Legal · Personal data
PRIVACY POLICY
Last updated September 2, 2026
This Privacy Policy explains how the individual sole proprietor operating under the TechImpacts brand ("TechImpacts", "we", "us", or "our") collects, uses, discloses, secures, and retains personal data when you visit our website, create an account, use our technology-intelligence and AI features, connect an integration, or contact us.
Account details, workspace content, usage, security, integration, and transaction records.
Providers support hosting, payments, email, analytics, authentication, integrations, and AI.
Email our privacy contact to ask about access, correction, deletion, or another applicable right.
1. Scope and responsibility
This Policy applies to TechImpacts websites and services that link to it. The individual sole proprietor operating the TechImpacts brand is responsible for deciding why and how the personal data described here is processed. When an organisation provides your TechImpacts account, that organisation may separately control account administration and the data it submits; its own privacy notice may also apply.
This Policy does not govern third-party websites, news sources, or services you open from TechImpacts. Those parties control their own privacy practices. It also does not replace any just-in-time notice or consent request shown for a particular feature.
2. Personal data we collect
Account and profile data
Account and profile data includes your name, email address, optional phone number, role, organisation, postal address, city, state, country, profile image, account identifiers, sign-in method, contact and notification preferences, subscription status, and account creation or update timestamps.
Authentication and security data
For password accounts, we store a one-way password hash rather than the password in readable form. We also process email-verification and password-reset tokens, session tokens in HTTP-only cookies, Google sign-in identifiers where used, last-sign-in time, IP address, device or browser description, security notices, and records used to prevent fraud or abuse.
Content and workspace data
Content and workspace data includes chat messages and AI responses, chat titles and history, IsoMorph inputs, mappings and outputs, saved articles, favourites, collections, tags, product ideas, calendar events and attendee email addresses, activity history, notifications, feedback, and support messages. This content may contain personal data if you place personal data in it.
Payment, credit, and transaction data
Paddle acts as reseller and Merchant of Record for purchases. We receive payment and billing metadata from Paddle, such as customer, checkout, subscription, price, transaction status, dispute, refund, and billing-contact information. Paddle collects and processes full payment-instrument details on its hosted systems; TechImpacts does not store full card numbers or card security codes. We keep wallet, credit, usage-charge, and ledger records needed to operate and reconcile the service. Commercial rules are in the Terms of Service and Refund Policy.
Connected-service data
If you choose to connect Slack, we process workspace identifiers and names, bot credentials, granted scopes, channel identifiers, and content you direct us to post. If you connect Google Calendar, we process the connected Google account name and email, granted scopes, encrypted access and refresh tokens, selected calendar, event details, attendee details, and provider responses. You can disconnect these integrations from the product; provider-side settings may offer additional controls.
Technical and security data
Technical and security data includes IP address, device type, browser and user-agent information, operating system, request time, pages and features used, referral and approximate network information, cookie or session identifiers, error and performance events, and reCAPTCHA risk signals. We use these records to deliver, diagnose, protect, and improve the service.
Analytics and AI-usage metadata
If you accept analytics cookies and Google Analytics is configured, it may collect page interactions, device and browser information, approximate location derived from IP address, and cookie or online identifiers. Google Analytics is not loaded before that choice. Our internal AI-usage records contain identifiers, feature, model and provider, token counts, cost, credits, latency, status, and prompt version. The internal AI-usage analytics record is designed not to contain prompts, chat text, or model output, although that content is stored separately where needed for the feature itself.
Newsletter and communications data
If you subscribe to communications, we process your email address, source, subscription status, timestamps, communication preferences, and unsubscribe state. Service, security, and transaction messages may be necessary even when you opt out of marketing.
Please do not submit unnecessary sensitive data. TechImpacts is not designed for health records, government identifiers, precise financial credentials, biometric templates, or other special-category data. If you place sensitive or third-party personal data in a prompt, calendar event, message, or integration, you are responsible for having authority to do so.
3. Where personal data comes from
- Directly from you, including registration, profile, prompts, forms, purchases, and support.
- Automatically from your browser or device, including cookies, logs, analytics, and security signals.
- From your organisation, if it creates, administers, or pays for your account.
- From Google, when you use Google sign-in, reCAPTCHA, or connect Google Calendar.
- From Paddle, including payment, billing, refund, dispute, and subscription events.
- From Slack or another integration you authorise, within the scopes you approve.
- From public news and web sources, where our service associates public content with your saved items or analysis.
We do not purchase personal data from data brokers.
