Skip to content
Security & data handling

What happens to a request

IntakeOwl handles other people's customers' information, so here is plainly what we collect, how it's stored, who sees it, and what we never do.

What's collected

Only what the request needs: the problem details your niche's questions ask for, any photos the customer chooses to add, and the contact information they enter so you can reach them back.

Consent on every request

Before a request is submitted, the customer checks a box acknowledging that their details are shared with the business they're contacting. No request goes through without it, and the SMS opt-in stays off and unused in this version.

Encrypted in transit and at rest

Every page and every submission travels over HTTPS. Request data and photos are stored on reputable cloud services that encrypt data at rest — we don't run storage on a machine under a desk.

Where it runs

IntakeOwl runs on managed cloud infrastructure: a hosted Postgres database for request records, dedicated object storage for photos, and an established email provider for delivery. No request data is kept in spreadsheets or personal inboxes.

Who sees it

The business the request is for. A submitted request is delivered to that business's inbox. It is not shared with other businesses and is not sold or rented to anyone.

Photos

Photos are stored to attach to the request and shown to the receiving business. Customers should photograph the equipment or the problem — not documents, faces, or anything they wouldn't want shared with the business they're contacting.

How long it's kept

A real request is kept so the business can look it up later, and removed when you or the customer asks. Demo submissions are different: flagged as tests and deleted automatically within about two days.

Deletion on request

A person can ask for their request and photos to be deleted. Email hello@intakeowl.com and we remove the record and its files.

No badges we haven't earned

IntakeOwl is new. We have not completed a SOC 2 audit or signed HIPAA business-associate agreements, and we won't show compliance badges to suggest otherwise. What's above is what's actually true today. As the product matures and pilots ask for formal attestations, we'll pursue them — and only claim them once they're real. If a security questionnaire is a must for you now, tell us and we'll be straight about where we are.

What never happens to your data

  • It isn't sold, rented, or shared with third parties for their own use — a request goes to the business it was submitted to, nowhere else.
  • It isn't used to train models or to profile the people who submit requests.
  • Voice dictation audio never reaches our servers — the browser turns speech into editable text, and only the text is submitted.
  • Nothing is promised on your behalf — no response-time claims are attached to requests you receive.

The demo is sealed off

Anything you submit in the live demo is flagged as a test, emails no one, and is deleted automatically within about two days. It exists only so you can see the on-screen brief.

Read the privacy details