Contents — 24 sections
- In short (non-binding summary)
- Scope and definitions
- 2. The two surfaces this policy covers
- 3. Personal data we collect through the Telegram bot
- 4. Personal data we collect through the website
- 5. Content about other people
- 6. Where our information about you comes from
- 7. Your style profile — data we infer about you
- 8. Why we process your data, and our legal bases
- 9. What we deliberately do NOT collect
- 10. Product analytics (PostHog) — server-side, content-free, no cookies
- 11. LLM tracing (Langfuse) — this one does contain your content
- 12. Sub-processors and other recipients
- 13. AI providers, model training, and our no-sale commitment
- 14. Human access to your content
- 15. International transfers
- 16. How long we keep your data
- 17. Security
- 18. Your rights
- 19. Cookies — short summary
- 20. Children
- 21. Changes to this policy
- 22. Contact and company details
- Contact
This Privacy Policy explains how IX Labs collects, uses, shares and protects personal data in connection with the Ingy Telegram bot and the website at ingy.app. It is written to stand on its own: you do not need to read any other document to understand it.
In short (non-binding summary)
This box is a plain-English summary for convenience only. It is not part of the binding policy. If anything here differs from the numbered sections below, the numbered sections govern.
- We process what you send the bot. Links, files, instructions, voice messages and the posts we generate for you. We need this content to produce your drafts.
- We build a "style profile" about how you write. This is data we infer about you, not just data you gave us. Section 7 explains it in full, and you can ask us to delete it.
- Our product analytics deliberately contain no content. No post text, no source text, no instruction text, no titles, no notes. URLs are reduced to hostname only and IP-based geolocation is switched off. Section 9 lists exactly what we do not collect.
- Third parties process your content to make the product work — including Anthropic, OpenAI, Supadata, Firecrawl and our tracing provider Langfuse. Some are outside the UK. Section 12 names every one.
- We do not and will not sell your personal data. We are not currently training models on your content, but we reserve the right to do so under the limits and exclusions in Section 13, and you can opt out at any time by emailing [email protected].
Scope and definitions
1.1 The capacities in which we process personal data. We process personal data in more than one capacity, and which one applies determines who is responsible for it.
- As a controller, we decide why and how personal data is processed when we provide Ingy to you directly as an individual user. That is the processing this policy describes.
- As a processor, we process personal data on behalf of, and on the documented instructions of, a business customer that has entered into our Data Processing Agreement. In that case the business customer is the controller and its own privacy notice governs; our obligations are set out in that agreement rather than here.
- Separately, Creem acts as an independent controller for payment data, and Telegram as an independent controller for the messaging platform. Neither processes that data on our instructions. Section 12 explains both.
1.2 In this policy, "we", "us" and "our" mean IX Labs. "You" and "your" mean the individual whose personal data we process. "Ingy" means our Telegram bot, available at @IngyAppBot, and our website at ingy.app.
1.3 Data Protection Officer. We have not appointed a Data Protection Officer. We are not required to appoint one under UK data protection law. All privacy questions, requests and complaints should be sent to [email protected], and we will handle them directly.
1.4 This policy is governed by UK data protection law, meaning the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications (EC Directive) Regulations 2003 as amended (PECR), including the amendments made by the Data (Use and Access) Act 2025.
2. The two surfaces this policy covers
2.1 Ingy exists in two places, and they behave very differently. Read the section that applies to you.
(A) The Telegram bot — @IngyAppBot
2.2 This is where the product actually is. You interact with Ingy inside Telegram. You send it sources and instructions, and it drafts posts for you.
2.3 There are no cookies in the Telegram bot at all. Cookies are a web browser technology. The bot does not run in a browser and does not set, read or store cookies or any equivalent device-storage identifier on your device. All measurement relating to the bot happens on our own servers, from data we already hold because you sent it to us.
2.4 Because there is no storage of or access to information on your device in the bot, PECR's consent rule for cookies and similar technologies does not apply to bot-side analytics. Our server-side product analytics and our LLM tracing in the bot run under our legitimate interests, as described in Sections 10 and 11. They are not gated by any cookie banner, because there is no cookie to consent to.
