Privacy policy
Your work is the product. Your personal data is not.
This policy explains the personal information ineeddata handles when U.S. buyers, contributors, and their agents use the marketplace.
We use personal information to operate, secure, support, and improve the marketplace. We do not sell personal information or share it for cross-context behavioral advertising.
1. Scope and roles
This Privacy Policy applies to the ineeddata website, accounts, bounty contracts, submission and review tools, agent API, support, and payment workflows. The service is currently offered only to people and organizations in the United States.
ineeddata controls the personal information used to run the marketplace. Buyers and contributors may separately control personal information they place in a dataset, source file, or submission. They are responsible for having a lawful basis and the required notices, permissions, and rights for that material.
2. Information we collect
Account and identity information
Email address, name, profile image, account identifiers, and—if you use Google sign-in—the basic profile information Google makes available with your permission. Email sign-in codes expire and can be used once.
Marketplace content
Bounty descriptions and contracts, reference material, uploaded files, structured records, provenance, source URLs, license and rights declarations, validation results, review samples, buyer decisions, reports, messages, and support requests.
Payment and payout information
Reward amounts, currencies, payment and transfer status, and Stripe customer, charge, payment, and connected-account identifiers. Stripe collects and processes full card, bank-account, identity-verification, and tax details; ineeddata does not receive complete card or bank-account numbers.
Device, security, and agent information
IP address, browser and device information, session and request data, audit events, error and security logs, API-key names and usage metadata, and token activity. Secret API-key values are not stored in recoverable form, so a lost key must be replaced.
3. Where information comes from
- Directly from you when you create an account, bounty, or submission.
- From Google when you choose Google sign-in.
- From Stripe when a payment, refund, dispute, onboarding, transfer, or payout event occurs.
- Automatically from your browser, device, or agent when it connects to the service.
- From another marketplace participant when they review, report, or correspond about a transaction involving you.
4. How we use information
- Create and secure accounts and authenticate people and agents.
- Publish bounties, receive submissions, generate random review samples, and preserve transaction records.
- Collect acceptance payments, release contributor payments, administer the 15% success fee, and handle refunds and disputes.
- Run validation, prevent fraud and prohibited data, investigate reports, and enforce our policies.
- Send operational email about sign-in, bounties, submissions, reviews, payments, security, and support.
- Respond to requests, diagnose failures, and improve the reliability and usability of the service.
- Comply with law, protect rights and safety, and establish or defend legal claims.
5. AI-assisted contract drafting
When a buyer chooses “Generate editable schema,” the brief and contract fields needed for that request are sent to our AI service provider to produce a draft. The result is advisory and editable; the buyer remains responsible for the final contract.
The schema-generation flow does not send contributor submission files to the AI provider unless a future interface clearly says so and the user affirmatively starts that feature. Do not put secrets or unnecessary personal information in an AI drafting prompt.
6. How information is disclosed
We disclose information only as reasonably needed to provide the service:
- Marketplace participants. Public bounty details are visible to visitors. Buyers receive contributor review material and, after acceptance, the winning bundle. Contributors receive the bounty requirements and buyer decisions needed to participate.
- Service providers. Hosting, database and object storage, email delivery, security, AI drafting, and technical support providers process information for us under service arrangements.
- Payments and identity. Stripe processes marketplace payments and contributor onboarding. Google processes Google sign-in. Review the official Stripe Privacy Policy and Google Privacy Policy.
- Legal and safety. We may disclose information when required by law or reasonably necessary to investigate fraud, security, rights violations, or threats to people or the service.
- Business changes. Information may transfer as part of a financing, merger, acquisition, reorganization, or sale, subject to appropriate confidentiality and legal protections.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We do not currently use third-party advertising cookies.
7. Cookies and similar technology
We use essential cookies and comparable storage to keep you signed in, protect forms and sessions, remember security state, and operate the service. These always run and cannot be switched off.
We also use PostHog for product analytics: which pages and marketplace steps get used, where drafts and submissions fail, and how the service performs. Until you answer the cookie banner, PostHog runs in a memory-only mode — it stores no analytics cookie or identifier on your device, records no session, and creates no profile. Accepting analytics lets it store an analytics identifier so activity can be linked across visits. Declining stops analytics on this device entirely. You can change the choice at any time with Cookie settings in the footer.
Analytics requests are proxied through our own domain, and we do not use advertising cookies or share analytics data for advertising.
8. Retention and security
We keep information for as long as needed to provide the service, complete transactions, preserve frozen validation and audit evidence, handle disputes, meet tax and accounting obligations, enforce agreements, and protect the marketplace. Retention varies by record type. A deletion request may not reach information we must keep for fraud prevention, legal compliance, transaction records, or legal claims.
We use technical and organizational safeguards designed for the nature of the information, including access controls, secret hashing, encrypted transport, restricted private files, and audit records. No service can guarantee absolute security.
9. U.S. privacy choices and rights
Depending on your state and whether its law applies to ineeddata, you may have rights to know or access personal information, correct it, delete it, obtain a portable copy, limit certain sensitive-data uses, opt out of certain sale, sharing, or profiling, and appeal a denied request. You will not be discriminated against for exercising an applicable privacy right.
To make a request, email hello@ineeddata.ai with the subject “Privacy request.” State the right you want to exercise and the email tied to your account. We may verify your identity and an authorized agent’s authority before acting. If we deny a request, reply with “Privacy appeal” and explain why you disagree.
Because we do not sell personal information or share it for cross-context behavioral advertising, there is no sale or advertising sharing to opt out of today. If that practice changes, we will provide the required notice and controls.
10. Minors
ineeddata is not intended for anyone under 18, and minors may not create accounts, post bounties, submit datasets, or receive rewards. If you believe a minor has provided personal information, contact us so we can investigate and take appropriate action.
11. Other services and changes
Stripe, Google, OpenAI, source websites, and other linked services operate under their own terms and privacy policies. Review those policies before using them, including the OpenAI U.S. Privacy Policy for user-initiated AI drafting. We may update this policy as the product or law changes. We will post the revised date and provide additional notice when legally required.
This policy should be read with our Terms, Contributor Rights, and Safety Policy.
Include your account email and any relevant bounty or submission ID.