Privacy Policy

Last updated: July 2026

This document reflects InnoBee's current features and practices as of the date above. We update it regularly as the platform changes.

1. Scope and Controller

This Privacy Policy explains how InnoBee ("we," "us," "our") collects, uses, discloses, and protects personal data when you use the InnoBee platform ("Platform"). InnoBee is the data controller for the personal data described here, except where we process data on behalf of an organization customer under a Data Processing Agreement — see Section 9.

2. Information We Collect

We collect the following categories of information:

2.1 Information you provide directly

  • Account information: name, email, password (hashed), profile photo, bio, and role preferences
  • Challenge and submission content: challenge briefs, submission files/text, judging scores and comments
  • Payment information: processed directly by Stripe — InnoBee does not store full card numbers
  • Communications: messages you send us, support tickets, and content submitted to InnoBee Queen
  • Organization data: if you create or join an organization account, company name, size, and billing contact

2.2 Information generated by your use of the Platform

  • Activity data: challenges created/joined, submissions made, judging activity, Hive Score and tier history, Coins earned/spent
  • Device and technical data: IP address, browser type, device identifiers, and log data
  • Cookies and similar technologies — see our Cookie Policy for full detail and how to manage your preferences

2.3 Information from third parties

  • Authentication providers if you sign in via a third-party identity provider
  • Payment confirmation data from Stripe
  • Publicly available information you or others post in connection with a published challenge or Pitch Deck

3. How We Use Your Information

We use personal data for the following purposes:

  • Operating the Platform: creating your account, running challenges, processing submissions and judging, calculating Hive Score, operating the Innovation Wallet and BeeShop
  • Payments: processing subscription fees, à la carte purchases, and prize/sponsorship fund escrow and payout via Stripe
  • Communications: service notifications, security alerts, and — where you have opted in — product updates and marketing
  • AI features: providing InnoBee Queen's conversational and Agent Mode features (see Section 4 for how this data is handled specifically)
  • Safety and integrity: detecting fraud, sockpuppeting, plagiarism, and abuse; enforcing our Terms of Service and Community Guidelines
  • Legal compliance: responding to lawful requests, tax and financial reporting, and enforcing our agreements
  • Improving the Platform: aggregated and anonymized analytics on feature usage

4. Data Sent to InnoBee Queen and AI Features

When you use InnoBee Queen, the content of your conversation (and, in Agent Mode, the actions you authorize) is sent to our AI model provider (currently Anthropic) to generate a response. This may include challenge content, submission drafts, or other text you choose to share with Queen.

We do not send your account password, full payment card details, or other users' private data to the AI model provider as part of normal Queen usage.

We do not permit our AI model provider to use InnoBee customer data to train their general-purpose models, consistent with standard API-level data usage terms; if this ever changes for a specific feature, we will disclose it clearly before you use that feature.

5. How We Share Information

We do not sell your personal data. We share personal data only in the following circumstances:

  • With other users, as intended by the Platform's design — for example, a challenge creator sees the profile and submission of a participant, per your privacy settings and the challenge's visibility
  • With service providers who process data on our behalf under contract, currently including Supabase (database and authentication infrastructure), Stripe (payments), Resend (transactional email), and Anthropic (AI features)
  • With a buyer or successor in the event of a merger, acquisition, or sale of assets, subject to this Policy or a materially equivalent one
  • When required by law, subpoena, or to protect the rights, property, or safety of InnoBee, our users, or the public
  • With your explicit consent for any purpose not listed above

6. Data Retention

We retain account and activity data for as long as your account is active and as needed to provide the Platform, comply with legal obligations (including tax and financial recordkeeping), resolve disputes, and enforce our agreements.

When you delete your account, we delete or anonymize your personal data within 90 days, except: (a) data we must retain for legal, tax, or accounting purposes, (b) data underlying completed challenges where removal would materially affect other users' legitimate records (for example, a public leaderboard or awarded certification — this is anonymized rather than fully deleted where feasible), and (c) data preserved under a legal hold.

Backups are retained on a rolling cycle and are not immediately purged on deletion, but are not used for any purpose other than disaster recovery and are purged on our standard backup rotation schedule.

7. Security

We use industry-standard security measures including encryption in transit (TLS) and at rest, row-level security policies on all database tables scoping access to authorized users, and role-based access controls for our own personnel.

We conduct regular internal production audits across authentication, database, security, hosting, deployment, monitoring, scaling, and recovery layers (among others), and engage external penetration testing on a recurring basis — see our Trust Center at innobee.buzz/trust for our current practices and how to request documentation.

No system is completely secure. If you become aware of a security vulnerability, please report it per our responsible disclosure process at innobee.buzz/trust rather than disclosing it publicly.

8. Your Privacy Rights

Depending on your location, you may have some or all of the following rights regarding your personal data. To exercise any of these rights, email privacy@innobee.buzz — we will respond within the timeframe required by applicable law (typically 30 days, or 45 days for California requests where extended).

8.1 If you are in the EEA, UK, or Switzerland (GDPR / UK GDPR)

Under the GDPR and UK GDPR, you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate or incomplete data
  • Erasure ("right to be forgotten"), subject to the retention exceptions in Section 6
  • Restrict or object to certain processing, including for direct marketing
  • Data portability — receive your data in a structured, commonly used, machine-readable format
  • Withdraw consent at any time where processing is based on consent, without affecting processing before withdrawal
  • Lodge a complaint with your local data protection authority

8.2 Legal basis for processing (GDPR / UK GDPR)

We process personal data on the following legal bases: performance of our contract with you (operating your account and the Platform), our legitimate interests (fraud prevention, Platform security, and product improvement, balanced against your rights), your consent (marketing communications and optional cookies), and compliance with legal obligations (tax and financial recordkeeping).

8.3 International data transfers

Where personal data is transferred outside the EEA/UK to our service providers, we rely on Standard Contractual Clauses or an equivalent lawful transfer mechanism with each processor.

8.4 If you are a California resident (CCPA / CPRA)

Under the CCPA/CPRA, you have the right to:

  • Know what personal information we collect, use, and disclose
  • Delete personal information, subject to statutory exceptions
  • Correct inaccurate personal information
  • Opt out of the "sale" or "sharing" of personal information — InnoBee does not sell personal information and does not share it for cross-context behavioral advertising
  • Limit use of sensitive personal information
  • Non-discrimination for exercising any of these rights

8.5 Other jurisdictions

If you are located in a jurisdiction with a comparable data protection law not listed above (for example, Brazil's LGPD, Canada's PIPEDA, or other regional frameworks), we extend equivalent rights to you on request at privacy@innobee.buzz.

9. Organization Customers and the Data Processing Agreement

If your organization uses InnoBee to process personal data of others (for example, running an internal innovation program with employee participants), InnoBee acts as a data processor on your organization's behalf for that data, under a Data Processing Agreement (DPA) available at innobee.buzz/policies/dpa. Contact legal@innobee.buzz to execute a DPA for your organization.

10. Children's Privacy

The Platform is not directed at children under 16, and we do not knowingly collect personal data from children under 16. If we learn we have collected such data, we will delete it. Contact privacy@innobee.buzz if you believe a child has provided us personal data.

11. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will provide at least 14 days' notice via email or an in-Platform notice before the changes take effect.

12. Contact

Questions about this Privacy Policy or your data can be sent to privacy@innobee.buzz. For security-specific concerns, see security@innobee.buzz and our Trust Center.