Privacy Policy

Last updated: May 27, 2026

1. Introduction

inkSTR ("we", "our", or "us") operates the inkSTR platform at inkstr.co. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

2. Information We Collect

We may collect the following types of information:

  • Account information: name, email address, and password when you create an account.
  • Project and business data: property details, business descriptions, content strategies, blog posts, keyword research results, and other content you create or import through our platform.
  • Property images: photos you upload to your image library. These are stored in cloud object storage (AWS S3 or Cloudflare R2) and served via CDN.
  • PMS data: when you connect a property management system (e.g., Hospitable, OwnerRez), we retrieve guest reviews, guest messages, property listings, and amenity details from that integration on your behalf. This data is used solely to inform content generation and is not shared with third parties.
  • Competitor research data: during strategy generation, we crawl publicly available web pages (competitor sites, SERP results) to gather market intelligence. No personal data from those pages is stored — only aggregated topic and keyword signals.
  • Site crawl data: when you provide your website URL, we may crawl your sitemap and public blog pages to assess content maturity and identify existing topics. Only structural metadata (page count, publish dates, topic headings) is stored.
  • Third-party credentials: API keys, OAuth tokens, and access credentials for services you connect (e.g., Wix, WordPress, Hospitable, Google Search Console). These are encrypted at rest using AES encryption.
  • Usage data: log data, device information, and how you interact with our platform, used to maintain and improve the service.
  • Billing information: payment method details are collected and processed by Stripe. inkSTR does not store full card numbers or CVV codes. We receive and store a Stripe customer ID and subscription status.

3. How We Use Your Information

  • To provide, maintain, and improve our services.
  • To generate AI-powered content strategies, keyword plans, and blog posts on your behalf.
  • To publish content to connected third-party platforms at your direction.
  • To submit published article URLs to the Google Indexing API for faster search indexing.
  • To communicate with you about your account, billing, and our services.
  • To process payments securely through our payment processor (Stripe).
  • To detect and prevent fraud, abuse, or violations of our Terms of Service.

4. Third-Party Services

Our platform integrates with third-party services. When you use these integrations, your data may be processed by those services according to their own privacy policies. We only share the minimum data necessary for each integration to function.

  • Anthropic (Claude AI): article content, keyword data, and business context are sent to Anthropic's API to generate content. See Anthropic's Privacy Policy.
  • Stripe: billing and payment processing. Card data is handled entirely by Stripe and never passes through inkSTR servers. See Stripe's Privacy Policy.
  • Wix: when you connect a Wix site, article content and images are published to your blog via the Wix API using credentials you provide.
  • WordPress: when you connect a WordPress site, article content is published via the WordPress REST API using credentials you provide.
  • Custom webhook / AI-built sites: when you configure a webhook endpoint, article content is sent to the URL you specify. You are responsible for the security and privacy practices of that endpoint.
  • Google Search Console and Google Indexing API: OAuth tokens and article URLs are shared with Google's APIs to retrieve search performance data and request indexing of published content. See Google's Privacy Policy.
  • DataForSEO: keyword and market data requests (including your target keywords and geographic markets) are sent to DataForSEO's API to retrieve search volume and keyword difficulty data.
  • Hospitable: when you connect a Hospitable account via Personal Access Token, we retrieve property listings, guest reviews, and guest messages to inform content generation.
  • OwnerRez: when you connect an OwnerRez account, we retrieve property listings, guest reviews, and guest messages to inform content generation.
  • AWS S3 / Cloudflare R2: property images you upload are stored in cloud object storage and served via CDN. Images are accessible via URL and are not access-restricted.
  • PostHog: if you consent to analytics (see “Cookies and Tracking” below), product usage events, page views, and masked session recordings are sent to PostHog to help us understand and improve the product. When you are signed in, these events are associated with your account. Analytics stays off unless you opt in. See PostHog's Privacy Policy.
  • BrightLocal: if you use our local SEO citation features, business profile details (such as name, address, phone, and categories) are sent to BrightLocal to build and manage local directory listings. See BrightLocal's Privacy Policy.

5. Data Security

We implement appropriate security measures to protect your data, including:

  • AES encryption of all API keys and third-party credentials at rest.
  • Secure session management with HTTP-only, SameSite cookies.
  • HTTPS-only connections with HTTP Strict Transport Security (HSTS).
  • Rate limiting on authentication endpoints to prevent brute-force attacks.
  • Row-level data isolation: all stored data is scoped to your account and cannot be accessed by other users.

No method of transmission over the internet is 100% secure. We cannot guarantee absolute security of data transmitted to or from our platform.

6. Data Retention

We retain your data for as long as your account is active or as needed to provide you services. PMS data (guest reviews and messages) retrieved from connected integrations is cached temporarily and refreshed when you initiate a new strategy or content generation. You may request deletion of your account and all associated data by contacting us at hello@inkstr.co.

7. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, or delete your personal data, as well as the right to object to or restrict certain processing. Users subject to GDPR (EU/EEA) or CCPA (California) may have additional rights including data portability and the right to know what personal data we hold. To exercise any of these rights, please contact us at hello@inkstr.co.

8. Cookies and Tracking

Necessary cookies. We use HTTP-only session cookies for authentication. These are required for the service to function and cannot be disabled while using the platform.

Product analytics (optional, off by default). With your consent, we use PostHog to collect product usage analytics — including page views, feature interactions, and masked session recordings (text inputs are masked) — to understand how the product is used and to improve it. Analytics is disabled for every visitor until you accept it via the consent banner; if you decline, no analytics cookies, page-view tracking, or session recording run. When analytics is enabled and you are signed in, these events are associated with your account (for example, your email, name, and plan) so we can analyze usage and support you.

We do not use third-party advertising cookies, and we do not sell your personal data. You can change your choice at any time by clearing your browser storage for this site, which will bring the consent banner back.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date. For material changes, we will notify you by email or via an in-app notice.

10. Contact Us

If you have questions about this Privacy Policy, please contact us at hello@inkstr.co.

inkSTR octopus logo
© 2026 inkSTR. All rights reserved.