Privacy Policy
The short version. We collect what we need to run your account, deliver the design service you asked for, and take payment. We never see or store your card number — Stripe handles that. We don't sell personal data or use it for advertising. Your designs are yours; we don't train models on them. You can access, correct, export or delete your data at any time.
- Who is responsible for your data
- What we collect
- Why we use it, and our legal basis
- Payments and card data
- AI processing of your designs and prompts
- Who we share data with
- International transfers
- How long we keep it
- Your rights
- European Economic Area and United Kingdom
- Canada
- Australia
- United States
- Cookies and similar technologies
- Security
- Children
- Changes
- Contact and complaints
1. Who is responsible for your data
InnovaBeam is the controller of the personal data described in this policy (in some laws, the "business" or "organisation" responsible for it).
InnovaBeam LLC
30 N Gould St Ste R
Sheridan, WY 82801
United States
Email: contact@innovabeam.com
2. What we collect
| Category | Examples | Where it comes from |
|---|---|---|
| Account data | Email address, display name, password (stored only as a cryptographic hash by our authentication provider), profession or role if you provide it, sign-in method. | You, at sign-up. Or Google, if you sign in with a Google account. |
| Your designs and files | CAD models, drawings, images, documents, project names, chat messages with our assistant and our specialists. | You, as you use the Service. |
| Subscription and billing data | Plan, price paid, billing cycle, subscription status, renewal date, billing country, the country your card was issued in, any VAT/tax identifier you supply, and payment references. | You and Stripe. Not your card number — see section 4. |
| Usage data | Features used, actions taken in the app, timestamps, approximate error and performance information. | Automatically, as you use the Service. |
| Technical data | IP address, browser and device type, and session identifiers. | Automatically, from your device. |
| Support and feedback | Messages you send us, feedback submissions, and any screenshot you choose to attach. | You. |
We do not deliberately collect special categories of data (such as health or biometric data). Please do not put such data into designs, file names or chat messages.
3. Why we use it, and our legal basis
Where the GDPR or UK GDPR applies, our legal bases are shown in the last column.
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and run your account; authenticate you; keep you signed in. | Account, technical | Performance of a contract |
| Provide the design workspace: store, render, convert and share your models. | Designs, usage | Performance of a contract |
| Fulfil design requests handled by our specialists. | Designs, account, messages | Performance of a contract |
| Take payment, manage subscriptions, prevent failed and duplicate charges. | Billing | Performance of a contract |
| Meet tax obligations and keep accounting records, including evidence of the customer's location where tax law requires it. | Billing, technical | Legal obligation |
| Send service messages: delivery notices, payment problems, security and policy changes. | Account | Performance of a contract |
| Keep the Service secure: detect abuse, enforce limits, investigate incidents. | Technical, usage | Legitimate interests — protecting the Service and its users |
| Understand which features are used so we can improve them. | Usage | Legitimate interests — improving a service you asked for |
| Send re-engagement or product emails where you have not opted out. | Account, usage | Consent, or legitimate interests where permitted; you can unsubscribe at any time |
| Establish, exercise or defend legal claims. | Any relevant | Legitimate interests / legal obligation |
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights, and you may object — see section 9.
4. Payments and card data
Payments are processed by Stripe, Inc. as an independent controller of the payment data it collects.
We never receive your card number, expiry date or security code. Those are entered on Stripe's own hosted checkout page and go directly to Stripe. InnovaBeam's servers never see them and cannot store them.
What we do receive from Stripe, and store: whether payment succeeded, the amount and currency, the subscription and customer reference, the billing country you entered, the country your card was issued in, any tax identifier you supplied, and the renewal date.
We keep the billing country and card country because tax law for digital services requires a seller to hold evidence of where the customer is located. We record whether those two pieces of evidence agree, so that inconsistent cases can be reviewed by a person.
Stripe's handling of payment data is governed by its own privacy policy at stripe.com/privacy.
5. AI processing of your designs and prompts
When you use the AI assistant, sketch generation, translation or summarisation, the text and any images you supply are sent to Google's Gemini API to generate a response, and the response is returned to you.
- This happens only when you use an AI feature. Simply storing a model does not send it to an AI provider.
- We do not use your content to train our own models.
- Google processes this data under its own terms as our processor for the API service. We do not control Google's retention for abuse-monitoring purposes.
If you would prefer your designs never be sent to a third-party AI provider, do not use the AI features; the rest of the workspace functions without them.
6. Who we share data with
We do not sell personal data, and we do not share it for cross-context behavioural advertising. We share it only with:
| Recipient | Purpose | Location |
|---|---|---|
| Google Cloud / Firebase | Hosting, database, file storage, authentication | United States |
| Google (Gemini API) | AI features you actively use | United States |
| Stripe | Payments, subscriptions, invoices | United States |
| Resend | Transactional and notification email | United States / EU |
| Our specialists | Fulfilling design requests you submit | As applicable |
| Professional advisers, authorities | Where legally required, or to establish or defend legal claims | As applicable |
If our business is ever sold or reorganised, personal data may transfer to the acquirer, who would remain bound by this policy or give notice of any change.
