Privacy notice
How we process data for the website, Dashboard, billing and API.
Last updated: 30 September 2026
Controller and contact
Innovius UG (haftungsbeschränkt), Elbestraße 1A, 14513 Teltow, Germany, is responsible for the customer and website administration described here. Send privacy requests to info@innovius.ai.
Account and login
We use your business email to send a time-limited login link. Dashboard and the separate partner portal require signed session cookies and a cookie protecting against forged form requests. Partner registration also checks an organisation invitation and permitted work-email domain. Dashboard login sessions (also in the partner portal) expire after 24 hours, login links after 15 minutes. Used links cannot be reused, and partner access is checked again on every request. Dashboard login sessions are separate from API sessions: an API session holds a replacement map for your application and is described under content storage and deletion.
We keep a pseudonymous account identifier, associations with Stripe customers and purchases, entitlements, API-key verification hashes and labels, revocation information, offline activation records and usage events. Usage events contain request references, counts, processing tier and timestamps, not submitted content. These records and cached entitlement information are stored locally to authenticate requests, enforce balances, prevent duplicate fulfillment and recover service. They remain personal data where linkable to a person.
The email address is needed to access an account; company and billing details are needed to complete a paid order and issue an invoice. Without these details, the corresponding service cannot be provided. Support message content is provided at your choice. Network metadata, such as IP addresses and request times, is processed to deliver connections, limit abuse and investigate technical incidents.
Billing and entitlement activation
Stripe processes billing, company and payment data you enter at checkout and in the customer portal. Full card details are not passed to our API. Stripe provides invoices and manages payments and subscriptions. Depending on the processing, Stripe acts as a processor or independent controller, for example for statutory payment and fraud-prevention duties. Details: Stripe Privacy Center.
RevenueCat, Inc. manages purchase recognition, entitlements and consumption information associated with the pseudonymous account ID. Stripe handles company, contact, tax and payment details, subscriptions and invoices. We may retrieve the information needed to reconcile a purchase or provide billing access; monetary accounting remains with the payment providers. Neither provider receives routine inference text or replacement mappings from ShinrAI.
RevenueCat DPA · RevenueCat Privacy · Stripe DPA
API content and local installation
For managed processing, Innovius acts on your company’s instructions under the data processing agreement. Synchronous text, supported images/documents, audio recordings and generated replacement mappings are processed in memory; we do not keep a replay history of these requests. Keep any mapping needed for restoration in your own application. We do not use API content to train models or for any purpose of our own. Routine service logs exclude input and result content, mappings and plaintext API secrets.
Content storage and deletion
| Processing | Storage and retention |
|---|---|
| Direct requests | Text, images, audio and replacement mappings are processed in memory for the request and are not stored. A request that names an API session adds its new replacements to that session. |
| Asynchronous jobs | Uploads, job sources and results are encrypted; in the native PII API v2 each customer has its own key. The job source and the job request are deleted when the run ends. An upload is deleted when the last job that reads it ends; an upload created with the keep option stays at most 24 hours after the upload or after the submission of the last job that reads it, whichever is later. Results expire at the latest 24 hours after submission, or earlier when you delete the job. Job content is excluded from routine backups. |
| API sessions | An API session holds a replacement map with original values for your application. It is encrypted and bound to your account. It ends when the time to live you set runs out (one hour by default), at the latest 24 hours after creation, or 7 days when your account enables extended sessions. You can delete it at any time; otherwise it is deleted automatically about one hour after it expires. Sessions are excluded from backups. |
| Retry fingerprints (Idempotency-Key) | For safe retries, the service keeps a hash of the Idempotency-Key and the request. The hash contains no readable content. For direct requests it is held in memory only and ends at the latest with the next restart of the service. For jobs it is kept with the job, at most 24 hours after submission. |
| Receipts of hosted MCP tools | A keyed hash of the request identifier and of the input, without readable content. It is kept with the usage records to prevent double charging. |
| Saved templates and dictionaries | If you explicitly create reusable configurations, their definitions and saved dictionary values are retained encrypted until you delete them or request removal. This can include cryptographic material explicitly embedded in a template. These resources are separate from transient requests and are included in operational backups. |
| Customer-controlled storage and keys | Where you configure external storage or key-management connections, the selected provider processes the data needed for that operation on your instructions. Copies in your source or destination storage follow your own retention settings. Compatibility with Azure, AWS or Google does not by itself send content to those providers. |
Data handling and retention in the developer documentation
With entirely local offline operation, inference content and the installation’s private key remain on your infrastructure. To issue activation, we retain the installation ID, public key, signed license and purchased quota association. These activation records contain no inference text. Your organization controls local mappings, saved configurations, access and backups.
Hosting, email and recipients
The ShinrAI website, Dashboard, private partner portal and managed processing are hosted on STACKIT in Germany. Speech recognition for audio runs on a second STACKIT server in Germany; it processes recordings in memory and keeps no copy. STACKIT is operated by Schwarz Digits Cloud GmbH & Co. KG. Support names, addresses, messages and internal notes are encrypted in a separate portal database. Assigned implementation partners and support staff receive access only for the cases and customers routed to them, unless Innovius explicitly grants broader team access. SMTP2GO (Sand Dune Mail Ltd., New Zealand) delivers login and service notifications containing only a case reference and portal link, without the conversation content. Support data is separate from inference requests.
