Privacy Policy
1. Scope
Innex is an AI influencer marketing workspace operated by W2Z AI Inc., a California corporation ("Innex", "we", "us"). This policy explains how we handle personal information across:
- the Innex website (innexai.ai, innexai.co, and their subdomains), including the "Book a demo" form; and
- the Innex application (app.innexai.ai, app.innexai.co, and other application domains) and its APIs.
Three situations need to be kept apart:
- Account, billing, and website usage data — we are the data controller and decide how that information is handled under this policy.
- Content customers put into their workspace (campaign material, creator lists a customer uploads, email correspondence, uploaded files, conversations with the AI assistant) — we act as a data processor on the customer's instructions, and the customer is the controller.
- Innex's own creator database (the one we compile from public sources and make searchable to all customers) — we are the data controller. See Section 6.
This policy does not cover third-party websites or social platforms we link to; each has its own privacy policy.
2. Information we collect
What you give us
- Account information: work email, name, avatar, organization name, account role (brand or agency), the social platforms and target markets you care about, interface language, and invite code. We sign you in with one-time codes, so we never store a password for you.
- Preferences and settings: time zone (read from your browser and saved to your account, used for scheduling and send times), the AI assistant's default approval mode, and interface preferences.
- Workspace content: campaign plans, KPIs and budgets, schedules and milestones, creator lists and notes, email drafts and threads, files uploaded to the campaign library, and your conversations with the AI assistant.
- Demo request form: name, work email, company name, preferred meeting time, and time zone, plus the page language and a source tag recorded at submission. We use these to log the booking, send you a confirmation email, and notify our team.
- What you send us directly: the content and attachments of support emails.
What you authorize us to access on your behalf
- Email accounts: you can connect a mailbox by OAuth with a provider we currently support, or by entering SMTP credentials. Once connected, Innex works as a full mail client: we draft and send on your behalf, and we read that account's inbox and sent mail — bodies, attachments, threads, and read state — and let you search, reply, forward, and mark messages read inside Innex. That is what lets creator replies and your campaigns be tracked in one place. Tokens and SMTP credentials are stored encrypted, and you can disconnect at any time in settings.
What we collect automatically
- Log and device data: IP address, browser and operating system, access times, the pages or endpoints requested, and error details.
- Usage and billing data: your subscription tier, per-period feature usage, and your quota and account balance state.
- Cookies and local storage: see Section 8.
What we get from third parties
- Public creator profiles: see Section 6.
- Payment information: subscriptions are processed by Stripe. Full card numbers and payment credentials never reach our servers; what we receive from Stripe is subscription and billing status, used to enable the corresponding entitlements.
3. How we use it
- Providing the service: creator discovery and matching, campaign management, drafting and sending outreach, analytics dashboards.
- Running AI features: see Section 4.
- Accounts and billing: provisioning, subscriptions, credit and quota accounting, invoices.
- Security and abuse prevention: detecting unusual sign-ins, rate limiting, and preventing spam and fraud.
- Support and service notices: verification codes, status updates, and material changes.
- Product improvement: analyzing aggregated or de-identified usage. We do not use one customer's workspace content to improve features for other customers.
- Marketing communications: only where you have consented or the law otherwise permits, and always with an unsubscribe link.
- Legal obligations, and establishing or defending legal claims where necessary.
We process information only for the purposes listed above. Some of that is needed to provide and secure the Service, bill you, or meet legal obligations; other processing — such as marketing communications — happens only with your consent or where otherwise permitted.
4. AI features and your data
The Innex assistant calls third-party large language models to interpret your instructions, draft emails, and summarize creator and campaign data. To do that we send the model provider the context needed for the task — typically your instruction, the current conversation, the relevant campaign and creator fields, and any files you explicitly selected.
- We do not train our own models on your workspace content, and for external models we use only API tiers whose provider terms do not permit customer inputs to be used to train general-purpose models.
- Model providers may process this data only to provide the service to you — as our sub-processors for workspace content, and as our processors for other data.
- Actions with outside effects require human approval. Actions such as sending email, syncing an email draft, adding or removing creators from a campaign, changing creator status, and editing pipeline targets, KPIs, budgets, or milestones all pause for your approval — unless you change the default approval mode in settings, or switch an individual conversation to full-autonomy mode.
