Skip to content
ancilAn INSIDEA company
Legal

Privacy Policy

How Ancil collects, stores, and processes your data, including HubSpot data.

v2.0Effective August 4, 2026

1. Who is the controller

INSIDEA, Inc., 8 The Green, Ste R, Dover, DE 19901, United States, is the controller for Ancil account, billing, security, and product-usage data. Contact privacy@insidea.com.

For HubSpot CRM data we read or write at your direction, you are the controller and we are the processor.

2. What we collect

Account information you provide: name, work email, workspace name, role.

HubSpot data we access via OAuth: the scopes you grant on connect, including (subject to your portal’s subscription) contacts, companies, deals, lists, workflows, and other CRM objects.

Usage telemetry: pages visited, audit runs, feature flags. We do not sell this data.

Security and support data: IP-derived security signals, user agent, authentication and administrative events, support communications, and versioned legal-acceptance records.

Billing data: plan, subscription, invoice, and transaction references. Payment-card details are handled by Stripe and are not stored by Ancil.

3. What we do with it

Generate audits, findings, drafted fixes, and the Daily Brief.

Improve the product: aggregated, de-identified patterns inform new audit rules.

Send transactional and product emails. We do not send marketing email to anyone in your HubSpot CRM.

4. Legal bases

Contract: create and administer accounts, provide requested product features, support connected services, and bill for subscriptions.

Legitimate interests: secure Ancil, prevent abuse, maintain service reliability, understand product performance, and communicate about an active business account. We balance these interests against your rights.

Consent: optional marketing communication and any non-essential browser storage or tracking that requires consent. Consent can be withdrawn at any time.

Legal obligation: preserve records and respond to lawful requests where applicable.

5. How we store and protect it

Account and CRM-derived data sits in Supabase-backed Postgres in encrypted form at rest. HubSpot OAuth tokens are encrypted at the application layer with AES-256-GCM before they touch the database.

TLS 1.2+ in transit at every hop. Backups are encrypted.

6. Recipients and sub-processors

We disclose data only to authorised personnel, professional advisers, authorities when legally required, and service providers needed to operate Ancil.

Our current provider register identifies hosting, authentication, database, email, job processing, AI, billing, monitoring, analytics, communication, and customer-authorised CRM providers at ancil.ai/legal/subprocessors.

We do not sell personal data. We do not use Customer Data for third-party advertising.

7. Retention

Account data: while your workspace is active, plus 90 days after deletion.

Audit data: while your workspace is active, plus 30 days after deletion.

You can request earlier deletion at hello@ancil.ai.

Legal-acceptance, billing, security, and audit evidence may be retained longer where necessary to establish, exercise, or defend legal claims or satisfy law. Backup copies expire through the managed backup lifecycle.

8. Your rights

Subject to applicable law, you can request access, rectification, deletion, restriction, portability, or objection, withdraw consent, or opt out of targeted advertising where applicable. Reach us at privacy@insidea.com. We verify requests and respond within the legally required period.

You may lodge a complaint with your local data-protection authority. California and other eligible US residents may use the same contact to exercise applicable access, correction, deletion, portability, or opt-out rights without discrimination.

9. International transfers

INSIDEA is headquartered in the United States and uses service providers in multiple jurisdictions. Where required, transfers rely on adequacy decisions, the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and supplementary measures.

10. Cookies and browser storage

Ancil currently uses browser storage and cookies necessary for authentication, security, workspace selection, and user preferences. See ancil.ai/legal/cookies.

If Ancil introduces non-essential browser analytics, advertising, profiling, or session replay, it will request consent where required before activating those technologies.

11. Automated decision-making

Ancil provides findings, drafts, recommendations, and governed implementation support. It does not make solely automated decisions that produce legal or similarly significant effects on individuals. Customers must review outputs and remain responsible for their decisions and lawful use.

12. Children

Ancil is not intended for use by anyone under 18. We do not knowingly collect data from children.

13. Changes

We will post changes here and update the version + effective date. Material changes will also be emailed to workspace owners.

14. Contact

Privacy requests: privacy@insidea.com. Security reports: security@ancil.ai. Postal contact: INSIDEA, Inc., 8 The Green, Ste R, Dover, DE 19901, United States.

Questions or requests: hello@ancil.ai.