legal
Privacy
What is collected, where it lives, what leaves the EEA, and how to get it back or have it deleted.
Written from the system, not from a template. Every statement here describes what the software actually does — the region, the sub-processors, what is collected, what is retained, what leaves the EEA. It is a description of a system rather than legal advice, and it is published rather than sent after a call. If your counsel needs redlines, or your own paper, that is a conversation and not a problem.
▸Contents — 13 clauses
- 1Who this notice is from
- 2Two different relationships
- 3What is collected, and from whom
- 4Storage on your device
- 5Where it is, and the one thing that leaves
- 6Why we are allowed to hold it
- 7How long it is kept
- 8Who else touches it
- 9Security
- 10Your rights, and how to use them
- 11Children
- 12Changes to this notice
- 13Complaining
Contents
- 1Who this notice is from
- 2Two different relationships
- 3What is collected, and from whom
- 4Storage on your device
- 5Where it is, and the one thing that leaves
- 6Why we are allowed to hold it
- 7How long it is kept
- 8Who else touches it
- 9Security
- 10Your rights, and how to use them
- 11Children
- 12Changes to this notice
- 13Complaining
1Who this notice is from#
Touch Grass AB is a private limited company (aktiebolag) registered in Sweden since 2024, registration number 559484-7435, registered office Idunsgatan 46, 214 46 Malmö, Sweden. It operates Inkstand and is the party you are dealing with in every document on this site.
The company is established in Sweden, which is in the EEA, so the General Data Protection Regulation applies directly and the supervisory authority is Integritetsskyddsmyndigheten (IMY). There is no group of companies behind this and no parent elsewhere.
Questions about this notice, and any request under clause 10, go to privacy@touchgrass.consulting. Whether a data protection officer or an Article 27 representative is required here is No data protection officer is appointed, and no Article 27 representative is appointed in the United Kingdom. Privacy enquiries and data subject requests go to privacy@touchgrass.consulting.; being established in the EEA, no EU representative is needed, and none is appointed in the UK.
Being established in the EEA does not mean nothing leaves it. Storage and the database stay in Stockholm, and the AI features send text to a provider outside the EEA. Clause 5 says exactly which ones and exactly what they send.
2Two different relationships#
The same product puts us in two positions at once, and which one applies changes what you can ask of us.
3What is collected, and from whom#
4Storage on your device#
This site and this product set no cookies. Not one — not for analytics, not for sign-in, not for preferences. Everything kept on your device is browser storage, it is listed in full below, and every entry is either strictly necessary for something you asked for or a convenience that remembers a choice you made.
| Key | Store | What it is for | Goes away when |
|---|---|---|---|
sb-…-auth-token | Local | Your signed-in session and its refresh token. | You sign out, or clear site data. |
carousel.invite_token | Session | Carries an invitation across the sign-in round trip, so redemption survives the page reload the email link causes. | You close the tab, or sign out. |
carousel.share_token.… | Local | Your own copy of a review link you created. The server holds only a hash and genuinely cannot show you the link again. | You revoke the link, or clear site data. |
cst.deckRail.collapsed | Local | Whether you left the editor rail open or shut. | You clear site data. |
carousel.reviewer_name | Local | On a review link only: the name a reviewer typed, so a second comment does not mean typing it again. | You clear site data. |
carousel.reviewer_role | Local | As above, for the role beside the name. | You clear site data. |
Under the ePrivacy rules, storage that is strictly necessary to provide a service the user asked for does not require consent, and storage that does anything else does. The list above is entirely the first kind, which is the reason there is no banner. We would rather you could check that claim against a table of key names than take it on the word of a page that has a banner covering it.
