Imitation Engine

Legal

Privacy Policy.

Imitation Engine holds strikingly little about you, and that is architectural rather than aspirational: the plugin runs on your machine, so the pages it crawls and the code it writes never touch our servers. What we do hold is your email, your subscription state, your project names and URLs, and a usage ledger. This page accounts for all of it.

Effective
27 July 2026
Last updated
27 July 2026
Version
1.0

Who we are

This policy explains how [YOUR FULL LEGAL NAME], a sole proprietorship established under the laws of India, trading as “Imitation Engine” (“we”, “us”), handles personal data. We are the data controller (the Data Fiduciary under India’s Digital Personal Data Protection Act, 2023) for the data described here.

It covers imitationengine.com, the dashboard, the documentation, our API and the Imitation Engine plugin for Claude Code. It does not cover Anthropic’s handling of your Claude Code usage, Razorpay’s handling of your payment details, or any third-party website you choose to clone — each has its own policy and its own controller.

What never reaches us

Start here, because it removes most of the questions people expect this page to answer. The plugin executes inside your own Claude Code session, on your own machine, over your own network. Our API is a thin bookkeeping surface, and the following never leaves your computer:

  • the content of any page you crawl — no HTML, no DOM dumps, no computed styles, no screenshots, no downloaded assets;
  • the code we generate — components, pages, Tailwind classes, test specs, diffs and reports all stay in your working directory;
  • any credentials, cookies, headers or sessions you supply to reach a gated target;
  • your own source code, repositories, file paths, environment variables or local configuration;
  • your Claude Code conversations, prompts or model output — those are between you and Anthropic;
  • the personal data of a target site’s users that may appear on a page you crawl.

Consequence

Because we never receive it, we cannot search it, disclose it, restore it, hand it to a regulator, or lose it in a breach of our systems. It also means we cannot recover it for you — your local artefacts are yours to back up.

What we collect

The complete inventory. Everything in the first column exists in a database table or a provider’s console, and nothing outside this table is collected by us.

CategoryFieldsSource
AccountEmail address, internal user id, authentication method (Google sign-in or email one-time link), sign-up and last sign-in timestampsYou, at sign-up
Authentication securityIP address, user agent and session records kept by our authentication provider for sign-in securityAutomatic, your browser
SubscriptionPlan, billing period, status, amount and currency, trial flag, period start and end, cancellation date, count of successful charges, and the Razorpay subscription, customer, plan and payment identifiersYou and Razorpay
Plugin credentialA SHA-256 hash of your plugin token, its short display prefix, creation, last-used and revocation timestamps. The token itself is shown once and never storedGenerated on request
Machine identifierA truncated one-way hash of your device hostname and operating-system username, sent as the x-ie-client header, used to cap how many machines share one tokenThe plugin
ProjectsProject name, root URL, status, discovered page hierarchy (paths and titles of the site you chose to crawl), your page selection, page counters, run timestampsThe plugin and your dashboard actions
Usage ledgerOne append-only row per metered command: command name, units, plan, metering window, project and token reference, timestampAutomatic, on each command
API request logRoute, HTTP status, machine identifier, timestamp for each API call — the basis for rate limiting and abuse detectionAutomatic, on each request
Support correspondenceYour emails to us and our replies, including anything you choose to paste into themYou
Server logsStandard web-server request logs held transiently by our hosting providerAutomatic
We do not collect card or bank details, government identifiers, location data, biometrics, advertising identifiers or any special-category data, and we do not buy personal data from anyone.

A note on project URLs

A root URL and a page hierarchy are normally corporate rather than personal data — but they do reveal what you are working on, and in unusual cases a URL can contain personal data. Treat the Project name and URL as visible to us, keep credentials and personal identifiers out of them, and delete a Project when you no longer need it.

