Indago Privacy Policy
1. About this policy
Indago, Inc. ("Indago," "we," "us," "our") builds software that helps regulatory teams prepare and evaluate submissions to health authorities. This policy explains what information we collect, why we collect it, who we share it with, how long we keep it, and what you can ask us to do with it.
This policy covers:
- indago.bio and its pages, our marketing website
- app.indago.bio, the Indago platform
- The Indago Regulatory Drafting Agent ("IRDA"), our connector that makes the Indago engine available inside Claude and other compatible clients
- Sales, support, and other business communications with us
This policy does not cover third-party products you reach through ours. That includes Anthropic's Claude, Microsoft SharePoint and OneDrive, Google Drive, and your own identity provider. Your use of those services is governed by your agreement with them.
2. The two roles we play
We handle information in two different capacities, and the rules differ for each.
We act as a controller for information where we decide why and how it is used. That covers website visitors, prospects, the people who administer a customer account, billing contacts, and people who contact us for support.
We act as a processor for Customer Content. Customer Content belongs to the customer. We handle it on that customer's instructions, for the purpose of providing the service, and under that customer's agreement with us. If you work for an Indago customer and you want to access, correct, or delete information held inside your organization's workspace, contact your organization first. We will support them in responding.
Where a signed customer agreement and this policy say different things about Customer Content, the signed agreement governs.
3. Terms used in this policy
Customer Content means the source documents a customer uploads or authorizes us to read, the structured evidence and assertions we extract from them, the drafts and sections we generate, edits made in the Notebook, version history, comments, and exports.
Account Data means the information needed to create and operate an account: name, work email address, organization, role and permissions, and authentication records.
Usage Data means operational records of how the service runs: which operations were requested, when, by which account, how long they took, token and page counts, job outcomes, and similar telemetry.
Website Data means information collected when you visit indago.bio, including what you submit through a form and standard server and log data.
4. What we collect
4.1 Website visitors
When you request a demo or otherwise contact us through indago.bio, we collect what you enter: name, work email address, company, phone number, program stage, and anything you write in the message field. These fields exist so we can schedule and prepare for a conversation with you.
Our web infrastructure also records standard technical information when a page is served, including IP address, browser and device type, referring page, and timestamps. This is used for security, abuse prevention, and basic operation of the site.
4.2 Prospect and sales information
We run outbound sales. In the course of that we collect and maintain business contact information about people in roles relevant to regulatory affairs: name, job title, employer, work email address, work phone number, and public professional profile information. We obtain this from the person directly, from publicly available sources, and from third-party business data providers and lead generation agencies we engage.
We store this in our customer relationship management system along with a record of our communications with you. We do not seek or want personal information about you outside a business context.
If you would rather we did not hold your information for this purpose, write to privacy@indago.bio and we will remove it and suppress future outreach.
4.3 Account and identity information
Access to the Indago platform and to IRDA requires an account. We use a third-party identity provider to authenticate users and to support single sign-on. Through it we receive your name, work email address, the organization you belong to, and authentication events such as sign-in times and method.
A work email address is required. The domain of that address is recorded separately and is used to associate users with the organization they belong to.
We also record a version-stamped acceptance of our terms against your identity, with the date and time of acceptance.
4.4 Customer Content
When a customer uses the platform or IRDA, we receive and process the documents that customer chooses to give us. In practice these are regulatory and scientific records: protocols, investigator brochures, nonclinical and clinical study reports, CMC documentation, prior summaries, and working drafts.
Documents reach us in two ways:
- Direct upload to app.indago.bio
- Authorization of a specific external location, such as a named SharePoint site, OneDrive folder, or Google Drive folder, which we then read server-side
Where you authorize an external location, the scope is fixed at the moment you authorize it. We read only what was in scope at that time. We do not discover or pull additional material later, and we do not write anything back into your document store. You are shown the exact scope granted and how to revoke it.
From those documents we derive and store structured evidence: extracted passages with page and paragraph coordinates, atomic assertions, tags, text chunks, embeddings, and the provenance graph that links generated text back to its source. We also store the drafts we generate, their version history, the refinement instructions a user enters, edits, comments, approvals, and export records.
4.5 Usage and operational data
We record how the service is used. This includes the operations requested, the account and program they belong to, timestamps, document and page counts, token consumption, job status and outcome, remaining allowance, and errors. Application logs are retained on a short cycle.
We use this to operate and bill the service, to enforce usage limits and rate limits, to detect abuse, to diagnose failures, and to understand which parts of the product are used.
