Privacy Policy.
This notice sets out how Invoke HQ, Inc. collects, uses, discloses and retains personal data in connection with the Invoke platform, and the rights available in respect of that data. It is written to be read: the categories are the categories actually processed, and the recipients are the recipients actually engaged.
Two capacities, and why the distinction matters.
Invoke handles personal data in two distinct capacities. Which one applies determines who is accountable for it and to whom a request should be directed.
- 1.1Invoke as controller
- In respect of account holders, prospective customers, visitors to the website and correspondents, Invoke determines the purposes and means of processing and acts as a controller. This notice is the notice required of a controller, and a request under Section 10 in respect of such data should be made to Invoke directly.
- 1.2Invoke as processor
- In respect of data a customer causes to be processed through its workspaces — the arguments passed to a tool, the content of workspace memory, the records of a customer’s own end users — Invoke acts as a processor on that customer’s documented instructions. The customer is the controller. A data subject with a request in respect of such data should direct it to that customer, and Invoke will assist the customer in responding. The terms of that processing are set out in the data processing agreement available from security@invokehq.run.
- 1.3Application
- This notice applies to the invokehq.run website, the hosted Service and the console. It does not apply to a third-party service the customer elects to connect, nor to Foundry running on the customer’s own infrastructure, where data does not reach Invoke at all unless the customer pushes it.
What is collected, and what is not.
2.1 Categories collected
| Account and identity | Name, email address, profile image and authentication identifiers, together with the organisation, workspaces and role to which the account belongs. |
| Billing | Billing contact, billing address and subscription record. Payment card details are collected and held by the payment processor; Invoke does not receive a primary account number. |
| Correspondence | The content of support requests, security reports and other messages sent to Invoke, together with the address they were sent from. |
| Execution metadata | Tool identifier, arguments, Principal, timing, outcome and cost for each execution performed through a workspace, together with the signed receipt recording it. Where a Customer's own configuration causes personal data to appear in a tool argument, that data is processed by Invoke as a processor under Clause 1.2. |
| Workspace memory | Context expressly shared between agents by the Customer, together with its revision history. |
| Operational logs | Request logs, error traces, IP address, user-agent string and timestamps, generated in the ordinary course of serving a request. |
| Product analytics | Pages viewed and features used within the web application, collected as described at Clause 5.2. |
- 2.2Sources
- Personal data is obtained directly from the individual, generated by use of the Service, received from an identity provider where the individual elects to sign in with one (Section 3), or received from the payment processor in respect of billing status. Invoke does not purchase personal data and does not acquire it from data brokers.
2.3 Categories not collected
- Plaintext credentials — API credentials are retained as
SHA-256digests only. Connector credentials are never returned by the API. - Cardholder data — held by the payment processor; Invoke does not receive a primary account number.
- Special category data — Invoke does not knowingly collect data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health, sex life or sexual orientation, and asks that such data not be submitted to the Service.
- Training corpora — no personal data is used to train, fine-tune or evaluate any model.
- Advertising identifiers — Invoke operates no advertising cookies, no cross-context behavioural advertising and no third-party ad networks.
What is received from a Google account, and what is done with it.
Where an individual elects to sign in with Google, authentication is mediated by Clerk. This clause states the position in the specific terms Google requires.
- 3.1Data received
- Invoke receives only the basic profile information released by Google on sign-in: name, email address, email verification status, profile image and the Google account identifier. Invoke requests no other Google API scope, and accesses no Gmail, Drive, Calendar, Contacts or other Google user data.
- 3.2Use
- That information is used solely to create and authenticate the account, to identify the individual within their organisation, and to send service and security notices. It is not used for advertising, is not sold or shared, is not disclosed to any third party other than the sub-processors listed at Clause 6.1, and is not used to train, fine-tune or evaluate any model.
- 3.3Limited use
- Invoke’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
- 3.4Disconnection
- An individual may disconnect the Google connection at any time from their Google account security settings, and may delete their Invoke account under Clause 10.3. Disconnection does not by itself delete the Invoke account.
