Privacy Policy
Last updated: 8 August 2026
Conciq is a business-support platform operated by Innorve Inc. ("Conciq", "we", "us"). This policy explains what we collect, why, and the choices you have. It applies to conciq.com and the Conciq platform, and it is written for our customers in the United States and the United Kingdom.
The short version: your data exists on Conciq so that we can do work for you. We don't sell it, we don't let AI providers train their models on it, and access inside our team is limited to the people working on your requests.
1. What we collect
- Account data — name, email address, and password or OAuth identity (Google or Microsoft) used to sign in.
- Business profile — company name, industry, team size, website, location, and brand details you confirm during onboarding.
- Request content — the requests you submit, messages you exchange with us, files you upload, and the deliverables we return.
- Knowledge base content — documents you add so that our work reflects your business.
- Billing data — subscription plan, credit usage, and payment records. Card details are collected and stored by Stripe, not by us.
- Usage data — log and device information needed to run, secure, and improve the service.
2. How we use it
- To fulfil your requests. Work is performed by our AI systems and by our vetted fulfilment specialists, working together under quality review.
- To personalise the service — your knowledge base and request history make future work faster and more accurate for your business only. Your data is never used to serve another customer.
- To bill you, support you, and send service communications.
- To operate and improve the platform, using aggregated or de-identified information wherever possible.
- To meet legal obligations.
Personal information and AI processing. Before request content is processed by AI models, our redaction pipeline automatically detects and masks sensitive identifiers (such as Social Security or National Insurance numbers, bank account numbers, and card numbers). The pipeline is fail-closed: if redaction cannot run, processing is blocked. Our AI subprocessors are contractually restricted from using your content to train their models.
3. Legal bases (UK)
Where UK GDPR applies, we process personal data on these bases: performance of a contract (delivering the service you signed up for), legitimate interests (securing and improving the platform, communicating with business contacts), legal obligation (tax, accounting, and lawful requests), and consent where we ask for it specifically. For personal data contained in the content you upload, you are the controller and Conciq acts as your processor under our data processing terms; a signed Data Processing Agreement is available on request at support@conciq.com.
4. Who we share it with
We share data only with subprocessors that help us run Conciq, under contracts that restrict what they can do with it:
- Supabase — database, file storage, and authentication
- Stripe — payments and billing
- OpenAI — AI processing (redacted content, no model training)
- Resend — transactional email
- Vercel — web hosting; Railway — API hosting
- Upstash — caching; Inngest — background job orchestration
Members of our fulfilment team access request content on a need-to-know basis under confidentiality agreements. We disclose data if required by law, and in a merger or acquisition your data remains protected by this policy. We do not sell personal information and we do not share it for cross-context behavioural advertising.
5. International transfers
Our infrastructure is hosted in the United States. Our fulfilment specialists may access request content from other countries. For UK customers, transfers of personal data outside the UK are protected by the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with transfer risk assessments and the security measures described on our Security page.
6. Retention
We keep your data while your account is active. When you close your account, or ask us to, we delete your content within 30 days except where the law requires longer retention (for example billing records). Backups are purged on a rolling schedule.
7. Your rights
United Kingdom: you have the right to access, correct, delete, restrict, or object to the processing of your personal data, and to data portability. You can complain to the Information Commissioner's Office (ico.org.uk), though we would welcome the chance to resolve any concern first.
United States: depending on your state, you may have rights to access, correct, delete, or obtain a copy of your personal information, and to opt out of certain processing. We honour these requests regardless of state where practicable.
To exercise any right, email support@conciq.com. We respond within 30 days.
8. Security
Data is encrypted in transit and at rest, tenants are isolated at the database level with row-level security, and every action on a request is logged. Details are on our Security page.
9. Children
Conciq is a business service for users aged 18 or over. We do not knowingly collect data from children.
10. Changes and contact
If we make material changes to this policy we will notify you by email or in-product before they take effect. Questions, requests, or complaints: support@conciq.com, Innorve Inc., United States.