Legal
Privacy Policy
01What this policy covers
This policy covers our website and every app we publish — the ones we have now and the ones we release later. Where a particular app handles something differently, we say so in that app and that notice sits alongside this one rather than replacing it.
Two words are used throughout. Consumer apps are the ones you sign up for yourself. Organisation products are the ones a school, employer, or association gives you access to. Which one you are using changes who is responsible for your data, so it is worth knowing which you have.
02Who we are, and who is responsible
Inspiro Labs Ltd (company no. 16895325), registered in England and Wales at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.
For our consumer apps we are the data controller. We decide what is collected and why, and this policy governs it.
For organisation products the organisation is the controller and we are their processor. They decide what is held and for how long; we act on their written instructions under a separate agreement. If you want your data corrected or removed, ask them first — the decision is theirs, and we will help them carry it out.
Our Data Protection Officer is Nahum Joseph Jacob, reachable at legal@inspirolabs.dev.
03What data we collect
- Account data
- Your email address and authentication identifier. If an organisation gave you the account, whatever identifier they use for you.
- Content you create
- Whatever you save in the app — notes, records, entries, uploads, messages. Stored so you can reach it across your devices.
- Usage and technical data
- Crash reports, device and app version, and basic measurements of which features are used. We use these to find faults and decide what to build.
- Payment data
- If you buy something, the fact and status of the purchase. Card details are handled by the app store or payment provider and never reach us.
- Correspondence
- What you send us when you get in touch, and our reply.
We do not sell your data, we do not use it for advertising, and we do not build advertising profiles.
04Where we get it from
Usually from you, as you use the app. For organisation products we also receive data from the organisation — class lists, roles, and similar — which they are responsible for holding lawfully and for telling you about. If you sign in with a third-party account, we receive the identifier and email address that provider releases to us, and nothing else.
05How we use your data, and why we are allowed to
- To run the service
- Giving you the thing you signed up for, syncing your content, taking payment. This is performance of our contract with you.
- To keep it working
- Fixing faults, preventing abuse, keeping accounts secure, and deciding what to improve. This is our legitimate interest in running a service that works and is not abused. You can object to it at any time.
- To meet obligations
- Keeping records the law requires us to keep, and answering lawful requests. This is our legal obligation.
- Anything you have agreed to
- Where we ask for consent — optional analytics, marketing, anything sensitive — that consent is the basis, and you can withdraw it whenever you like without affecting what we did before you withdrew it.
You do not have to give us anything beyond what an account needs. Without an email address and password we cannot create an account or sync your content, so that much is a condition of the service rather than a legal requirement.
06Sensitive information
Some of what we build touches religious belief. If you keep study notes in one of our apps, that content can reveal what you believe — and under UK data protection law information about religious or philosophical belief is special category data, which gets stronger protection.
We handle it on the basis of your explicit consent, given when you create that content. You can withdraw it by deleting the content or your account. We do not infer belief from your behaviour, we do not use this content for any purpose other than showing it back to you and syncing it, and we never share or sell it.
We do not ask for health data, and our apps are not designed to collect it. If an organisation product ever needs to hold something sensitive — a pastoral note, an access arrangement — the organisation is the controller and their notice governs it.
07AI features and your content
Some of our products are designed to use AI to draft, summarise, or suggest. None of those features are live yet, and no content you give us is sent to an AI model provider today. We use AI tools internally to help build our software; they never receive customer data.
Before any AI feature ships we will update this page to name the provider, say exactly what is sent and why, and set out how long they hold it. We will tell you before it takes effect rather than after.
Two commitments will hold whenever that happens. Your content will not be used to train models, ours or anyone else’s. And AI output is a draft for a person to accept, edit, or reject — never the final word on anything that affects someone.
08Automated decisions
We do not make decisions about you by automated means alone where those decisions would have a legal or similarly significant effect — no automated grading, no automated assessment of a person, no automated exclusion from anything. Where a product suggests an outcome, a person decides. If that ever changes we will update this page first and tell you what rights you have.
09Who else touches your data
Only the providers that run the service for us:
- Supabase
- Authentication and database hosting.
- Vercel
- Website and application hosting.
