Who we are
This policy explains how [YOUR FULL LEGAL NAME], a sole proprietorship established under the laws of India, trading as “Imitation Engine” (“we”, “us”), handles personal data. We are the data controller (the Data Fiduciary under India’s Digital Personal Data Protection Act, 2023) for the data described here.
- Place of business: [STREET ADDRESS], [AREA], [CITY], [STATE] [PIN], India
- Privacy contact: legal@imitationengine.com
It covers imitationengine.com, the dashboard, the documentation, our API and the Imitation Engine plugin for Claude Code. It does not cover Anthropic’s handling of your Claude Code usage, Razorpay’s handling of your payment details, or any third-party website you choose to clone — each has its own policy and its own controller.
What never reaches us
Start here, because it removes most of the questions people expect this page to answer. The plugin executes inside your own Claude Code session, on your own machine, over your own network. Our API is a thin bookkeeping surface, and the following never leaves your computer:
- the content of any page you crawl — no HTML, no DOM dumps, no computed styles, no screenshots, no downloaded assets;
- the code we generate — components, pages, Tailwind classes, test specs, diffs and reports all stay in your working directory;
- any credentials, cookies, headers or sessions you supply to reach a gated target;
- your own source code, repositories, file paths, environment variables or local configuration;
- your Claude Code conversations, prompts or model output — those are between you and Anthropic;
- the personal data of a target site’s users that may appear on a page you crawl.
Consequence
Because we never receive it, we cannot search it, disclose it, restore it, hand it to a regulator, or lose it in a breach of our systems. It also means we cannot recover it for you — your local artefacts are yours to back up.
What we collect
The complete inventory. Everything in the first column exists in a database table or a provider’s console, and nothing outside this table is collected by us.
| Category | Fields | Source |
|---|---|---|
| Account | Email address, internal user id, authentication method (Google sign-in or email one-time link), sign-up and last sign-in timestamps | You, at sign-up |
| Authentication security | IP address, user agent and session records kept by our authentication provider for sign-in security | Automatic, your browser |
| Subscription | Plan, billing period, status, amount and currency, trial flag, period start and end, cancellation date, count of successful charges, and the Razorpay subscription, customer, plan and payment identifiers | You and Razorpay |
| Plugin credential | A SHA-256 hash of your plugin token, its short display prefix, creation, last-used and revocation timestamps. The token itself is shown once and never stored | Generated on request |
| Machine identifier | A truncated one-way hash of your device hostname and operating-system username, sent as the x-ie-client header, used to cap how many machines share one token | The plugin |
| Projects | Project name, root URL, status, discovered page hierarchy (paths and titles of the site you chose to crawl), your page selection, page counters, run timestamps | The plugin and your dashboard actions |
| Usage ledger | One append-only row per metered command: command name, units, plan, metering window, project and token reference, timestamp | Automatic, on each command |
| API request log | Route, HTTP status, machine identifier, timestamp for each API call — the basis for rate limiting and abuse detection | Automatic, on each request |
| Support correspondence | Your emails to us and our replies, including anything you choose to paste into them | You |
| Server logs | Standard web-server request logs held transiently by our hosting provider | Automatic |
A note on project URLs
A root URL and a page hierarchy are normally corporate rather than personal data — but they do reveal what you are working on, and in unusual cases a URL can contain personal data. Treat the Project name and URL as visible to us, keep credentials and personal identifiers out of them, and delete a Project when you no longer need it.
Why we use it, and on what legal basis
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and run your account, authenticate you, and give you the dashboard | Account, authentication security | Performance of our contract with you |
| Take payment, manage renewals, handle failures, refunds and cancellations | Account, subscription | Performance of contract; legal obligation for tax and accounting records |
| Authenticate the plugin and enforce your plan’s allowances | Plugin credential, usage ledger, subscription | Performance of contract |
| Enforce one subscription per person, detect seat sharing, rate-limit and prevent abuse | Machine identifier, API request log, plugin credential | Legitimate interests — protecting the service and our revenue against misuse |
| Show you your projects, page hierarchies and usage figures | Projects, usage ledger | Performance of contract |
| Provide support and answer your questions | Support correspondence, account, projects | Performance of contract; legitimate interests |
| Keep the service secure, investigate incidents, debug faults | API request log, server logs, account | Legitimate interests; legal obligation where a breach is reportable |
| Understand aggregate usage to decide what to build | Aggregated and de-identified usage data | Legitimate interests |
| Send service and billing notices you cannot opt out of (renewal failures, security, changes to terms) | Account, subscription | Performance of contract; legal obligation |
| Send product news, if you have asked for it | Account | Consent — withdrawable at any time |
| Comply with law, respond to lawful requests, establish or defend legal claims | Any of the above, as strictly necessary | Legal obligation; legitimate interests |
We do not train on your data
We do not use your projects, page hierarchies, usage data or support correspondence to train, fine-tune or evaluate any machine-learning model, and we do not supply them to anyone else for that purpose.
Who processes it for us
We are a small operation and rely on established providers. Each acts as our processor (or, for payments, as an independent controller of its own records) under a written agreement, and each is engaged only for the purpose shown.
| Provider | Role | Data it sees | Primary location |
|---|---|---|---|
| Supabase | Managed Postgres database and authentication | Everything in the inventory above except payment instruments | Region we selected; group entities in the US and EU |
| Razorpay Software Private Limited | Payments, subscriptions and mandates | Your name, email, contact details and payment instrument; subscription and transaction records | India |
| Vercel | Hosting of the website, dashboard and API | Request metadata and transient server logs | Global edge; United States |
| Email delivery and support inbox provider | Transactional email and correspondence | Your email address and the content of messages | United States or EU |
Anthropic is not on this list. Claude Code is your own relationship with Anthropic — we send it nothing and receive nothing from it.
