Incraft

Privacy Policy

Effective Date: March 30, 2026

1. Who We Are and Scope

This Privacy Policy explains how Incraft (“Incraft,” “we,” “us,” or “our”), operated by LaunchSpace LLC, collects, uses, discloses, and protects personal information when you visit incraft.io, create AI-generated meditation sessions, sign in, purchase a subscription, or otherwise use our website and related services (collectively, the “Service”).

This Policy applies to anonymous visitors, signed-in users, and paying subscribers. It does not apply to third-party websites, apps, or services that we do not control, even if they are linked from or used with the Service.

2. Information We Collect

Depending on how you use the Service, we may collect the following categories of information:

2.1 Account and sign-in information

  • Anonymous account/session data. When you first visit the Service, we may create an anonymous account through Supabase Auth so you can use the Service without immediately signing in with email. For anonymous users, we do not collect an email address through the anonymous sign-in flow.
  • OAuth sign-in information. If you choose to sign in with Google or Apple, we may receive information from that provider, such as your email address, display name or full name, and avatar or profile photo URL.
  • Profile information. We store account-related information such as your user ID, email, display name, avatar URL, whether the account is anonymous, your plan, credits, and saved preferences.

2.2 Meditation content and generation data

  • Your meditation prompts and any personal information you choose to include in them.
  • Your selected options and settings, such as voice, duration, protocol, soundscape, category, intent, title, and sound preferences.
  • Generated outputs and related records, such as scripts, audio file URLs, generation status, timestamps, and performance/timing data.

2.3 Billing and subscription information

  • If you purchase a paid plan, Stripe processes your payment. We receive billing and subscription metadata such as your email address, Stripe customer and subscription identifiers, plan, billing cycle, status, and related transaction metadata.
  • We do not store full payment card numbers on our own servers.

2.4 Technical, security, and anti-abuse data

  • Authentication and session cookies used to keep you signed in and maintain secure sessions.
  • Hashed IP information for anonymous rate limiting. For anonymous users, we store a SHA-256 hash of the IP address and a daily count to enforce usage limits; we do not store the raw IP address for that purpose.
  • Operational metadata needed to keep the Service working, such as timestamps, request status, generation outcomes, and performance metrics.

2.5 Support communications

If you contact us, we collect the information you include in your message, such as your name, email address, and the contents of your request.

2.6 Information we do not intentionally collect through the Service

  • We do not request access to your microphone, camera, or precise geolocation through the Service.
  • Based on the current implementation, we do not use third-party advertising cookies, ad networks, or third-party analytics scripts.

2.7 Sensitive information

We do not ask you to provide medical records, government identification numbers, or precise geolocation data to use the Service. However, because meditation prompts are free text, you may choose to include sensitive or health-related information about stress, sleep, anxiety, or other personal matters. Please avoid including highly sensitive personal information unless it is truly necessary for the meditation you want to generate.

3. How We Use Information

  • Provide, operate, personalize, and maintain the Service.
  • Create and manage anonymous and authenticated accounts and keep you signed in.
  • Generate personalized meditation scripts and audio sessions, and deliver playback to you.
  • Store and organize your sessions, generations, preferences, credits, and subscriptions.
  • Process subscriptions, billing events, credits, refunds, and account-related transactions.
  • Enforce anonymous usage limits, detect misuse, and protect the security and integrity of the Service.
  • Troubleshoot problems, monitor performance, improve reliability, and develop features.
  • Respond to support requests and account inquiries.
  • Comply with legal obligations and enforce our terms, policies, and rights.

4. How AI and Audio Processing Works

When you request a meditation, we send your prompt and selected generation options to our script-generation provider so a meditation script can be created. The generated script text is then sent to our text-to-speech provider so audio can be rendered. We intentionally do not send your user ID to the script-generation API. Generated audio is stored and delivered through AWS-hosted storage/CDN infrastructure and our audio proxy.

5. Cookies and Similar Technologies

We use cookie-based session technology that is necessary for authentication and secure session management. These cookies help keep you signed in and allow session refresh and account continuity. Based on the current implementation, we do not use third-party advertising cookies and we do not use third-party analytics scripts. If we introduce non-essential cookies or tracking tools in the future, we will update this Policy and, where required, request consent.

