Welcome to Ichnos.io (“Ichnos,” “we,” “us,” or “our”). This Privacy Policy explains how we collect, use, disclose, store, and protect information when you visit our website, join our waitlist, create an account, use our browser extension, or otherwise interact with our services (collectively, the “Services”).

By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy.

1

Scope of This Privacy Policy

This Privacy Policy applies to information we collect through:

This Privacy Policy does not apply to third-party websites, services, or content that may be linked to, saved from, or accessible through our Services.

2

Information We Collect

We may collect the following categories of information.

A. Information You Provide Directly

Depending on how you interact with the Services, you may provide us with:

  • Name
  • Email address
  • Password (stored only in hashed form; plaintext passwords are not stored)
  • Contact form content, including your name, email address, and message
  • Waitlist submission information, including your email address
  • Any other information you choose to provide when communicating with us

B. Account Information

When you register for an account, we may collect and maintain:

  • your name;
  • your email address;
  • your password hash;
  • your account role or permissions;
  • account status information, such as suspension or ban status; and
  • account-related settings and internal identifiers.

C. Saved Page and Bookmark Data

If you use Ichnos to save web pages, we may collect and store information associated with those saved pages, including:

  • the URL of the page;
  • the page title;
  • the text content of the page, subject to system limits;
  • AI-generated summaries;
  • AI-generated tags; and
  • vector embeddings or similar machine-readable representations used to enable semantic search and related features.

These data elements are used to allow you to retrieve pages later using natural-language search and to power related product features.

D. Search Queries

We collect the search terms and natural-language queries you submit in order to provide search results, improve retrieval quality, maintain security, and support service functionality.

E. Technical, Device, and Log Information

When you use the Services, we may automatically collect certain technical information, including:

  • IP address
  • browser type
  • device information
  • operating system
  • user agent string
  • session identifiers
  • referring URLs
  • timestamps of access and actions
  • error logs and performance data

F. Audit and Security Logs

We may maintain internal logs of significant account and platform activity, including:

  • event names;
  • user IDs;
  • IP addresses;
  • user agent information;
  • associated metadata, such as bookmarked URLs or authentication events; and
  • timestamps.

These logs are used for security, fraud prevention, system integrity, debugging, enforcement of our terms, and internal administrative purposes.

G. Cookies and Similar Technologies

We may use cookies, session cookies, CSRF tokens, local storage, and similar technologies to:

  • authenticate users;
  • maintain sessions;
  • protect the Services;
  • remember user preferences;
  • support website functionality; and
  • understand usage patterns.

You may be able to control cookies through your browser settings, but disabling certain cookies may limit functionality.

3

How We Use Information

We may use collected information for the following purposes:

A. To Provide and Operate the Services

We use information to:

  • create and manage accounts;
  • authenticate users;
  • enable page saving and retrieval;
  • generate summaries, tags, and semantic search results;
  • provide “connected ideas” or related-content functionality; and
  • support the waitlist, extension, and website functionality.

B. To Process Saved Content Using AI Features

To provide core product functionality, we may process saved page content and search queries using internal systems and third-party AI service providers, including for:

  • generating embeddings;
  • generating summaries;
  • generating tags;
  • ranking results;
  • improving result coverage and retrieval quality; and
  • supporting additional search mechanisms.

C. To Communicate With You

We may use your information to:

  • send account-related communications;
  • notify you about updates, product access, or launch status;
  • respond to support requests and contact form submissions; and
  • send service notices, security notices, and legal notices.

Where required by law, we will obtain consent before sending marketing communications, and you may opt out of those communications at any time.

D. To Maintain Security and Prevent Misuse

We may use information to:

  • detect, investigate, and prevent fraud, abuse, unauthorized access, or violations of our Terms;
  • maintain audit trails;
  • enforce our policies;
  • suspend or restrict harmful accounts; and
  • protect users, the Services, and third parties.

E. To Improve the Services

We may use information to:

  • understand user behavior and product usage;
  • troubleshoot bugs and system issues;
  • develop new features;
  • monitor service performance; and
  • improve relevance, search quality, and overall user experience.

F. To Comply With Legal Obligations

We may use and retain information as necessary to comply with applicable law, respond to lawful requests, resolve disputes, and enforce legal rights.

G. For Safety, Abuse Prevention, and Legal Compliance

We may use personal information, saved content, metadata, logs, IP addresses, user agent information, and related account activity to detect, prevent, investigate, and respond to suspected fraud, abuse, infringement, unlawful activity, security incidents, or violations of our Terms or other policies.

We may also use and preserve such information to protect our Services, users, rights holders, and third parties, and to comply with applicable law, legal process, governmental requests, court orders, or regulatory obligations.