(B) The website — ingy.app
2.5 The website has a home page, comparison articles under /vs/, this legal library under /legal/, a /subscribe checkout page and a /thanks confirmation page. This is the only place where cookies and similar technologies are used.
2.6 On the website we use strictly necessary cookies, which do not require your consent, and analytics/measurement cookies, which we only set after you have given consent through our cookie banner. Until you accept, website analytics run cookie-free — nothing is stored on or read from your device. Section 19 explains this in full.
2.7 Nothing you consent to or refuse on the website changes how the bot works, and nothing in the bot sets anything on your device.
3. Personal data we collect through the Telegram bot
3.1 Telegram account identifiers. When you start a conversation with Ingy, Telegram passes us:
- your Telegram user ID;
- your Telegram username, if you have one;
- your Telegram language code.
3.2 We use these to identify your account, associate your drafts and settings with you, and reply to you in an appropriate language.
3.3 Content you submit. We process whatever you send the bot in order to produce your drafts. This includes:
- article URLs;
- video links;
- uploaded video files;
- typed instructions;
- voice messages, which are transcribed to text so that we can act on them.
3.4 Content you submit may contain personal data about you or about other people, depending on what you send. Section 5 explains your responsibilities when you send us material about other people.
3.5 Output we generate for you. We store the posts Ingy drafts for you, their successive versions, and their block structure, so that you can revisit, edit and reuse them.
3.6 Your style profile. We derive and store a model of how you write. Because this is data about you that we infer rather than data you hand us, we address it separately in Section 7.
3.7 Subscription and billing records. We store your subscription status, your plan, your quota usage, and records of payment events (for example that a payment succeeded, failed or was refunded, and when). Card details and other payment credentials are handled by Creem, not by us — see Section 12.
3.8 Support correspondence. If you email us or message us for support, we process the contents of that correspondence in order to help you and to keep a record of the issue.
4. Personal data we collect through the website
4.1 Server and security data. Like any website, our hosting infrastructure processes technical data necessary to deliver pages and keep the service secure and available, including IP address and request metadata. This is necessary to operate the site and to detect and prevent abuse.
4.2 Checkout data. If you go to /subscribe, the checkout is operated by Creem (Armitage Labs OÜ) as Merchant of Record. You enter your payment details with Creem. We receive from Creem the transaction and subscription records we need to give you access and to keep our accounts — we do not receive or store your full card number.
4.3 Cookies and similar technologies. See Section 19. Analytics cookies are off until you accept them.
4.4 Any email address you give us. If you give us an email address — for example to contact us, or to receive updates where we offer that — we process it for the purpose you gave it to us for. We only send marketing email where we have a lawful basis to do so, and any marketing email will include a one-click unsubscribe.
5. Content about other people
5.1 Ingy is a drafting tool. You choose what to feed it. If the sources or instructions you send contain personal data about other people — for example an article about a named individual, or a video featuring someone — that data will be processed by us and by the providers listed in Section 12 in order to produce your draft.
5.2 You are responsible for making sure you have the right to send us the material you send, and for complying with any law, contract or platform rule that applies to your use of that material.
5.3 Please do not send the bot special category data (such as health, biometric, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation data), criminal offence data, or anyone's confidential information. The product is not designed for that, and we do not ask for it.
6. Where our information about you comes from
6.1 Most of the personal data we hold comes directly from you — you send it to the bot, or you enter it on the website.
6.2 Some comes from Telegram, which passes us your user ID, username and language code when you use the bot.
6.3 Some comes from Creem, which tells us the outcome of your payments and the state of your subscription.
6.4 Some we generate or infer ourselves: your drafts, your usage counts, and your style profile.
6.5 Some is retrieved from public sources at your instruction: when you give us a link, our providers fetch that page or that video transcript so we can work from it.
