INURO LEGAL
Privacy Policy
1. Who we are
Inuro is owned and operated by RV Ventures AS, Org. no. 938 218 641, Karl Johans gate 25, 0159 Oslo, Norway, support@inuro.app. RV Ventures AS is the data controller for the personal data described in this Policy.
2. The short version
Inuro is designed to require relatively little personal data. Projects created using Inuro Free are stored locally by default and are not automatically uploaded merely because they are created or edited. Studio users may deliberately use Inuro Cloud, in which case project data and related metadata are stored and synchronized through Inuro's cloud infrastructure. RV Ventures AS does not analyze private projects to study how users create, does not use creative work to build advertising profiles, does not sell personal data, and does not use projects or creative content to train AI models without a separate appropriate legal basis. Inuro currently does not use third-party behavioral analytics such as Google Analytics or Meta Pixel.
3. Account information
Account processing may include email address, display name, unique account identifier, account timestamps, verification status, authentication information, current plan/entitlement, subscription state and security events. Purpose: creating, maintaining and securing accounts and providing the selected plan. Legal basis: GDPR Article 6(1)(b) where necessary to provide the requested service and Article 6(1)(f) for security and administration where applicable.
4. Free projects and Try Inuro
Ordinary Free projects, project-library information, snapshots, Assets and Brand Profiles may be stored locally in the browser/device. RV Ventures AS generally cannot access or recover such local information. Try Inuro (Guest) follows the same local-first approach and does not provide export. Guest-to-account transfer is an exception: the current Guest project may be temporarily transferred to the backend solely to preserve it during account creation. After successful restoration locally, the server copy is deleted. If transfer is not completed, the temporary copy is automatically deleted after its 24-hour transfer period.
5. Studio Cloud and synchronization
When a Studio user enables or uses cloud functionality, Inuro may process and store project files, project state, previews or other project data reasonably necessary to provide cloud storage, synchronization, recovery and related functionality. Processing may also include account ID, project IDs, timestamps, version/synchronization metadata, storage paths, file sizes, hashes and technical status information. Studio currently includes limited cloud storage as presented with the plan. Cloud processing is performed to provide the requested paid service under GDPR Article 6(1)(b).
6. Authentication and security
Inuro uses Supabase for authentication and related backend services. Processing may include login/logout/signup/verification/password-reset/email-change/session events, request information, timestamps, account identifiers, IP/network information, security and error information. The primary Inuro Supabase project is hosted in Ireland, AWS eu-west-1. Purpose: authentication, account operation, security, abuse prevention and troubleshooting.
7. Public-site session and plan handoff
Inuro may use limited first-party session and plan indicators across Inuro-controlled subdomains so that the public website can present appropriate navigation and plan-relevant content to a signed-in user. These indicators are used for interface presentation and do not themselves grant access to Studio, cloud data or other paid functionality. Actual account access and entitlement remain subject to authenticated backend verification.
8. Transactional email
Inuro uses Resend for transactional account and service email, including verification, password resets, email changes, security notifications, cancellation confirmations, failed-payment notices where sent by Inuro, plan-expiry notices and cloud-retention/recovery messages. Resend stores relevant customer data in the United States. Processing may include email address, message content and technical delivery information. Transactional messages are service communications rather than optional marketing.
9. Cloudflare and cloud storage infrastructure
Inuro uses Cloudflare to deliver and protect its websites and web application and may use Cloudflare R2 for Inuro cloud-file storage. Cloudflare may process IP addresses, routing information, browser/device information, request information, security information, timestamps and, where cloud functionality is used, stored project objects and related storage metadata. Cloudflare Web Analytics / RUM is disabled for Inuro unless this Policy is updated to state otherwise.
10. Payments, Stripe Managed Payments and Link
Paid Inuro subscriptions are processed using Stripe. For transactions processed through Stripe Managed Payments, Stripe's Sold through Link service acts as merchant of record for the customer transaction. Stripe and Link may process payment-method details, billing information, transaction information, subscription state, applicable indirect-tax information, payment failures, fraud-prevention information, support information and related technical data. Stripe Managed Payments may calculate, collect and remit applicable indirect taxes and may provide transaction-level payment support as part of the merchant-of-record service.