- Email and push
- Sending the messages the service needs to send.
- Crash and analytics
- Finding faults and understanding use.
- Payments
- Taking payment where a product is paid for directly.
Each acts on our written instructions only. We do not share your data with anyone else unless the law requires it, and we do not sell or rent it to anyone at all. A current list of the providers we use is available on request.
10Where your data is held
Our infrastructure is hosted in the United Kingdom and the European Economic Area. Transfers to the EEA are covered by the UK’s adequacy regulations. If a provider needs to process data elsewhere we use the International Data Transfer Agreement or the UK Addendum to standard contractual clauses, and we will update this page before that happens.
11How long we keep data
- Your account and content
- For as long as the account is active. Deleted within 30 days of you deleting the account.
- Correspondence
- Kept while the matter is open, then for up to two years.
- Records the law requires
- Kept for as long as the relevant law requires — for purchases, six years.
- Backups
- Overwritten on their normal cycle, within 90 days.
For organisation products the organisation sets retention, and we delete on their instruction or when our agreement with them ends.
12Keeping your data safe
Data is encrypted in transit and at rest. Access is limited to the people who need it for their work and is protected by individual accounts rather than shared credentials. No system is perfect, so if a breach happens that puts your rights at risk we will tell the ICO within 72 hours and tell you without undue delay.
13Your rights
You can ask us to:
- Give you a copy
- Of the personal data we hold about you.
- Correct it
- If something is wrong or incomplete.
- Delete it
- Where we no longer need it, or you withdraw consent.
- Restrict or object
- To how we use it, including anything based on our legitimate interests.
- Port it
- In a machine-readable form, to take elsewhere.
Email legal@inspirolabs.dev and we will respond within one month. We will not charge you or treat you differently for asking. If an organisation gave you your account, ask them first — the decision is theirs to make.
14Deleting your account
Every app that lets you create an account lets you delete it from inside the app, without asking us. If you would rather not use the app, email legal@inspirolabs.dev and we will do it for you. Deleting the account deletes your content — see how long we keep data, above. Deactivating or signing out is not the same thing, and does not delete anything.
16Marketing
We send service messages — security notices, receipts, changes to these terms — because running the service requires it. Anything promotional only goes to people who asked for it, and every such message has an unsubscribe link that works. We do not pass your address to anyone else for their own marketing, ever.
17Children and young people
Some of what we build is used by people under 18 — that is the point of the school products, and younger readers use our study apps too. We follow the ICO’s Age Appropriate Design Code: settings start at their most protective, we collect the least we can, we do not profile children, and we do not use design patterns that nudge anyone into giving up more than they meant to.
In the UK a child can consent to an online service from age 13. Below that we need parental consent, and our consumer apps are not intended for under-13s signing up alone. Other countries set the age between 13 and 16; where you are, the local age applies.
Where a school or organisation is the controller, they are responsible for the lawful basis for holding a child’s data and for telling families about it. We support them in that; we do not do it instead of them. If you believe a child’s data is held here and should not be, write to legal@inspirolabs.dev and we will deal with it.
18If our business changes
If Inspiro Labs is sold, merged, or reorganised, personal data may transfer to the new owner — who would be bound by this policy until they give you notice of a different one. We will tell you before it happens and you will be able to delete your account first.
19Where you live
We are based in the United Kingdom and this policy is written to UK standards, which we apply to everyone wherever they are.
Philippines. Our education products are tested in Philippine schools. Personal data collected there is handled in line with the Data Privacy Act of 2012 as well as UK law, and you can complain to the National Privacy Commission.
European Economic Area. Where the EU GDPR applies to you, the same rights described here apply and you can complain to your local supervisory authority.
20Changes to this policy
We will post any change on this page and update the date above. If a change materially affects you we will tell you in the apps affected, or by email, before it takes effect.
21How to contact us or complain
Write to legal@inspirolabs.dev. If our answer does not satisfy you, you can complain to the Information Commissioner’s Office at ico.org.uk, or to the National Privacy Commission at privacy.gov.ph if you are in the Philippines. You can complain to a regulator without coming to us first, though we would rather have the chance to put it right.