Intakes

Privacy Policy

Last updated 9 September 2026

Intakes is an inventory and cost-accounting application for people who buy, make and resell goods. This policy explains what we hold, why, and what you can ask us to do about it. It is written to be read, not to be survived.

Who we are

Intakes is operated by Clean Code LLC, a Minnesota limited liability company ("we", "us"). For anything in this policy, including requests about your data, write to support@intakes.app.

What we hold

Four kinds of thing, and it is worth keeping them apart.

1. Your account

WhatWhy
Email addressIt identifies your account and is how we reach you about it.
First and last nameSo teammates see a person rather than an address.
Profile picture, if you upload oneOptional. Nothing depends on it.
Whether you have confirmed your email, and when you accepted these termsRequired to open an account, and a record that you did.
Which workspaces you belong to and what you may do in themAccess control.

We do not store your password. Credentials are held by Ory Kratos, which we run on our own servers — so it is not a third party we hand your password to, but it is also not somewhere we can read it from. The same is true of passkeys: we hold a public key, never anything that can be used to sign in as you.

2. Your business data

Everything you record in a workspace: items, purchases, suppliers, costs, stock, production runs, sales, returns, listings, photographs, and free-text notes. We hold it so the application can show it back to you and calculate from it. We do not read it for any other purpose, we do not use it to train anything, and we do not sell it or share it with advertisers.

One thing to be aware of, because it is your choice rather than ours: notes and reference fields are free text, so whatever you type into them is what we end up holding. If you record a buyer's name or address in a note, that is personal data about that person, and you are the one who decided to put it there.

If you connect a marketplace account — such as eBay — to one of your sales channels, we hold the access credential that marketplace gives us, encrypted, and use it only for what the application says it does with that account, such as bringing in your orders. Disconnecting deletes it. What it brings in — orders, the buyers named on them — is business data like the rest.

3. Operational records

WhatWhy
An audit trail of who changed what, and when, inside your workspaceSo your own team can answer that question. It is visible to you in the app.
Counts used for billing — how many items you hold, how many sales you completeThese are what a subscription is priced on. Counts only, never contents.
Server logs of requests to the serviceKeeping it running and diagnosing faults.

4. What you write to us

The contact form on this website, and the one inside the app, send us an email — nothing is stored in a ticket system, because we do not run one. The message goes to our support mailbox and stays there like any other email, for as long as we keep our correspondence.

WhatWhy
The name and email address you type into the formSo we know who wrote and where to send the answer. From the website we take your word for both — you do not need an account to write to us.
Your messageIt is the thing you sent us.
The page you wrote from, and your browser's user-agent stringContext for answering, especially when the message is "this page is broken".

When you write from inside the app we add what we already know — your account, the workspace you were in, and the app version — so that you do not have to describe it. We do not ask a captcha to stand between you and writing to us; the form is rate-limited by address instead.

What we deliberately do not do

Cookies and local storage

We use no advertising or analytics cookies, so there is no consent banner to dismiss. The website's visitor counting sets no cookie and stores nothing in your browser. What the application does use:

Who else processes it

We keep this list short on purpose. Today it is:

ProviderWhat forWhere
Google Cloud PlatformHosting, database, and storage of uploaded imagesUnited States
MailtrapDelivering email we send you — confirmation codes, invitations, password resetsEuropean Union
PlausibleCounting visits to the public website — pages, referrers, country and device type. No cookies and no personal identifiers.European Union
StripePayments, once paid subscriptions begin. Card details go to Stripe directly and never reach our servers.United States

If you are in the UK or the EEA, your data may be transferred to the United States by the providers above under their standard contractual clauses.

How long we keep it

Your business data stays for as long as your account does — that is the point of an inventory system, and deleting last year's purchases would break this year's cost figures. When you ask us to delete your account, we remove your workspaces and their contents, including uploaded images. Backups are on a rolling schedule and are overwritten within 30 days.

We act on a deletion request within 30 days of confirming it is really you asking. Cancelling a subscription is not a deletion request — it stops the billing, and your data stays where it is until you ask us to remove it.

Messages you send us live in our support mailbox rather than in the product, so deleting an account does not reach them; ask and we will delete the correspondence too.

Two things survive deliberately. Billing records — invoices, what was charged and when — are kept for as long as tax and accounting law requires us to keep them, so a request to delete everything cannot reach those; and email-delivery logs are held by our email provider under their own retention policy.

Your rights

You can ask us to show you what we hold, correct it, delete it, or send you a copy in a portable form. Write to support@intakes.app and we will answer within 30 days. If you are in the UK or EEA and think we have handled your data badly, you may also complain to your national data protection authority.

One boundary is worth being clear about, and it follows from the free-text point above. For personal data you recorded about other people — a buyer's name in a note, a supplier's contact details — you decide what happens to it and you can edit or delete it yourself, in the app, at any time. We hold it on your behalf and act on your instructions. If one of your buyers asks to be erased, that request is yours to answer; we will help you do it, but we will not reach into your records on a stranger's say-so.

Security

Traffic is encrypted in transit. Passwords are hashed by our sign-in service and are not readable by us. Two-step sign-in with a passkey is available and we recommend turning it on. Each workspace's data is separated from every other workspace's, and you can sign out every other device from your account page at any time.

We will tell you without undue delay if a breach affects your data. No system is perfectly secure, and we will not pretend otherwise.

Children

Intakes is a business tool and is not intended for anyone under 18.

Changes

If we change this policy in a way that matters, we will email you before it takes effect. The date at the top always reflects the current version.