The status page status.shinrai.innovius.io is a static page on United Domains webspace in Germany. When you open it, United Domains processes access log data to deliver the page and protect its servers, for example your IP address, the time, the requested file and the browser type. United Domains keeps these logs under its own retention rules. We rely on Article 6(1)(f) GDPR: our legitimate interest in a status page that stays reachable when our own servers fail.
Ticket attachments and their original filenames are encrypted with the support conversation. Accepted images are decoded and re-encoded to remove metadata; other allowed files are downloaded rather than executed in the browser. Files remain quarantined when malware scanning is unavailable. Attachments follow the ticket’s access checks and 90-day deletion period.
Billing and communications providers may process data outside the EEA. Their contractual data protection terms and, where required, appropriate transfer safeguards apply, particularly EU standard contractual clauses or relevant adequacy decisions. You may request information and copies of safeguards applicable to your data. German inference hosting does not mean all billing and email data is processed exclusively in Germany.
Purposes, legal bases and retention
Pre-contract steps, contract performance and handling requests rely on Article 6(1)(b) GDPR where you are the contracting party. For a business customer’s employees and operational security, we rely on Article 6(1)(f): legitimate interests in business communication, secure services and abuse prevention. Statutory billing and evidence obligations rely on Article 6(1)(c).
Operational account and usage records are retained while needed for active entitlements, non-expiring purchased capacity, reconciliation, fraud prevention or legal claims. Deletion requests are reviewed individually; cancelling renewal does not automatically delete the account or purchased packs. Invoices generally follow the German statutory eight-year retention period, with longer retention where legally required. Support conversations are deleted 90 days after resolution. Content-free support audit records are kept for 12 months.
Routine encrypted operational backups rotate on a 14-day schedule and include the partner portal and encrypted saved configurations, but exclude request content, asynchronous job content and API sessions. Deleted portal content may therefore remain in an encrypted backup until that backup expires. Service logs rotate by size rather than a fixed number of days; relevant incident evidence may be retained until the incident and associated claims are resolved.
Private aggregate reporting
We count ordinary website and API requests and operational checkout outcomes on our German servers to understand website reach, campaign landing-page performance and service reliability. Only fixed page, source, campaign name, language, response and outcome categories enter reporting, including which section of the home page (plans, example, checkout) was reached and whether a demo run or checkout was started, always per source category and never per visitor; no IP addresses, visitor identifiers, full URLs, advertising click IDs, request content or payment details are retained in reporting.
Daily totals are retained for 400 days and hourly traffic and service-health totals for 30 days. A size-limited, identifier-free processing buffer is excluded from backups. Checkout identifiers remain in the separate operational records described above; reporting does not build visitor profiles or connect visits. Incoming DNT/GPC signals exclude audience measurement, while necessary payment operations and aggregate service health continue.
Only active Innovius administrators can access these reports. For page requests that already carry a necessary ShinrAI login cookie, a private server-side check validates the existing session and reduces it immediately to visitor, customer, Innovius staff, partner or unavailable. The report retains only these fixed aggregate categories, never the cookie, email, account identifier or browsing history. DNT/GPC skips this audience classification. We rely on Article 6(1)(f) GDPR for the limited processing necessary to produce these statistics: our legitimate interests in assessing website effectiveness and maintaining a reliable purchase and service flow. We add no analytics cookies, browser tracking scripts or advertising pixels. The necessary browser functions and your rights described below remain applicable.
Advertising conversion reporting: if you reach this site through a Google Ads or Microsoft Advertising link and then start a checkout in that same tab, we store that link’s advertising click ID (gclid or msclkid) together with the checkout record on our German servers for 90 days. If the purchase is paid, we report it back to the advertising network as a conversion: only the click ID, the payment time and the amount with its currency leave our systems; no name, e-mail address, account, order content or other personal data is sent. The network matches the click ID to the ad click on its side under its own privacy terms. The click ID is not used in the aggregate reporting above and is deleted after 90 days. We rely on Article 6(1)(f) GDPR under the same balancing: measuring paid campaigns without profiles, with a bounded retention period. You may object at any time using the contact below, and nothing is stored or sent when your browser signals DNT or GPC.
Cookies and browser storage
We use necessary Dashboard, partner-session and CSRF cookies for secure login and a 30-day cart cookie containing product selections only. A language you explicitly choose is saved locally in your browser until you clear it. For campaign measurement, the page keeps a traffic source category (for example "google_ads" or "direct") and an optional campaign name in the browser’s session storage for the duration of the tab (keys shinrai-source, shinrai-source-slug, shinrai-source-seen); no identifier or URL is stored there, nothing is sent when your browser signals DNT or GPC, and the values disappear when the tab closes. If you arrived through a Google Ads or Microsoft Advertising link, the page also keeps that link’s advertising click ID (gclid or msclkid) in the same tab-scoped session storage (key shinrai-click) and sends it once, only if you start a checkout in that tab, as described under advertising conversion reporting above; it is never sent with any other request, never placed in a cookie, and it disappears when the tab closes. These functions rely on section 25(2) TDDDG where necessary to provide the service you request. This ShinrAI site does not embed advertising trackers or third-party analytics. Stripe’s hosted checkout has its own privacy and cookie information.
Your rights
Subject to legal requirements, you have rights of access, rectification, erasure, restriction and portability. You may object to processing based on legitimate interests for reasons relating to your situation. Consent may be withdrawn for the future. We make no solely automated decisions with legal or similarly significant effects using your account data.
You may complain to a data protection authority, in particular the Brandenburg Commissioner for Data Protection and Access to Information. If data subjects contact us about API job content, we assist the responsible business customer in handling their request.