Privacy Policy
Last updated:
Data controller
What we collect
- Account data: email, name, public handle, locale.
- Booking data: client name, email, references, design preferences, appointment times.
- Payment metadata via Stripe (we never see card numbers).
- Usage data: pages viewed, AI tokens consumed, abuse-prevention logs.
- Cookies as described in the Cookie Policy.
Legal bases (GDPR)
Subprocessors
Google user data
When an artist connects their Google account, Inkfloww accesses Google user data via Google APIs strictly to deliver the booking features the artist enabled. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Scopes we request and why
openid,userinfo.email,userinfo.profile— identify the Google account being linked and show it in the dashboard.https://www.googleapis.com/auth/calendar.events— create, update, move, and cancel Google Calendar events that correspond to the artist's bookings, and read the artist's availability to prevent double-booking.https://www.googleapis.com/auth/gmail.send— send booking confirmations, reminders, deposit requests, and consent-form links from the artist's own Gmail address, so clients recognise the sender.
How Google user data is used, stored and shared
- Use: only for the booking, calendar-sync and client-communication features described above. We do not use Google user data to serve advertising, and we do not use it to develop, train, improve or fine-tune generalised AI or machine-learning models.
- Storage: Google OAuth access and refresh tokens are encrypted at rest in our database (AES-GCM). Event metadata we create is kept only as long as the related booking is active plus the retention period stated above. Gmail message content is not archived by Inkfloww; we send through the Gmail API and store only delivery status.
- Sharing: Google user data is never sold. It is not shared with third parties except the subprocessors strictly needed to operate the feature (Cloudflare hosting, Supabase database, Google itself), only to the extent required to deliver or improve user-facing features, to comply with applicable law, or as part of a merger/acquisition subject to equivalent protections.
- Human access: Inkfloww personnel do not read Google user data except (a) with the artist's explicit consent, (b) for security investigations, (c) to comply with applicable law, or (d) in aggregate/de-identified form for internal operations.
Revoking access
Artists can disconnect Google at any time from Dashboard → Calendar → Disconnect Google, which deletes the stored tokens, or by revoking access directly at myaccount.google.com/permissions. Revocation stops all further Google API calls immediately.
AI providers and isolation from Google user data
Inkfloww uses third-party large-language-model providers, accessed exclusively through the Lovable AI Gateway, to power the client-facing intake assistant that talks to prospective clients on an artist's public booking page. The underlying models currently used are OpenAI GPT-5 family and Google Gemini 2.5 family. These providers act as data processors under contractual terms that prohibit using submitted content to train their generalised models.
The use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, Inkfloww enforces strict data isolation between Google user data and the AI providers:
- Google user data obtained via Google APIs (Calendar events, availability, Gmail send metadata, OAuth profile) is never sent to, or shared with, any AI/ML provider — not for inference, not for training, not for fine-tuning, not for model evaluation, and not for any human review by the AI provider.
- The AI assistant only receives data the prospective client voluntarily types into the public chat (name, contact email, tattoo idea, reference images, budget, preferred dates) plus the artist's own public profile fields (bio, styles, portfolio). None of this is obtained from a Google API.
- When the AI proposes appointment slots, it uses only an abstracted availability window computed on our servers; raw Google Calendar event contents (titles, attendees, descriptions) are never included in AI prompts.
- Emails sent via Gmail on behalf of the artist are composed from Inkfloww-owned templates and booking fields. The Gmail API is used only as a transport; message bodies are not sent to any AI provider.
- Inkfloww does not use Google user data to develop, improve, train or fine-tune any generalised AI/ML model, whether our own or a third party's.