What we store. What we never touch.
How Inciteful handles your clients’ data: what it keeps, the access it asks for, where it runs, and how you take everything out again.
How does Inciteful handle client data? In plain words.
Inciteful stores what it measures for each client: the tracked questions, every AI answer with its sources, reports, Proof records and Agent chats. It asks for one read-only Google permission, never publishes to a client’s site, and lets you export everything, or delete a client or the whole account, yourself.
There are no badges on this page, only what the product does. The privacy policy has the legal detail.
The least access that does the job.
- One Google permission
- “View Search Console data for your verified sites”. Read-only, per client, and optional.
- Server logs, only if you send them
- AI traffic reads the events your server posts with the workspace’s token. Optional, and in beta.
- API keys
- Shown once and stored hashed. A team member’s key cannot push changes.
- Your own Anthropic key
- Optional, encrypted at rest, and used only for supported analysis.
- Card details
- Held by Stripe, not by us.
- Web pages the Agent reads
- Treated as data, never as instructions. At most four pages in a run.
Export it. Or delete it.
- Export
- All account data as JSON, from the Account page.
- Delete a client
- Erases that client’s evidence, chats and Proof records.
- Delete the account
- Removes the account and its content. Short-lived backups and the records the law makes us keep, such as amounts for tax, are the exceptions.
- Cancel, or let a trial end
- The account goes read-only. Nothing is deleted unless you delete it.
- Client report links
- Private by default. Rotate or unpublish one at any time.
Named providers. Named in the privacy policy too.
- Vercel
- Application hosting.
- Neon
- Database hosting: your account and its content.
- Stripe
- Payments. Card data goes straight to Stripe.
- Resend
- Transactional email.
To get the answers it measures, Inciteful sends your tracked questions to the AI model and answer data providers it uses to put them to each engine. The privacy policy lists who processes what.
Practices, not badges.
- Encrypted at rest
- Keys and credentials you connect.
- Hashed API keys
- A key is shown once. Only its hash is kept.
- Ownership checked on the server
- Every route checks that the workspace belongs to the account asking.
- Rate limits
- On sign-in, on one-time codes and on runs.
- Cross-site request protection
- On every action that changes something.
- Guarded page fetches
- Outbound fetches cannot be pointed at internal addresses.
A person answers. No ticket maze.
- Docs
- Setup, the MCP server, the CLI and the API.
- The company
- Inciteful Ltd, registered in England and Wales, company number 17400405. 128 City Road, London, EC1V 2NX.
Questions about trust, answered plainly.
What client data does Inciteful store?
For each client workspace: the tracked questions, every AI answer with its sources, the reports, Proof records and Agent chats. Card details are held by Stripe, not by Inciteful.
Does Inciteful publish or change anything on a client’s site?
No. Inciteful measures, plans and checks. Changes are made by your own tools and people.
What access to Google does it need?
One read-only permission, per client: “View Search Console data for your verified sites”. It is optional, and nothing is written back.
Can I export or delete our data?
Yes. You can export all account data as JSON from the Account page. Deleting a client erases its evidence, chats and Proof records. You can also delete the whole account yourself.
What happens to our data if we cancel?
The account goes read-only. Nothing is deleted unless you delete it.
Who can see a client report?
Anyone with its private link, and no one else. You can rotate the link or unpublish the report at any time. Prospect reports are the exception: they are made to be shared through a public link.
How do I get support?
Write to hello@tryinciteful.com. Setup guides, the MCP server, the CLI and the API are covered in the docs.