RV Ventures AS receives identifiers, subscription and payment status, and other information reasonably necessary to provide and administer the Inuro subscription, but does not receive or store full payment-card details. Stripe and Link process information under their own applicable terms and privacy information and may conduct configured payment-recovery or retry processes for unsuccessful renewals.
11. Browser storage
Inuro uses browser-side storage such as localStorage, sessionStorage, IndexedDB, browser file-system functionality where supported, first-party cookies and other storage necessary to provide requested application functionality. This may store local projects, snapshots, Project Manager information, Assets, Brand Profiles, interface preferences, authentication-session persistence, Stay logged in state, public-site session/plan presentation indicators, temporary signup/account-recovery state and Try Inuro transfer information. These technologies are primarily used for requested functionality rather than cross-site tracking. Inuro does not currently use advertising or behavioral-analytics cookies.
12. Product development, AI and advertising
RV Ventures AS does not currently use behavioral analytics to monitor how users create inside Inuro. Product development may instead use voluntary feedback, support conversations, surveys, polls, community discussions and feature requests. Inuro Free and Studio do not use private creative work to train AI models. Future AI functionality that transmits user-selected content will require updated transparency before launch. Advertising may be introduced in the future, but any consent, tracking, profiling or disclosure requirements will be assessed before deployment.
13. Service providers and international processing
Principal providers may include Supabase for authentication/backend and temporary Try Inuro transfer, Cloudflare for delivery/infrastructure/security and cloud object storage, Resend for transactional email, and Stripe (including Stripe Managed Payments / Sold through Link where used) for subscription, payment, merchant-of-record, indirect-tax and transaction-support services. Providers may use authorized subprocessors. The primary Inuro Supabase project is hosted in Ireland (AWS eu-west-1). Cloudflare operates a global network. Resend stores relevant customer data in the United States.
Stripe and Link may process data in jurisdictions described in their applicable privacy and data-processing documentation. Where GDPR requires safeguards for transfers outside the EEA, RV Ventures AS uses or relies upon an appropriate permitted transfer mechanism.
14. Retention, subscription expiry and cloud recovery
Personal data is retained only as long as reasonably necessary, subject to legal requirements. Account information is generally retained while the account exists. Temporary Try Inuro transfers are deleted after successful transfer or automatically after the 24-hour period if incomplete. Locally stored projects are controlled by browser/device storage. When a cloud-enabled paid plan expires, eligible cloud projects may be retained for up to 30 days to provide recovery and download. Inuro may send the user a secure, time-limited recovery link associated with the account and relevant cloud data. After the retention period, retained cloud project data may be permanently deleted. Transaction, accounting and payment records may be retained for periods required by applicable law.
15. Account deletion
Users may request or perform account deletion through available controls. Account deletion does not automatically delete locally stored projects, and clearing local browser data does not necessarily delete an account. Cloud and subscription data may be deleted or retained according to the applicable service-retention, security, accounting and legal requirements. Inuro will not represent data as recoverable after it has been permanently deleted.
16. Licensing and entitlement information
Inuro may process account ID, current plan, subscription state, resource IDs, dependencies, required entitlement, timestamps, cryptographic signatures/hashes and technical licence records to provide licensed functionality, enforce entitlements, prevent abuse and establish export licensing status. Entitlement verification is designed not to require inspection of the visual content of private artwork.
17. Rights, complaints, younger users, automation and security
Users may have GDPR rights of access, correction, deletion, restriction, objection, portability and withdrawal of consent where applicable, and may complain to a competent authority including Datatilsynet in Norway. Inuro accounts are intended for users aged 13 or older and ordinary registration does not require date of birth. RV Ventures AS does not currently use personal data for solely automated decisions producing legal or similarly significant effects. Reasonable technical and organizational security measures are used, although no internet service can guarantee absolute security.
18. Changes and contact
This Policy may be updated as Inuro's services, providers, processing or law change, with additional notice or consent where legally required. Contact: RV Ventures AS, Org. no. 938 218 641, Karl Johans gate 25, 0159 Oslo, Norway, support@inuro.app.