Privacy Policy

Last updated: March 29, 2026

1. Introduction

Inherit (“we”, “us”, or “our”) operates the Inherit platform at useinherit.com. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service. Please read it carefully. By using Inherit, you agree to the practices described here.

2. Information We Collect

Account information: When you sign up, we collect your email address and, optionally, your name. This information is used solely to create and manage your account.

CRM data: When you connect HubSpot or Salesforce, we read account, contact, and activity data from your CRM to generate handoff briefs. We do not store your CRM credentials — authentication uses OAuth 2.0 tokens, which you can revoke at any time.

Usage data: We collect information about how you use the platform — pages visited, features used, and actions taken — to improve the product.

Payment information: Payments are processed by Stripe. We do not store your credit card numbers or banking details. Stripe’s privacy policy governs payment data.

3. How We Use Your Information

  • To provide, operate, and improve the Inherit platform
  • To generate AI-powered account handoff briefs using your CRM data
  • To send transactional emails (account confirmation, billing receipts)
  • To respond to support requests
  • To detect and prevent fraud or abuse
  • To comply with legal obligations

We do not sell your personal data to third parties.

4. AI Processing

Inherit uses Anthropic’s Claude API to generate account briefs. CRM data you select is sent to Anthropic for processing. Anthropic’s API usage policies prohibit using submitted data to train their models. No personally identifiable information is sent to Anthropic beyond what is necessary to generate your requested brief.

5. Data Storage and Security

Your data is stored in Supabase (PostgreSQL), hosted on AWS infrastructure. All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). We use row-level security to ensure users can only access their own data.

No system is perfectly secure. While we take commercially reasonable measures to protect your information, we cannot guarantee absolute security.

6. Data Retention

We retain your account data for as long as your account is active. If you cancel, your data is retained for 30 days to allow exports, then permanently deleted. You may request immediate deletion by contacting us at privacy@useinherit.com.

7. Third-Party Services

We use the following third-party services:

  • Supabase — database and authentication
  • Stripe — payment processing
  • Anthropic — AI brief generation
  • Resend — transactional email
  • Vercel — hosting and edge functions
  • PostHog — product analytics (anonymised)

8. Cookies

We use essential cookies for authentication (session tokens). We use analytics cookies (PostHog) to understand product usage. You can disable non-essential cookies in your browser settings. Disabling cookies may affect certain features of the platform.

9. Your Rights

You have the right to:

  • Access a copy of the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your data
  • Withdraw consent at any time (including revoking CRM OAuth access)
  • Data portability — export your handoffs and briefs as PDFs

To exercise any of these rights, email privacy@useinherit.com.

10. Children’s Privacy

Inherit is not directed at individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by posting a notice on the platform. Your continued use of Inherit after changes are posted constitutes your acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy, please contact us at privacy@useinherit.com.