7. Your style profile — data we infer about you
7.1 We treat this section as the most important disclosure in this policy, because it is the least obvious thing we do.
7.2 What it is. As you use Ingy, we build and maintain a "style profile": a derived model of how you write. It is not a copy of your posts. It is an abstraction of your writing behaviour across six facets:
| Facet | What it captures |
|---|---|
| Voice | Tone, register, persona and attitude that characterise your writing |
| Format | How you structure a post — length, paragraphing, use of lists, openers and closers |
| Lexicon | Words, phrases, terminology and turns of phrase you tend to use or favour |
| Metrics | Measurable characteristics of your writing, such as typical lengths and ratios |
| Rules | Positive instructions you have given or that we have inferred about how you want posts written |
| Avoid | Things you do not want — words, formats, claims or patterns you have rejected |
7.3 Why we say it is personal data. The style profile is inferential personal data: information about an identified individual that we have derived rather than been told. Under UK GDPR it is personal data in exactly the same way as data you typed in yourself, and all of your rights in Section 18 apply to it — including the right to access it, to have it corrected, and to have it erased.
7.4 How we build it. It is derived from the content you submit, the drafts we produce, and your reactions to those drafts (for example edits you make, versions you keep, and instructions you give about what to change).
7.5 What we use it for. Solely to make the posts Ingy drafts for you sound more like you. It is used to serve you.
7.6 Automated processing. Building and applying the style profile is automated. It is not automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 UK GDPR — the output is a draft that you are free to edit, discard or ignore. We do not use the style profile to make decisions about your access to the service, your pricing, or anything else that affects your rights.
7.7 Your control. You can ask us at any time, at [email protected], to show you your style profile, to correct it, or to delete and rebuild it. Deleting it will reduce how well Ingy matches your voice until it is rebuilt.
7.8 Retention. We keep your style profile while your account is active. It is deleted when your account is deleted. See Section 16.
8. Why we process your data, and our legal bases
8.1 UK GDPR requires us to have a lawful basis for each purpose. Ours are set out below.
| # | Purpose | Personal data used | Legal basis |
|---|---|---|---|
| 1 | Providing the Ingy service: receiving your sources and instructions, transcribing audio, retrieving page and video content, generating drafts, storing your posts and versions | Telegram identifiers, submitted content, generated posts and versions | Contract — necessary to perform our contract with you |
| 2 | Building and applying your style profile so drafts sound like you | Submitted content, generated posts, your edits and instructions | Contract — necessary to perform our contract with you |
| 3 | Managing your subscription, plan, quota and access | Subscription status, plan, quota usage, payment event records | Contract |
| 4 | Customer support | Correspondence, account and usage records | Contract |
| 5 | Product analytics: understanding retention, churn, funnels and feature usage (content-free — see Section 10) | Counts, enumerated values, durations, hostnames, coarse geography | Legitimate interests — understanding how our product is used so we can run and improve it |
| 6 | LLM tracing: debugging, quality assurance and understanding model cost (contains content — see Section 11) | Prompts and outputs keyed to a user ID | Legitimate interests — operating, debugging and improving a reliable service and controlling its cost |
| 7 | Security, fraud and abuse prevention; investigating suspected misuse | Account, usage, technical and where necessary content data | Legitimate interests — protecting our service, our users and our business |
| 8 | Improving the service and developing our models within the limits in Section 13 | Content you created while a permitting policy version was in force, excluding the categories listed in 13.4 | Legitimate interests — improving a product our users pay for |
| 9 | Website cookies that are not strictly necessary, and marketing email where we send it | Cookie and measurement identifiers on the website; email address | Consent — you may withdraw it at any time |
| 10 | Keeping financial, tax and accounting records | Transaction and subscription records | Legal obligation |
| 11 | Establishing, exercising or defending legal claims, and responding to lawful requests | Whatever is relevant and necessary | Legitimate interests, and legal obligation where a law requires it |
8.2 Our legitimate interests assessment, in short. Where we rely on legitimate interests, we have considered whether our interest is overridden by your interests, rights and freedoms. We have limited the data used (for example by excluding all content from product analytics), restricted who can access it, applied retention limits, and given you a right to object under Section 18. You can ask us for more detail about any legitimate interests assessment at [email protected].
8.3 You can object. You have the right to object to any processing we carry out on the basis of legitimate interests. See Section 18.
9. What we deliberately do NOT collect
9.1 This section describes design choices we have made. They are commitments, and they are accurate as at the version date of this policy.
9.2 Our product analytics contain no user content. Our product analytics system (PostHog, see Section 10) deliberately does not receive:
- the text of any post we generate for you;
- the text of any source you give us;
- the text of any instruction you type;
- titles;
- notes.
