Privacy policy
The short version: we do not store what you write, we hide private numbers before the AI sees your text, and we keep only what is needed to run your account.
Last updated: 8 October 2026
Who we are
Inkaret is run by Inkaret, 15, Ramnagar, Katargam, Surat, Gujarat, India (“we”, “us”). For any privacy question, write to [email protected].
What we do with the text you write
- We read it only when you ask. The extension reads a message box, or the text you selected, at the moment you choose an action. It does not monitor your typing or the pages you visit.
- We do not store it. Your text and the result are held in our server’s memory only while your request is answered. They are not written to a database, a log or a backup.
- We hide private numbers first. Before your text is sent to the AI, we replace details that have a recognisable form with placeholders: government and tax ID numbers in the formats we recognise (for example passport, social security, national insurance, Aadhaar and PAN numbers), payment card numbers, bank account numbers including IBANs, phone numbers, email addresses and dates of birth. Formats we do not yet recognise are not replaced. The real values are put back only in the result shown to you.
- What is not hidden. People’s names and other free-form personal details cannot be detected reliably, so they are sent as you wrote them. Do not use Inkaret for text you are not permitted to share with a service provider.
What we keep
| Information | Why we keep it |
|---|---|
| Your email address and, if you sign in with Google, your name and Google account ID | To create your account and sign you in |
| “About me” choices (for example “Business owner”, “Formal”) | To shape results. These are picked from fixed lists; there is no free-text field. |
| A record of each installed extension or app, and when it was last used | So you can see and sign out your devices |
| For each use: the date and time, the action (for example “Rephrase”), the length of the text, how many details were hidden, and which AI model answered | To apply usage limits, prevent abuse and understand costs. The text itself is not part of this record. |
| One-time sign-in codes (stored only in scrambled form) and the network address they were requested from | To sign you in by email and stop repeated attempts |
We do not sell your information, and we do not use it for advertising.
Who else handles your data
| Service | What it receives |
|---|---|
| AI providers: Anthropic, OpenAI or Google | The text of your request with private numbers already replaced by placeholders, sent through their business APIs to produce the result. One provider handles each request. |
| Google (sign-in) | Only what is needed to confirm your identity, if you choose “Sign in with Google” |
| Our email service | Your email address and the sign-in code, if you choose to sign in by email |
| Our hosting provider | Stores the account information listed above |
| Paddle (when paid plans start) | Payment details, which go to Paddle directly and never reach us |
The Chrome extension
- It needs access to the pages you visit so that it can show the pen icon in message boxes and put results back. It reads page content only when you choose an action.
- It stores on your device: your sign-in token, whether the icon is switched on, and the list of sites where you have hidden it.
- It never opens password, payment card or one-time-code fields.
- Inkaret’s use of information received from Chrome follows the Chrome Web Store User Data Policy, including its Limited Use requirements.
Cookies
The website uses one essential cookie to keep you signed in and one to protect forms from misuse. We do not use advertising or tracking cookies.
How long we keep things
- Account information: until you delete your account.
- Usage records: up to 24 months, then deleted or made anonymous.
- Sign-in codes: 10 minutes of validity, removed shortly after.
Your choices
- See and change your details and devices on your account page.
- Delete your account there at any time. This removes your profile, devices and usage records.
- Ask us for a copy of your information, or to correct it, at [email protected]. We answer within 30 days.
Children
Inkaret is not intended for children under 13, and we do not knowingly collect information from them.
Security
Connections are encrypted. Device tokens and sign-in codes are stored only in scrambled form. No system is perfectly secure; if we learn of a breach affecting your information, we will tell you.
Changes to this policy
If we change this policy in a way that matters, we will update the date above and tell signed-in users before the change takes effect.