Legal
Privacy Policy
Last updated August 15, 2026 — policy version 2026-08-15.v1
1. The short version
We collect the minimum we need to run Intake: account details when you sign up, and the content you put into your intake flows. We don't sell personal data and we run no advertising trackers. This site measures how it is used; in the EEA, UK, Switzerland and Quebec we ask before setting any cookie, everywhere else you can switch it off from the foot of any page, and we honour your browser's Global Privacy Control signal — §2 describes it in full. Your clients' answers are there to compose your briefs. During early access we also ask free-plan accounts for consent to keep a de-identified copy of the brand strategy itself — stripped of names, emails, and account details — to improve the product. Paid plans are never used this way, accounts in the EU, UK and Switzerland are never used this way, and any profile you mark as client work is excluded entirely.
2. On this website
We count how this site is used — which pages are opened, which links are followed, which on-page controls are pressed, how far down a page people read. There are no advertising trackers, nothing is shared with ad networks, and none of it is ever sold.
Whether that counting uses a cookie depends on where you are. In the EEA, the UK, Switzerland and Quebec we ask you first, and unless you say yes we count you against a random identifier that lives in the browser tab and is gone when you close it — never linked to you, your account, or any later visit. In the United States and the rest of Canada we set the cookie without asking, because the law there gives you a right to refuse rather than a right to be asked. Either way the choice stays yours, permanently: Cookie choices, at the foot of any page, turns it off again and deletes the identifier. And if your browser sends a Global Privacy Control signal, we treat that as a refusal on its own — you are never asked and the cookie is never set.
When that cookie is set — because you accepted, or because you are somewhere we do not ask — it is one first-party cookie on intake.design that lasts 13 months. It holds nothing but a random identifier. What it lets us do is recognise a repeat visit as the same person and — if you go on to create an account — connect the pages you read beforehand to it, which is how we learn which parts of this site are worth keeping. It is never shared and never used for advertising.
We measure in two ways, both chosen to keep as little as possible. Our host, Cloudflare, counts visits at its own edge — no cookies, no fingerprinting, and no company involved that was not already carrying every request to this site. Alongside it, our analytics provider PostHog receives the counts described above; those are sent through our own servers rather than from your browser, and we do not pass on your IP address, which is why we can tell how a page is doing but not where you are. Cloudflare also tells us which country your request came from, and inside Canada which province, so we know whether to ask you the cookie question; that is used to decide and to check that question, is never stored, and is never passed on to PostHog. Two pages talk to another company directly: /sign-in and /sign-up load the sign-in form from Clerk, who handle our accounts — and if you are signed in, every page checks with Clerk to keep your session alive, which is what lets the navigation show your account. Everything else, fonts included, is served from our own domain. Cloudflare also keeps standard server logs (IP address, request time) for security and operations.
If you sign up for product updates near the foot of the homepage, we store the one email address you give us there, based on the checkbox consent you give at that moment — it ships unchecked, and nothing is stored unless you tick it yourself. That address is used only to occasionally tell you about new Intake features. It stays on our own infrastructure (Cloudflare), is never handed to a separate marketing or email platform, never sold, and never linked to a product account even if you later create one with the same address. To be removed, email privacy@intake.design.
If you join the Enterprise waitlist from the pricing section, we store the email address you give us, the company or team name if you add one, and the time you ticked the opt-in box — which ships unchecked, and nothing is stored without it. We use it only to tell you when Enterprise is available and to talk with you about it. It is kept in our database at Cloudflare, and a copy of each new sign-up is emailed to our team’s inbox, which Google hosts, so we can reply to you. It is never sold, never added to the product-updates list above, and never linked to a product account. We keep it until Enterprise launches and we have contacted you, or until you ask us to remove it: email privacy@intake.design.
3. In the app
When you create an account we collect your name and email, handled by our authentication provider, Clerk. The intake flows you run store what you and your clients submit, including answers, uploaded assets and imported portfolio work, because that is the product: we process it to compose your briefs and to power in-flow suggestions. By default that processing runs through Google's Gemini models acting as our service provider, routed over Cloudflare's network. For a limited set of features, free-plan accounts may instead be routed to GPU hardware we own and operate ourselves, running open-weight models that never leave our own infrastructure. Whichever handles a request, it receives the brand answers without your name, email, or account details, and may not use them for its own purposes. Payment details for paid plans are handled by our payment processor and never touch our servers.
4. What we never do
We never sell your personal data. We never use your clients' private intake responses for advertising or to train models made available to anyone else. We never publish your briefs. Sharing is always your action.
5. Who we share with
Only the service providers that run Intake: Cloudflare (hosting and delivery), Clerk (authentication), Google (the language-model processing that composes briefs and powers suggestions, and the team inbox that receives Enterprise waitlist sign-ups — not fonts, which we self-host), PostHog (product analytics inside the app, and the usage counts described in §2 for this site), and a payment processor for paid plans. Each receives only what its role requires. Beyond that, we disclose data only if the law compels it or to protect the Service from abuse.
6. Retention and deletion
Account data and flow content are kept while your account is active. Delete a flow, a brief, or your whole account, and we remove the data from the live Service within a reasonable period; routine backups expire on their own schedule.
De-identified brand-strategy content kept for product improvement (section 7) is stored apart from your account and is not linked back to you. We can't remove content from a data set we've already prepared and used, and we can't remove it from a model that has already been trained. What we can do — and do — is exclude you from everything we prepare from that point on. If you want to know whether anything of yours was included before you opted out, ask us at the address below.
7. Product improvement, and your choices
During Intake's early-access period, and only if you're on the free plan, we ask for your consent to use a de-identified version of your brand-strategy content — things like your offerings, audience, and positioning — to improve Intake and the technology behind it. We ask when you create your account, and we record which version of this policy you agreed to.
Paid plans are never used for this. If you're on a paid plan, nothing you create is used to train or improve Intake's models, and there is nothing you need to switch off. If you're in the EU, the UK, or Switzerland, we don't use your content this way either, whatever plan you're on. Where we can't determine your location, we treat you as though you are.
Before anything is used, we remove what identifies you: your name, email address, phone number and account details are never included, and we strip business names, contact details and website addresses at the point we prepare the data. Attachments and images you upload are never used for this, on any plan, regardless of your settings.
You can turn product-improvement use off at any time in Settings → Privacy, or by emailing privacy@intake.design. It takes effect from the next time we prepare training data. You can also mark any individual brand profile as client work — if you're an agency, freelancer or consultant working on someone else's brand, use this: a profile marked client work is excluded completely, whatever your plan and whatever your account-level setting says.
8. Your rights
Wherever you are, we honor the substance of the GDPR and CCPA: you can ask for a copy of your personal data, ask us to correct it, or ask us to delete it. Email privacy@intake.design (or hello@intake.design) and we'll respond within 30 days. You won't be treated differently for exercising these rights.
9. Security
Traffic is encrypted in transit, access to production data is limited to those who operate the Service, and authentication is delegated to a dedicated provider rather than built in-house. No internet service can promise perfect security; if a breach affects your personal data we will notify you without undue delay.
10. Children
Intake is a professional tool and not directed at children. We don't knowingly collect personal data from anyone under 16.
11. Changes and contact
If this policy changes materially we'll give notice on the site or by email before the change takes effect. Questions, requests, complaints: privacy@intake.design. See also our Terms of Service.