Why we use it, and on what legal basis

PurposeData usedLegal basis
Create and run your account, authenticate you, and give you the dashboardAccount, authentication securityPerformance of our contract with you
Take payment, manage renewals, handle failures, refunds and cancellationsAccount, subscriptionPerformance of contract; legal obligation for tax and accounting records
Authenticate the plugin and enforce your plan’s allowancesPlugin credential, usage ledger, subscriptionPerformance of contract
Enforce one subscription per person, detect seat sharing, rate-limit and prevent abuseMachine identifier, API request log, plugin credentialLegitimate interests — protecting the service and our revenue against misuse
Show you your projects, page hierarchies and usage figuresProjects, usage ledgerPerformance of contract
Provide support and answer your questionsSupport correspondence, account, projectsPerformance of contract; legitimate interests
Keep the service secure, investigate incidents, debug faultsAPI request log, server logs, accountLegitimate interests; legal obligation where a breach is reportable
Understand aggregate usage to decide what to buildAggregated and de-identified usage dataLegitimate interests
Send service and billing notices you cannot opt out of (renewal failures, security, changes to terms)Account, subscriptionPerformance of contract; legal obligation
Send product news, if you have asked for itAccountConsent — withdrawable at any time
Comply with law, respond to lawful requests, establish or defend legal claimsAny of the above, as strictly necessaryLegal obligation; legitimate interests

We do not train on your data

We do not use your projects, page hierarchies, usage data or support correspondence to train, fine-tune or evaluate any machine-learning model, and we do not supply them to anyone else for that purpose.

Cookies and tracking

  • Authentication cookies. Strictly necessary. Set by our authentication provider to keep you signed in and to protect the session. Blocking them means you cannot log in.
  • Theme preference. A small entry in your browser’s local storage remembering light or dark mode. Never leaves your browser.
  • Payment cookies. Razorpay Checkout sets its own cookies during payment, for fraud prevention and to complete the transaction, governed by Razorpay’s privacy policy.

We run no advertising, marketing, profiling or cross-site tracking cookies, no third-party analytics, no session recording, no heatmaps and no advertising pixels. Because we only use strictly necessary cookies, no consent banner is required. If we ever add analytics we will update this page first and, where the law requires consent, ask for it before setting anything.

We honour Global Privacy Control and Do Not Track signals in the sense that there is nothing for them to switch off — we do not track you across sites in the first place.

Who processes it for us

We are a small operation and rely on established providers. Each acts as our processor (or, for payments, as an independent controller of its own records) under a written agreement, and each is engaged only for the purpose shown.

ProviderRoleData it seesPrimary location
SupabaseManaged Postgres database and authenticationEverything in the inventory above except payment instrumentsRegion we selected; group entities in the US and EU
Razorpay Software Private LimitedPayments, subscriptions and mandatesYour name, email, contact details and payment instrument; subscription and transaction recordsIndia
VercelHosting of the website, dashboard and APIRequest metadata and transient server logsGlobal edge; United States
Email delivery and support inbox providerTransactional email and correspondenceYour email address and the content of messagesUnited States or EU
Sub-processors change as infrastructure changes. This table is kept current; material additions are announced on this page.

Anthropic is not on this list. Claude Code is your own relationship with Anthropic — we send it nothing and receive nothing from it.

Disclosure, and no sale of data

Important

WE DO NOT SELL PERSONAL DATA. WE DO NOT SHARE IT FOR CROSS-CONTEXT BEHAVIOURAL ADVERTISING. WE DO NOT RENT, TRADE OR MONETISE IT IN ANY FORM, AND WE HAVE NEVER DONE SO.

We disclose personal data only:

  • to the processors listed above, for the purposes listed;
  • where you ask us to, or direct us to (for example, telling us to discuss your account with a colleague);
  • to our professional advisers — accountant, lawyer, auditor — under confidentiality;
  • where required by law, a court, a regulator, a tax authority or valid legal process; we will tell you unless we are prohibited from doing so;
  • to establish, exercise or defend legal claims, including passing the relevant facts to a complainant or an insurer;
  • to a buyer or successor if the business, or the part of it running this service, is sold, merged or reorganised — in which case this policy continues to apply to data transferred until the acquirer publishes its own, and we will notify you by email or on the site;
  • in aggregated or de-identified form that cannot reasonably identify you.

International transfers

We operate from India and use providers with infrastructure in India, the European Economic Area and the United States, so your data may be transferred to and processed in countries other than your own, including ones whose laws differ from yours.