- Model output can be wrong. Review it yourself before it goes out, especially email to creators and any external commitment.
5. Mailbox authorization and Google API Limited Use
When you connect Gmail through Google OAuth, we request a single scope: gmail.modify (full identifier: https://www.googleapis.com/auth/gmail.modify). This restricted scope lets Innex read messages and attachments in the connected mailbox; create, update, delete, and send drafts; send, reply to, and forward messages; and change message state, such as marking messages read. We obtain the connected Gmail address through the Gmail users.getProfile method under this same scope; this flow does not request separate Google identity or profile scopes. Note that this grant covers the whole connected mailbox, not only campaign-related correspondence. Innex's built-in mail workspace reads your inbox and sent mail so you can view, search, reply to, and track messages inside Innex. If you would rather Innex not touch the rest of your work mail, connect a mailbox dedicated to outreach.
Innex's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Concretely:
- mailbox data is used only to provide Innex's outreach and reply-tracking features to you;
- it is never used for advertising, sold, or transferred to data brokers;
- it is never used to train generalized AI or machine learning models; and
- our staff do not read your email content except with your explicit consent, for a security investigation, where required by law, or when the data has been aggregated and de-identified.
You can disconnect a mailbox at any time in Innex settings, and revoke access from your Google account's third-party access page. On disconnect we delete the stored credentials and also attempt to revoke the token with Google programmatically; if we cannot confirm that revocation with Google, the app asks you to remove Innex from your Google account's third-party access page yourself.
6. Creator data: where it comes from and your rights
Innex helps brands find and contact creators, so we process information about creators. It comes from:
- publicly visible profile and post pages on social platforms (TikTok, Instagram, YouTube and others) — display name, handle, avatar, bio, follower and view counts, and public post metrics;
- contact details creators publish themselves in a public bio, such as a business email or social handle;
- public URLs customers submit for crawling, and creator lists customers upload; and
- email correspondence between a creator and a customer, sent through the customer's connected mailbox.
Innex's own creator database holds only publicly visible information: we do not bypass logins, paywalls, or platform technical restrictions to reach non-public content, and we do not deliberately collect special categories of personal data. Creator lists a customer uploads and correspondence in a connected mailbox do not go into that database — they are the customer's workspace content, processed on the customer's instructions as described in Section 1.
If you're a creator
Email support@w2z.ai to see, correct, or delete what we hold about you. We'll act promptly. For records in our own creator database we handle the request directly; where the information was uploaded by a customer or arose in a customer's own mailbox, we forward the request to that customer and assist.
If you received an outreach email sent through Innex: the sender is the brand or agency using Innex, and they are responsible for that message. Replying to them directly is the most effective way to stop contact. You can also write to us — we will pass the request to that customer and handle our own database records about you as described above.
7. Who we share it with
We do not sell personal information, and we do not disclose it so that ads can be targeted to you based on your activity across unrelated services. We share only in these situations:
Inside your organization
Members of the same workspace can see the content in it. Workspaces are isolated from one another.
Service providers
We use providers in the following categories. For data we control they act as our processors; where we handle workspace content for a customer they act as our sub-processors:
- Hosting and storage;
- Payment processing;
- Authentication;
- Email delivery — verification codes and system notifications;
- AI model inference;
- Web crawling and content extraction — fetching and parsing URLs a user submits, for example to generate a campaign plan;
- Form and notification tooling — storing website demo requests and notifying our team.
We put data processing terms in place with our providers requiring them to process data only on our instructions and to maintain appropriate security. Enterprise customers can contact support@w2z.ai to sign a Data Processing Agreement (DPA) and to request the current sub-processor list.
Other situations
- Legal requirements — to comply with law, a court order, or a lawful government request.
- Protecting rights — to prevent fraud or abuse, or protect the rights and safety of Innex, our users, or the public.
- Business changes — in a merger, acquisition, or sale of assets, data may transfer as part of the transaction. We'll notify you in advance.
8. Cookies and local storage
Essential cookies
After you sign in we set an HttpOnly session cookie to keep you signed in. The service cannot run without it, so there is no opt-out.
Browser local storage
- Website: interface language, and the monthly/annual toggle on the pricing page.
- Application: interface preferences such as language, sidebar collapsed state, whether you've completed the product tour, Discover column choices, and the AI suggestions toggle — plus a one-time state value used during the OAuth flow.
Most of this stays in your browser. Two exceptions: your interface language is also saved to your account so it follows you across devices, and the OAuth state value is sent to our server during the callback, where it is checked and then discarded.
Third-party tracking
Neither the website nor the application currently loads third-party advertising or behavioral analytics trackers. If that changes we'll update this policy first, and obtain consent where the law requires it.
Third-party requests your browser makes directly
Even without trackers, your browser connects to third parties in two places: the website's home page loads front-end runtime libraries from a public CDN (unpkg.com), and creator avatars and thumbnails shown in the application are served by the originating platform's image hosts. Those requests expose your IP address and browser details to the recipient, which we cannot control on your behalf.
9. Data storage, international transfers, and security
W2Z AI Inc. is headquartered in the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States or in other countries where our service providers operate.
We protect international transfers through one or more of the following mechanisms, as applicable:
- Adequacy decisions — transfers to countries a competent authority has determined provide adequate protection;
- Standard Contractual Clauses (SCCs) — approved contractual terms incorporated into our agreements with service providers; and
- Supplementary measures — technical and organizational measures providing an equivalent level of protection where local law requires them.
Security measures
- TLS encryption in transit, and encryption at rest by our cloud provider;
- session cookies with the HttpOnly and SameSite attributes, and API endpoints served from the same site (same registrable domain) to reduce cross-site risk;
- encrypted storage of mailbox tokens and SMTP credentials;
- least-privilege internal access with audit logging; and
- tenant isolation, so one organization cannot see another's content.
No system is perfectly secure. If a breach affects your personal information, we'll notify you and provide the other notices applicable law requires.
10. How long we keep it
- Account and workspace data — your individual profile is kept for the life of your account and deleted or anonymized when you close it; workspace content remains for as long as the customer's workspace is active, and does not disappear because one member leaves. After the workspace is closed or the subscription ends, we retain its content for 30 days so an authorized administrator can export it, then delete or anonymize within 90 days, unless the law requires otherwise.
- Mailbox authorization — access tokens are deleted promptly on disconnect or revocation.
- System logs — typically 12 months.
- Billing and transaction records — as required by tax and accounting rules, typically 7 years.
- Demo request forms — 24 months.
- Creator profiles — for as long as needed to serve the customers using them; deletion requests are handled per Section 6.
11. Your rights
Wherever you are, you have the same rights. You can ask us to:
- access the personal information we hold about you;
- correct information that is inaccurate;
- delete it;
- give you a copy of your data;
- stop using your information for a particular purpose; and
- withdraw consent you previously gave (withdrawal doesn't affect processing done before it).
You can change your profile and preferences yourself in the application's Settings. Data export and account closure are currently handled by us on request — for those and anything else, email support@w2z.ai and we'll respond promptly. We may need to verify your identity first.
Requests about account, billing, or website usage data, or about Innex's own creator database, are handled by us directly. Only where the personal information exists solely in customer-controlled workspace content do we refer the request to that customer and assist — being a member of a customer's team does not by itself make all information about you customer-controlled.
12. Children
Innex is a business product. Account holders must be 18 or older, and we do not knowingly create accounts for minors.
Creator data is a separate matter: public social profiles rarely state an age and we do not infer one, so we cannot guarantee our database holds no public information about creators who are minors. If you are a minor, or the guardian of one, write to support@w2z.ai and we will delete the relevant records. If we learn that a minor has given us personal information directly, we delete it promptly.
13. Changes to this policy
This policy describes Innex as it works today. We will keep changing the product, and how it handles data will change with it — this policy is updated to match. We'll update the date at the top, and for material changes — a new purpose for data, or a new category of sub-processor — we'll give you at least 30 days' notice by email or in-app. Continuing to use Innex after a change takes effect means you accept the updated policy.
14. Contact us
For questions or complaints about this policy, or to exercise your rights:
W2Z AI Inc.
Email: support@w2z.ai
We respond promptly on receipt.