Legal

Privacy Policy

Effective date:

This policy describes how Imperal, Inc. handles information when you use Imperal Cloud and its agent, Webbee. We have tried to write it the way we write everything else: plainly, and without claiming more than we do.

1. Who we are

Imperal, Inc. (“Imperal”, “we”) operates imperal.io, the Imperal Cloud panel at panel.imperal.io, and the agent Webbee. We are the data controller for the information described in this policy.

For anything in this document, including requests about your own data, write to support@imperal.io.

2. What we collect and why

We collect what an account and a paid plan actually require, nothing is gathered “just in case”.

Categories of personal data Imperal collects, why, and the legal basis
DataWhy we need itLegal basis
Email addressYour account identity, sign-in, email verification, and service notices.Performance of a contract
Full name and nicknameIdentifying your account and addressing you in the product.Performance of a contract
PasswordAuthentication. Stored only as a salted hash, we never hold the plaintext.Performance of a contract
Billing address, city, postal code, state, countryInvoicing and determining the tax that applies to your purchase.Contract and legal obligation
Phone number (optional)Billing contact and account recovery. You may leave it blank.Consent
Company name and tax ID (business accounts)Issuing correct business invoices and applying VAT/GST rules.Contract and legal obligation
Usage and credit recordsMetering what your agents run, so your balance and invoices are accurate and auditable.Performance of a contract
Support correspondenceAnswering you, and keeping a record of what was agreed.Legitimate interest

We do not sell personal data, and we do not share it with advertising networks or data brokers.

3. What your agent sees

Webbee acts on your instructions, so the things you ask it to do pass through the platform. Two consequences are worth stating outright:

  • Your conversations and the actions taken are stored on your account so the agent keeps context between sessions and so every action remains attributable to a request you made.
  • Content you hand to the agent , a file you upload, a mailbox you connect, a database you point it at, is processed to carry out that request. What it contains is up to you, so treat it as you would any system you grant access to.
  • Actions are logged. Metering and accountability both depend on it: you can see what ran, what it cost, and when.

Model providers

Running an agent means sending the relevant part of a request to a language-model provider. Those providers process that content only to return a response for your request. Enterprise customers can bring their own model, in which case prompts go to the provider you configure instead.

4. Services you connect

Extensions let you connect your own accounts, mail, servers, databases, analytics, and so on. When you authorise one:

  • We store the credential or token needed to keep that connection working, and nothing beyond it.
  • We use that access only to perform actions you request through Imperal.
  • Disconnecting a service deletes the stored credential for it.
  • The connected provider's own privacy policy continues to govern the data held on their side.

5. Analytics and cookies

This website runs a self-hosted analytics tracker on our own infrastructure. It is served first-party, from this domain, and reports only to us, no analytics vendor, no advertising SDK, and no third-party tracking pixel is loaded on imperal.io.

The marketing site does not set advertising or profiling cookies, which is why you are not greeted by a consent banner. Two small pieces of browser storage are used for the product itself, both strictly functional: a short-lived entry that carries your session across a bank 3-D Secure redirect during checkout, and a flag that tells the signup form your email was verified. The panel additionally sets the session cookie needed to keep you signed in.

6. Who else processes your data

We keep the list of processors short, and each one has a specific job:

Third parties that process data on Imperal's behalf
ProcessorPurposeWhat it receives
StripePayment processing for subscriptions and credit top-ups.Card details go directly to Stripe and never reach our servers; we hold only the outcome, the last four digits, and the card brand.
Language-model providersProducing the agent's responses and tool calls.The content relevant to the request you made.
Our own hosting infrastructureRunning the platform, its databases, and its backups.Operated by us on servers we control.

7. How long we keep it

  • Account data: for as long as your account exists.
  • Billing and invoice records: retained after closure where tax and accounting law requires it.
  • Usage and credit records: kept as the audit trail behind past invoices.
  • Conversations and agent history: kept on your account until you clear them or close the account.
  • Connection credentials: deleted when you disconnect the service, or when the account is closed.

Closing your account removes it from the platform. Anything the law requires us to keep, invoices, chiefly, is retained for the required period and for nothing else.

8. How we protect it

  • Everything is served over HTTPS, with HSTS enforced across imperal.io and its subdomains.
  • Passwords are stored only as salted hashes.
  • Connection credentials and secrets are held encrypted.
  • Access to production systems is restricted to the people who need it, and privileged actions are logged.
  • Destructive actions in the product require explicit confirmation before they run.

No platform can promise perfect security, and we will not pretend otherwise. If a breach ever affects your personal data, we will notify you and the relevant authority as the law requires.

9. Your rights

Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, restrict or object to processing, receive it in a portable form, or withdraw consent you previously gave.

Much of this is self-service in the panel: your profile and billing details are editable, invoices and usage are exportable, and conversations can be cleared. For anything else, write to support@imperal.io and we will respond within the period the applicable law sets, one month under the GDPR. You may also complain to your local data protection authority.

10. International transfers

Imperal runs infrastructure in more than one region, and our processors may operate elsewhere, so your data may be processed outside your own country. Where such a transfer happens, we rely on the safeguards the law provides for it, such as the European Commission’s standard contractual clauses.

11. Children

Imperal is a product for professional use and is not directed at children under 16. We do not knowingly collect their data; if you believe a child has created an account, tell us and we will remove it.

12. Changes to this policy

When this policy changes we update the effective date at the top of the page. If a change materially affects how we handle your personal data, we will tell account holders directly rather than quietly editing the page.

13. Contact

Contact

Questions about this policy, or want to exercise a right described in it? Write to support@imperal.io

imperal.io