Privacy Policy
Effective: July 6, 2026
Who we are
Instila is an AI chief of staff for software companies. It reads the tools you connect, builds a memory of how your company works, and prepares work for your approval. This policy covers instila.net, our website. Data inside a connected workspace is covered by the product privacy terms shown before you connect anything; where those differ from this policy, they govern the data the product processes.
What we collect on this site
Early-access data. When you request access, we store your email address and how you found us (UTM parameters, referrer).
Messages you send us. When you email us, we keep your message and address so we can reply.
Usage data. Basic logs, pages visited, features used, errors, to run and improve the site.
What we do not do
- We do not sell your data.
- We do not use it to profile you for advertising.
- We do not train AI models on it.
How we use your data
- To respond to you and provide early access to Instila.
- To email you about Instila and its launch. We only email you about what you asked for, and you can opt out at any time.
- To operate, secure, and improve the website.
Sub-processors we use
- Vercel, website and edge hosting.
- Supabase, database hosting for early-access entries, encrypted at rest with AES-256.
- Resend, transactional email delivery.
- Clerk, identity and authentication, if and when you create an account.
- Stripe, payment processing when we bill you. Instila never sees or stores your card number.
Instila reads a connected tool only after you grant access to it, and only the channels, repositories and projects you select. We do not train models on your company's data. Disconnecting a tool removes what came from it.
Data retention and deletion
- We keep your early-access email until you ask us to remove it, or until we launch and you decline to continue.
- Data held inside a connected workspace, including the memory Instila builds, is governed by that workspace's retention and deletion controls. You can delete the memory in whole or a single fact at a time.
- You can request deletion at any time by emailing mail@instila.net.
Security
AES-256 encryption at rest. TLS 1.3 in transit. Access to stored data is logged and limited to what's needed to operate the service. We target SOC 2 Type II certification within 12 months of a product's public launch.
Your rights (GDPR & CCPA)
If you're in the EU, UK, or California, you have the right to access, correct, export, or delete your personal data at any time. To exercise any of these rights, email mail@instila.net. We will respond within 30 days.
Cookies
We keep cookies to a minimum, an authentication session cookie if you sign in (set by Clerk), and nothing more. No advertising cookies. No third-party tracking pixels.
Changes to this policy
We will post any change here, and the effective date at the top of this page will always reflect the current version. Material changes to the product's privacy terms are communicated in the product itself.
Contact
Questions or requests: mail@instila.net
Instila, Toronto, Ontario, Canada