Privacy Policy/Version 1.0·Effective 10 August 2026

Privacy Policy.

This notice sets out how Invoke HQ, Inc. collects, uses, discloses and retains personal data in connection with the Invoke platform, and the rights available in respect of that data. It is written to be read: the categories are the categories actually processed, and the recipients are the recipients actually engaged.

Section 1Scope and roles

Two capacities, and why the distinction matters.

Invoke handles personal data in two distinct capacities. Which one applies determines who is accountable for it and to whom a request should be directed.

1.1Invoke as controller
In respect of account holders, prospective customers, visitors to the website and correspondents, Invoke determines the purposes and means of processing and acts as a controller. This notice is the notice required of a controller, and a request under Section 10 in respect of such data should be made to Invoke directly.
1.2Invoke as processor
In respect of data a customer causes to be processed through its workspaces — the arguments passed to a tool, the content of workspace memory, the records of a customer’s own end users — Invoke acts as a processor on that customer’s documented instructions. The customer is the controller. A data subject with a request in respect of such data should direct it to that customer, and Invoke will assist the customer in responding. The terms of that processing are set out in the data processing agreement available from security@invokehq.run.
1.3Application
This notice applies to the invokehq.run website, the hosted Service and the console. It does not apply to a third-party service the customer elects to connect, nor to Foundry running on the customer’s own infrastructure, where data does not reach Invoke at all unless the customer pushes it.
Section 2Personal data processed

What is collected, and what is not.

2.1 Categories collected

Account and identityName, email address, profile image and authentication identifiers, together with the organisation, workspaces and role to which the account belongs.
BillingBilling contact, billing address and subscription record. Payment card details are collected and held by the payment processor; Invoke does not receive a primary account number.
CorrespondenceThe content of support requests, security reports and other messages sent to Invoke, together with the address they were sent from.
Execution metadataTool identifier, arguments, Principal, timing, outcome and cost for each execution performed through a workspace, together with the signed receipt recording it. Where a Customer's own configuration causes personal data to appear in a tool argument, that data is processed by Invoke as a processor under Clause 1.2.
Workspace memoryContext expressly shared between agents by the Customer, together with its revision history.
Operational logsRequest logs, error traces, IP address, user-agent string and timestamps, generated in the ordinary course of serving a request.
Product analyticsPages viewed and features used within the web application, collected as described at Clause 5.2.
2.2Sources
Personal data is obtained directly from the individual, generated by use of the Service, received from an identity provider where the individual elects to sign in with one (Section 3), or received from the payment processor in respect of billing status. Invoke does not purchase personal data and does not acquire it from data brokers.

2.3 Categories not collected

  • Plaintext credentials — API credentials are retained as SHA-256 digests only. Connector credentials are never returned by the API.
  • Cardholder data — held by the payment processor; Invoke does not receive a primary account number.
  • Special category data — Invoke does not knowingly collect data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health, sex life or sexual orientation, and asks that such data not be submitted to the Service.
  • Training corpora — no personal data is used to train, fine-tune or evaluate any model.
  • Advertising identifiers — Invoke operates no advertising cookies, no cross-context behavioural advertising and no third-party ad networks.
Section 3Sign-in with Google

What is received from a Google account, and what is done with it.

Where an individual elects to sign in with Google, authentication is mediated by Clerk. This clause states the position in the specific terms Google requires.

3.1Data received
Invoke receives only the basic profile information released by Google on sign-in: name, email address, email verification status, profile image and the Google account identifier. Invoke requests no other Google API scope, and accesses no Gmail, Drive, Calendar, Contacts or other Google user data.
3.2Use
That information is used solely to create and authenticate the account, to identify the individual within their organisation, and to send service and security notices. It is not used for advertising, is not sold or shared, is not disclosed to any third party other than the sub-processors listed at Clause 6.1, and is not used to train, fine-tune or evaluate any model.
3.3Limited use
Invoke’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
3.4Disconnection
An individual may disconnect the Google connection at any time from their Google account security settings, and may delete their Invoke account under Clause 10.3. Disconnection does not by itself delete the Invoke account.
Section 4Purposes and legal bases

Why each category is processed.

Legal bases are stated by reference to the UK and EU General Data Protection Regulation. Where processing rests on legitimate interests, Invoke has considered the rights of the individual and the basis is stated below rather than asserted generically.

