Legal
Privacy Policy
Effective date: March 1, 2025 · Last updated: March 13, 2026
This Privacy Policy describes how Digital Decibels LLC ("Invokati," "we," "us," or "our") collects, uses, shares, and protects information when you use our website and Service at invokati.com and related subdomains. By using the Service, you agree to the practices described in this Policy.
1. Information We Collect
a. Information You Provide
- Account information: Email address, username, and password when you register.
- Profile information: Name, company, job title, and other fields you choose to fill in.
- Payment information: Billing name and address. Payment card details are processed directly by Stripe and are not stored on our servers.
- Content you create: Workflow configurations, dashboard layouts, lead records, media files, custom payloads, and other data you enter or upload to the Service.
- Communications: Messages you send to our support team.
b. Information Collected Automatically
- Usage data: Pages visited, features used, actions taken, timestamps, and session duration.
- Device and browser data: IP address, browser type, operating system, and referring URLs.
- Cookies and similar technologies: Session cookies required for login and security. We do not use third-party advertising cookies.
- API activity: Requests made to our API, including endpoint, timestamp, and response codes.
c. Information from Third Parties
- Stripe: We receive confirmation of payment status and a Stripe Customer ID. We do not receive full card numbers.
- n8n integrations: When you connect n8n instances, execution metadata is pulled or pushed to our platform according to your configuration. We do not access your n8n credentials directly beyond storing the API key you provide.
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service.
- Process transactions and manage your subscription via Stripe.
- Send transactional emails: account confirmation, password reset, billing receipts, and health alerts you configure.
- Authenticate your identity and secure your account and API keys.
- Enforce our Terms of Service and detect fraud or abuse.
- Respond to your support requests.
- Monitor and analyze usage patterns to improve the Service.
- Comply with legal obligations.
We do not sell your personal information to third parties. We do not use your content or workflow data to train AI models.
3. How We Share Your Information
We share your information only in the following circumstances:
- Service providers: We use trusted third-party vendors to help operate the Service, including Stripe (payments), cloud hosting providers (infrastructure), and transactional email providers. These vendors are contractually bound to protect your information and may not use it for their own purposes.
- Within your organization: Users you add to your team or group can see the resources and content you share with that group, as configured by you.
- Legal requirements: We may disclose your information if required by law, regulation, or valid legal process, or to protect the rights, property, or safety of Invokati, our users, or the public.
- Business transfers: If Invokati is acquired or merged, your information may be transferred as part of that transaction. We will notify you via email before your information becomes subject to a different privacy policy.
4. Data Retention
We retain your account information and content for as long as your account is active or as needed to provide the Service. After account deletion, we may retain certain information for up to 90 days to comply with legal obligations, resolve disputes, and enforce our agreements. Anonymized aggregate data may be retained indefinitely.
If you request deletion of your account, please contact us at support@invokati.com. We will process your request within 30 days.
5. Data Security
We implement industry-standard security measures to protect your information, including:
- HTTPS encryption for all data in transit.
- Encrypted storage for sensitive fields such as API keys and n8n credentials.
- Access controls limiting employee access to user data on a need-to-know basis.
- Session cookies scoped to the base domain with HttpOnly and SameSite attributes.
No method of transmission or storage is 100% secure. If you discover a security vulnerability, please report it to security@invokati.com.
6. Cookies
We use cookies solely for the following purposes:
- Session cookies: Required to keep you logged in across subdomains. These are deleted when you close your browser or log out.
- Preference cookies: Store settings such as dark/light mode and sidebar state in your browser's localStorage. No personal information is transmitted.
We do not use tracking, advertising, or analytics cookies from third parties. You can disable cookies in your browser settings, but doing so will prevent you from logging in.
7. Third-Party Services
Stripe
Payment processing is handled by Stripe, Inc. When you subscribe, you are subject to Stripe's Privacy Policy. Stripe may collect your payment card data, billing address, and device information directly. We receive only a customer ID and subscription status from Stripe.
n8n
If you connect a self-hosted or cloud n8n instance, you control what data flows between n8n and Invokati. You are responsible for ensuring that data sent through n8n workflows to our platform complies with applicable privacy laws and your own users' expectations.
Hosting and Infrastructure
Our Service is hosted on cloud infrastructure. Data may be processed in the United States or other jurisdictions where our hosting providers operate. We ensure adequate safeguards are in place for any international transfers.
8. Your Rights and Choices
Depending on your jurisdiction, you may have the right to:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate or incomplete information.
- Deletion: Request deletion of your personal information (subject to retention obligations).
- Portability: Request your data in a machine-readable format.
- Objection or restriction: Object to or request restriction of certain processing activities.
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, contact us at support@invokati.com. We will respond within 30 days. We may need to verify your identity before processing your request.
9. Children's Privacy
The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us at support@invokati.com and we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email to your registered address at least 14 days before taking effect. The "Last updated" date at the top of this page will always reflect the most recent revision. Continued use of the Service after the effective date constitutes acceptance of the updated Policy.
11. Contact Us
If you have questions, concerns, or requests related to this Privacy Policy, please contact us:
Digital Decibels LLC — Privacy Teamsupport@invokati.com