Legal

Privacy Policy

What we collect, why, and the controls you have, across the InnerSmith site, waitlist, and blog. Written to be read, not skimmed past.

Last updated: August 15, 2026

InnerSmith (“we,” “us”) operates this website, the InnerSmith Blog, and the InnerSmith waitlist. This policy explains what personal information we collect, how we use and share it, and the rights you have. It applies to this website and our pre-launch communications; the InnerSmith app will carry its own in-app privacy policy at launch.

On this page
  1. 1. Information We Collect
  2. 2. How We Use Information
  3. 3. How We Share Information
  4. 4. Cookies and Tracking Technologies
  5. 5. Your Privacy Rights
  6. 6. Data Retention
  7. 7. International Data Transfers
  8. 8. Security
  9. 9. Children’s Privacy
  10. 10. Third-Party Links
  11. 11. Contact Us
  12. 12. Changes to This Policy

1. Information We Collect

Information you provide directly

  • Waitlist and newsletter data. When you join the InnerSmith waitlist, on the landing page or through the blog, we collect your email address, the page you signed up from, and the time of signup.
  • Correspondence. If you email us or reply to our messages, we keep the contents of that correspondence so we can respond and improve.

Information collected automatically

  • Device and log data. Like most websites, our servers record IP address, browser type and version, operating system, referring URL, pages viewed, and time stamps. We use this for security, diagnostics, and to understand aggregate site usage.
  • Cookies and similar technologies. We use essential cookies and browser storage needed for the site to function, and, once marketing begins, the analytics and advertising technologies listed in Section 4. See that section for exactly what runs, why, and how to opt out.

Information from other sources

We do not buy personal information about you. If you interact with InnerSmith on social platforms (for example, commenting on a post), we receive what those platforms make available under their own policies.

2. How We Use Information

  • To operate, maintain, secure, and improve this website and the blog.
  • To send you the waitlist confirmation and the launch updates you signed up for.
  • To respond to your questions and messages.
  • To measure how our pages and campaigns perform, so we can improve them (analytics, once enabled).
  • To reach people likely to be interested in InnerSmith and measure ad performance (advertising, once enabled).
  • To protect the security and integrity of our site and services, and to detect and prevent abuse.
  • To comply with legal obligations and enforce our terms.

Where the GDPR or similar laws apply, we rely on: your consent (marketing emails, non-essential cookies), our legitimate interests (site security, aggregate analytics, improving our content), performance of a contract (delivering something you asked for), and compliance with legal obligations.

3. How We Share Information

  • Service providers. Cloud hosting, email delivery, analytics, and advertising partners who process data on our behalf, bound by contractual confidentiality and data-protection obligations, and only to the extent needed to perform services for us.
  • Professional advisors. Lawyers, auditors, and insurers where reasonably necessary.
  • Legal compliance. If required by law, subpoena, or to protect the rights, safety, and property of InnerSmith, our users, or the public.
  • Corporate transactions. In connection with a merger, acquisition, financing, or sale of assets, in which case this policy continues to apply to your information until you are told otherwise.
  • At your direction. When you ask us to share something.

We do not sell your personal information, and we do not share it with third parties for their own independent marketing.

4. Cookies and Tracking Technologies

We use cookies and similar technologies, small files and browser storage, to make the site work, to understand how it is used, and to measure our marketing. Where the GDPR or UK GDPR applies, we set non-essential cookies only with your consent; where the CCPA/CPRA applies, you can opt out of any use of cookies that counts as a “sale” or “sharing” of personal information, as described in Section 5. Browser-level controls such as blocking, deleting, or limiting cookies in your settings always apply on top of anything below.

On your first visit, a cookie banner offers two choices: Accept cookies, or Only necessary. Choosing Only necessary keeps advertising and marketing cookies switched off while the site continues to work normally. Your choice is stored for 12 months in a cookie named innersmith_cookie_consent. To change it, clear that cookie in your browser and the banner will ask again.

Strictly necessary storage is always active, because the site does not work without it: security and load-balancing cookies, session storage that remembers an intro animation has already played, and the note that you joined the waitlist so we don’t ask you twice. None of it is used to track you across other sites.

For analytics, we use Google Tag Manager and Google Analytics to understand, in aggregate, which pages are read, where visitors come from, and whether the site is working as intended. You can opt out of Google Analytics at any time with Google’s browser add-on (tools.google.com/dlpage/gaoptout). We also use Microsoft Clarity, which builds anonymized heatmaps and session replays to show us where pages confuse people. Clarity loads only if you choose Accept cookies, typed input is masked by default, and we configure masking for any field that could contain personal information.

When our advertising begins, we will additionally use the Meta Pixel and the LinkedIn Insight Tag to measure campaign performance and build audiences for InnerSmith campaigns on those platforms. You can control how Meta and LinkedIn use your data for ads in your account settings (facebook.com/adpreferences and linkedin.com/psettings/advertising). We will update this section when that happens and, where consent is required, ask first.

We also use preference storage to remember small choices you make, like a dismissed notice, so we don’t repeat them.

5. Your Privacy Rights

European Economic Area, United Kingdom, and Switzerland

You have the right to access, correct, delete, or receive a copy of your personal data; to object to or restrict certain processing; and to withdraw consent at any time (without affecting processing that happened before you withdrew it). You also have the right to lodge a complaint with your local data protection authority.

California

Under the CCPA/CPRA, California residents may request to know, correct, or delete the personal information we hold about them, and to opt out of “sale” or “sharing” as those terms are defined in the law. We do not sell personal information; if our use of advertising cookies is considered “sharing,” you can opt out through the cookie controls described in Section 4. We will never discriminate against you for exercising these rights.

Other U.S. states

Residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, and Utah) have similar rights of access, correction, deletion, and opt-out of targeted advertising.

To exercise any of these rights, email [email protected]. We will verify your request (usually by confirming control of the email address on file) and respond within the time required by the applicable law.

6. Data Retention

We keep personal information only as long as needed for the purposes above: waitlist and newsletter data until you unsubscribe or ask us to delete it, or until the program ends; correspondence for as long as needed to resolve and learn from it; server logs for a limited period for security and diagnostics. When information is no longer needed, we delete or anonymize it. Retention criteria are the sensitivity of the data, the purpose it serves, and any legal obligations to keep it.

7. International Data Transfers

Our infrastructure is hosted in the United States. If you access the site from elsewhere, your information is transferred to and processed in the U.S. Where required, for transfers from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum.

8. Security

We protect your information with technical and organizational measures appropriate to a pre-launch marketing site: TLS encryption in transit, access controls on our servers, separation of collected signups from the deployed application, and regular software updates. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we design so that little is collected in the first place.

Our signup forms are protected by Google reCAPTCHA, which looks at interaction signals to tell people from automated scripts. It loads only when you start filling in a form, and its use is subject to the Google Privacy Policy (policies.google.com/privacy) and Terms of Service (policies.google.com/terms).

9. Children’s Privacy

This site is not directed to children, and we do not knowingly collect personal information from anyone under 16 (or under 13 where that is the applicable threshold). If you believe a child has provided us personal information, contact [email protected] and we will delete it.

11. Contact Us

Questions, requests, or complaints about privacy at InnerSmith: email [email protected] with “Privacy” in the subject line. If you are in the EEA or UK, you may also contact your local data protection authority.

12. Changes to This Policy

We will update this policy as InnerSmith grows, most notably when the app launches and when analytics or advertising technologies are switched on. We will change the “Last updated” date above with every revision and, for material changes, add a notice on this page. Continued use of the site after a change means the updated policy applies.

Privacy contact

InnerSmith Privacy
[email protected]