legal

Privacy policy

Last updated: 20 May 2026 · Effective: 20 May 2026
Template notice. This document reflects InputGate's actual technical practices but has not been reviewed by counsel. Review with a qualified lawyer in your jurisdiction before relying on it for compliance.

Summary

InputGate is an inbound-filtering API. We handle two distinct categories of personal data:

For submission data, your default retention setting is "flagged_only": we score the submission, immediately discard the fields and IP if it's clean, and only retain content for submissions flagged as spam (for review). You can override this to "none" per request to prevent any retention of submission content.

1. Who we are

This policy applies to InputGate (the "Service") operated by FreeMan LLC ("we", "us", "our"), with a registered office at Spokane, WA 99201, USA.

For data-protection inquiries, contact our Data Protection point of contact at [email protected].

2. Data we collect

2.1 Account data (you)

CategorySourceWhy we have it
Email addressYou provide it at sign-upAuthentication, billing, transactional notices
Authentication identifierClerk (our auth provider)To recognise you between sessions
Plan & billing identifierYou / StripeTo bill the correct plan
API key hashesGenerated by the serviceTo authenticate API requests (we store only SHA-256 hashes, never raw keys)
Usage countersAuto-generated per API callTo enforce monthly quotas

2.2 Submission data (your end-users, processed on your behalf)

When you call POST /v1/check, you forward us:

Whether and for how long we retain submission content is controlled by you via the retention parameter — see §5 Retention.

3. Purposes & lawful basis

PurposeLegal basis (GDPR Art. 6)
Operating your account & processing API callsPerformance of contract
Billing & tax compliancePerformance of contract / legal obligation
Filtering spam on behalf of customers (submission data)Legitimate interest of the customer; we process as processor under the DPA
Maintaining quota countersLegitimate interest (billing accuracy)
Security & abuse preventionLegitimate interest
Transactional emails (quota alerts, security notices)Performance of contract

4. Retention

4.1 Submission data — your choice, per request

The retention parameter on every /v1/check request controls retention of submission content:

Where content is retained, it is automatically deleted after 30 days by default, or after the retention window configured on your account (Scale plan and above). The deletion runs daily.

4.2 Account & billing data

Retained for the duration of your account and for up to 7 years after closure, as required by tax and accounting regulations in our jurisdiction.

4.3 Backups

Encrypted backups are rotated on a 30-day cycle. Erasure requests are honoured against live systems immediately; backup data containing erased records is overwritten in the normal rotation.

5. Sharing & sub-processors

We do not sell personal data. We share data only with the following sub-processors, each bound by a written data-processing agreement:

Sub-processorRoleLocation
Cloudflare, Inc.Edge compute, database (D1), object storage (R2), hostingGlobal edge; primary regions configurable
IPinfo.ioGeoIP lookups on client_ipUSA
ClerkAuthentication identity providerUSA
StripePayment processingUSA / EU

We do not transfer submission content to any sub-processor other than as required to operate the service. The current list is maintained at inputgate.cloud/sub-processors; material changes are notified by email at least 30 days in advance.

6. International transfers

Where personal data is transferred outside the EEA/UK, we rely on Standard Contractual Clauses (SCCs) and, where applicable, additional safeguards such as transit encryption and pseudonymisation. EU-only deployment is available on the More plan — contact us.

7. Your rights under GDPR & UK GDPR

If you are a data subject in the EEA, UK, or another jurisdiction with similar rights, you may:

To exercise any of these rights, email [email protected]. We respond within 30 days.

8. Security

We apply technical and organisational measures appropriate to the risk:

9. Cookies

The InputGate API does not set cookies. The InputGate dashboard uses essential cookies for authentication (via Clerk) and CSRF protection. We do not use advertising, tracking, or analytics cookies that share data with third parties.

10. Children

InputGate is a B2B service not directed at children under 16. We do not knowingly collect personal data from children. If you believe we have, contact us and we will delete the data.

11. Changes to this policy

We will notify you by email of material changes at least 30 days before they take effect. Non-material changes (typos, clarifications) may be made without notice; the "Last updated" date at the top reflects the most recent revision.

12. Contact

Data Protection point of contact: [email protected]
General: [email protected]
Postal: FreeMan LLC, Spokane, WA 99201, USA

Operating an InputGate account on behalf of an organisation? You're a controller of your end-users' data and we're your processor. See our Data Processing Agreement.