4

Sensitive Content and Redaction

Ichnos may attempt to detect and redact certain sensitive strings, such as API keys, access tokens, and passwords, before content is stored server-side. However, this redaction process is best effort only and is not guaranteed to identify or remove all sensitive information.

Accordingly:

Our efforts to identify and redact secrets or sensitive material are intended to reduce risk, not to permit storage of unlawful, unauthorized, infringing, or regulated content. Users remain solely responsible for the content they choose to save or process through the Services.

5

How We Share Information

We do not sell your personal information for money. We may share information in the following circumstances:

A. Service Providers and Vendors

We may share information with vendors and service providers that perform services on our behalf, such as:

  • hosting providers;
  • infrastructure providers;
  • email or communications vendors;
  • analytics providers;
  • customer support tools; and
  • AI processing providers.

These providers may access information only as reasonably necessary to perform services for us, subject to contractual or legal restrictions where applicable.

B. AI and Processing Providers

To provide core functionality, page content and search query text may be transmitted to third-party AI providers for processing, including the generation of embeddings, summaries, tags, and related retrieval functionality.

By using the Services, you acknowledge that content you save and search queries you submit may be processed by such third-party providers in accordance with their applicable terms and privacy practices.

C. Legal Compliance and Protection

We may disclose information if we believe in good faith that doing so is necessary to:

  • comply with applicable law, regulation, court order, or legal process;
  • respond to lawful governmental requests;
  • protect our rights, property, or safety;
  • protect the rights, property, or safety of users or others;
  • investigate fraud, abuse, or security incidents; or
  • enforce this Privacy Policy or our Terms of Service.

D. Business Transfers

If we are involved in a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar transaction, information may be transferred as part of that transaction, subject to applicable legal requirements.

E. With Your Direction or Consent

We may share information when you direct us to do so or otherwise consent.

F. Disclosure for Enforcement and Protection

We may disclose information, including account information, saved content, logs, metadata, and other related records, to law enforcement, regulators, rights holders, courts, service providers, or other third parties where we believe such disclosure is necessary or appropriate to investigate suspected unlawful activity, enforce our Terms, respond to infringement claims, protect rights or safety, comply with legal obligations, or reduce legal or security risk.

6

Legal Bases for Processing

If and to the extent applicable under laws such as the GDPR or UK GDPR, we may process personal data on the following legal bases:

7

Data Retention

We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Services, maintain business records, enforce agreements, resolve disputes, and comply with legal obligations.

In general:

Deleted information may persist for a limited time in backups, logs, archives, or systems maintained for disaster recovery, legal compliance, fraud prevention, or legitimate business purposes.

8

Account Deletion and Your Choices

You may have the ability to delete your account through the Services or by contacting us. If you request account deletion:

Deletion of your account does not necessarily guarantee immediate removal of all information from every system, including logs, caches, archives, or backups.

You may also contact us to request access to, correction of, or deletion of your personal information, subject to applicable law.

9

Your Privacy Rights

Depending on your location, you may have certain rights regarding your personal information, including the right to:

We may need to verify your identity before fulfilling a request. We may also deny or limit requests where permitted by law.

If you are a California resident, you may have rights under applicable California privacy laws. If you are in the European Economic Area, United Kingdom, or another jurisdiction with similar protections, you may have additional rights under applicable data protection law.

To exercise your rights, contact us at: privacy@ichnos.io

10

Children's Privacy

The Services are not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13 without legally valid authorization.

If you are located in a jurisdiction with a higher digital consent age, the minimum age for use may be higher. If we learn that we have collected personal information from a child in violation of applicable law, we may delete that information and take appropriate action.

If you believe a child has provided information to us in violation of this section, please contact us immediately.

11

International Data Transfers

Your information may be processed and stored in countries other than the country in which you reside, including countries that may have different data protection laws.

Where required by applicable law, we will take appropriate steps designed to ensure that cross-border transfers are subject to adequate safeguards.

12

Data Security

We implement reasonable administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, and disclosure.

However, no method of transmission over the Internet or method of electronic storage is completely secure. Therefore, we cannot guarantee absolute security, and you use the Services at your own risk.

You are responsible for maintaining the confidentiality of your account credentials and for using appropriate caution when saving content through the Services.

13

Third-Party Websites and Content

The Services may allow you to save, access, or interact with content originating from third-party websites. We are not responsible for the privacy, security, availability, accuracy, or practices of such third-party sites or services.

Your interactions with third-party websites remain governed by their own terms and privacy policies.

14

Do Not Track

Some browsers may transmit “Do Not Track” signals. Because there is not yet a universally accepted standard for responding to such signals, we do not currently guarantee that we respond to all such signals.

