HomePrivacy Policy

Privacy Policy

Effective: July 24, 2026

Information We Collect

We collect information you provide directly — such as your name, email address, and API keys for third-party integrations like The Main Frame. We also collect usage data such as search queries, page views, and session duration to improve our services. We do not sell your personal data to third parties.

How We Use Your Data

Your data is used to operate and improve Intronect, including personalizing search results, powering AI Mode, and syncing your connected profiles. Search queries may be used in aggregate, anonymized form to improve our index quality.

Third-Party Integrations

When you connect a third-party service like The Main Frame, we store your API key encrypted at rest and use it only to fetch your authorized profile data. We never share your API keys with other users or third parties beyond the integration you authorized.

Cookies & Local Storage

We use session cookies to keep you logged in and local storage for UI preferences. We do not use third-party advertising cookies. You can clear cookies at any time via your browser settings.

Data Retention

We retain your account data for as long as your account is active. If you delete your account, all personal data is removed within 30 days, except as required by applicable law.

Your Rights

Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data. To exercise these rights, contact us at privacy@intronect.com. We respond to all requests within 30 days.

Security

We implement multiple layers of security to protect your data. All traffic is encrypted in transit via TLS (HSTS enforced). API keys for third-party integrations are encrypted at the application level using AES-256-GCM before being written to the database — a unique random IV is generated per key, the plaintext is never stored, and all ciphertext is versioned to support safe key rotation without downtime. Sensitive endpoints (sign-in, key verification, AI search) are rate-limited per IP address to block brute-force attacks. All significant account actions — connecting integrations, disconnecting, syncing, and key re-encryption — are recorded in a tamper-evident audit log with timestamp and IP. HTTP security headers (Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy) are enforced on every response to protect against XSS, clickjacking, and MIME-sniffing attacks.

Contact

For privacy-related inquiries, email privacy@intronect.com. For legal requests, contact legal@intronect.com.