  • For transfers out of the EEA or the UK we rely on the European Commission’s Standard Contractual Clauses (with the UK Addendum or the UK IDTA as applicable), on an adequacy decision where one covers the destination, or on our provider’s own approved transfer mechanism.
  • For transfers from India, we transfer only to countries not restricted by the Central Government under section 16 of the DPDP Act, and we review that list when it changes.
  • Contact legal@imitationengine.com for a copy of the relevant safeguards, redacted as necessary for commercial confidentiality.

How long we keep it

DataRetention
Account and subscription recordWhile your account exists; deleted or anonymised within 30 days of account deletion, except where a financial record must be kept
Billing and tax recordsUp to 8 years from the end of the relevant financial year, as required by Indian tax and accounting law — this obligation overrides a deletion request
Projects, page hierarchies and selectionsUntil you delete the project, or within 30 days of account deletion
Usage ledgerRetained with billing records, since it evidences what was charged and enforced
Plugin token hashesWhile active; revoked tokens and their metadata kept up to 12 months for security investigation
API request logUp to 12 months, then deleted or aggregated — it powers rate limiting and abuse detection
Support correspondenceUp to 24 months from the last message in the thread
Server logsAs held transiently by our hosting provider, typically days to weeks
Anything under legal holdFor as long as a claim, investigation or dispute reasonably requires, then deleted

Security

Measures we take are described on the Security page: TLS in transit, encryption at rest by our providers, row-level isolation so one account cannot read another’s data, plugin tokens stored only as hashes, server-side authorisation on every API route, request and machine limits, and secrets held outside the codebase — the plugin itself contains none.

Important

No system is perfectly secure. We cannot and do not guarantee that your data will never be accessed, altered, disclosed or destroyed by an unauthorised party, and we accept no liability for a security incident beyond what the law requires of us and what the Terms of Service permit. Protecting your own credentials, plugin token and device is your responsibility.

Your rights, and how to use them

Wherever you live, you can ask us to do the following, and we apply these to everyone rather than only where a law compels it:

  • Access — get a copy of the personal data we hold about you and a summary of how it is processed.
  • Correct — have inaccurate or incomplete data fixed or completed.
  • Delete — have your account and its data erased, subject to records we must keep for tax, accounting or legal-defence reasons.
  • Port — receive the data you gave us in a structured, machine-readable format.
  • Object or restrict — object to processing based on legitimate interests, or ask us to pause processing while a dispute about it is resolved.
  • Withdraw consent — for anything we do on the basis of consent, without affecting what was lawful before.
  • Complain — to us first, and to your supervisory or data protection authority in any case.

Write to legal@imitationengine.com from the email address on your account. We respond within 30 days, and will tell you if we need longer for a complex request. We may ask you to verify your identity — we will not disclose data to someone who might not be you. There is no charge unless a request is manifestly unfounded or repetitive, and we will never treat you worse for making one.

In plain English

Most of it you can do yourself: your email and projects are editable in the dashboard, tokens can be regenerated or left revoked, and cancelling ends future billing. Email us for a full export or a complete deletion.

If you are in India — the DPDP Act, 2023

  • We are the Data Fiduciary; you are the Data Principal. We process your data for the lawful purpose of providing the service you asked for, and for the additional purposes set out above.
  • You have the right to access a summary of your data and our processing, to correction and completion, to erasure, to grievance redressal, and to nominate another individual to exercise your rights if you die or become incapacitated. To nominate someone, email us their name and contact details.
  • Where we rely on consent, you may withdraw it at any time with the same ease as you gave it, by emailing legal@imitationengine.com. We will stop processing on that basis and erase the data unless a law requires us to keep it.
  • You are expected to give accurate information and not to make a false or frivolous grievance or request — the Act contemplates penalties for doing so.
  • Our Grievance Officer is reachable at legal@imitationengine.com and at the postal address in Contact and grievances. If you are not satisfied with our response you may complain to the Data Protection Board of India.
  • This page also serves as our privacy notice under Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