4. How and why we use personal data
| Purpose | Typical data | Legal ground where required |
|---|---|---|
| Create accounts, authenticate users, provide features, preserve workspaces, and answer support requests. | Account, session, profile, workspace, content, and support data. | Performing our contract with you or taking requested pre-contract steps. |
| Process purchases, maintain credits and entitlements, issue invoices, and handle payment events. | Account identifiers, Paddle metadata, subscription, credit, ledger, and usage records. | Contract performance and compliance with tax, accounting, fraud, and payment obligations. |
| Generate AI-assisted summaries, chat responses, mappings, and related results. | Prompts, selected source content, conversation context, mapping inputs, and usage metadata. | Contract performance; legitimate interests in operating and improving requested features. |
| Connect and operate integrations you choose. | Integration account details, tokens, scopes, channels, calendars, events, and directed content. | Your request or consent, and contract performance. |
| Secure the service, prevent fraud and abuse, debug faults, and enforce our rules. | Network, device, session, log, activity, payment-risk, and account data. | Legitimate interests, contract performance, and legal obligations. |
| Measure service performance and understand feature use. | Google Analytics data, internal usage metrics, and de-identified or aggregated reports. | Consent where required; otherwise legitimate interests in product operation and improvement. |
| Send requested newsletters, product updates, security notices, and service communications. | Name, email, preferences, account, device, security, and transaction information. | Consent for optional marketing; contract, legitimate interests, or legal obligations for service messages. |
| Meet legal duties, respond to lawful requests, establish claims, and protect people or the service. | Data relevant to the request, dispute, incident, or legal duty. | Legal obligation, public interest where applicable, and legitimate interests. |
The precise legal ground depends on your location and the context. Where we rely on consent, you may withdraw it, but withdrawal does not affect processing already carried out lawfully. If data is needed to create an account, process a purchase, secure the service, or provide a requested feature, we may be unable to provide that part of the service without it.
5. AI processing and automated outputs
TechImpacts sends the information needed for an AI request to the provider configured for that feature, currently OpenAI or Google Gemini. This can include your prompt, conversation context, selected article text, or IsoMorph inputs. The provider returns generated content, while TechImpacts records operational usage metadata for billing, reliability, and cost analysis.
AI outputs can be inaccurate and are not used by TechImpacts to make solely automated decisions that produce legal or similarly significant effects about you. Do not place confidential or personal data in a prompt unless it is necessary and you are authorised to use it. Provider handling is also subject to the safeguards in our service arrangements and the provider's applicable privacy documentation.
6. When we disclose personal data
We disclose personal data only as needed for the purposes described here. We do not sell personal data, and we do not use personal data for cross-context behavioural advertising. We may disclose data to:
| Recipient or category | Purpose and data involved |
|---|---|
| Paddle | Reseller and Merchant of Record services, hosted checkout, payment methods, billing, subscriptions, invoices, tax handling, refunds, disputes, fraud controls, and customer billing details. |
| OpenAI and Google Gemini | AI inference using the prompt, context, source material, and identifiers required to return and troubleshoot an AI result. |
| Google services | Google sign-in, reCAPTCHA security checks, Google Analytics, and Google Calendar when you connect it. |
| SendGrid | Account verification, password reset, security, transaction, support, and newsletter email delivery. |
| Slack | Workspace connection, channel discovery, and content you direct TechImpacts to send to Slack. |
| Infrastructure and operations providers | Application hosting, database, content delivery, security, monitoring, backups, and technical support, including Render, MongoDB Atlas, and Cloudflare where configured. |
| Your organisation and authorised users | Account administration, shared workspaces, billing, and content you choose to share, subject to their permissions. |
| Professional advisers and authorities | Legal, audit, insurance, security, tax, fraud-prevention, and compliance matters, or a valid legal request. |
| Corporate transaction parties | Due diligence or transfer connected with a financing, reorganisation, merger, acquisition, or sale, subject to confidentiality and applicable law. |
Providers may process data in countries where they or their subprocessors operate. Their own services may also collect information directly from you under their privacy notices—for example, Paddle's hosted checkout or Google's authorisation screen.
8. International data transfers
TechImpacts is based in India, while our providers and their subprocessors may operate in India, the United States, and other countries. Those countries may have different data-protection laws. Where applicable law requires a transfer mechanism or contractual safeguard, we use an available lawful mechanism and supplementary protections appropriate to the transfer. Contact us to request information about safeguards relevant to your data.