9.3 URLs are reduced to hostname only in product analytics. If you give the bot a link, our analytics record only the hostname (for example example.com), never the full URL, path or query string.
9.4 IP-based geolocation is disabled in our product analytics. We have switched it off. Any geography we hold in analytics is coarse, and we do not derive your location from your IP address in that system.
9.5 We do not collect your payment card details. Card data goes to Creem. We never see or store your full card number.
9.6 We do not ask for, and do not want, special category or criminal offence data. See Section 5.3.
9.7 We do not sell personal data. See Section 13.6.
9.8 We do not use cookies or any device-storage identifiers in the Telegram bot. See Section 2.3.
9.9 Please note what this section does not say. It does not say that no human ever sees your content — that would not be true, and Section 11 and Section 14 explain honestly who can and when. It does not apply to our LLM tracing system, which by design does contain content (Section 11).
10. Product analytics (PostHog) — server-side, content-free, no cookies
10.1 We use PostHog to understand how the product is used. In the bot, this runs entirely server-side: we send events from our own servers. No cookies and no device identifiers are involved in the bot.
10.2 What is recorded. Counts, enumerated values (for example which of a fixed set of features was used), durations, hostnames, and coarse geography.
10.3 What is not recorded. No user content of any kind — no post text, no source text, no instruction text, no titles, no notes. URLs are reduced to hostname only. IP-based geolocation is disabled.
10.4 What we use it for. Retention analysis, churn analysis, funnel analysis and feature-usage analysis, so that we can see what works, what is broken and what to build.
10.5 Legal basis: legitimate interests, not consent. This is important and we want it to be unambiguous. Because there are no cookies and no access to information stored on your device in the bot, PECR's consent requirement does not apply here. Bot-side product analytics therefore run under our legitimate interests (Section 8.1, purpose 5), and they are not governed by the cookie banner on our website. The cookie banner on ingy.app governs the website only.
10.6 Your right to object. You may still object to this processing under Article 21 UK GDPR. Email [email protected].
11. LLM tracing (Langfuse) — this one does contain your content
11.1 We want to be straightforward about this, because it is different from Section 10.
11.2 We use Langfuse to trace how our AI pipeline behaves. Unlike our product analytics, Langfuse traces do contain the actual prompt and output content, keyed to a user ID. In practice that means the source material and instructions sent to the model, and the text the model returns, can appear in a trace linked to your account.
11.3 Why we do it. Three reasons, and only these three: debugging (finding out why something went wrong), quality (seeing whether outputs are good and improving them), and understanding model cost.
11.4 Where it runs. Langfuse is hosted in the EU cloud. See Sections 12 and 14.
11.5 Legal basis. Legitimate interests (Section 8.1, purpose 6). We cannot operate, debug or improve an AI product without being able to see what the model was asked and what it produced.
11.6 Access controls. Trace data is subject to the same access restrictions as the rest of your content — see Section 14.
11.7 Your right to object. You may object under Article 21 UK GDPR by emailing [email protected]. Note that if we cannot trace your requests, our ability to diagnose problems affecting your account is reduced.
12. Sub-processors and other recipients
12.1 We use the third parties below. We do not sell your personal data to any of them or to anyone else.
| Provider | What they do for us | Do they receive your content? | Location of processing |
|---|---|---|---|
| Anthropic | AI generation — producing your drafts | Yes — sources, instructions and drafts | Outside the UK, including the USA |
| OpenAI | Whisper audio transcription — turning your voice messages into text | Yes — your voice message audio and its transcript | Outside the UK, including the USA |
| Supadata | Video transcript retrieval — obtaining transcripts for video links you give us | Yes — the video link and the retrieved transcript | Outside the UK, including the USA |
| Firecrawl | Article page fetching, used as a fallback when we cannot retrieve a page directly | Yes — the URL and the retrieved page content | Outside the UK, including the USA |
| Langfuse | LLM tracing for debugging, quality and cost (Section 11) | Yes — prompt and output content, keyed to a user ID | EU cloud |
| PostHog | Product analytics (Section 10), and website analytics in a separate project (Section 19) | No — no user content in either project; hostnames only, plus website page addresses | United States |
| Creem (Armitage Labs OÜ, Estonia) | Merchant of Record and payment processing. Creem is a separate, independent controller for payment data, not our processor, and applies its own privacy terms to that data | Payment and billing data; not your drafting content | Outside the UK, in the EU |
| Telegram | The messaging platform the product runs on. Your messages to and from Ingy travel through Telegram, and Telegram applies its own terms and privacy practices to your Telegram account | Yes — as the transport layer for everything you send and receive in the bot | Per Telegram's own arrangements |
| Hetzner Online GmbH | Hosting and database — our servers and your stored data | Yes — stored content resides on this infrastructure | Germany |
12.2 Except for Creem and Telegram, the providers above act as our processors: they process personal data on our instructions, under a written contract that includes the terms required by Article 28 UK GDPR.
