Privacy notice
How we process data for the website, Dashboard, billing and API.
Last updated: 9 September 2026
Controller and contact
Innovius UG (haftungsbeschränkt), Elbestraße 1A, 14513 Teltow, Germany, is responsible for the customer and website administration described here. Send privacy requests to info@innovius.ai.
Account and login
We use your business email to send a time-limited login link. Dashboard requires a signed session cookie and a cookie protecting against forged form requests. These are necessary for the requested function. Sessions expire after 24 hours by default, login links after 15 minutes. Used links cannot be reused.
We keep a pseudonymous account identifier, associations with Stripe customers and purchases, entitlements, API-key verification hashes and labels, revocation information, offline activation records and usage events. Usage events contain request references, counts, processing tier and timestamps, not submitted content. These records and cached entitlement information are stored locally to authenticate requests, enforce balances, prevent duplicate fulfillment and recover service. They remain personal data where linkable to a person.
The email address is needed to access an account; company and billing details are needed to complete a paid order and issue an invoice. Without these details, the corresponding service cannot be provided. Support message content is provided at your choice. Network metadata, such as IP addresses and request times, is processed to deliver connections, limit abuse and investigate technical incidents.
Billing and entitlement activation
Stripe processes billing, company and payment data you enter at checkout and in the customer portal. Full card details are not passed to our API. Stripe provides invoices and manages payments and subscriptions. Depending on the processing, Stripe acts as a processor or independent controller, for example for statutory payment and fraud-prevention duties. Details: Stripe Privacy Center.
RevenueCat, Inc. manages purchase recognition, entitlements and consumption information associated with the pseudonymous account ID. Stripe handles company, contact, tax and payment details, subscriptions and invoices. We may retrieve the information needed to reconcile a purchase or provide billing access; monetary accounting remains with the payment providers. Neither provider receives routine inference text or replacement mappings from ShinrAI.
RevenueCat DPA · RevenueCat Privacy · Stripe DPA
API content and local installation
For managed processing, Innovius acts on your company’s instructions under the data processing agreement. Synchronous text, supported images/documents and generated replacement mappings are processed in memory; we do not keep a replay history of these requests. Keep any mapping needed for restoration in your own application. Routine service logs exclude input and result content, mappings and plaintext API secrets.
Content storage and deletion
| Processing | Storage and retention |
|---|---|
| Asynchronous jobs | Inputs and results are encrypted on the managed service. Inputs are removed when processing ends; remaining job data expires 24 hours after submission and is purged automatically. Job content is excluded from routine backups. |
| Saved templates and dictionaries | If you explicitly create reusable configurations, their definitions and saved dictionary values are retained encrypted until you delete them or request removal. This can include cryptographic material explicitly embedded in a template. These resources are separate from transient requests and are included in operational backups. |
| Customer-controlled storage and keys | Where you configure external storage or key-management connections, the selected provider processes the data needed for that operation on your instructions. Copies in your source or destination storage follow your own retention settings. Compatibility with Azure, AWS or Google does not by itself send content to those providers. |
With entirely local offline operation, inference content and the installation’s private key remain on your infrastructure. To issue activation, we retain the installation ID, public key, signed license and purchased quota association. These activation records contain no inference text. Your organization controls local mappings, saved configurations, access and backups.
Hosting, email and recipients
The ShinrAI website, Dashboard and managed processing are hosted on STACKIT in Germany. STACKIT is operated by Schwarz Digits Cloud GmbH & Co. KG. SMTP2GO (Sand Dune Mail Ltd., New Zealand) delivers login and service emails. Support form messages, including the email address and message you provide, are forwarded to our company mailbox and may be retained in that correspondence. These are separate from inference requests.
Billing and communications providers may process data outside the EEA. Their contractual data protection terms and, where required, appropriate transfer safeguards apply, particularly EU standard contractual clauses or relevant adequacy decisions. You may request information and copies of safeguards applicable to your data. German inference hosting does not mean all billing and email data is processed exclusively in Germany.
Purposes, legal bases and retention
Pre-contract steps, contract performance and handling requests rely on Article 6(1)(b) GDPR where you are the contracting party. For a business customer’s employees and operational security, we rely on Article 6(1)(f): legitimate interests in business communication, secure services and abuse prevention. Statutory billing and evidence obligations rely on Article 6(1)(c).
Operational account and usage records are retained while needed for active entitlements, non-expiring purchased capacity, reconciliation, fraud prevention or legal claims. Deletion requests are reviewed individually; cancelling renewal does not automatically delete the account or purchased packs. Invoices generally follow the German statutory eight-year retention period, with longer retention where legally required. Support correspondence is retained for handling the case and necessary contractual or legal evidence.
Routine operational backups rotate on a 14-day schedule and include encrypted saved configurations, but exclude asynchronous job content. Service logs rotate by size rather than a fixed number of days; relevant incident evidence may be retained until the incident and associated claims are resolved. Removing a saved resource from the active service does not immediately remove it from existing backups.
Cookies and browser storage
We use necessary session and CSRF cookies for secure login and a 30-day cart cookie containing product selections only. A language you explicitly choose is saved locally in your browser until you clear it. These functions rely on section 25(2) TDDDG where necessary to provide the service you request. This ShinrAI site does not embed advertising trackers or third-party analytics. Stripe’s hosted checkout has its own privacy and cookie information.
Your rights
Subject to legal requirements, you have rights of access, rectification, erasure, restriction and portability. You may object to processing based on legitimate interests for reasons relating to your situation. Consent may be withdrawn for the future. We make no solely automated decisions with legal or similarly significant effects using your account data.
You may complain to a data protection authority, in particular the Brandenburg Commissioner for Data Protection and Access to Information. If data subjects contact us about API job content, we assist the responsible business customer in handling their request.