5Where it is, and the one thing that leaves#
6Why we are allowed to hold it#
| What | Basis | Reasoning |
|---|---|---|
| Account and workspace membership | Contract | There is no way to give someone access to a workspace without knowing who they are and which one. |
| Content and everything in it | Contract, on your organisation’s instructions | Held to run the service. See the data processing agreement for the processor terms. |
| Governance and audit records | Legitimate interest | An audit trail that could be edited by the party it holds accountable would serve no purpose. The interest is the customer’s as much as ours. |
| Comments and sign-offs from review links | Legitimate interest of the customer | Someone who is asked to approve a post is being asked precisely so their approval is on the record. |
| Invite requests and integration votes | Consent, given by sending the form | You typed it in to ask for something. Withdraw it at any time and the row goes. |
| Security and abuse prevention | Legitimate interest | Rate limits, token expiry, and refusing a request that looks like an attack. |
Where the basis is legitimate interest you can object under clause 10, and we have to stop unless there is a compelling reason not to. For an insert-only audit record that reason usually exists and we will say so plainly rather than quietly not acting.
7How long it is kept#
- Content is kept until you or your account owner deletes it. There is no automatic expiry and no configurable retention schedule.
- Deleting an account removes its workspaces and its invitations, and deleting a workspace removes its projects, carousels, versions, assets, templates and generation records.
- Export and generation records survive the deletion of an individual carousel, because their purpose is to evidence what was released. They do not survive the deletion of the workspace they belong to.
- Review links carry a mandatory expiry set when they are created, and can be revoked before it. Comments and sign-offs made through a link are part of the carousel's record and go when the carousel does.
- Your account is removed on request, which revokes your access. Records naming you as the person who released something remain, for the reason above.
- Invite requests are kept until the queue is dealt with and are deleted on request at any time.
- Backups are whatever the managed database platform provides on our plan. No restore has been tested, so no retention window or recovery objective is published here. Ask and you will get the plan details rather than a number.
8Who else touches it#
The complete list, what each one does and where each one sits, is the sub-processors page. It is short because keeping it short is treated as a design constraint: two features that would have been easy with an external service were written in-house rather than add a name to it.
Beyond that, personal data is disclosed only where the law requires it, and we will tell you about a demand unless we are prohibited from doing so. If the business is ever sold or merged, the data goes with it and you will be told before it does, in time to get your data out.
Our own staff access is limited by database policy rather than by an internal rule. A platform administrator can read account names, membership, workspace names, invitations and governance records. They cannot read carousels, projects, uploaded assets or templates, because no policy grants it. The mechanism is described on the security page.
9Security#
Rather than summarise it into something reassuring, the whole picture is on the security page, the measures we are contractually committed to are in annex II of the data processing agreement, and the route for reporting a flaw is the vulnerability disclosure policy.
No certification or third-party audit is held or claimed. Sign-in is possession of a mailbox, with no second factor and no single sign-on. If a personal data breach affects you we will tell you without undue delay, and we will tell you what we do not yet know as well as what we do.
10Your rights, and how to use them#
Where we are the controller you can ask for a copy of your data, correction of anything wrong, erasure, restriction of processing, portability of what you gave us, and you can object to anything resting on legitimate interest. Where consent is the basis you can withdraw it, and withdrawing does not affect what happened before.
Send it to privacy@touchgrass.consulting. You will get an answer within one month and it costs nothing. If a request is refused you will be told why, and told that you can complain.
How the request is actually handled. By us, rather than through a self-service screen. Everything is keyed to a workspace, so locating one person’s data is quick, and a person reads the request rather than a form processing it — which matters most for the requests a form would get wrong.
Where we are the processor — which is most content — the request belongs with the customer whose workspace holds it. Send it to them, or send it to us and we will identify the customer and pass it on.
11Children#
Inkstand is sold to organisations for professional use and is not directed at children. No account should be created for anyone under sixteen. No age verification is performed, so if you believe a child's data has reached the product, tell us and it will be removed.
12Changes to this notice#
The version number and effective date at the head of this document are the only place either is recorded. A change that materially affects how personal data is handled will be notified by email to account owners before it takes effect, and the effective date will be the date of the change rather than the date it was written.
13Complaining#
If you think your data has been handled improperly, you can complain to Integritetsskyddsmyndigheten (IMY), the Swedish supervisory authority, at https://www.imy.se, or to the authority in the EU country where you live or work. You do not have to raise it with us first, though we would rather you did, because most of what looks like a violation from outside is answerable in a paragraph.
Privacy notice, version 0.3, effective 29 July 2026. Every agreement, and who you are contracting with, on the legal index.