Innov8iveLabs / Privacy

Privacy Policy

What we collect, why, and how to make us stop.

Effective 2026-08-19

Who we are

Innov8ive Labs, LLC, an Ohio limited liability company trading as Innov8iveLabs, is an independent software studio operated by Jonathan Poeder. We are the controller of the personal information described here.

c/o United States Corporation Agents, Inc., 1991 Crocker Road #600-755, Westlake, OH 44145, USA
contact+privacy@i8l.tech

What this covers

This is our single privacy policy. It applies to i8l.tech, every product site and app under it, and the studio's internal operations tools. That includes valid8 (formerly clipcleared), gener8, investig8, memsync, lodestar and ClickPad.

Each product's terms page carries a short schedule saying what that product stores and for how long. A schedule adds detail to this policy rather than replacing it. Where a product is supplied under a separate signed agreement, that agreement governs the data handled inside it.

If you visit the website

We use Cloudflare Web Analytics. It is cookieless. It does not fingerprint you, does not follow you across other sites, and does not build a profile. It reports aggregates: page views, referrers, broad country and device category.

Our host, Cloudflare, processes standard request data such as IP address and user agent to serve pages and to defend against abuse. That is a normal part of running a website and is retained only briefly.

We also keep a count of visits by place, because Cloudflare's analytics reports no detail below the country. When a request reaches us, we look its IP address up in a city database held as a file on our own server, and we keep only what that lookup returns: country, region, city, and a coordinate rounded to roughly a kilometre, which is the centre of a town rather than a location. Those are stored as daily totals per place, so a row says eleven visits from Chicago on this date. No row describes one visit or one person.

What this specifically does not do

The IP address itself is never written to disk. It is used for the lookup and discarded in the same breath. The lookup happens on our hardware against a local file, so no third party is asked who you are, and nothing about your visit leaves our server. There is no identifier, no cookie and no profile involved, and because only totals are kept there is nothing to single you out from.

What we do not do

No advertising trackers. No third-party ad networks. No social pixels. No selling, renting or licensing of personal information, to anyone, ever. No cross-site tracking.

If you email us

Mail to our addresses reaches a mailbox hosted by Zoho. We keep correspondence so that we can reply and keep an accurate record of what was agreed.

Some of our addresses carry a tag, such as contact+gener8@i8l.tech. That tells us which page you wrote from. It is used for routing, not for profiling.

If you hold an account

Some products, memsync among them, are open to public sign-up. For those we store your email address, a hash of your password (scrypt, so we never hold the password itself), the API tokens issued to your machines, and your display preferences such as timezone and clock format. We use it to run your account and to email you about it: verification, password resets, and notices about your subscription.

When you sign in, a session cookie is set purely to keep you signed in. It carries no analytics and is not used for tracking.

Whatever you then store in a product is yours. In memsync's case each account's data lives in its own separate database file, not in a shared table keyed by customer, so one account's content is not reachable from another's. Our other portals remain single-operator and passcode protected.

If you pay us

Card payments are processed by Stripe. Your card number never reaches our servers and we never store it. We keep the Stripe customer and subscription identifiers, and the status of your subscription, because billing does not work without them. Purchases made inside an iOS app are processed by Apple under Apple's own terms and we receive only the fact of the purchase.

Business contact information we collect for outreach

This is the part most policies bury, so it is stated plainly.

We identify companies that may be a fit for our products and collect business contact information about the relevant people at them: name, role, employer, business email address, and links to publicly posted company pages. We collect this from publicly accessible sources. We do not collect it from private groups, we do not buy contact lists, and we do not scrape platforms whose terms forbid it.

We use it for one purpose: to contact you once, from a named human, about whether a specific product is relevant to your work. Our basis for this is our legitimate interest in reaching potential business customers, balanced against a genuinely low impact on you.

Who can see it

Only Jonathan Poeder. It is not shared with, sold to, or licensed to any other party.

How to stop it

Every message we send identifies who we are and offers a way to opt out. Ask, in any form and in any words, and we will add you to a permanent suppression list and not contact you again. We keep the minimum record needed to honour that, which is the point of it. Write to contact+privacy@i8l.tech and we will also delete what we hold if you would rather we did that.

Who processes data on our behalf

  • Cloudflare: hosting, content delivery, and the cookieless analytics described above.
  • Zoho: email hosting for our mailboxes.
  • Anthropic: AI models we use to draft and review content. Where our research tools summarise a company, the business contact information described above may be processed by these models to produce that summary.
  • Stripe: payment processing and the billing portal for paid subscriptions. Stripe is the controller of your card details, which we never see.
  • Apple: distribution of our iOS apps and, where an app sells a subscription, the purchase itself.

Each of these acts on our instructions. None of them is permitted to use your information for their own purposes.

The city database used for the visit counts described above is deliberately not on this list. It is a file we hold, not a service we call, so no data about you reaches its publisher. It is DB-IP City Lite, used under CC BY 4.0.

How long we keep things

  • Analytics: aggregate only, and never tied to you.
  • Correspondence: for as long as the relationship or a legal or accounting obligation requires, then deleted.
  • Business contact information: deleted when it is no longer relevant, or immediately on request.
  • Suppression entries: kept indefinitely, deliberately. Deleting them would mean we could contact you again by mistake.
  • Account and product data: for as long as the account is open. After a subscription ends we keep it for 30 days so you can return or export it, warn you by email before the deadline, and then delete it. Ask us to delete it sooner and we will.
  • Billing records: kept as long as tax and accounting law requires, which is longer than the account itself.

Your rights

Ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, or tell us to stop contacting you. One email does all of these: contact+privacy@i8l.tech. We do not require a particular form of words and we will not make you create an account to ask.

Depending on where you live you may have further rights under laws such as the GDPR or the CCPA, including the right to complain to a supervisory authority. We have never sold personal information and have no plans to.

Children

Our products are business tools. They are not directed at children and we do not knowingly collect information from anyone under 16.

Changes

If this policy changes materially we will change the effective date at the top and, where we hold your address and the change affects you, tell you directly.