Skip to content
Inkstand

legal

Privacy

What is collected, where it lives, what leaves the EEA, and how to get it back or have it deleted.

Version 0.3Effective 29 July 202613 min readTouch Grass AB

Written from the system, not from a template. Every statement here describes what the software actually does — the region, the sub-processors, what is collected, what is retained, what leaves the EEA. It is a description of a system rather than legal advice, and it is published rather than sent after a call. If your counsel needs redlines, or your own paper, that is a conversation and not a problem.

Contents — 13 clauses

1Who this notice is from#

Touch Grass AB is a private limited company (aktiebolag) registered in Sweden since 2024, registration number 559484-7435, registered office Idunsgatan 46, 214 46 Malmö, Sweden. It operates Inkstand and is the party you are dealing with in every document on this site.

The company is established in Sweden, which is in the EEA, so the General Data Protection Regulation applies directly and the supervisory authority is Integritetsskyddsmyndigheten (IMY). There is no group of companies behind this and no parent elsewhere.

Questions about this notice, and any request under clause 10, go to privacy@touchgrass.consulting. Whether a data protection officer or an Article 27 representative is required here is No data protection officer is appointed, and no Article 27 representative is appointed in the United Kingdom. Privacy enquiries and data subject requests go to privacy@touchgrass.consulting.; being established in the EEA, no EU representative is needed, and none is appointed in the UK.

Being established in the EEA does not mean nothing leaves it. Storage and the database stay in Stockholm, and the AI features send text to a provider outside the EEA. Clause 5 says exactly which ones and exactly what they send.

2Two different relationships#

The same product puts us in two positions at once, and which one applies changes what you can ask of us.

2.1We are the controller for the data needed to run the business: the account behind a sign-in, the record of who holds a seat in which account, invitation requests sent from this website, and the votes cast on the integrations page. Nobody instructs us about those. This notice is the account of them.
2.2We are a processor for everything an account puts into the product — carousels, captions, brand kits, uploaded images, review comments. Your organisation decides what goes in and what it is for; we act on the instructions expressed by the actions its people take. The terms of that arrangement are the data processing agreement, not this notice.
2.3If you are a member of somebody else's account and want content about you removed, the fastest route is the account owner. We will pass on a request sent to us, and we will not delete a customer's records on the say-so of one of their users unless the law requires it.

3What is collected, and from whom#

3.1Account. Your email address, and a display name if you set one. Sign-in is a one-time link to that address, so there is no password to hold and none is stored.
3.2Content. Carousels, captions, projects, brand kits, uploaded images and fonts, and templates, belonging to the workspaces you can reach. Any personal data inside them is there because someone put it there — a name in a testimonial, a face in a photograph — and it is processed under clause 2.2 rather than this one.
3.3Governance records. Every export and every generation writes a record naming the person who did it, the exact wording they acknowledged, a fingerprint of the content, the brand rules as they stood at that moment, the model that was called if one was, and a written reason for anything waived. Findings inside those records can quote short fragments of the content that was checked, which is what makes them evidence rather than a timestamp. These records are insert-only in the database. Nobody can edit or delete one after the fact — not the account owner, not us.
3.4External reviewers. A customer can send a link that opens one carousel to somebody with no account. If that person comments or signs off, the product records the name and role they typed, what they wrote, and a fingerprint of the version they were looking at. It also records that the link was opened and how many times. A name typed into a page reachable by anyone holding the link is self-asserted and the system treats it that way; it is not evidence of identity and is never folded into a release record without a signed-in member confirming they read it.
3.5People who ask for an invite. The form on this site takes an email address, and optionally a name, a company, what you would use it for, your sector, team size, how many brands you run, and which surfaces you would want checked. The integrations page takes an optional email with a vote. Both exist to decide what to build and who to let in. Neither is readable by anyone but us.
3.6What is not collected. No analytics, no advertising pixels, no session recording, no fingerprinting, no third-party script of any kind, on this website or in the product. No profiles are built, nothing is sold, and nothing is shared with anyone for their own purposes. The copy checker at /check runs entirely in your browser and sends the text you paste nowhere at all.

4Storage on your device#

This site and this product set no cookies. Not one — not for analytics, not for sign-in, not for preferences. Everything kept on your device is browser storage, it is listed in full below, and every entry is either strictly necessary for something you asked for or a convenience that remembers a choice you made.

KeyStoreWhat it is forGoes away when
sb-…-auth-tokenLocalYour signed-in session and its refresh token.You sign out, or clear site data.
carousel.invite_tokenSessionCarries an invitation across the sign-in round trip, so redemption survives the page reload the email link causes.You close the tab, or sign out.
carousel.share_token.…LocalYour own copy of a review link you created. The server holds only a hash and genuinely cannot show you the link again.You revoke the link, or clear site data.
cst.deckRail.collapsedLocalWhether you left the editor rail open or shut.You clear site data.
carousel.reviewer_nameLocalOn a review link only: the name a reviewer typed, so a second comment does not mean typing it again.You clear site data.
carousel.reviewer_roleLocalAs above, for the role beside the name.You clear site data.

Under the ePrivacy rules, storage that is strictly necessary to provide a service the user asked for does not require consent, and storage that does anything else does. The list above is entirely the first kind, which is the reason there is no banner. We would rather you could check that claim against a table of key names than take it on the word of a page that has a banner covering it.