If you are in the EEA, UK or Switzerland

  • We are the controller for the processing described here. Our legal bases are in the table under Why we use it: mostly performance of a contract, with legitimate interests for security, anti-abuse and seat enforcement, legal obligation for financial records, and consent for optional product email.
  • Where we rely on legitimate interests we have balanced them against your rights, and we will share our assessment on request. You may object at any time.
  • You have the rights in Your rights, including the rights under Articles 15 to 22 UK/EU GDPR, and the right to lodge a complaint with your national supervisory authority — for example the Irish Data Protection Commission or the UK Information Commissioner’s Office. You may do so without contacting us first, though we would rather you gave us a chance to fix it.
  • We do not carry out automated decision-making producing legal effects or similarly significant effects on you. Quota enforcement is a deterministic contractual limit on a paid feature, not a decision about you.
  • Providing your email and payment details is necessary to enter into the contract; without them we cannot give you an account.
  • Transfers are covered in International transfers. We are established in India and have not appointed an Article 27 representative; if that becomes required we will name one here.

If you are in California or another US state

This section addresses the CCPA as amended by the CPRA, and reads across to comparable laws in Colorado, Connecticut, Virginia, Utah, Texas and other states with equivalent rights.

  • Categories we collect. Identifiers (email, account and machine identifiers, IP address), commercial information (subscription and transaction records), internet or network activity (API request logs, server logs), and your own correspondence. Sources, purposes and disclosures are in the tables above.
  • No sale, no sharing. We have not sold personal information, and have not shared it for cross-context behavioural advertising, in the preceding 12 months or ever. We therefore offer no “Do Not Sell or Share My Personal Information” link, because there is nothing to opt out of.
  • Sensitive personal information. We do not collect it, do not infer characteristics from it, and do not use or disclose it beyond what the law permits without a right to limit.
  • Your rights. To know, access and receive a portable copy; to correct; to delete; to limit use of sensitive information (not applicable, as above); to opt out of sale or sharing (not applicable); and not to be discriminated against for exercising any of them.
  • How to exercise them. Email legal@imitationengine.com. We verify requests against your account email. An authorised agent may act for you with written permission we can verify.
  • Shine the Light. We do not disclose personal information to third parties for their direct marketing purposes.

Data you process yourself

When the plugin crawls a target site, it may encounter personal data on those pages — names in testimonials, avatars, comments, an author byline, data behind a login you used. That processing happens on your machine, under your control, for your purposes.

Important

For that data you are the controller and we are not a processor of it, because we never receive it. You alone are responsible for having a lawful basis, for honouring the rights of those individuals, for minimising and deleting what you do not need, and for any notification obligation if it leaks from your systems. Your indemnity in the Terms of Service covers claims arising from it.

Practical advice: crawl staging or seeded environments where you can, strip personal data from the output before it enters a training pipeline, and never point the plugin at a page showing someone else’s account.

Children

The service is for professional developers and is not directed to anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, write to legal@imitationengine.com and we will delete it. Do not use the plugin to clone services aimed at children — see the Acceptable Use Policy.

Breach notification

If a personal data breach affecting you occurs in our systems, we will notify the relevant authority and affected individuals within the timeframes the applicable law requires — including the Data Protection Board of India under the DPDP Act, CERT-In where its directions apply, and supervisory authorities within 72 hours under the GDPR where the threshold is met. Notification is not an admission of fault or liability.

Changes to this policy

We update this page as the product and our providers change. The current version and its effective date are always at the top. For a change that materially reduces your protections or expands our use of your data, we will give notice by email or in the dashboard at least 14 days beforehand and, where consent is required, ask for it. Continued use after the effective date is acceptance of the updated policy.

Contact and grievances

  • Privacy, data requests, grievances and security reports: legal@imitationengine.com — begin your message with the subject so it is triaged correctly
  • Grievance Officer and Data Protection contact: [YOUR FULL LEGAL NAME], [STREET ADDRESS], [AREA], [CITY], [STATE] [PIN], India

Include the email address on your account and enough detail to identify the request. Acknowledgement within 72 hours, substantive response within 30 days. Escalation routes: the Data Protection Board of India, your EEA or UK supervisory authority, or your state Attorney General, as applicable to you. For requests about the plugin’s local behaviour, note the constraint in What never reaches us we cannot return data we never received.

Questions about this document? Write to legal@imitationengine.com. This page is provided for transparency and does not constitute legal advice.