Privacy Policy

Last updated August 30, 2026.

1. Who controls your data

DeepInquiry is the controller of personal information collected through the DeepInquiry website, API, and widget (the "Service"). Contact for privacy matters: api@deepinquiry.ai.

2. What we collect

We collect three categories of information:

Account information

  • Email address (required to create an account and receive your API key).
  • Plan and subscription status (Free, Starter, Pro, Scale, Enterprise; active / past_due / canceled).
  • The hash of your API key. We generate the raw key on the server, send it to you once by email, and store only a SHA-256 hash — we can't recover your key if you lose it, only issue you a new one.

Billing information

  • Handled entirely by Stripe. We receive from Stripe a customer ID, subscription ID, subscription status, and current-period timestamps — enough to gate your API access. We do not receive or store your card number, CVC, or full billing address.

Usage information

  • Which API endpoint each request hit, when it was made, and what fact ID (if any) it returned — used for quota accounting, rate limiting, and product analytics.
  • The IP address the request came from, kept only in short-lived server logs for abuse and security investigation (typically 30 days at Vercel, our hosting provider).
  • Standard browser cookies on deepinquiry.ai for session state when you're signed in. No third-party ad cookies, no cross-site tracking pixels.

What we don't collect: we don't ask for your name, address, phone number, date of birth, or any special-category data (health, religion, race, etc.).

3. How we use it

  • Operate the Service — authenticate your API key, enforce quotas, rate-limit, bill your card, send you transactional email (welcome, key rotation, billing failure).
  • Improve the Service — aggregate usage statistics (which endpoints are popular, error rates, latency). This is at the anonymized-aggregate level; we don't profile individual customers.
  • Comply with law — respond to lawful requests from regulators, courts, or law enforcement.
  • Protect the Service — investigate abuse, fraud, or attacks.

We do not use your API-request payloads or responses to train AI models. We do not sell, rent, or trade your personal information.

4. Legal bases (GDPR / UK GDPR)

If you're in the EU, UK, or Switzerland, our legal bases are:

  • Contract — for account creation, key issuance, quota enforcement, and billing (Article 6(1)(b)).
  • Legitimate interests — for security, abuse prevention, and product-improvement analytics on aggregate data (Article 6(1)(f)). You can object; contact us and we'll evaluate.
  • Legal obligation — for tax, accounting, and responses to lawful requests (Article 6(1)(c)).

5. Who we share with (subprocessors)

We use these third-party services to run DeepInquiry. Each of them receives only the minimum data they need for their function:

SubprocessorPurposeData sharedLocation
StripePayments, subscriptionsEmail, billing details, cardUS
VercelWebsite + API hostingRequest logs, IPUS / global CDN
SupabaseManaged PostgresAccount + usage rowsUS
ResendTransactional emailEmail addressUS
SentryError monitoringError stacks, request URLsUS
CloudflareDNS + edge networkRequest metadata, IPGlobal

We may add or replace subprocessors over time. When we do, we'll update this table. If you're on an Enterprise plan and need a notice-in-advance clause, email api@deepinquiry.ai.

6. International data transfers

Our servers and subprocessors are primarily in the United States. If you're in the EU/UK, your data will be transferred to and stored in the US. Where required, we rely on the EU Standard Contractual Clauses (and UK IDTA / Swiss addenda) that our subprocessors have in place, and on the EU-US Data Privacy Framework where applicable.

7. How long we keep it

  • Account records — while your account is active, plus up to 24 months after you delete it, to handle billing disputes and legal requirements.
  • API usage logs — up to 13 months, then aggregated and the row-level data is deleted.
  • Server request logs at Vercel — typically 30 days.
  • Billing records — retained for at least 7 years to meet tax and accounting rules.

8. Your rights

Depending on where you live, you have some or all of these rights over your personal information:

  • Access — ask for a copy of the personal information we hold about you.
  • Correction — ask us to fix inaccurate information.
  • Deletion — ask us to delete your account and associated personal information. We may retain billing records we're legally required to keep.
  • Portability — receive your data in a machine-readable format.
  • Objection / restriction — object to certain processing based on legitimate interests, or ask us to restrict processing while a dispute is being resolved.
  • Opt out of "sale" — we don't sell personal information as defined by the CCPA/CPRA, but California residents have the right to opt out anyway, and this section is your opt-out mechanism.
  • No retaliation — we won't discriminate against you for exercising these rights.

To exercise any of these, email api@deepinquiry.ai from the address on your account. We'll respond within 30 days (GDPR) or 45 days (CCPA/CPRA), and may need to verify your identity first. EU residents may also complain to their local Data Protection Authority; UK residents may complain to the ICO.

9. Cookies

deepinquiry.ai uses a small set of first-party cookies strictly for sign-in session state and CSRF protection. We do not set advertising, cross-site tracking, or third-party analytics cookies. If we ever add product analytics that use cookies, we'll add a consent banner and update this section.

10. Children

DeepInquiry is not directed at children under 13 (or 16 in the EU/UK). We do not knowingly collect personal information from children. If you believe we have collected information from a child, email us and we'll delete it.

11. Security

We use industry-standard security controls including TLS in transit, hashing (SHA-256) for API keys at rest, managed database encryption at rest (Supabase), and least-privilege access to production systems. No system is 100% secure — if you find a vulnerability, email api@deepinquiry.ai and we'll respond fast.

12. Changes to this policy

We'll update this policy when our data practices change. Non-material updates (typo fixes, new links) go into effect on publication. Material updates (new subprocessors handling personal data, new categories collected, changed retention windows) will be announced by email to registered users at least 14 days before they take effect.

Contact

Privacy questions or data-rights requests: api@deepinquiry.ai.

DeepInquiry is operated by Epic Sky, LLC, a Delaware limited liability company.