Privacy Policy

Last updated: 2026-07-01 · Applies to all use of getinner.ai and the Inner API.

Plain-English summary. We collect the minimum needed to run scans and let you sign in: your email, your API key, and the packages you tell us to look at. We don't sell your data. Scan bytes stay in ephemeral sandbox storage; hashes and findings persist so we can serve verdicts and reproduce them. If you want your account deleted, email us.

1. Who we are

This Policy explains how Inner Technologies, Inc., a Delaware corporation doing business as Inner ("Inner", "we", "us"), collects and handles personal information when you use getinner.ai, the Inner API, or embed our badge on your website.

2. What we collect

CategoryWhatWhy
AccountEmail, display name, API keySign-in, rate-limiting, contact for account issues.
Scan inputPackage name, version, ecosystem; git URLs you submitTo run the scan and return a verdict.
Scan artifactsPackage tarballs (transient), file hashes, static findings, behavioral traces (egress log, audit events, exit codes)To produce verdicts and reproduce them for review. Package bytes are held in ephemeral sandbox storage during the scan and then destroyed with the sandbox instance.
LLM promptPackage name, declared purpose from public registry, top findings, cross-referenced verdictsSent to our LLM provider (OpenAI) to produce a final verdict. Prompt does NOT include your account email or API key.
TelemetryIP address (for rate-limiting), request timestamps, error rates, aggregate scan countsOperate the Service, prevent abuse, monitor uptime.
CookiesA basic-auth session for /admin (staff only). No third-party ad or tracking cookies on public pages.Sign-in.

3. What we do NOT collect

4. How we use information

5. Who we share information with

Our sub-processors handle infrastructure required to run the Service:

We may also share information (a) with your consent, (b) if required by law, (c) to protect our rights or the safety of our users, or (d) in connection with a merger or acquisition, subject to this Policy.

6. Retention

WhatHow long
Account recordsUntil account deletion + 30 days for audit backups.
Scan verdicts + hashesRetained indefinitely; verdicts are signed evidence.
Package tarballs (sandbox bytes)Ephemeral. Destroyed with the sandbox instance, typically within minutes of the scan.
LLM request logs (our side)90 days, then deleted.
IP address in access logs30 days, then aggregated.

7. Your rights

If you're in the EU, UK, California, or another jurisdiction with data-subject rights, you may have the right to access, correct, delete, or export your personal information, and to object to certain processing. Email privacy@getinner.ai to exercise these rights. We'll respond within 30 days.

8. Security

9. Children

The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe we have, email privacy@getinner.ai and we will delete it.

10. International transfers

Inner is operated from the United States. If you access the Service from outside the U.S., you consent to your information being processed in the U.S., subject to appropriate safeguards where required by law.

11. Changes to this Policy

We may update this Policy periodically. Material changes will be announced at least 15 days in advance. The "Last updated" date at the top always reflects the current version.

12. Contact

Privacy: privacy@getinner.ai
Security: security@getinner.ai
General: founders@getinner.ai