4.6 IRDA connector
IRDA is a remote connector. When you install and use it, we additionally collect:
- Your identity and work email domain, captured at sign-in on our hosted page rather than inside the chat
- Your acceptance of our connector terms, version-stamped
- The program you create and its target submission type
- The authorization grant and the scope you approved for the source location you connected
- The requests you make through the connector's tools and the arguments those requests carry, which includes the text of instructions you type
- Identifiers and cryptographic hashes of every draft we generate, so that a draft can later be verified as ours
- The number of installations associated with a single email domain
Section 8 explains what does and does not cross between Indago and the client application.
4.7 Payment information
Paid connector subscriptions are purchased through a hosted checkout operated by a third-party payment processor. Card details are entered on the processor's page and never reach Indago systems. We receive and store a subscription record, a customer reference, the plan purchased, and billing status.
Platform subscriptions and packages are contracted and invoiced directly. For those we hold billing contact details, purchase order references, and invoice and payment records.
4.8 Support and communications
If you contact us for support, by email or through a shared channel such as a dedicated Microsoft Teams channel, we keep the correspondence and any material you send us with it.
5. Content we do not accept
Indago is built for regulatory and scientific documentation. It is not built for, and is not authorized to receive, the following:
- Protected Health Information as defined under HIPAA, and any other individually identifiable patient health data
- Personal information about individuals beyond the business contact details of the people working on a program
- Payment card data
- Government identification numbers
Indago is not a HIPAA covered entity or business associate, does not offer a Business Associate Agreement, and its systems are not certified for the handling of PHI. Submission material is expected to be de-identified before it reaches us. Removing direct and indirect identifiers from clinical material before upload is the customer's responsibility, and this obligation is stated in our terms.
Do not upload this material or authorize a location that contains it. If you are unsure whether a document is clean, strip the identifiers first or leave the document out of scope. We may refuse to process, or may remove, material we identify as falling into these categories.
If you believe prohibited content has been uploaded or authorized in error, contact privacy@indago.bio and we will work with you to remove it.
6. How we use information
We use the information described above to:
- Provide the service: ingest and index documents, extract evidence, generate drafts, run gap analysis, answer questions against a corpus, maintain version history and audit trails, and produce exports
- Create and secure accounts, authenticate users, and enforce role-based permissions and tenant boundaries
- Meter usage, apply plan allowances and ceilings, bill subscriptions and packages, and prevent abuse of free tiers
- Maintain the integrity of what we generate, including watermarking working drafts and verifying a draft against its stored hash on request
- Diagnose faults, monitor availability, and improve reliability and performance
- Respond to sales enquiries, provide support, and send service and administrative messages
- Send commercial messages to business contacts where permitted, with an opt-out in each one
- Meet legal, tax, accounting, and audit obligations, and enforce our terms
7. Artificial intelligence and model training
We do not hand your documents or your drafts to model providers as training data. Your source documents, the evidence we extract from them, and the drafts generated for you are not used to train a third-party provider's models, and are not pooled with other customers' material for that purpose. We hold model providers to contractual terms that prohibit training on the data we send them.
Generating a draft requires sending relevant passages from your corpus, together with our own instructions, to a large language model operated by a third-party provider. That processing happens under a data processing agreement, for the purpose of returning your result, and for no other purpose.
We do use pseudonymized platform analytics and interaction metadata to refine, calibrate, and improve the Indago engine and the platform itself. That includes how users interact with the product, how documents are labeled and tagged, prompting and refinement behavior, system feedback, timings, token consumption, job outcomes, and which features are used. This material is pseudonymized before it is used, it stays inside Indago and its contracted processors, and it is used to make the product more accurate and more reliable for the people paying for it.
Nothing in this section limits our obligations under a signed customer agreement.
8. The connector boundary
IRDA runs inside a third-party client application, currently Claude. Because that raises a reasonable question about where data goes, we state the boundary plainly.
Stays on Indago infrastructure at all times:
- Your source documents and every file we read from an authorized location
- The index, embeddings, and provenance graph derived from them
- Our prompt library and section templates
- The model call that generates regulatory text, which runs on our own provider account
Crosses into the client application:
- The words you type
- The arguments of the tool calls the client makes on your behalf
- Whatever our tools return, which includes generated draft text, excerpts, citations, gap findings, and answers to questions about your corpus
Never happens:
- Source files uploaded through the client application
- Our prompts exposed to the client application in any form
- Anything written back into your SharePoint, OneDrive, or Drive
Once our output is in the client application, it is part of your conversation with that provider and is governed by your agreement with them. We are not affiliated with Anthropic and have no partnership with them. Your Claude subscription, your organization's administrative controls over connectors, and your conversation history with Claude are matters between you and that provider.
9. Who we share information with
We do not sell personal information and we do not share it for cross-context behavioral advertising.