5Where it is, and the one thing that leaves#

5.1The database, authentication, and file storage are in the European Union — Stockholm. There is one region and no option to choose another. The website itself is a static bundle on a content delivery network, holds no customer data, and is served from Frankfurt (eu-central-1), pinned in the deployment configuration..
5.2There is no application server of ours in the middle. The product is a browser application talking to the managed platform directly, so there is no tier of ours holding a copy of your content in transit.
5.3Four features send text to a model provider, and they are the only outbound path. Deck generation, brand-guideline reading, the deck compliance review, and claim research. Each is an explicit action by a user, none of them runs on its own, and the rule engine that does the deterministic checking is code in your browser and never leaves it. Claim research additionally performs a web search, which means the text of the claim reaches a search provider as well. The routing service and the model providers behind it are outside the EEA, so using any of the four is a transfer.
5.4Those transfers rest on the European Commission's standard contractual clauses as incorporated by the sub-processors' own terms, and on the assessment a customer makes before turning the features on. We have not carried out and published a transfer impact assessment of our own. If your policy is that no content may leave the EEA, the product is usable without any of the four features and the compliance engine still runs. The current list of who receives what is on the sub-processors page.

6Why we are allowed to hold it#

WhatBasisReasoning
Account and workspace membershipContractThere is no way to give someone access to a workspace without knowing who they are and which one.
Content and everything in itContract, on your organisation’s instructionsHeld to run the service. See the data processing agreement for the processor terms.
Governance and audit recordsLegitimate interestAn audit trail that could be edited by the party it holds accountable would serve no purpose. The interest is the customer’s as much as ours.
Comments and sign-offs from review linksLegitimate interest of the customerSomeone who is asked to approve a post is being asked precisely so their approval is on the record.
Invite requests and integration votesConsent, given by sending the formYou typed it in to ask for something. Withdraw it at any time and the row goes.
Security and abuse preventionLegitimate interestRate limits, token expiry, and refusing a request that looks like an attack.

Where the basis is legitimate interest you can object under clause 10, and we have to stop unless there is a compelling reason not to. For an insert-only audit record that reason usually exists and we will say so plainly rather than quietly not acting.

7How long it is kept#

  • Content is kept until you or your account owner deletes it. There is no automatic expiry and no configurable retention schedule.
  • Deleting an account removes its workspaces and its invitations, and deleting a workspace removes its projects, carousels, versions, assets, templates and generation records.
  • Export and generation records survive the deletion of an individual carousel, because their purpose is to evidence what was released. They do not survive the deletion of the workspace they belong to.
  • Review links carry a mandatory expiry set when they are created, and can be revoked before it. Comments and sign-offs made through a link are part of the carousel's record and go when the carousel does.
  • Your account is removed on request, which revokes your access. Records naming you as the person who released something remain, for the reason above.
  • Invite requests are kept until the queue is dealt with and are deleted on request at any time.
  • Backups are whatever the managed database platform provides on our plan. No restore has been tested, so no retention window or recovery objective is published here. Ask and you will get the plan details rather than a number.

8Who else touches it#

The complete list, what each one does and where each one sits, is the sub-processors page. It is short because keeping it short is treated as a design constraint: two features that would have been easy with an external service were written in-house rather than add a name to it.

Beyond that, personal data is disclosed only where the law requires it, and we will tell you about a demand unless we are prohibited from doing so. If the business is ever sold or merged, the data goes with it and you will be told before it does, in time to get your data out.

Our own staff access is limited by database policy rather than by an internal rule. A platform administrator can read account names, membership, workspace names, invitations and governance records. They cannot read carousels, projects, uploaded assets or templates, because no policy grants it. The mechanism is described on the security page.

9Security#

Rather than summarise it into something reassuring, the whole picture is on the security page, the measures we are contractually committed to are in annex II of the data processing agreement, and the route for reporting a flaw is the vulnerability disclosure policy.

No certification or third-party audit is held or claimed. Sign-in is possession of a mailbox, with no second factor and no single sign-on. If a personal data breach affects you we will tell you without undue delay, and we will tell you what we do not yet know as well as what we do.

10Your rights, and how to use them#

Where we are the controller you can ask for a copy of your data, correction of anything wrong, erasure, restriction of processing, portability of what you gave us, and you can object to anything resting on legitimate interest. Where consent is the basis you can withdraw it, and withdrawing does not affect what happened before.

Send it to privacy@touchgrass.consulting. You will get an answer within one month and it costs nothing. If a request is refused you will be told why, and told that you can complain.

How the request is actually handled. By us, rather than through a self-service screen. Everything is keyed to a workspace, so locating one person’s data is quick, and a person reads the request rather than a form processing it — which matters most for the requests a form would get wrong.

Where we are the processor — which is most content — the request belongs with the customer whose workspace holds it. Send it to them, or send it to us and we will identify the customer and pass it on.

11Children#

Inkstand is sold to organisations for professional use and is not directed at children. No account should be created for anyone under sixteen. No age verification is performed, so if you believe a child's data has reached the product, tell us and it will be removed.

12Changes to this notice#

The version number and effective date at the head of this document are the only place either is recorded. A change that materially affects how personal data is handled will be notified by email to account owners before it takes effect, and the effective date will be the date of the change rather than the date it was written.

13Complaining#

If you think your data has been handled improperly, you can complain to Integritetsskyddsmyndigheten (IMY), the Swedish supervisory authority, at https://www.imy.se, or to the authority in the EU country where you live or work. You do not have to raise it with us first, though we would rather you did, because most of what looks like a violation from outside is answerable in a paragraph.

Privacy notice, version 0.3, effective 29 July 2026. Every agreement, and who you are contracting with, on the legal index.