Legal
Privacy Policy
What we collect, why, and the controls you have, across the InnerSmith site, waitlist, and blog. Written to be read, not skimmed past.
Last updated: August 15, 2026
InnerSmith (“we,” “us”) operates this website, the InnerSmith Blog, and the InnerSmith waitlist. This policy explains what personal information we collect, how we use and share it, and the rights you have. It applies to this website and our pre-launch communications; the InnerSmith app will carry its own in-app privacy policy at launch.
On this page
1. Information We Collect
Information you provide directly
- Waitlist and newsletter data. When you join the InnerSmith waitlist, on the landing page or through the blog, we collect your email address, the page you signed up from, and the time of signup.
- Correspondence. If you email us or reply to our messages, we keep the contents of that correspondence so we can respond and improve.
Information collected automatically
- Device and log data. Like most websites, our servers record IP address, browser type and version, operating system, referring URL, pages viewed, and time stamps. We use this for security, diagnostics, and to understand aggregate site usage.
- Cookies and similar technologies. We use essential cookies and browser storage needed for the site to function, and, once marketing begins, the analytics and advertising technologies listed in Section 4. See that section for exactly what runs, why, and how to opt out.
Information from other sources
We do not buy personal information about you. If you interact with InnerSmith on social platforms (for example, commenting on a post), we receive what those platforms make available under their own policies.
2. How We Use Information
- To operate, maintain, secure, and improve this website and the blog.
- To send you the waitlist confirmation and the launch updates you signed up for.
- To respond to your questions and messages.
- To measure how our pages and campaigns perform, so we can improve them (analytics, once enabled).
- To reach people likely to be interested in InnerSmith and measure ad performance (advertising, once enabled).
- To protect the security and integrity of our site and services, and to detect and prevent abuse.
- To comply with legal obligations and enforce our terms.
Where the GDPR or similar laws apply, we rely on: your consent (marketing emails, non-essential cookies), our legitimate interests (site security, aggregate analytics, improving our content), performance of a contract (delivering something you asked for), and compliance with legal obligations.
5. Your Privacy Rights
European Economic Area, United Kingdom, and Switzerland
You have the right to access, correct, delete, or receive a copy of your personal data; to object to or restrict certain processing; and to withdraw consent at any time (without affecting processing that happened before you withdrew it). You also have the right to lodge a complaint with your local data protection authority.
California
Under the CCPA/CPRA, California residents may request to know, correct, or delete the personal information we hold about them, and to opt out of “sale” or “sharing” as those terms are defined in the law. We do not sell personal information; if our use of advertising cookies is considered “sharing,” you can opt out through the cookie controls described in Section 4. We will never discriminate against you for exercising these rights.
Other U.S. states
Residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, and Utah) have similar rights of access, correction, deletion, and opt-out of targeted advertising.
To exercise any of these rights, email [email protected]. We will verify your request (usually by confirming control of the email address on file) and respond within the time required by the applicable law.
6. Data Retention
We keep personal information only as long as needed for the purposes above: waitlist and newsletter data until you unsubscribe or ask us to delete it, or until the program ends; correspondence for as long as needed to resolve and learn from it; server logs for a limited period for security and diagnostics. When information is no longer needed, we delete or anonymize it. Retention criteria are the sensitivity of the data, the purpose it serves, and any legal obligations to keep it.
7. International Data Transfers
Our infrastructure is hosted in the United States. If you access the site from elsewhere, your information is transferred to and processed in the U.S. Where required, for transfers from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum.
8. Security
We protect your information with technical and organizational measures appropriate to a pre-launch marketing site: TLS encryption in transit, access controls on our servers, separation of collected signups from the deployed application, and regular software updates. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we design so that little is collected in the first place.
Our signup forms are protected by Google reCAPTCHA, which looks at interaction signals to tell people from automated scripts. It loads only when you start filling in a form, and its use is subject to the Google Privacy Policy (policies.google.com/privacy) and Terms of Service (policies.google.com/terms).
9. Children’s Privacy
This site is not directed to children, and we do not knowingly collect personal information from anyone under 16 (or under 13 where that is the applicable threshold). If you believe a child has provided us personal information, contact [email protected] and we will delete it.
10. Third-Party Links
The blog cites external sources, and our pages may link to other sites. Those sites have their own privacy practices, which we do not control and this policy does not cover.
11. Contact Us
Questions, requests, or complaints about privacy at InnerSmith: email [email protected] with “Privacy” in the subject line. If you are in the EEA or UK, you may also contact your local data protection authority.
12. Changes to This Policy
We will update this policy as InnerSmith grows, most notably when the app launches and when analytics or advertising technologies are switched on. We will change the “Last updated” date above with every revision and, for material changes, add a notice on this page. Continued use of the site after a change means the updated policy applies.
Privacy contact
InnerSmith Privacy
[email protected]