We share information with service providers who process it on our behalf, under contract, for the purposes described in this policy:
- Cloud infrastructure and hosting, including compute, storage, database, content delivery, queueing, secrets management, and logging, in the United States
- Our identity provider, for authentication and single sign-on
- Our large language model provider, which receives document text for extraction and drafting, under a data processing agreement that prohibits training on that text
- Our payment processor, for connector subscriptions
- Business software we use to run the company, including productivity and collaboration tools, customer relationship management, accounting, and email
- Business data providers and lead generation agencies, in relation to prospect information only
We also disclose information where we are legally required to, where it is necessary to establish or defend a legal claim, or to protect the rights and safety of Indago, our customers, or the public. If Indago is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this policy.
A current list of the sub-processors used to deliver the platform is available on request from privacy@indago.bio. Customers under a signed agreement will be notified of material changes to that list.
10. Security
Our security program is built around isolation, least privilege, and encryption.
- All traffic between your browser and the platform is encrypted in transit using TLS 1.2 or higher. Plain HTTP is redirected.
- Documents and database records are encrypted at rest using AES-256 through our cloud provider's managed encryption services.
- Application servers, workers, and the database sit in private network segments with no public addresses. There is a single encrypted entry point from the internet.
- Each customer's records are held in a dedicated database schema, and cross-tenant reads are refused by the database engine itself rather than by application code. Each customer's documents are stored under a separate prefix in object storage.
- Credentials and API keys are held in a managed secrets service and injected at runtime. They are never stored in code or in container images.
- Access to the platform is authenticated and governed by role-based permissions. Multi-factor authentication is required for internal administrative access, and internal access follows the principle of least privilege.
- Document downloads are served through short-lived, single-object links. The underlying storage stays private.
- Infrastructure is defined as code and changes go through review. Container images are scanned for known vulnerabilities on every build, and static and dependency analysis run in our build pipeline.
No system is perfectly secure, and we do not claim otherwise. If you believe you have found a vulnerability, report it to privacy@indago.bio.
11. How long we keep information
Customer Content on the platform is retained for the duration of the subscription. Once a subscription lapses or is terminated, Customer Content is deleted 90 days later, which leaves time to take a final export. Deletion can be carried out earlier at your request, and a written certification of deletion is available on request. Where a signed customer agreement sets a different period, that agreement governs.
Customer Content associated with an IRDA account, including the processed corpus, the index, and derived drafts, is deleted 90 days after the subscription lapses, is terminated, or the account goes idle. You are warned before that happens. A single tool call deletes your corpus, its index, and the derived data on demand at any time.
Account Data is kept while the account is active and for a reasonable period afterwards to handle disputes and meet legal obligations.
Usage Data is kept for billing, security, and capacity purposes. Application logs are retained on a 30-day cycle. Encrypted database backups are retained on a 7-day cycle, which means deleted records may persist in backups for up to that period before ageing out.
Prospect and sales information is kept while there is a legitimate business interest in the relationship, and is deleted on request.
Billing, tax, and accounting records are retained for the periods required by law.
12. Your rights and choices
Depending on where you live, you may have the right to ask us to give you a copy of the personal information we hold about you, correct it, delete it, restrict or object to how we use it, or receive it in a portable format. You may also have the right not to be treated differently for exercising these rights.
To make a request, write to privacy@indago.bio. We will verify your identity before acting, and we will respond within the period required by applicable law. There is no charge for a reasonable request.
If your information sits inside an Indago customer's workspace, we will refer your request to that customer, who decides how their workspace is handled. We will assist them in responding.
You can opt out of commercial email at any time using the link in the message or by writing to privacy@indago.bio. We will still send you messages about your account and the service.
13. Cookies and similar technologies
The Indago platform uses cookies that are necessary to sign you in and keep your session secure. These cannot be turned off without breaking access to the product.
The marketing website sets only the basic cookies needed to serve pages and to protect our forms from automated abuse. We do not run advertising or tracking pixels on it, and we do not load third-party marketing tags.
We do not use advertising cookies and we do not allow third parties to track you across other sites through our properties.
14. Where information is processed
Indago operates in the United States and our infrastructure is hosted in a United States region. If you access the service from outside the United States, your information will be transferred to and processed in the United States, where data protection law differs from that of your own country. Where a transfer requires a lawful mechanism, we put appropriate contractual safeguards in place, and customers can request them from privacy@indago.bio.
15. Children
Indago is a business product. It is not directed at children, and we do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it.
16. Changes to this policy
We may update this policy as the product, the law, or our practices change. When we do, we will revise the version number and the last updated date at the top and publish the new version at this address. If a change materially affects how we handle personal information, we will give notice through the product or by email before it takes effect.
Where a customer is under a signed agreement, changes to this policy do not alter the terms of that agreement for its current term.
17. How to reach us
Indago, Inc.
254 Chapman Rd, Ste 208 #27568, Newark, DE 19702
Privacy and security enquiries: privacy@indago.bio
General: hello@indago.bio