Security and privacy
Client conversations are the most sensitive input a tool like this receives. This page states, plainly, how InkDraft handles that data. Every claim here is verifiable or has a link to the mechanism behind it.
Your transcripts never train AI models
All AI requests are routed through providers configured with explicit data-collection denial and zero-data-retention endpoints. This means your call transcripts, proposal content, and client data are processed for your request and then discarded at the model layer. They are not used for training, fine-tuning, or improving any AI model.
Passkey authentication
InkDraft supports passkey login, which means you can sign in with a fingerprint, face scan, or hardware key instead of a password. Passkeys are phishing-resistant by design: there is no password to steal, reuse, or brute-force. This is a stronger authentication posture than password-plus-2FA, and it is available today on every account.
Document access control
Workspace documents are accessible only to members of the organization that owns them. This is enforced in the application layer and backed by row-level security at the database. There is no shared-tenant data pool; workspace access is scoped per organization, and there is no path through the application that crosses that boundary.
Documents shared with clients use unguessable public tokens and, when enabled by the sender, access-code protection. Public links do not expose the sender's workspace and can be revoked or regenerated at any time.
Swiss-operated
InkDraft is built and operated by Hiestand Digital in Switzerland. Swiss data protection law (the FADP, revised 1 September 2023) applies to how the company processes personal data. EU and EEA customers are additionally covered by the GDPR through InkDraft's obligations as a data processor.
Application hosting runs on Vercel's infrastructure. The database is hosted by Supabase. Both providers' data processing terms are documented in the privacy policy.
What is not claimed
InkDraft does not currently claim that all data stays in Switzerland. Application hosting and database hosting use infrastructure that may route through or store data in other jurisdictions. This page will be updated if and when the hosting configuration changes to support a Switzerland-only data residency claim.
Encryption
All data in transit is encrypted via TLS. Database connections use TLS with certificate pinning. Data at rest is encrypted by the hosting provider at the storage layer. There is no application-layer encryption of document content at this time, as the regulatory requirements that would mandate it (HIPAA, PCI-DSS) do not apply to InkDraft's use case.
Payment security
Payment processing is handled entirely by Stripe. InkDraft never sees, stores, or has access to credit card numbers or bank account details. Stripe is PCI-DSS Level 1 certified.
Questions
Security questions reach a person directly at info@inkdraft.io. The full legal terms are in the privacy policy, the terms of service, and the data processing agreement.