9. How long we keep personal data
We keep personal data only for as long as reasonably necessary for the purpose collected, including to provide the service, maintain security, comply with law, resolve disputes, and enforce agreements. The period depends on the data and context:
- Account, profile, and workspace records are generally kept while the account is active and then until deletion is completed, subject to legal, backup, fraud, dispute, and security exceptions.
- Chat sessions, activity, saved items, calendar events, and IsoMorph mappings remain until you delete available items, your organisation removes them, or a valid deletion request is completed, subject to exceptions.
- Integration credentials are kept while the integration is connected. The product removes stored access or refresh credentials when the supported disconnect process completes, although limited logs, revoked-connection metadata, and backups may remain temporarily.
- Session and reset credentials are short-lived. Current access cookies last up to one hour, refresh cookies up to 30 days, and password-reset tokens up to one hour unless replaced or invalidated earlier.
- Payment, ledger, tax, accounting, refund, and dispute records are retained for the period required to reconcile transactions, comply with law, and establish or defend claims.
- Security, operational, and AI-usage records are retained according to risk, troubleshooting, billing, audit, and legal needs; content-minimised or aggregated records may be kept longer.
- Newsletter data is kept while subscribed. After unsubscribe, we may retain a limited suppression record so we honour the opt-out.
When retention is no longer justified, we delete, de-identify, or isolate the data. Backups are removed on their normal replacement cycle unless preservation is legally required.
10. Security and incidents
We use technical and organisational measures designed to protect personal data. Current examples include one-way password hashing, HTTP-only session cookies, encrypted stored integration tokens, role-based access, provider credential separation, authentication checks, audit and usage records, and transport encryption in deployed environments. Access is limited according to operational need.
No system is completely secure. You are responsible for protecting your credentials, using a trusted device, and notifying us promptly about suspected unauthorised access. If a personal-data breach occurs, we will investigate, contain, document, and notify affected people or authorities when applicable law requires it.
11. Your privacy rights and choices
Depending on where you live and which law applies, you may ask us to access the personal data we hold, correct inaccurate data, delete data, restrict processing, object to processing, receive portable data, withdraw consent, or obtain information about recipients and sources. You may also opt out of optional marketing and complain to a competent data-protection authority. We will not discriminate against you for exercising an applicable privacy right.
India
To the extent applicable under the Digital Personal Data Protection Act, 2023 as its provisions come into force, you may request a summary of personal data and processing, correction or erasure, grievance redressal, and nomination of another individual to exercise rights in the circumstances provided by law. You may also withdraw consent where consent is the basis of processing. Statutory exceptions may apply.
European Economic Area and United Kingdom
Where the GDPR or UK GDPR applies, rights may include access, rectification, erasure, restriction, portability, objection—including an unconditional objection to direct marketing—and withdrawal of consent. You may lodge a complaint with your local supervisory authority. Some rights depend on the legal ground and are subject to exemptions.
United States
If a state privacy law applies to TechImpacts and to your data, rights may include knowing or accessing data, correction, deletion, portability, opting out of sale or targeted-advertising sharing, limiting certain sensitive-data uses, and appealing a denied request. TechImpacts does not currently sell personal data or use it for cross-context behavioural advertising, so there is no separate sale of data to opt out of. An authorised agent may submit a request where law permits, subject to verification.
How to exercise a right
Email support@techimpacts.com with the subject “Privacy Request” and describe the request and the account email involved. We may need to verify your identity and authority before acting. We respond within the period required by applicable law. A right may be limited where we must retain data for security, transactions, legal compliance, another person's rights, or legal claims; if so, we will explain the applicable reason where required.
12. Children
TechImpacts is intended for people aged 18 or older and is not directed to children. We do not knowingly collect personal data from a child through the service. If you believe a child has provided personal data, contact us so we can investigate and take appropriate action.
13. Changes to this Policy
We may update this Policy when our services, providers, or legal obligations change. We will post the updated version and revise the date above. If a change materially affects how we use personal data, we will provide additional notice or seek consent when applicable law requires it. Earlier versions may be requested from our privacy contact.
14. Contact and grievances
Privacy and grievance contact
TechImpacts — an individual sole-proprietor brand based in India
Email: support@techimpacts.com
Subject line: Privacy Request or Privacy Grievance
Please include enough information for us to identify the issue without sending unnecessary sensitive data. Privacy requests and grievances are handled separately from billing and service disputes. For billing, refunds, credits, or cancellation, review the Terms of Service and contact support.