PRIVACY POLICY

Your information and your choices.

This notice covers the Innocept public website, business workspace and connected Google accounts. Last updated: 6 October 2026.

At a glance
  • You choose which Google accounts to connect.
  • Connecting an account does not start email, document or spreadsheet automation.
  • Disconnecting access and deleting stored information are different actions.
  • You can make a privacy request without creating an account.

Who operates Innocept

Innocept is operated by Ashlin.

Correspondence address: 167-169 Great Portland Street, London, W1W 5PF.

Phone: +44 (0)20 4625 4472.

Support and privacy contact: admin@innocept.co.uk.

Innocept provides a business workspace for small and local businesses. For questions about this notice or your information, use our public contact form and select General question. Business customers decide what information they enter about their own customers and must provide those customers with appropriate privacy information. If your enquiry was submitted to another business using Innocept, contact that business first; we can help identify the appropriate request route.

Information collected

  • Accounts: your email address, optional display name and authentication identifiers. Firebase Authentication manages sign-in credentials.
  • Business workspace: business details, membership, employee and task configuration, permissions, connection records and activity or usage records generated by available features.
  • Contact enquiries: name, business name, email, optional phone number, topic, message, contact permission, submission time, enquiry reference and follow-up status. A hashed email identifier and counts help limit repeated submissions.
  • Service operation: request and diagnostic information processed by hosting and authentication services, such as request times, network information and errors.

Connected Google accounts

When you connect an account, Google asks you to authorize the requested permissions. We receive an account identifier and email label, authorization credentials, and the data needed for the checks below. Credentials are stored in Google Secret Manager; connection metadata is stored with your business in Firestore.

  • Google Calendar: we request calendar event and free/busy permissions. Connection setup checks busy-time access. The current public release does not automatically create appointments.
  • Google Sheets: we request spreadsheet read/write permission and check the granted authorization. Current connection setup does not read or write spreadsheet contents.
  • Google Drive: we request read-only Drive permission and check API access using a request for at most one file identifier. Current connection setup does not download or process document contents.
  • Gmail: we request read-only mailbox permission and check the mailbox profile’s email address. Current connection setup does not read message bodies, ingest mail or send replies.

The permissions shown by Google can cover more information than these setup checks use. Any later data-processing feature must be explained before it is enabled. See current connection capabilities.

How information is used

We use account and business information to provide the workspace, manage access, maintain connections, record available operations and respond to support requests. We use operational information to diagnose failures and limit abuse. Contact submissions are used to respond and follow up; they do not subscribe you to a marketing mailing list.

Google data and Limited Use

Innocept’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not sold, used for advertising or used to train generalized AI models. Access is limited to the user-facing purposes described here; any human access must be limited to permitted purposes such as support with your agreement, security, or legal obligations.

Service providers and AI

Google Cloud and Firebase provide hosting, authentication, database, background processing, logging and credential storage. The current public Google connection checks do not send Gmail messages, Drive documents or spreadsheet contents to an AI provider. The software also supports optional OpenAI-assisted setup and custom-submission interpretation; these features are not enabled in the current public deployment. If enabled later, the relevant information and provider will be explained before use. We do not claim that all processing stays in the UK; provider operations may involve other countries.

Storage and access

Business records are associated with a business identifier and protected by server-side membership checks. Stored OAuth credentials are accessed by authorized backend services rather than exposed in browser configuration. These controls reduce risk but do not guarantee that every security incident can be prevented.

Retention, disconnecting and deletion

Workspace records remain stored until deleted through an available business-deletion operation or a handled support request. The application does not currently enforce an automatic expiry period for workspace records or contact enquiries. Ask us about retention for your particular data; we must also consider any applicable legal or security requirements.

Disconnect a Google account in Connections to disable the stored credential used by that connection. This does not delete existing activity or revoke the entire Google authorization. You can remove the Google authorization at Google Account connections; doing so may affect all Innocept connections sharing that authorization.

Business deletion is processed in the background and removes the business’s Firestore records after disabling its stored integration credentials. Disabled secret versions are not automatically destroyed by this operation. It does not itself delete your Firebase login identity or infrastructure logs. For account removal, contact enquiries, remaining credential records or a broader deletion request, use the contact form. We may need to verify your identity and authority before acting; do not send passwords or signing secrets.

Browser storage

Authentication uses browser storage to maintain your session. The workspace also remembers your selected business. The public application does not currently include advertising trackers or an analytics SDK. Google authentication and hosting services may process technical information needed to provide their services.

Your requests

You can contact us about access, correction, deletion, objections to processing or other applicable privacy rights. Include the account email or enquiry reference and the business involved, without including unnecessary customer information. You can also raise a concern with the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint.

Changes

We will update this notice when the service’s data handling changes. New permissions or materially different uses will be explained before the relevant feature is enabled.

Terms of service · Contact Innocept