6. Legal Bases for Processing (EEA/UK/Switzerland)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, we generally process personal data on one or more of the following bases: (a) to perform our contract with you or take steps you request before entering into a contract; (b) for our legitimate interests, such as securing, operating, improving, and supporting the Service; (c) to comply with legal obligations; and (d) with your consent where consent is required by law.

7. How We Share Information

We do not sell personal information, and we do not share personal information with ad networks or for cross-context behavioral advertising.

7.1 Service providers and processors

  • Supabase, which provides authentication, database, and related backend services.
  • Stripe, which processes subscription payments, billing, and related payment events.
  • Our script-generation provider and AWS-hosted text-to-speech, storage, and delivery infrastructure, which process prompts, scripts, and audio to provide the Service.
  • Google or Apple, if you choose to use those providers to sign in.

7.2 Other disclosures

  • We may disclose information if required by law, regulation, legal process, or governmental request.
  • We may disclose information when we believe it is necessary to protect the rights, property, safety, or security of Incraft, our users, or others.
  • If Incraft is involved in a merger, acquisition, financing, reorganization, sale of assets, or similar transaction, information may be transferred as part of that process, subject to applicable law.

8. International Data Transfers

The Service and our service providers may process information in countries other than your own, including the United States. For example, certain AI, text-to-speech, storage, and delivery services are hosted in AWS us-east-1, and the region for Supabase depends on project configuration. If you access the Service from outside those jurisdictions, your information may be transferred to and processed in countries that may have different data protection laws from those in your home country. Where required, we will use appropriate safeguards for such transfers.

9. Data Retention

We retain personal information for as long as reasonably necessary to provide the Service, maintain your account, process transactions, enforce limits, resolve disputes, comply with legal obligations, and protect the Service.

9.1 Retention examples

  • Account and profile information may be retained while your account is active and for a reasonable period afterward as needed for legal, billing, security, or recordkeeping purposes.
  • Meditation sessions, generations, scripts, and audio-related records may be retained until you delete them, request deletion, or we no longer need them for the purposes described in this Policy.
  • Session deletion may be implemented as a soft delete in our systems before later cleanup.
  • Billing, subscription, and credit-ledger records may be retained as needed for accounting, tax, fraud-prevention, dispute-resolution, and compliance purposes.
  • Audio delivered through our audio proxy may remain temporarily cached for up to approximately 24 hours.
  • Hashed IP-based rate-limit records may be retained for as long as reasonably necessary to enforce anonymous usage limits and protect the Service.

10. Security

We use administrative, technical, and organizational measures designed to protect personal information. These measures include secure authentication and session handling, row-level access controls in our backend, security headers, hashed IP rate-limiting for anonymous users, allowlist-based audio proxying, route protection for restricted areas, and signature verification for Stripe webhooks. No method of transmission over the internet or electronic storage is completely secure, so we cannot guarantee absolute security.

11. Your Rights and Choices

Depending on where you live, you may have privacy rights regarding your personal information. These rights may include the right to access, know about, correct, delete, restrict certain processing of, object to certain processing of, or receive a portable copy of your personal information, subject to applicable exceptions.

11.1 Managing information in the Service

  • You may be able to update certain profile details, such as your display name and preferences, through the Service.
  • If you want to request access, correction, deletion, or a copy of your information, you can contact us using the contact details below.

11.2 California notice

If you are a California resident, California law may provide rights such as the right to know, delete, correct, and opt out of the sale or sharing of personal information, subject to certain limitations. Incraft does not sell personal information and does not share personal information for cross-context behavioral advertising.

11.3 EEA/UK/Switzerland notice

If you are in the EEA, UK, or Switzerland, you may also have rights to information, access, rectification, erasure, restriction, portability, objection, and to lodge a complaint with your local data protection authority, as provided by applicable law.

11.4 Verification and limits

We may need to verify your identity before acting on certain requests. Some rights are limited by law and may not apply in every circumstance.

12. Children's Privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13 through the Service. If you believe that a child under 13 has provided personal information to us, please contact us so we can investigate and take appropriate action.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will post the updated Policy on the Service and update the Effective Date above. Your continued use of the Service after an updated Policy becomes effective means the updated Policy will apply to your use of the Service, to the extent permitted by law.

14. Contact Us

Incraft is operated by LaunchSpace LLC.

If you have questions, requests, or concerns about this Privacy Policy or your personal information, you can contact us at:

contact@launchspace.org

Terms of ServiceContact