7. International transfers
We are based in the United States and our providers are largely US-based, so personal data of users in the EEA, UK, Switzerland, Canada or Australia is transferred outside their home country.
For transfers from the EEA and UK, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum / International Data Transfer Agreement where applicable), together with the safeguards offered by our providers. You may request a copy of the relevant safeguards by writing to us.
8. How long we keep it
| Data | Retention |
|---|---|
| Account and profile | While your account exists, then deleted or anonymised within 30 days of account deletion. |
| Designs, models, files, project chat | While your account exists. Deleted with the account, subject to backup cycles of up to 90 days. |
| Billing and tax records | Retained for as long as tax and accounting law requires — commonly 7 years — even after account deletion. |
| Subscription and payment audit records | Retained with billing records, as evidence of what was charged and why. |
| Security and abuse records | Up to 24 months. |
| Shared model links | Expire automatically 7 days after creation. |
| Support correspondence | Up to 24 months after the matter is closed. |
9. Your rights
Wherever you live, you can ask us to:
- Access the personal data we hold about you, and receive a copy;
- Correct data that is wrong or incomplete;
- Delete your data, subject to records we must keep by law (such as invoices);
- Export your data in a portable, machine-readable format;
- Object to or restrict certain processing, including processing based on legitimate interests;
- Withdraw consent at any time where we rely on it, without affecting processing already carried out;
- Unsubscribe from non-essential email using the link in any such message.
Write to contact@innovabeam.com. We will respond within 30 days, or tell you if we need longer where the law allows. We will not charge you or treat you differently for exercising a right. We may need to verify your identity first.
We do not make decisions producing legal or similarly significant effects about you by automated means alone.
10. European Economic Area and United Kingdom
If you are in the EEA or UK, the GDPR or UK GDPR applies and section 9 sets out your rights under it, including the right to data portability and the right to object.
You also have the right to lodge a complaint with your national supervisory authority. In the UK that is the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to address your concern first.
11. Canada
We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial legislation, including Quebec's Law 25.
We collect only what is needed for the purposes described here, obtain consent where required, and you may withdraw consent subject to legal and contractual restrictions. You may ask for access to your information and challenge its accuracy. You may complain to us first and then to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or your provincial regulator.
As noted in section 7, personal information is stored and processed outside Canada, principally in the United States, and is therefore subject to the laws of those countries.
12. Australia
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
You may request access to and correction of your personal information under APP 12 and APP 13 by writing to us. As set out in section 7, we disclose personal information to overseas recipients, principally in the United States.
If you are unhappy with how we have handled your information, contact us first. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au).
13. United States
Residents of California, Colorado, Connecticut, Virginia and other states with comprehensive privacy laws have rights to know, access, correct, delete and obtain a portable copy of their personal information, and to be free from discrimination for exercising those rights. Section 9 explains how to exercise them.
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under the California Consumer Privacy Act. We have not done so in the preceding twelve months. We do not knowingly process the personal information of anyone under 16 for those purposes.
Where state law provides for an appeal against our decision on a request, you may appeal by replying to our response, and you may contact your state Attorney General if you remain dissatisfied.
14. Cookies and similar technologies
We keep our use of cookies and local storage deliberately minimal, and we do not use advertising or cross-site tracking cookies.
| What | Purpose | Type |
|---|---|---|
| Authentication tokens | Keep you signed in securely between visits. | Strictly necessary (local storage) |
ib_signed_in | A flag, not a session, letting the marketing site show "Go to Dashboard" instead of "Log In". | Strictly necessary (cookie) |
| Local model cache | Stores your models in your browser so they open quickly. | Strictly necessary (IndexedDB) |
| Product analytics | First-party record of which features are used. Not shared with advertisers. | Analytics |
You can clear this data through your browser at any time; doing so will sign you out and clear locally cached models.
15. Security
We use encryption in transit, access controls that restrict data to the account it belongs to, server-side enforcement of permissions, and audit records for changes affecting billing and access. Payment card data never reaches our systems.
No system is perfectly secure. If a breach affects your personal data and the law requires notification, we will notify you and the relevant regulator within the timeframes that apply — for the GDPR, without undue delay and within 72 hours of becoming aware where feasible.
16. Children
The Service is not directed at children under 16, and we do not knowingly collect their personal data. If you believe a child has given us personal data, write to us and we will delete it.
17. Changes
We may update this policy. The version and date at the top always show the current edition. For material changes we will give notice by email or in the Service before they take effect.
18. Contact and complaints
Privacy questions, requests and complaints: contact@innovabeam.com
InnovaBeam LLC
30 N Gould St Ste R
Sheridan, WY 82801
United States