded via an internal email service to our team for review. This data is not shared with any external marketing or advertising platform.
5. Data Retention
We retain your personal data for as long as your account exists or as long as is necessary to provide the Service. If you request deletion of your account, we will remove your personal data as described in Section 6.
Search query logs (including raw query text) are retained indefinitely for service debugging and improvement purposes. If you would like your search history deleted, you may request this by emailing legal@m.inspirationindex.app.
Anonymous quota data (device identifier and hashed IP) is retained for the life of the quota enforcement system and does not correspond to any identified individual.
6. Your Rights
Depending on your location, you may have the following rights regarding your personal data. To exercise any of these rights, email legal@m.inspirationindex.app. We will respond within a reasonable timeframe.
6.1 Rights Under PIPEDA (Canada)
Right of access — you may request a copy of the personal data we hold about you.
Right to rectification — you may request that inaccurate or incomplete personal data be corrected.
Right to withdraw consent — where processing is based on consent, you may withdraw it at any time. Withdrawing consent may affect your ability to use certain features of the Service.
6.2 Rights Under GDPR (European Economic Area)
If you are located in the EEA, you have additional rights under the GDPR:
Right to erasure ("right to be forgotten") — you may request that we delete your personal data. We will process verified deletion requests manually via email. Certain data may be retained where required by law or for legitimate interests.
Right to data portability — you may request a machine-readable export of your personal data.
Right to object — you may object to processing of your personal data where we rely on legitimate interests as a legal basis.
Right to restrict processing — in certain circumstances, you may request that we limit how we use your data.
Right to lodge a complaint — you have the right to lodge a complaint with your local data protection authority if you believe we have not handled your data lawfully.
6.3 Account Deletion
There is currently no self-serve account deletion feature. To request deletion of your account and associated personal data, email legal@m.inspirationindex.app from the email address associated with your account. We will process your request and confirm deletion.
7. Children's Privacy
The Service is intended for users aged 16 and older. We do not knowingly collect personal data from anyone under 16. If you believe a person under 16 has provided us with their personal data, please contact us at legal@m.inspirationindex.app and we will take steps to delete it.
8. Data Security
We take reasonable technical measures to protect your personal data, including password hashing, encrypted session tokens, and hashing of IP addresses before storage. However, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security.
9. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date at the top of this page. Your continued use of the Service after any changes constitutes your acknowledgment of the updated policy. We encourage you to review this page periodically.
10. Contact
For any questions, requests, or concerns about this Privacy Policy or how we handle your personal data, contact us at legal@m.inspirationindex.app.
Last updated: March 2026