12.3 Creem acts as a separate controller for payment data. That means Creem decides how it processes payment data and is responsible to you directly for it. We remain the controller for the subscription and payment event records we hold (Section 3.7).
12.4 Telegram is the platform on which the bot operates. We do not control Telegram. Your relationship with Telegram, including how Telegram handles your account and your messages, is governed by Telegram's own terms and privacy policy.
12.5 Other recipients. We may also disclose personal data to: our professional advisers (such as lawyers and accountants) where they need it and are bound by confidentiality; law enforcement, regulators or courts where we are legally required to, or where it is necessary to establish, exercise or defend legal claims; and a buyer or successor in the event of a merger, acquisition or sale of assets, in which case we will notify you and this policy will continue to apply until replaced.
12.6 We may change sub-processors as the product develops. Material changes will be reflected in an updated version of this policy under Section 21.
13. AI providers, model training, and our no-sale commitment
How AI providers process your content
13.1 Ingy cannot work without sending your content to AI providers. When you give the bot a source and an instruction:
- the audio of a voice message goes to OpenAI for transcription;
- a video link goes to Supadata to retrieve a transcript;
- an article URL goes to Firecrawl where we need a fallback to fetch the page;
- the resulting material and your instructions go to Anthropic, which generates the draft;
- the prompt and output are recorded in Langfuse for the purposes in Section 11.
13.2 These providers process this content in order to return a result to us. We contract with them as processors (except Creem and Telegram, which are addressed in Section 12) and instruct them to process only for the purpose of delivering their service to us.
Model training
13.3 We are not currently training models on your content. We reserve the right to do so in future. Content may be used to develop and improve the service and its models, subject to the limits below.
13.4 Exclusions — content we will never use for this purpose:
- never third-party source material — the articles, pages, videos and transcripts we retrieve on your behalf;
- never voice audio recordings;
- never content from accounts covered by a data processing agreement with us;
- never content from users who have opted out.
13.5 Two further limits:
- Opt out at any time. Email [email protected]. There is no cost and no penalty, and it does not affect your access to the service.
- Version-gated eligibility. Only content created while a version of this policy permitting such use is in force is eligible. We will not retrospectively apply a future permission to content you created earlier.
No sale of personal data
13.6 We do not sell your personal data, and we will not sell your personal data. We do not share it with third parties for their own independent marketing purposes. The only third parties who receive it are those in Section 12, for the purposes stated there.
14. Human access to your content
14.1 We are not going to tell you that no one ever reads your content. That would not be true of any service of this kind, and we would rather be accurate than reassuring.
14.2 The honest position: a small number of authorised personnel may access user content where necessary to operate, debug, secure or improve the service, and to investigate suspected abuse or to comply with the law. Access is limited to those who need it and is restricted on a need-to-know basis.
14.3 In practice this means access may occur when, for example:
- we are diagnosing a fault that affects your drafts or your account;
- we are investigating a security incident;
- we are investigating suspected abuse of the service or a breach of our rules;
- we are responding to a support request from you;
- we are required to by law, a court order or a valid request from a competent authority;
- we are assessing output quality in order to improve the product.
14.4 Personnel with such access are bound by confidentiality obligations. Access to systems containing content is controlled and limited.
14.5 Our sub-processors may also have personnel with access to data on their own systems, under their own contractual and security obligations to us.
15. International transfers
15.1 Some of the providers in Section 12 process personal data outside the United Kingdom, including in the United States of America. Specifically: Anthropic, OpenAI, Supadata, Firecrawl and PostHog. Creem processes payment data in the European Union.
15.2 Where we transfer personal data out of the UK, we rely on one of the following safeguards, as applicable to the provider and destination:
- UK adequacy regulations, where the UK Government has decided that the destination country provides an adequate level of protection; or
- the UK International Data Transfer Agreement (IDTA), or the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, supported by a transfer risk assessment.
15.3 Langfuse processes in the EU cloud. Hetzner Online GmbH hosts in Germany. Transfers to the EEA are covered by UK adequacy regulations for the EEA.
15.4 Telegram operates its own international infrastructure. Because Telegram is the platform on which the bot runs and not our processor, your messages transit Telegram's systems under Telegram's own arrangements, which we do not control.
15.5 You can request a copy of the relevant safeguards by emailing [email protected]. We may redact commercial terms.
16. How long we keep your data
16.1 We keep personal data only as long as we need it for the purposes in this policy, or as long as the law requires.
| Category | Retention |
|---|---|
| Your posts, their versions and block structure | Kept while your account is active. Deleted when your account is deleted. |
| Your style profile | Kept while your account is active. Deleted when your account is deleted. |
| Submitted content (sources, instructions, transcripts) held in your account | Kept while your account is active; deleted when your account is deleted |
| Payment and financial records | Retained for 6 years, as required by UK tax and accounting law. These survive account deletion because we are legally required to keep them. |
| Product analytics | Retained in aggregate form for trend analysis |
| LLM traces | Retained for as long as needed for debugging, quality and cost analysis, then deleted |
| Support correspondence | Kept for as long as needed to resolve the matter and to handle any follow-up or dispute |
| Records needed for legal claims | Kept until the relevant limitation period expires |
16.2 Backups are cycled on a routine schedule. Data deleted from live systems may persist in backups for a short period before being overwritten in the normal course.
17. Security
17.1 We take appropriate technical and organisational measures to protect personal data, including:
- encryption of data in transit;
- access controls, so that access to systems holding content is limited to those who need it (Section 14);
- infrastructure hosted with a professional provider (Hetzner Online GmbH, Germany);
- contractual security obligations on our sub-processors;
- restricted administrative access and confidentiality obligations on personnel.
17.2 No system is completely secure, and we cannot guarantee absolute security. We do not promise that a breach can never happen.
17.3 If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours where required, and we will tell you without undue delay where the breach is likely to result in a high risk to you.
17.4 The Telegram layer is not ours. Messages between you and Ingy travel through Telegram. The security of your Telegram account — including your password, your device, and whether you use Telegram's own security features — is your responsibility and Telegram's, not ours.
18. Your rights
18.1 Under UK GDPR you have the following rights in relation to your personal data:
| Right | What it means |
|---|---|
| Access | To be told whether we process your data and to receive a copy of it |
| Rectification | To have inaccurate data corrected and incomplete data completed — this includes your style profile |
| Erasure | To have your data deleted, where one of the grounds in Article 17 applies |
| Restriction | To have us limit how we use your data in certain circumstances |
| Portability | To receive data you provided to us in a structured, commonly used, machine-readable format, and to have it sent to another controller where technically feasible |
| Objection | To object to processing based on legitimate interests, including our product analytics, LLM tracing and service improvement. You may object to direct marketing at any time and we will always stop |
| Withdraw consent | Where we rely on consent — website cookies and marketing email — to withdraw it at any time. Withdrawal does not affect processing carried out before you withdrew |
18.2 How to exercise your rights. Email [email protected]. Tell us what you want and, so we can find your data, your Telegram username or user ID.
18.3 Timing and cost. We will respond within one month. We may extend this by up to two further months for complex or numerous requests, and we will tell you if we do. Requests are free, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse — and we will explain why.
18.4 Identity. We may need to take steps to satisfy ourselves that a request comes from you, to avoid disclosing your data to someone else.
18.5 Limits. Some rights are qualified. For example, we may not be able to erase payment records that UK law requires us to keep for 6 years (Section 16), and we may retain data where necessary to establish, exercise or defend legal claims. We will always tell you if we rely on an exemption and why.