PurposeCategoriesLegal basis
Providing the ServiceAccount and identity, execution metadata, workspace memoryPerformance of a contract (GDPR Art. 6(1)(b))
Maintaining the audit recordExecution metadata, receipts, identity of the PrincipalLegitimate interests — an audit record that can be altered is not an audit record (Art. 6(1)(f))
Security, abuse prevention and integrityOperational logs, IP address, credential digestsLegitimate interests in securing the Service and protecting customers (Art. 6(1)(f))
Support and correspondenceAccount and identity, correspondencePerformance of a contract; legitimate interests (Art. 6(1)(b), (f))
Billing and collectionBilling record, account and identityPerformance of a contract; legal obligation (Art. 6(1)(b), (c))
Understanding product useProduct analyticsLegitimate interests in improving the Service, or consent where required by local law (Art. 6(1)(f) or (a))
Service and security noticesAccount and identityPerformance of a contract; legal obligation in the case of breach notification (Art. 6(1)(b), (c))
Compliance with lawAny category, to the extent compelledLegal obligation (Art. 6(1)(c))
4.1No secondary use
Personal data is not used for a purpose materially different from those stated above without further notice and, where required, consent. In particular, it is not used to train models, is not sold, and is not disclosed for another party’s marketing.
4.2Marketing
Invoke sends product and marketing email only where the recipient has requested it or where permitted by applicable law in respect of an existing customer. Every such message carries an unsubscribe mechanism, and withdrawal takes effect promptly. Service and security notices are not marketing and cannot be unsubscribed from while an account remains open.
Section 5Cookies and analytics
5.1Strictly necessary cookies
The Service sets cookies required for authentication and session management, placed by Clerk, and cookies required for security and load balancing. These cannot be disabled without preventing sign-in.
5.2Product analytics
Invoke uses PostHog to understand how the web application is used. Analytics requests are proxied through a first-party path rather than loaded from a third-party domain, so that no third-party cookie is set and no cross-site identifier is created. Analytics data is used in aggregate to improve the product; it is not used to build a profile for advertising and is not disclosed to any advertising network.
5.3No advertising or cross-context tracking
Invoke operates no advertising cookies, no advertising pixels and no cross-context behavioural advertising, and does not participate in any third-party advertising network.
5.4Global Privacy Control
Invoke honours the Global Privacy Control signal where a browser transmits one, and treats it as an opt-out of analytics for that browser.
Sections 6 and 7Disclosure and transfers

Who receives personal data, and where it goes.

6.1 Sub-processors

The following third parties process personal data in the course of providing the Service. Each is engaged under a written agreement imposing obligations no less protective than those in this notice. The authoritative, dated register — including the location and purpose of each — is maintained at Security § 12.

VercelFrontend hosting and edge delivery
RenderAPI and control-plane compute
SupabaseManaged Postgres — ledger, receipts, workspace records
Amazon Web ServicesUnderlying infrastructure for managed Postgres and backups
ClerkAuthentication, session and organisation management
PostHogProduct analytics in respect of the web application (first-party proxied)
Model providersEngaged only where the Customer elects to route model traffic through the Service
6.2Other disclosures
Personal data is otherwise disclosed only:
  • (a)to professional advisers bound by a duty of confidence;
  • (b)where compelled by law, by a court or by a regulator, in which case Invoke will notify the affected customer unless prohibited from doing so, and will resist a request which appears overbroad or unlawful;
  • (c)in connection with a merger, acquisition or sale of assets, in which case this notice continues to apply until superseded on notice;
  • (d)with the individual's consent.
6.3No sale or sharing
Invoke does not sell personal information and does not share it for cross-context behavioural advertising, as those terms are defined by the California Consumer Privacy Act, and has not done so in the preceding twelve months. This includes personal information of individuals under 16.
7.1Processing location
All personal data is processed and stored in the United States. Residency within the European Union is not presently offered and is stated as a roadmap item at Security § 6.5.
7.2Transfer mechanism
Where personal data is transferred from the European Economic Area, the United Kingdom or Switzerland to the United States, the transfer is made under the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable, and subject to a transfer impact assessment. A copy of the clauses as executed is available on request.
Sections 8 and 9Retention and security

How long data is kept, and how it is protected.

