Learn how we collect, use, and protect your information when you use our INVSBL services.
At INVSBL, we keep your sensitive data yours. This Privacy Statement explains how we collect, use, disclose, and protect information when you use our INVSBL application and algorithm (collectively, the "Services"). It reflects our current architecture: we route your requests to third-party model providers via any OpenAI-compatible endpoint — including frontier, self-hosted, and open-weight models. Our intelligent routing layer automatically detects private, personally identifiable (PII), and sensitive data in your prompts and ensures that such information is never retained by model providers or used for model training. INVSBL stores only zero-knowledge encrypted conversation data on our servers — encrypted on your device before transmission. We cannot read, access, or decrypt your content; only you hold the keys.
INVSBL, Inc. ("INVSBL," "we," "us," or "our") provides privacy-first AI software that orchestrates any OpenAI-compatible model — frontier, self-hosted, or open-weight. Our intelligent routing layer detects private, PII, and sensitive data in your prompts and ensures such information is shielded from provider retention and model training.
This Privacy Statement applies to our desktop and mobile applications, websites, and related services that link to it.
We minimize sharing.
We route your requests to third-party model providers. Our routing layer ensures that private, PII, and sensitive data detected in your prompts is shielded from provider retention and training. Provider selection and data-handling policies vary by endpoint; INVSBL's protections focus specifically on your confidential information.
Infrastructure vendors (cloud hosting, database, email delivery) may process account/billing and operational data as processors under contract. They are prohibited from using it for their own purposes.
We may disclose information if required by law or to protect INVSBL, our users, or the public, consistent with legal standards.
If we undergo a merger, acquisition, or asset sale, account and billing data may transfer as permitted by law. If any change reduces your privacy rights, we'll provide notice and choices where required.
We may share non-personal, aggregated operational statistics (e.g., uptime) that cannot reasonably identify you.
We implement administrative, technical, and organizational safeguards, least‑privilege access, encryption in transit and at rest for account data, and strict internal controls. No method of electronic transmission or storage is perfectly secure, but we continually improve our defenses.
If embeddings or profile signals are generated to power on-device features, they are stored client-side alongside your content and follow the same local deletion controls. We do not use embeddings for training, ads, or content analytics, and we never sell them.
Retained while your account is active and as required for legal, tax, security, and fraud-prevention obligations. Where applicable law permits, you may request deletion or restriction; some records must be kept to comply with statutory requirements.
Server-side conversation data is stored exclusively in zero-knowledge encrypted form and is subject to the same TTL and deletion controls described above. Encrypted backups may exist for account/billing systems only and are used solely for disaster recovery.
If required to preserve records for litigation or investigations, we may place a temporary legal hold on account/billing data until the matter is resolved.
Any server-side data (e.g., account/billing) is encrypted in transit and at rest and protected by least-privilege access controls and audit logging. Only authorized personnel with a need-to-know may access limited data to operate the Services or fulfill your requests (e.g., export/delete).
Regardless of settings, we never sell your prompts/outputs or embeddings. INVSBL never uses your data to train our own models. Our routing layer ensures that private, PII, and sensitive data is shielded from third-party model training.
Depending on your location, you may have rights to access, correct, delete, export, or restrict processing of your personal data. You can:
To exercise rights, contact contact@invsbl.dev. We will respond consistent with applicable laws (e.g., GDPR, CCPA/CPRA).
The Services are not directed to children under 13 (or under 16 in the EEA). We do not knowingly collect personal information from children.
If account/billing data is processed outside your country, we use appropriate safeguards (e.g., Standard Contractual Clauses) as required by law. Conversation data stored on INVSBL servers is zero-knowledge encrypted and unreadable by INVSBL or any third party. Our routing layer additionally protects sensitive data from provider retention.
We may update this Privacy Statement to reflect changes in our practices or legal requirements. If we make material changes, we will post the update here and, where required, notify you.
If you have any questions or concerns about this privacy statement, please contact us.
Contact Us