18.6 Deletion on request via Telegram. Telegram's Bot Developer Terms require bot developers to delete a user's data on that user's request. We honour this. If you ask us to delete your data, we will delete your account data, your posts and versions, and your style profile, subject only to the legal retention obligations in Section 16.
18.7 Complaints. If you are unhappy with how we handle your data, please tell us first at [email protected] so we can try to put it right. You also have the right to complain to the UK supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom
Website: ico.org.uk
Helpline: 0303 123 1113
18.8 Complaining to the ICO does not affect any other legal remedy you may have.
19. Cookies — short summary
19.1 This is a self-contained summary. You do not need any other document to understand our cookie position.
19.2 The Telegram bot sets no cookies at all. Cookies are a browser technology; the bot does not use them and does not store or access information on your device. Nothing in this section applies to the bot.
19.3 Cookies exist only on our website, ingy.app. We use two categories:
- Strictly necessary cookies. These are required for the site to work: session and security, checkout functionality on
/subscribe, and remembering your cookie choice itself. Under PECR these do not require your consent, and you cannot turn them off through our banner without breaking the site. - Analytics and measurement cookies. These require your consent. No analytics cookie is set unless you accept. Until then, website measurement runs cookie-free: it keeps no identifier on your device, so page views cannot be linked across visits.
19.4 How we ask. When you first visit ingy.app from the UK, the EU or the wider EEA, you will see a banner with an equally prominent Accept and Decline, each a single click. Neither is pre-selected, no analytics cookie is set before you choose, and none is set at all if you decline or simply ignore it. Visitors outside those countries are not shown a banner; Cookie Policy Section 6.2.2 explains what that means.
19.5 Changing your mind. You can withdraw your consent at any time by deleting our cookies for ingy.app in your browser, which returns website analytics to the cookie-free default and makes the banner ask you again on your next visit. You can also email [email protected] and we will confirm the withdrawal and erase the data associated with it. Cookie Policy Section 7.5 gives the detail.
19.6 A note on the law. The Data (Use and Access) Act 2025 amended PECR with effect from 5 February 2026, so that certain first-party analytics cookies can be used without consent. We have chosen not to rely on that exemption. We ask for consent for all analytics cookies on our website, which is the stricter approach.
19.7 The banner governs the website only. Our bot-side product analytics (Section 10) and LLM tracing (Section 11) involve no cookies and are not gated by the banner. They run under legitimate interests, and you can object to them under Section 18.
19.8 Browser controls. You can also block or delete cookies in your browser settings. Blocking strictly necessary cookies may stop parts of the website, including checkout, from working.
20. Children
20.1 Ingy is for adults. The service is 18+.
20.2 We do not knowingly collect personal data from anyone under 18. The service is not directed at children and we do not design it for them.
20.3 If you believe a person under 18 has provided us with personal data, contact [email protected] and we will delete it.
21. Changes to this policy
21.1 We may update this policy as the product, our providers or the law change.
21.2 Every version carries a version number and an effective date at the top. The current version is 1.1, effective 30 August 2026.
21.3 Where a change is material — for example a new purpose, a new category of data, or a change to model training under Section 13 — we will take reasonable steps to bring it to your attention before it takes effect, such as a message in the bot or a notice on ingy.app.
21.4 As stated in Section 13.5, permissions relating to model training apply only to content created while a version of this policy permitting that use is in force. We will not apply a future permission retrospectively.
21.5 Continuing to use Ingy after a change takes effect means the updated policy applies to your continued use. It does not, by itself, constitute consent where the law requires separate consent.
22. Contact and company details
22.1 For any privacy question, request or complaint:
Email: [email protected]
22.2 For legal matters and formal notices:
Email: [email protected]
22.3 We have not appointed a Data Protection Officer, as we are not required to do so. Privacy queries go to [email protected].
22.4 Supervisory authority: the Information Commissioner's Office, ico.org.uk.
End of Privacy Policy — Version 1.1, effective 30 August 2026.
Contact
IX Labs
27 Old Gloucester Street, London, WC1N 3AX, United Kingdom
General enquiries: [email protected]
Legal notices: [email protected]