Innsegall Privacy Policy. Local-first Macintosh triage. Battle Scout reports stay on your device until you share them.
Legal
Privacy Policy
Alpha notice. This Privacy Policy describes Innsegall's practices during the Innsegall for Macintosh alpha (September 2026). We expect to update it before paid general availability and full counsel review. If we make material changes, we will revise the date above and notify alpha users when practical.
1. Overview
Innsegall is built local-first: Macintosh triage checks run on your device, and the primary artifact · your Battle Scout report · is stored locally unless you choose to export or share it.
This policy explains what information we collect, what stays on your Mac, and what happens when you email us, use optional clan sharing, or enable optional Parley AI features. It applies to innsegall.com, the Innsegall application for Macintosh, and related alpha services operated by Innsegall ("we," "us," "our").
2. Local-first design (Layer 1)
When you run a check in the Innsegall application:
- Read-only inspection modules examine configuration and signals on your Mac (for example launch agents, browser extensions, DNS settings, Gatekeeper status, and similar hygiene indicators).
- Results are assembled into a Battle Scout on your device.
- We do not upload your full file contents, browsing history, keystrokes, or screen captures to Innsegall servers as part of standard Layer 1 operation.
- Mutations (fixes) require your explicit confirmation in the app before changes are applied.
You control whether a Battle Scout leaves your Mac · via export, AirDrop, email attachment, clan share, or other channels you initiate.
3. Free tier · Voyage schedule (local only)
The free alpha tier includes two (2) Voyages per month on the 1st and 15th · scheduled hygiene that opens your Battle Scout and updates your Voyage chart. During alpha, this schedule is tracked locally on your Mac (for example in app preferences or secure local storage) · not via a cloud account required for basic use.
We do not receive your Voyage usage unless you purchase an extra run, subscribe to a clan plan, or otherwise interact with billing systems we enable in a future release. If local tracking is reset by reinstalling the app or clearing app data, that is handled on your device; we do not guarantee cloud-side reconciliation during alpha.
3a. Panic scout ($4.20 extra run)
The panic scout is the same read-only local engine as a free Voyage · it only unlocks an extra run on your calendar when you need clarity between the 1st and 15th.
- Runs stay on your Mac. We do not receive filenames, paths, browsing history, or your Battle Scout body when you pay $4.20.
- Payment is quota only. Stripe processes the one-time fee · you download a signed
license.json·innsegall plan --import-licenseupdates local credits. No scout contents cross our servers. - One credit per purchase. Each paid session issues one panic scout credit · replay of the same license on the same Mac is blocked locally.
- Non-refundable after delivery. Once
license.jsonis issued at checkout, the fee is final · see Terms §9.
4. Information we may collect
Information you provide
- Email alpha: If you email hello@innsegall.com to Sound the Horn or request alpha access, we receive your email address, message content, and metadata normal to email delivery. We use this only to respond about Innsegall, alpha onboarding, and billing you arrange with us. We do not sell contact lists.
- Support and billing: If you purchase extra scout runs or a clan plan during alpha, we may keep records of your email, transaction details, and seat assignments communicated by email or future checkout tools.
- Clan sharing (optional): If you use Bring your clan, you choose what Battle Scout content to share and with whom. Shared content is governed by the channel you use (Messages, email, etc.) as well as this policy.
Information collected automatically
- Website (innsegall.com v0.1): This marketing site does not use third-party analytics, advertising pixels, or social trackers in version 0.1. Our hosting provider (for example Vercel) may process standard server logs (IP address, user agent, requested URL, timestamp) for security and reliability · as described in Section 8.
- CLI improvement telemetry (default on): The Innsegall command-line scout may send once per day: an anonymized install ping (engine version, macOS major version, random install id) and category-count aggregates from your local scouts (verdict buckets, flow type, attention-check buckets) · never filenames, paths, or card bodies. Used only to improve checks and releases. Opt out:
innsegall plan --telemetry-off. - Update checks: On boot and after scans, the CLI may fetch
/.well-known/innsegall-gospel.jsononce per day to suggest a newer engine version · no scout data in that request. - App diagnostics (future): Crash reporting beyond the above will be described in an updated policy before it ships.
Information we do not collect in Layer 1
- No standing remote access to your Mac without a visible session you start.
- No sale of your personal information.
- No requirement to create an Innsegall account for basic local scout runs during alpha.
5. Parley · bring-your-own-key (BYOK)
Optional Parley assistance (when you Sound the Horn) may route prompts to AI providers. If you choose bring-your-own-key (BYOK) for Parley:
- Your API keys stay on your device (alpha: environment variables or app settings; Keychain in the Mac app when shipped). Innsegall servers do not receive them.
- Requests go from your Mac to the provider you configured, subject to that provider’s terms and privacy policy.
- Innsegall may assemble a redacted context from your Battle Scout for Parley (paths like
~/shortened, sensitive fields minimized) · still under your control before sending.
If you use Innsegall-hosted Parley routing in a future paid tier, we will disclose what is transmitted before you enable it.
6. How we use information
We use the limited information we collect to:
- Provide, maintain, and improve the Service during alpha.
- Respond to horn requests, support questions, and manual billing.
- Send operational messages about alpha builds, security notices, or policy updates (you may opt out of non-essential marketing if we send any).
- Protect against abuse, fraud, and violations of our Terms of Service.
- Comply with law and enforce our agreements.
We do not use Layer 1 Battle Scout contents for advertising profiling.
8. Retention and hosting logs
On your Mac: Battle Scouts and local quota data remain until you delete them or uninstall the app.
Email and billing records: We retain correspondence and transaction records as needed for support, accounting, and legal obligations · typically for the alpha period plus a reasonable archive window unless law requires longer retention.
Website logs: Server logs retained by our host are used for security and debugging and rotated according to the host’s standard schedule.
9. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or export personal information we hold about you, or to object to certain processing.
To exercise these rights during alpha, email hello@innsegall.com with the subject "Privacy request." We may need to verify your identity. We will respond within a reasonable time and as required by applicable law.
You can delete local Battle Scouts at any time in the app or by removing exported files. Uninstalling the Innsegall application removes locally stored app data subject to macOS behavior.
10. Security
We use reasonable administrative and technical measures to protect information we hold. No method of transmission or storage is completely secure. You are responsible for securing your Mac, Apple ID, email account, and any API keys you configure for Parley.
11. Children
The Service is not directed to children under 13 (or 16 in the EEA/UK where applicable). We do not knowingly collect personal information from children. Contact us if you believe we have done so and we will delete it.
12. International users
Innsegall is operated from the United States. If you access the Service from other regions, your information may be processed in the U.S. or where our service providers operate. We will describe any cross-border transfer mechanisms in an updated policy if required for your region.
13. Changes to this policy
We may update this Privacy Policy as the product moves beyond alpha. We will post the revised policy on innsegall.com/privacy with a new effective date. Material changes will be communicated to alpha users when practical.
14. Contact
Privacy questions or requests:
Innsegall
Email: hello@innsegall.com
Web: https://innsegall.com/