Privacy

Privacy summary for the ITK product

This page summarises how the current product handles account data, connected platform data, and billing-related information. It is written to match the present application architecture rather than a broader policy template.

What data the product stores

ITK stores account details needed for authentication, tenant assignment, reporting, integrations, and billing reconciliation. This may include names, email addresses, agency and client records, integration metadata, report content, and subscription records.

Connected platform data

The current product supports Meta, Google, Shopify, and WooCommerce connections. Tokens and credentials are intended to be handled through the hardened integration path and are not advertised publicly beyond the integrations the codebase actually supports.

How we share data

We do not sell, rent, or trade your data, including data obtained through connected Google integrations, to third parties. We share this data only with Anthropic, the provider of the Claude AI model, solely to generate the reports and insights you see within ITK. Anthropic does not use data sent through the API to train or improve its AI models. We do not share, transfer, or disclose Google user data for any purpose other than providing and improving the core functionality of the ITK platform.

How we protect data

Data in transit is encrypted using industry-standard TLS/SSL. Data at rest, including data from connected Google integrations, is stored using Supabase, which provides encryption at rest and row-level security to restrict access on a per-account basis. Access to this data within ITK is limited to the systems and processes required to deliver the service, and is protected by authentication and access controls.

Data retention and deletion

We retain data from connected Google integrations for as long as the integration remains connected and your account remains active, in order to provide our reporting and analytics services. If you disconnect a Google integration, the associated Google user data is deleted from our systems. If you delete your ITK account, all associated Google user data is deleted. You may also request deletion of your data at any time by contacting us.

Core processors

The application currently depends on Supabase for authentication and database services, Stripe for paid billing flows, Resend for transactional email where enabled, and Anthropic's Claude for AI-generated report sections when configured.

Public promise on privacy

The public site does not make unsupported claims around certifications, sector-specific compliance, or bespoke data processing terms. If you need those assurances before rollout, handle that as part of the commercial onboarding process.

Last updated: 13 July 2026