15

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make changes, we will post the updated version on this page and update the “Last Updated” date above. If required by law, we will provide additional notice or obtain consent.

Your continued use of the Services after any updated Privacy Policy becomes effective constitutes your acknowledgment of the revised Privacy Policy, to the extent permitted by law.

16

Browser Extension Privacy Notice

This section provides specific disclosures about the Ichnos.io browser extension (“Extension”) in accordance with the Chrome Web Store Developer Program Policies and applicable privacy laws.

A. What the Extension Collects

  • Authentication token: Your Ichnos.io API token, stored locally in your browser after the one-time setup, to authenticate requests to your account.
  • Page URL and title: The URL and title of the active tab, used to pre-fill the save form and to check for related bookmarks you have previously saved.
  • Page text content: The readable text of the page you explicitly choose to save, extracted at the moment you click “Save to Ichnos.”
  • Favicon URL: The favicon of the active tab, used only for display purposes inside the Extension popup.

B. Permissions Used and Why

  • activeTab: Reads the URL and title of the current tab when you click the Extension icon, to pre-fill the save form.
  • scripting: Injects a one-time script into the active tab when you click “Save to Ichnos” to extract the page’s readable text for AI summarization and semantic search.
  • storage: Persists your API token locally so you do not need to re-enter it each time you use the Extension.
  • tabs: Reads the active tab’s URL, title, and favicon when the popup opens to display a page preview and pre-fill the save form.
  • webNavigation: Listens for client-side navigation events in Single Page Applications (SPAs) built with frameworks such as Next.js, Nuxt, or Gatsby. This allows the Extension to update the related-bookmarks badge count when you navigate within an SPA without a full page reload.
  • Host permission (https://ichnos.io/*): Allows the Extension to communicate exclusively with the Ichnos.io backend API to save bookmarks, look up related pages, and validate your account token.

C. Data Collection: On Click vs. Background

On explicit click only: Page text content is extracted and sent to your Ichnos.io account only when you click “Save to Ichnos.” No page content is collected passively.

In the background: When you are logged in, the Extension sends the URL and title of each page you visit to the Ichnos.io API (/api/related) to check whether you have any previously saved bookmarks related to that page. This powers the badge count displayed on the Extension icon. The URL is used solely for this lookup and is not stored as a browsing history log. If you are not logged in (no API token stored), no background requests are made.

D. Active Tab Content

The Extension reads the text content of the active tab only when you explicitly initiate a save action. The content is transmitted to your Ichnos.io account for processing. It is not read, collected, or transmitted at any other time.

E. Purpose of Data Use

All data collected by the Extension is used exclusively to provide the Extension’s core features:

  • saving web pages to your personal Ichnos.io account;
  • generating AI summaries and tags for saved pages;
  • enabling natural-language semantic search over your saved pages; and
  • displaying a badge showing how many of your saved bookmarks relate to the page you are currently viewing.

No data collected by the Extension is used for advertising, analytics, profiling, or any purpose unrelated to providing these features. No data is sold or transferred to third parties.

F. AI Processing and Third-Party Providers

When you save a page, the extracted text content and any natural-language search queries you submit may be transmitted to a third-party AI provider (such as OpenAI) to generate summaries, tags, and vector embeddings that power semantic search. This transfer is necessary to provide the AI-driven features of the Service.

Our AI providers process this data on our behalf and are contractually prohibited from using it for their own model training or other independent purposes. Please review the privacy policies of applicable AI providers for more information about how they handle data.

G. Human Review

We do not routinely review the content of your saved pages. Human review of saved content may occur only in the following limited circumstances:

  • to investigate a report of policy-violating or illegal content;
  • to comply with a valid legal obligation, court order, or law enforcement request; or
  • to diagnose a specific technical issue reported by you, and only with your explicit consent.

H. Where Data Is Stored

  • Locally in your browser: Your API token and temporary per-tab related-bookmark results are stored in your browser’s local extension storage. Per-tab data is automatically deleted when the tab is closed.
  • On our servers: Your saved bookmarks, including page URL, title, text content, AI-generated summaries, tags, and vector embeddings, are stored in your Ichnos.io account on our servers.

I. Uninstalling the Extension and Deleting Your Data

To uninstall the Extension: Open your browser’s extension management page (e.g., chrome://extensions), find Ichnos.io, and click “Remove.” Uninstalling the Extension removes all locally stored data, including your API token.

To delete your account and all associated data: Log in to your Ichnos.io account, go to account settings, and use the account deletion option. You may also submit a data deletion request by contacting us at privacy@ichnos.io. Upon verified request, we will delete your account and all saved bookmark data from our servers, subject to any legal retention obligations.

17

Contact Us

If you have questions, requests, or concerns about this Privacy Policy or our privacy practices, you may contact us at: