Privacy Policy
This Privacy Policy explains what personal and business information IntakeOS ("IntakeOS," "we," "us," or "our") collects through the IntakeOS platform (including the VARA AI consultant and any related web, Slack, Teams, or email interfaces), how we use and share it, and the choices you have.
Version 2026-08-26.1 · Last updated August 26, 2026
Overview
IntakeOS is a platform that helps organizations discover, qualify, and prioritize automation and AI opportunities. As part of that service, our AI consultant (VARA) conducts conversational intake interviews with your team members, and the platform generates process maps, scores, ROI calculations, and narrative reports from that conversation. This policy covers every stage of that lifecycle: what we collect, how AI providers are involved in processing it, how long we keep it, and what rights you have over it.
This policy applies to visitors of our marketing site and to users of the IntakeOS application acting on behalf of a customer organization ("Customer," "you," or "your organization"). Where IntakeOS processes personal data on behalf of a Customer as part of the service, IntakeOS acts as a data processor (or "service provider" under applicable US state law) and the Customer acts as the data controller; a separate Data Processing Addendum (DPA) governs that processor relationship and is available on request.
Information we collect
We collect the following categories of information:
- Account and contact information - name, work email, organization, role, and authentication credentials when you or your organization create an account.
- Intake conversation content - everything submitted during an AI-assisted intake conversation with VARA, including free-text answers, uploaded documents, process descriptions, and any attachments or recordings your organization chooses to provide.
- Generated outputs - process maps, deterministic scores, ROI calculations, AI-generated narrative explanations, and exported reports produced from intake content.
- Usage and device data - log data, IP address, browser type, pages visited, and interaction events, collected automatically when you use the site or application.
- Communications - messages you send us through contact forms, support requests, or scheduled calls.
How we use information
- To operate the service: run intake conversations, compute scores and ROI, and generate reports and documents.
- To provide support, respond to inquiries, and manage your account.
- To maintain security, detect abuse, and enforce our Terms of Service.
- To send service-related communications, including notices of material changes to our policies.
- To improve the service using aggregated and de-identified data - for example, understanding which question flows are most common or how scoring thresholds perform across anonymized, aggregate patterns. We do not use your organization's identifiable intake content to train AI models, ours or our providers'.
- With your consent, or as required by law, regulation, or legal process.
AI sub-processors
VARA's conversational intake and narrative report generation are powered by third-party large language model (LLM) providers. Depending on your organization's configuration, this may include providers such as OpenAI, Anthropic, and Google (Gemini), or - for customers who configure their own infrastructure - your organization's own private or enterprise model deployment (see our Trust & Control page). Content submitted during an intake conversation, and the prompts derived from it, are sent to the configured AI provider over an encrypted connection so a response can be generated.
We operate under data processing agreements with our AI providers that prohibit using API inputs to train or improve their models. Deterministic scoring - which pattern is qualified, what the ROI is, whether a rule fires - is computed by our own rules engine, not by the AI provider; AI is used to generate explanatory narrative and to hold the conversation, not to make the underlying decision.
Other sub-processors
Beyond AI providers, we rely on a limited set of vetted vendors to operate the service, including:
- Cloud hosting and storage providers - to host the application, databases, and encrypted file storage described on our Security page.
- Email delivery providers - to send transactional email such as account notifications, report deliveries, and password resets.
- Analytics providers - to understand aggregate site usage (see Cookies & Analytics below).
Every sub-processor that touches Customer data signs a data processing agreement with confidentiality, security, and deletion obligations. We maintain a current sub-processor list and notify customers at least 30 days before adding a new sub-processor that will process their data, consistent with the sub-processor practices described on our Security page.
Data retention
We retain intake content, generated reports, and account data for as long as your organization's account is active, or as needed to provide the service. When your organization requests deletion, data is purged from primary storage within 30 days and from backups within 90 days, consistent with our Security page. We may retain limited data beyond that where required to comply with a legal obligation, resolve disputes, or enforce our agreements.
Security measures
We protect data with encryption in transit (TLS 1.3) and at rest (AES-256), role-based access control, organization-scoped data isolation, audit logging of administrative actions, and routine third-party penetration testing. Full technical and organizational detail is documented on our Security page, which this policy relies on and does not contradict. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Your rights
Depending on your location and applicable law (including GDPR and US state privacy laws), you may have the right to:
- Access the personal data we hold about you and receive a copy of it.
- Correct inaccurate or incomplete data.
- Request deletion of your data, subject to legal retention requirements.
- Export your data in a portable format.
- Object to or restrict certain processing, and withdraw consent where processing is based on consent.
If you are an individual whose information was submitted by your employer as part of an organization's intake, please contact your organization's administrator first, since IntakeOS processes that data on the organization's instructions; if you contact us directly, we will route your request appropriately. To exercise any of these rights, email privacy@intakeos.ai.
Children's privacy
IntakeOS is a business-to-business product intended for use by working professionals and is not directed at, nor knowingly used to collect personal information from, children under 16. If you believe a child has provided us with personal information, contact us and we will delete it.
International transfers
We are based in the United States and store data on US infrastructure by default, with an EU-region storage option available for enterprise contracts as described on our Security page. Where personal data is transferred internationally, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) for transfers out of the EU/UK/Switzerland.
Changes to this policy
We may update this Privacy Policy from time to time. Each version carries a version identifier and a "last updated" date shown at the top of this page. For material changes, we will provide advance notice - such as an in-app notice or an email to account administrators - before the change takes effect.
Contact
Questions about this policy or your data can be sent to privacy@intakeos.ai. For security-specific questions, see security@intakeos.ai.