Invistant
Privacy Policy
Last updated August 29, 2026
Effective date: July 31, 2026
Operator: Invistant (Richet / Invistant service) — contact via Talk to us or the email on your account communications.
Governing region: Alberta, Canada
This is a product-accurate policy for Invistant. Have counsel review before charging customers at scale.
1. Our promise: we do not sell or rent your data
We do not sell your personal information or your workspace content (job notes, photos, attached documents, search indexes, or Ask answers).
We do not share your personal information or workspace content with third parties for their advertising, marketing, or data-brokerage purposes.
We use your data only to operate and improve Invistant for you, to secure the service, to bill you, to communicate about the service, and to comply with law.
2. What Invistant is
Invistant is a browser application for field and service teams. You capture job notes, photos, and documents attached to jobs; ask questions across that workspace; and open cited sources to verify answers before you rely on them.
Some existing workspaces may also use the optional desktop agent Hoover to index live files on computers or network shares. Hoover is a legacy connector for paired pilots — not part of the default self-serve path.
3. Information we process
- Account data: name, email, password hash, workspace name, and authentication/session tokens.
- Billing data: subscription status and Stripe customer/subscription identifiers. Card details are handled by Stripe; we do not store full card numbers.
- Job content: notes, photos, and AI-derived fields (for example complaint/cause/correction drafts and photo captions) that you create in the product.
- Hoover / library: file metadata, paths, content hashes, light text summaries/chunks for search, and cached Ask answers. Original drive/file bytes are not uploaded to our object storage; they stay on machines you control. When you Ask or view a file, relevant extracted text or bytes may be transmitted through our API temporarily so we can answer or display the file while your agent is online.
- Usage / support: selected product actions may be logged for security, abuse prevention, and support (for example pairing an agent, Ask events, billing changes).
- Device / technical: IP address, user agent, and similar logs generated by normal web hosting.
4. Subprocessors (service providers)
We use processors who help us run the service under contracts that restrict their use of your data to providing their service to us:
- Stripe — payments and billing portal
- Mailgun — transactional email (for example trial welcome, password reset)
- OpenAI — AI features when enabled (Ask answers, embeddings/search, note/photo analysis). Document extracts and prompts may be sent to OpenAI to generate results.
- Cloudflare R2 (or equivalent object storage) — storage of job photo/evidence blobs and similar service data
- Hosting providers — servers, databases, and backups for the Invistant application
These providers are not buyers of your data. They process it only as needed for Invistant.
5. How we use information
- Provide, secure, and maintain the product
- Authenticate users and enforce trial/subscription access
- Generate search indexes and AI-assisted answers you request
- Send service emails you need (resets, trial, billing-related notices)
- Detect abuse, debug incidents, and fulfill legal obligations
6. Legal bases / consent (Canada)
We process personal information as needed to provide the service you request, to manage our business relationship, and where required by law. Where consent is required, you provide it by creating an account and using the service after reviewing this Policy and our Terms.
7. Workspace isolation
We design Invistant so each customer workspace’s content is kept separate from other customers’ workspaces through application-level access controls. No system is perfect; report suspected access issues immediately.
8. Retention, export, and deletion
We retain account and workspace data while your account is active and for a reasonable period afterward for backups, disputes, and legal requirements. You may request an export or deletion of your account/workspace data from the app (Account settings) or by contacting us. We will process verified requests within a reasonable time, subject to legal retention needs and backup cycles.
9. Cookies and analytics
We use cookies or local storage as needed for login sessions and the progressive web app. Marketing analytics (for example Plausible) is off unless we explicitly enable it; if enabled, we will update this Policy.
10. Security
We use industry-reasonable measures (encrypted transport, hashed passwords, access controls, backups). No method of transmission or storage is 100% secure. See also our Security page.
11. Children
Invistant is for business use. It is not directed to children under 13 (or the equivalent minimum age in your jurisdiction).
12. International processing
Your information may be processed in Canada and in other countries where our subprocessors operate (including the United States). Those countries may have different privacy laws than yours.
13. Changes
We may update this Policy. We will change the effective date above and, for material changes, provide additional notice (for example email or in-product notice) when appropriate.
14. Contact
Privacy questions or requests: use Talk to us or reply to an Invistant service email. Include enough detail for us to verify the account.