Privacy Policy

Last updated: June 17, 2026

1. Introduction

Invisible ("Invisible", "we", "us", or "our") operates the Invisible unified communication platform (the "Service"). This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our Service.

By using Invisible, you agree to the practices described in this policy. If you do not agree, please do not use the Service.

2. What Data We Collect

2.1 Account Data

When you create an Invisible account, we collect:

  • Email address
  • Display name
  • Account credentials (hashed password or OAuth tokens)

2.2 Communication Data

When you connect a third-party platform (Instagram, WhatsApp, iMessage, Gmail, Telegram, etc.), we access and store your conversation data to provide the unified inbox experience. This includes:

  • Message content (text, media attachments, reactions)
  • Conversation metadata (participants, timestamps, read status)
  • Sender and recipient identifiers
  • Media files (images, videos, voice messages, documents)

We access this data only through official platform APIs and OAuth authorization flows. You explicitly authorize each connection, and you can revoke authorization at any time from either Invisible or the respective platform's settings.

2.3 Platform Connection Data

For each connected platform, we store:

  • OAuth access tokens and refresh tokens (encrypted at rest)
  • Platform-specific user identifiers
  • Connection status and last sync timestamps

2.4 Usage Data

We collect anonymous usage analytics to improve the Service:

  • Feature usage patterns (which features are used, not message content)
  • Performance metrics (page load times, sync latency)
  • Device and browser type (for compatibility)
  • Error reports (for debugging)

3. How We Use Your Data

We use collected data exclusively to provide, improve, and secure the Service:

  • Unified Inbox: To display your conversations from connected platforms in a single interface
  • Search and Archive: To enable full-text search across your message history
  • AI Summaries: To generate conversation summaries you can read within the app
  • Sync: To keep your conversations up-to-date across platforms in real-time
  • Security: To detect unauthorized access, prevent abuse, and protect your account
  • Service Improvement: To fix bugs, improve performance, and develop new features

We do not use your data for advertising, user profiling, credit assessments, or any purpose unrelated to providing the Service.

4. How We Share Your Data

We do not sell, rent, or share your personal data with third parties for their own purposes, with the following limited exceptions:

  • Service Providers: We use third-party infrastructure providers (cloud hosting, database hosting) who process data solely on our behalf and under contractual obligations matching this policy
  • Platform APIs: We communicate with authorized platform APIs (Meta, Google, Apple, etc.) as necessary to sync your conversations — this is the core functionality you authorized
  • Legal Requirements: We may disclose data if required by law, court order, or governmental regulation
  • Safety: We may disclose data to protect the safety of our users or the public, consistent with applicable law

5. Data Retention

We retain your data only as long as necessary to provide the Service:

  • Active accounts: Data is retained for the duration of your account
  • Disconnected platforms: When you disconnect a platform, we delete the associated OAuth tokens and sync data within 30 days
  • Account deletion: When you delete your account, all personal data is deleted within 30 days. See our Data Deletion page for details
  • Legal holds: We may retain data longer if required by law or regulation, and only for the duration required

6. Data Security

We implement industry-standard security measures:

  • AES-256 encryption for data at rest
  • TLS 1.3 for all data in transit
  • Encrypted storage of OAuth tokens and credentials
  • Role-based access controls for internal systems
  • Regular security reviews and vulnerability assessments
  • Secure infrastructure with encrypted volumes and private networks

While no system is perfectly secure, we continuously work to protect your data against unauthorized access, alteration, disclosure, or destruction.

7. Your Rights

You have the right to:

  • Access: Request a copy of all personal data we hold about you
  • Correction: Request correction of inaccurate personal data
  • Deletion: Request deletion of your personal data (see Data Deletion)
  • Portability: Export your data in a machine-readable format
  • Revocation: Revoke OAuth authorization for any connected platform at any time
  • Objection: Object to processing of your data for specific purposes

To exercise any of these rights, contact us at [email protected]. We respond to all requests within 30 days.

8. Third-Party Platform Data

When you connect third-party platforms, their respective terms of service and privacy policies also apply to the data you authorize us to access. We process platform data only as described in this policy and in compliance with each platform's developer terms:

We do not sell, transfer, or share platform data with third parties. We process it solely to provide the unified inbox experience that you, the user, have authorized and can see in the Invisible interface.

9. Children's Privacy

Invisible is not intended for use by anyone under the age of 13. We do not knowingly collect personal data from children under 13. If we learn that we have collected data from a child under 13, we will delete it promptly.

10. International Data Transfers

Your data may be processed and stored on servers in the United States. If you are accessing the Service from outside the US, please be aware that your data will be transferred to and processed in the US. By using the Service, you consent to this transfer. We comply with applicable data protection laws including GDPR for EEA users.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service at least 30 days before they take effect. Your continued use of the Service after changes become effective constitutes your acceptance of the updated policy.

12. Contact

For privacy-related questions or to exercise your data rights:

Invisible