Privacy Policy

Last updated August 30, 2026.

1. Scope and controller

This Privacy Policy explains how DeepInquiry ( “we”, “us”, “our”) collects, uses, shares, and protects personal information when you use the DeepInquiry website at deepinquiry.ai, the API at api.deepinquiry.ai, the embeddable widget, and any related materials (together, the “Service”).

DeepInquiry is the “controller” of personal information under the EU and UK General Data Protection Regulations, and a “business” under the California Consumer Privacy Act as amended by the California Privacy Rights Act.

Contact for privacy matters: api@deepinquiry.ai.

2. What we collect

We collect the minimum information needed to operate the Service. We do not ask for your name, physical address, phone number, date of birth, or any special-category data (such as health, religion, or racial or ethnic origin).

CategoryExamplesSourcePurpose
Account informationEmail address, plan and subscription status, hashed API keyYou provide it at sign-up or when you rotate a keyCreate your account, authenticate requests, enforce quotas, contact you about the Service
Billing informationStripe customer ID, subscription ID, billing status, current-period timestampsReceived from Stripe when you subscribeDetermine access, invoice you, handle disputes
Usage informationEndpoint requested, timestamp, fact ID returned, HTTP status, IP address (short-lived), user agentGenerated automatically when your API key or the website is usedMeter usage, enforce rate limits, detect abuse, produce aggregate product analytics
CommunicationsThe content of emails or support tickets you send us and our repliesYou send them to usRespond to you and keep a record of the exchange
Device and log dataIP address, browser type and version, referring URL, request path, response codeServer logs at Vercel and CloudflareOperate, secure, and debug the Service

API Keys are stored only as one-way SHA-256 hashes. We generate the raw key on the server, deliver it to you once, and cannot recover it later — we can only issue you a new one.

3. Sources of personal information

We receive personal information from:

  • You directly, when you sign up, generate an API key, contact us, or subscribe to a paid plan.
  • Automatically, when you use the Service, from request headers, server logs, and cookies.
  • Our service providers, such as Stripe (which confirms your subscription status and billing state to us).

4. How we use personal information

We use personal information to:

  • Operate the Service — authenticate your API key, enforce quotas and rate limits, bill you through Stripe, send transactional email (welcome, key rotation, billing failure), and respond to support requests.
  • Secure the Service — detect and prevent abuse, fraud, unauthorized access, and attacks; investigate incidents.
  • Improve the Service — produce aggregated analytics on endpoint usage, error rates, and latency. This is done at the aggregate level; we do not profile individual customers.
  • Comply with law — respond to lawful requests from regulators, courts, or law enforcement; meet tax and accounting obligations.
  • Communicate with you — occasional product announcements (which you can unsubscribe from) and responses to your inquiries.

What we do not do. We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use your API request payloads or responses to train AI or machine-learning models. We do not use sensitive personal information for purposes beyond those permitted by CPRA without your consent.

5. Legal bases (GDPR / UK GDPR)

If you are in the European Economic Area, the United Kingdom, or Switzerland, our legal bases for processing are:

  • Contract (Article 6(1)(b)) — to create and administer your account, issue API keys, meter usage, bill you, and provide support.
  • Legitimate interests (Article 6(1)(f)) — to secure the Service against abuse, run aggregate product analytics, and communicate about material changes. You may object; contact us to discuss.
  • Legal obligation (Article 6(1)(c)) — for tax, accounting, and responses to lawful requests.
  • Consent (Article 6(1)(a)) — where we ask for it, such as for optional marketing emails. You can withdraw consent at any time.

6. Who we share information with

We share personal information with third-party service providers that help us operate the Service — hosting, payments, email delivery, error monitoring, and DNS. Each provider receives only the minimum data needed for its function and is bound by contract to protect that data and use it only on our instructions.

The current, dated list of our subprocessors — including the purpose, data categories, and processing location for each — is maintained at /subprocessors and is updated whenever we add or replace one.

We may also share personal information:

  • When required by law — in response to valid legal process, or to protect the rights, property, or safety of us, our users, or the public.
  • In a corporate transaction — in connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections. If control of the Service changes, we will notify affected users by email.
  • With your direction — for example, if you ask us to connect your account with a third-party tool.

7. International data transfers

Our servers and most of our subprocessors are located in the United States. If you are in the European Economic Area, the United Kingdom, or Switzerland, your personal information will be transferred to and stored in the United States. Where required, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum or Swiss addendum, as applicable) that our subprocessors have in place, and on the EU–U.S. Data Privacy Framework where applicable.