Why each category is processed.
Legal bases are stated by reference to the UK and EU General Data Protection Regulation. Where processing rests on legitimate interests, Invoke has considered the rights of the individual and the basis is stated below rather than asserted generically.
| Purpose | Categories | Legal basis |
|---|---|---|
| Providing the Service | Account and identity, execution metadata, workspace memory | Performance of a contract (GDPR Art. 6(1)(b)) |
| Maintaining the audit record | Execution metadata, receipts, identity of the Principal | Legitimate interests — an audit record that can be altered is not an audit record (Art. 6(1)(f)) |
| Security, abuse prevention and integrity | Operational logs, IP address, credential digests | Legitimate interests in securing the Service and protecting customers (Art. 6(1)(f)) |
| Support and correspondence | Account and identity, correspondence | Performance of a contract; legitimate interests (Art. 6(1)(b), (f)) |
| Billing and collection | Billing record, account and identity | Performance of a contract; legal obligation (Art. 6(1)(b), (c)) |
| Understanding product use | Product analytics | Legitimate interests in improving the Service, or consent where required by local law (Art. 6(1)(f) or (a)) |
| Service and security notices | Account and identity | Performance of a contract; legal obligation in the case of breach notification (Art. 6(1)(b), (c)) |
| Compliance with law | Any category, to the extent compelled | Legal obligation (Art. 6(1)(c)) |
- 4.1No secondary use
- Personal data is not used for a purpose materially different from those stated above without further notice and, where required, consent. In particular, it is not used to train models, is not sold, and is not disclosed for another party’s marketing.
- 4.2Marketing
- Invoke sends product and marketing email only where the recipient has requested it or where permitted by applicable law in respect of an existing customer. Every such message carries an unsubscribe mechanism, and withdrawal takes effect promptly. Service and security notices are not marketing and cannot be unsubscribed from while an account remains open.
Who receives personal data, and where it goes.
6.1 Sub-processors
The following third parties process personal data in the course of providing the Service. Each is engaged under a written agreement imposing obligations no less protective than those in this notice. The authoritative, dated register — including the location and purpose of each — is maintained at Security § 12.
| Vercel | Frontend hosting and edge delivery |
| Render | API and control-plane compute |
| Supabase | Managed Postgres — ledger, receipts, workspace records |
| Amazon Web Services | Underlying infrastructure for managed Postgres and backups |
| Clerk | Authentication, session and organisation management |
| PostHog | Product analytics in respect of the web application (first-party proxied) |
| Model providers | Engaged only where the Customer elects to route model traffic through the Service |
- 6.2Other disclosures
- Personal data is otherwise disclosed only:
- (a)to professional advisers bound by a duty of confidence;
- (b)where compelled by law, by a court or by a regulator, in which case Invoke will notify the affected customer unless prohibited from doing so, and will resist a request which appears overbroad or unlawful;
- (c)in connection with a merger, acquisition or sale of assets, in which case this notice continues to apply until superseded on notice;
- (d)with the individual's consent.
- 6.3No sale or sharing
- Invoke does not sell personal information and does not share it for cross-context behavioural advertising, as those terms are defined by the California Consumer Privacy Act, and has not done so in the preceding twelve months. This includes personal information of individuals under 16.
- 7.1Processing location
- All personal data is processed and stored in the United States. Residency within the European Union is not presently offered and is stated as a roadmap item at Security § 6.5.
- 7.2Transfer mechanism
- Where personal data is transferred from the European Economic Area, the United Kingdom or Switzerland to the United States, the transfer is made under the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable, and subject to a transfer impact assessment. A copy of the clauses as executed is available on request.
How long data is kept, and how it is protected.
- 8.1Retention periods
- (a)Ledger events and receipts — retained for the lifetime of the workspace to which they relate. An audit record subject to automatic expiry does not constitute an audit record, so these are not aged out on a timer.
- (b)Account and organisation records — retained while the account is open, and deleted on closure in accordance with (d).
- (c)Operational logs — retained for 30 days.
