Privacy Policy
Last updated 9 September 2026
Intakes is an inventory and cost-accounting application for people who buy, make and resell goods. This policy explains what we hold, why, and what you can ask us to do about it. It is written to be read, not to be survived.
Who we are
Intakes is operated by Clean Code LLC, a Minnesota limited liability company ("we", "us"). For anything in this policy, including requests about your data, write to support@intakes.app.
What we hold
Four kinds of thing, and it is worth keeping them apart.
1. Your account
| What | Why |
|---|---|
| Email address | It identifies your account and is how we reach you about it. |
| First and last name | So teammates see a person rather than an address. |
| Profile picture, if you upload one | Optional. Nothing depends on it. |
| Whether you have confirmed your email, and when you accepted these terms | Required to open an account, and a record that you did. |
| Which workspaces you belong to and what you may do in them | Access control. |
We do not store your password. Credentials are held by Ory Kratos, which we run on our own servers — so it is not a third party we hand your password to, but it is also not somewhere we can read it from. The same is true of passkeys: we hold a public key, never anything that can be used to sign in as you.
2. Your business data
Everything you record in a workspace: items, purchases, suppliers, costs, stock, production runs, sales, returns, listings, photographs, and free-text notes. We hold it so the application can show it back to you and calculate from it. We do not read it for any other purpose, we do not use it to train anything, and we do not sell it or share it with advertisers.
One thing to be aware of, because it is your choice rather than ours: notes and reference fields are free text, so whatever you type into them is what we end up holding. If you record a buyer's name or address in a note, that is personal data about that person, and you are the one who decided to put it there.
If you connect a marketplace account — such as eBay — to one of your sales channels, we hold the access credential that marketplace gives us, encrypted, and use it only for what the application says it does with that account, such as bringing in your orders. Disconnecting deletes it. What it brings in — orders, the buyers named on them — is business data like the rest.
3. Operational records
| What | Why |
|---|---|
| An audit trail of who changed what, and when, inside your workspace | So your own team can answer that question. It is visible to you in the app. |
| Counts used for billing — how many items you hold, how many sales you complete | These are what a subscription is priced on. Counts only, never contents. |
| Server logs of requests to the service | Keeping it running and diagnosing faults. |
4. What you write to us
The contact form on this website, and the one inside the app, send us an email — nothing is stored in a ticket system, because we do not run one. The message goes to our support mailbox and stays there like any other email, for as long as we keep our correspondence.
| What | Why |
|---|---|
| The name and email address you type into the form | So we know who wrote and where to send the answer. From the website we take your word for both — you do not need an account to write to us. |
| Your message | It is the thing you sent us. |
| The page you wrote from, and your browser's user-agent string | Context for answering, especially when the message is "this page is broken". |
When you write from inside the app we add what we already know — your account, the workspace you were in, and the app version — so that you do not have to describe it. We do not ask a captcha to stand between you and writing to us; the form is rate-limited by address instead.
What we deliberately do not do
- No advertising trackers, and no analytics inside the application. There is no Google Analytics, no advertising pixel, and no third-party script watching you use the application. The public website (intakes.app, not the application) counts its visitors with Plausible, a privacy-first service that records which pages were viewed, where visitors came from, and their country and device type — without cookies, without identifying anyone, and without following anyone to other sites.
- No selling or sharing of your data. Not to advertisers, not to data brokers, not to anyone.
- No use of your business data to train machine-learning models.
Cookies and local storage
We use no advertising or analytics cookies, so there is no consent banner to dismiss. The website's visitor counting sets no cookie and stores nothing in your browser. What the application does use:
- A short-lived session cookie set by our sign-in service while you sign in. It is closed again as soon as your session is established.
- Sign-in tokens, kept in your browser so you stay signed in.
- Local preferences — such as whether you chose the light or dark theme.
Who else processes it
We keep this list short on purpose. Today it is:
| Provider | What for | Where |
|---|---|---|
| Google Cloud Platform | Hosting, database, and storage of uploaded images | United States |
| Mailtrap | Delivering email we send you — confirmation codes, invitations, password resets | European Union |
| Plausible | Counting visits to the public website — pages, referrers, country and device type. No cookies and no personal identifiers. | European Union |
| Stripe | Payments, once paid subscriptions begin. Card details go to Stripe directly and never reach our servers. | United States |
If you are in the UK or the EEA, your data may be transferred to the United States by the providers above under their standard contractual clauses.
How long we keep it
Your business data stays for as long as your account does — that is the point of an inventory system, and deleting last year's purchases would break this year's cost figures. When you ask us to delete your account, we remove your workspaces and their contents, including uploaded images. Backups are on a rolling schedule and are overwritten within 30 days.
We act on a deletion request within 30 days of confirming it is really you asking. Cancelling a subscription is not a deletion request — it stops the billing, and your data stays where it is until you ask us to remove it.
Messages you send us live in our support mailbox rather than in the product, so deleting an account does not reach them; ask and we will delete the correspondence too.
Two things survive deliberately. Billing records — invoices, what was charged and when — are kept for as long as tax and accounting law requires us to keep them, so a request to delete everything cannot reach those; and email-delivery logs are held by our email provider under their own retention policy.
Your rights
You can ask us to show you what we hold, correct it, delete it, or send you a copy in a portable form. Write to support@intakes.app and we will answer within 30 days. If you are in the UK or EEA and think we have handled your data badly, you may also complain to your national data protection authority.
One boundary is worth being clear about, and it follows from the free-text point above. For personal data you recorded about other people — a buyer's name in a note, a supplier's contact details — you decide what happens to it and you can edit or delete it yourself, in the app, at any time. We hold it on your behalf and act on your instructions. If one of your buyers asks to be erased, that request is yours to answer; we will help you do it, but we will not reach into your records on a stranger's say-so.
Security
Traffic is encrypted in transit. Passwords are hashed by our sign-in service and are not readable by us. Two-step sign-in with a passkey is available and we recommend turning it on. Each workspace's data is separated from every other workspace's, and you can sign out every other device from your account page at any time.
We will tell you without undue delay if a breach affects your data. No system is perfectly secure, and we will not pretend otherwise.
Children
Intakes is a business tool and is not intended for anyone under 18.
Changes
If we change this policy in a way that matters, we will email you before it takes effect. The date at the top always reflects the current version.