8.1Retention periods
  • (a)Ledger events and receipts — retained for the lifetime of the workspace to which they relate. An audit record subject to automatic expiry does not constitute an audit record, so these are not aged out on a timer.
  • (b)Account and organisation records — retained while the account is open, and deleted on closure in accordance with (d).
  • (c)Operational logs — retained for 30 days.
  • (d)Deleted workspaces and closed accounts — purged within 30 days of deletion, including from backup media.
  • (e)Billing records — retained for the period required by tax and accounting law, notwithstanding closure of the account.
  • (f)Correspondence — retained while relevant to the matter and to any limitation period applying to it.
9.1Security measures
Personal data is encrypted in transit under TLS 1.2 or higher and at rest under AES-256. Access to production systems is restricted to named personnel, requires multi-factor authentication and is logged. Credentials are retained as digests rather than as plaintext. The full description of technical and organisational measures is published at Security, which is written for vendor assessment and is intended to be forwarded.
9.2Breach notification
Where a personal data breach occurs, Invoke notifies the affected customer without undue delay and in any event within 72 hours of confirmation, and notifies supervisory authorities and individuals where required by law.
Section 10Your rights

What may be requested, and how.

The rights available depend on where the individual is. Invoke does not distinguish between individuals when honouring a request that it is able to honour, and applies the rights below to all individuals as a matter of practice regardless of jurisdiction.

10.1Rights under the UK and EU GDPR
An individual in the United Kingdom or the European Economic Area has the right to request access to their personal data, its rectification, its erasure and the restriction of its processing; the right to data portability; the right to object to processing carried out on the basis of legitimate interests; and the right to withdraw consent where processing rests on consent, without affecting processing already carried out.
10.2Rights under California law
A California resident has the right to know the categories and specific pieces of personal information collected, the sources, the purposes and the categories of recipients; the right to delete personal information; the right to correct inaccurate personal information; the right to opt out of sale or sharing — which Invoke does not engage in, per Clause 6.3; the right to limit the use of sensitive personal information, which Invoke does not collect for a purpose requiring that limit; and the right not to receive discriminatory treatment for exercising a right. Invoke does not offer financial incentives for personal information. Comparable rights under the privacy laws of other states are honoured on the same terms.
10.3Exercising a right
A workspace may be deleted from the console at any time. Account deletion, access requests and export of the ledger in a machine-readable form are administered on request to security@invokehq.run, and are completed within 30 days. Invoke will verify the identity of the requester by reference to the account, and may decline a request it cannot verify. A request may be made by an authorised agent on production of authority. No fee is charged for a first request within any twelve-month period.
10.4Requests concerning customer data
Where a request concerns data processed by Invoke as a processor under Clause 1.2, Invoke will refer the requester to the relevant customer and will assist that customer in responding. Invoke will not itself erase or disclose such data other than on that customer’s instruction or where compelled by law.
10.5Complaints
A complaint may be made to Invoke at the address above and will receive a substantive response. An individual in the European Economic Area or the United Kingdom also has the right to complain to their local supervisory authority, and is not required to raise the matter with Invoke first.
Sections 11 to 13Automated decisions, children, and changes
11.1Automated decision-making
Invoke does not make decisions producing legal or similarly significant effects concerning an individual by automated means, and does not profile individuals for that purpose. Where a customer configures an agent that makes such a decision, the customer is the controller of that processing and is responsible for the lawful basis, the notice, the human involvement and any right of contest which the law requires. Section 5.4 of the Terms of Service allocates that responsibility expressly.
12.1Children
The Service is not directed to children. Invoke does not knowingly collect personal data from a person under 18. Where Invoke becomes aware that it has done so, it deletes that data. A parent or guardian who believes a child has provided personal data should contact the address at Clause 13.2.
13.1Changes to this notice
Invoke may amend this notice. The version and effective date are recorded in the document-control block above. Where an amendment is material, Invoke will give notice by electronic mail to account holders, or by prominent notice within the Service, before it takes effect.
13.2Contact
Enquiries, requests under Section 10 and complaints should be addressed to security@invokehq.run. The controller for the purposes of this notice is Invoke HQ, Inc.. Invoke has not appointed a data protection officer, not being required to do so; the address above is the point of contact for all matters arising under this notice.

Privacy enquiries.

Data processing agreements, transfer documentation and requests under Section 10 are handled by the same team that maintains the systems described at Security.