- (d)Deleted workspaces and closed accounts — purged within 30 days of deletion, including from backup media.
- (e)Billing records — retained for the period required by tax and accounting law, notwithstanding closure of the account.
- (f)Correspondence — retained while relevant to the matter and to any limitation period applying to it.
- 9.1Security measures
- Personal data is encrypted in transit under TLS 1.2 or higher and at rest under AES-256. Access to production systems is restricted to named personnel, requires multi-factor authentication and is logged. Credentials are retained as digests rather than as plaintext. The full description of technical and organisational measures is published at Security, which is written for vendor assessment and is intended to be forwarded.
- 9.2Breach notification
- Where a personal data breach occurs, Invoke notifies the affected customer without undue delay and in any event within 72 hours of confirmation, and notifies supervisory authorities and individuals where required by law.
What may be requested, and how.
The rights available depend on where the individual is. Invoke does not distinguish between individuals when honouring a request that it is able to honour, and applies the rights below to all individuals as a matter of practice regardless of jurisdiction.
- 10.1Rights under the UK and EU GDPR
- An individual in the United Kingdom or the European Economic Area has the right to request access to their personal data, its rectification, its erasure and the restriction of its processing; the right to data portability; the right to object to processing carried out on the basis of legitimate interests; and the right to withdraw consent where processing rests on consent, without affecting processing already carried out.
- 10.2Rights under California law
- A California resident has the right to know the categories and specific pieces of personal information collected, the sources, the purposes and the categories of recipients; the right to delete personal information; the right to correct inaccurate personal information; the right to opt out of sale or sharing — which Invoke does not engage in, per Clause 6.3; the right to limit the use of sensitive personal information, which Invoke does not collect for a purpose requiring that limit; and the right not to receive discriminatory treatment for exercising a right. Invoke does not offer financial incentives for personal information. Comparable rights under the privacy laws of other states are honoured on the same terms.
- 10.3Exercising a right
- A workspace may be deleted from the console at any time. Account deletion, access requests and export of the ledger in a machine-readable form are administered on request to security@invokehq.run, and are completed within 30 days. Invoke will verify the identity of the requester by reference to the account, and may decline a request it cannot verify. A request may be made by an authorised agent on production of authority. No fee is charged for a first request within any twelve-month period.
- 10.4Requests concerning customer data
- Where a request concerns data processed by Invoke as a processor under Clause 1.2, Invoke will refer the requester to the relevant customer and will assist that customer in responding. Invoke will not itself erase or disclose such data other than on that customer’s instruction or where compelled by law.
- 10.5Complaints
- A complaint may be made to Invoke at the address above and will receive a substantive response. An individual in the European Economic Area or the United Kingdom also has the right to complain to their local supervisory authority, and is not required to raise the matter with Invoke first.
- 11.1Automated decision-making
- Invoke does not make decisions producing legal or similarly significant effects concerning an individual by automated means, and does not profile individuals for that purpose. Where a customer configures an agent that makes such a decision, the customer is the controller of that processing and is responsible for the lawful basis, the notice, the human involvement and any right of contest which the law requires. Section 5.4 of the Terms of Service allocates that responsibility expressly.
- 12.1Children
- The Service is not directed to children. Invoke does not knowingly collect personal data from a person under 18. Where Invoke becomes aware that it has done so, it deletes that data. A parent or guardian who believes a child has provided personal data should contact the address at Clause 13.2.
- 13.1Changes to this notice
- Invoke may amend this notice. The version and effective date are recorded in the document-control block above. Where an amendment is material, Invoke will give notice by electronic mail to account holders, or by prominent notice within the Service, before it takes effect.
- 13.2Contact
- Enquiries, requests under Section 10 and complaints should be addressed to security@invokehq.run. The controller for the purposes of this notice is Invoke HQ, Inc.. Invoke has not appointed a data protection officer, not being required to do so; the address above is the point of contact for all matters arising under this notice.
Privacy enquiries.
Data processing agreements, transfer documentation and requests under Section 10 are handled by the same team that maintains the systems described at Security.