8. How long we keep it

CategoryRetention periodWhy
Account recordsWhile your account is active, plus up to 24 months after deletionBilling disputes, security investigations, legal defense
API usage rowsUp to 13 months, then aggregated and row-level data deletedMonthly quota accounting; trailing 12 months of analytics on the current billing cycle
Server request logs (Vercel, Cloudflare)Typically 30 daysDebugging, abuse investigation, incident response
Billing recordsAt least 7 yearsTax and accounting rules
Support and communicationsUp to 3 years after the last exchangeContinuity of support and dispute reference

9. Your rights

Depending on where you live, you may have some or all of these rights over your personal information:

RightApplies underWhat it means
AccessGDPR / UK GDPR / CCPAAsk for a copy of the personal information we hold about you.
CorrectionGDPR / UK GDPR / CCPAAsk us to fix inaccurate personal information.
DeletionGDPR / UK GDPR / CCPAAsk us to delete your account and associated personal information. We may retain records we are legally required to keep.
PortabilityGDPR / UK GDPR / CCPAReceive your data in a machine-readable format.
Objection / restrictionGDPR / UK GDPRObject to processing based on legitimate interests, or ask us to restrict processing while a dispute is resolved.
Withdraw consentGDPR / UK GDPRWhere processing is based on consent, withdraw it at any time (this does not affect processing before withdrawal).
Opt out of sale or sharingCCPA / CPRAWe do not sell or share personal information for cross-context behavioral advertising, but California residents may confirm this in writing at any time.
Limit use of sensitive personal informationCPRAWe do not use sensitive personal information for purposes beyond those permitted by law without your consent.
No retaliationCCPA / CPRAWe will not deny service, charge different prices, or provide a different level of quality for exercising these rights.

To exercise any of these rights, email api@deepinquiry.ai from the address on your account. We will respond within 30 days (GDPR/UK GDPR) or 45 days (CCPA/CPRA), and may need to verify your identity before acting. You may also authorize an agent to make a request on your behalf; we may verify the agent’s authority.

Complaints. EEA residents may lodge a complaint with their local Data Protection Authority; UK residents may complain to the Information Commissioner’s Office; Swiss residents may complain to the Federal Data Protection and Information Commissioner.

10. Cookies and similar technologies

The website at deepinquiry.ai uses only strictly necessary first-party cookies for sign-in session state and cross-site-request-forgery protection. We do not set advertising cookies, cross-site tracking pixels, third-party analytics cookies, or session-replay tools. If we ever add non-essential cookies, we will present a consent banner and update this section.

Because we do not run advertising trackers, we do not respond to browser “Do Not Track” signals in any specific way — our default behavior already matches what a DNT signal would ask for.

11. Security

We use industry-standard technical and organizational security controls to protect personal information, including:

  • TLS encryption in transit for all API and website traffic.
  • SHA-256 hashing of API keys at rest; raw keys are not retrievable.
  • Managed database encryption at rest (Supabase).
  • Principle-of-least-privilege access controls to production systems, with authentication logs.
  • Automated dependency-vulnerability scanning.

No system is 100% secure. In the event of a security incident affecting your personal information, we will notify you consistent with our legal obligations. If you believe you have found a vulnerability, please email api@deepinquiry.ai.

12. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. The Service’s automated behavior is limited to authentication, quota enforcement, and rate limiting, which apply the terms of your chosen Plan mechanically and do not profile you.

13. Children

The Service is not directed at children under 13 (or 16 in the European Union and United Kingdom). We do not knowingly collect personal information from children. If you believe we have collected information from a child, contact us and we will delete it.

14. Notice to California residents

This Privacy Policy is designed to comply with the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”).

  • Categories of personal information collected in the last 12 months: identifiers (email, hashed API key, IP), commercial information (subscription status), internet or other electronic network activity (usage logs), and geolocation data (approximate location derived from IP). Details are in Section 2.
  • Sources of personal information: you and automated collection during your use of the Service. See Section 3.
  • Business or commercial purposes for collection: operating, securing, and improving the Service; billing; legal compliance. See Section 4.
  • Categories disclosed to service providers: identifiers, commercial information, and internet activity, each to the providers listed at /subprocessors.
  • Sale or sharing of personal information: we do not sell personal information and we do not share personal information for cross-context behavioral advertising.
  • Sensitive personal information: we do not use or disclose sensitive personal information for purposes beyond those permitted by CPRA without your consent.
  • Retention: see Section 8.
  • How to exercise your rights: see Section 9.

15. Notice to residents of the EEA, UK, and Switzerland

DeepInquiry does not currently maintain an establishment in the European Union or the United Kingdom and does not target services at EEA or UK residents at a scale that requires a designated Article 27 representative. If you believe a representative is required in your jurisdiction for a matter involving your data, email api@deepinquiry.ai and we will designate one for that matter.

16. Changes to this Policy

We may update this Policy. Non-material updates (typographical fixes, new links, formatting) take effect on publication. Material updates (new categories of personal data collected, new purposes of use, new subprocessors receiving new data categories, changed retention windows, or a change to a consent-based practice) take effect no earlier than 14 days after we email registered users. We will archive prior versions on request.

Contact

Privacy questions or data-rights requests: api@deepinquiry.ai.

DeepInquiry is operated by Epic Sky, LLC, a Delaware limited liability company.