International transfers
We operate from India and use providers with infrastructure in India, the European Economic Area and the United States, so your data may be transferred to and processed in countries other than your own, including ones whose laws differ from yours.
- For transfers out of the EEA or the UK we rely on the European Commission’s Standard Contractual Clauses (with the UK Addendum or the UK IDTA as applicable), on an adequacy decision where one covers the destination, or on our provider’s own approved transfer mechanism.
- For transfers from India, we transfer only to countries not restricted by the Central Government under section 16 of the DPDP Act, and we review that list when it changes.
- Contact legal@imitationengine.com for a copy of the relevant safeguards, redacted as necessary for commercial confidentiality.
How long we keep it
| Data | Retention |
|---|---|
| Account and subscription record | While your account exists; deleted or anonymised within 30 days of account deletion, except where a financial record must be kept |
| Billing and tax records | Up to 8 years from the end of the relevant financial year, as required by Indian tax and accounting law — this obligation overrides a deletion request |
| Projects, page hierarchies and selections | Until you delete the project, or within 30 days of account deletion |
| Usage ledger | Retained with billing records, since it evidences what was charged and enforced |
| Plugin token hashes | While active; revoked tokens and their metadata kept up to 12 months for security investigation |
| API request log | Up to 12 months, then deleted or aggregated — it powers rate limiting and abuse detection |
| Support correspondence | Up to 24 months from the last message in the thread |
| Server logs | As held transiently by our hosting provider, typically days to weeks |
| Anything under legal hold | For as long as a claim, investigation or dispute reasonably requires, then deleted |
Security
Measures we take are described on the Security page: TLS in transit, encryption at rest by our providers, row-level isolation so one account cannot read another’s data, plugin tokens stored only as hashes, server-side authorisation on every API route, request and machine limits, and secrets held outside the codebase — the plugin itself contains none.
Important
No system is perfectly secure. We cannot and do not guarantee that your data will never be accessed, altered, disclosed or destroyed by an unauthorised party, and we accept no liability for a security incident beyond what the law requires of us and what the Terms of Service permit. Protecting your own credentials, plugin token and device is your responsibility.
Your rights, and how to use them
Wherever you live, you can ask us to do the following, and we apply these to everyone rather than only where a law compels it:
- Access — get a copy of the personal data we hold about you and a summary of how it is processed.
- Correct — have inaccurate or incomplete data fixed or completed.
- Delete — have your account and its data erased, subject to records we must keep for tax, accounting or legal-defence reasons.
- Port — receive the data you gave us in a structured, machine-readable format.
- Object or restrict — object to processing based on legitimate interests, or ask us to pause processing while a dispute about it is resolved.
- Withdraw consent — for anything we do on the basis of consent, without affecting what was lawful before.
- Complain — to us first, and to your supervisory or data protection authority in any case.
Write to legal@imitationengine.com from the email address on your account. We respond within 30 days, and will tell you if we need longer for a complex request. We may ask you to verify your identity — we will not disclose data to someone who might not be you. There is no charge unless a request is manifestly unfounded or repetitive, and we will never treat you worse for making one.
In plain English
Most of it you can do yourself: your email and projects are editable in the dashboard, tokens can be regenerated or left revoked, and cancelling ends future billing. Email us for a full export or a complete deletion.
If you are in India — the DPDP Act, 2023
- We are the Data Fiduciary; you are the Data Principal. We process your data for the lawful purpose of providing the service you asked for, and for the additional purposes set out above.
- You have the right to access a summary of your data and our processing, to correction and completion, to erasure, to grievance redressal, and to nominate another individual to exercise your rights if you die or become incapacitated. To nominate someone, email us their name and contact details.
- Where we rely on consent, you may withdraw it at any time with the same ease as you gave it, by emailing legal@imitationengine.com. We will stop processing on that basis and erase the data unless a law requires us to keep it.
- You are expected to give accurate information and not to make a false or frivolous grievance or request — the Act contemplates penalties for doing so.
- Our Grievance Officer is reachable at legal@imitationengine.com and at the postal address in Contact and grievances. If you are not satisfied with our response you may complain to the Data Protection Board of India.
- This page also serves as our privacy notice under Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
If you are in the EEA, UK or Switzerland
- We are the controller for the processing described here. Our legal bases are in the table under Why we use it: mostly performance of a contract, with legitimate interests for security, anti-abuse and seat enforcement, legal obligation for financial records, and consent for optional product email.
- Where we rely on legitimate interests we have balanced them against your rights, and we will share our assessment on request. You may object at any time.
- You have the rights in Your rights, including the rights under Articles 15 to 22 UK/EU GDPR, and the right to lodge a complaint with your national supervisory authority — for example the Irish Data Protection Commission or the UK Information Commissioner’s Office. You may do so without contacting us first, though we would rather you gave us a chance to fix it.
- We do not carry out automated decision-making producing legal effects or similarly significant effects on you. Quota enforcement is a deterministic contractual limit on a paid feature, not a decision about you.
- Providing your email and payment details is necessary to enter into the contract; without them we cannot give you an account.
- Transfers are covered in International transfers. We are established in India and have not appointed an Article 27 representative; if that becomes required we will name one here.
If you are in California or another US state
This section addresses the CCPA as amended by the CPRA, and reads across to comparable laws in Colorado, Connecticut, Virginia, Utah, Texas and other states with equivalent rights.
- Categories we collect. Identifiers (email, account and machine identifiers, IP address), commercial information (subscription and transaction records), internet or network activity (API request logs, server logs), and your own correspondence. Sources, purposes and disclosures are in the tables above.
- No sale, no sharing. We have not sold personal information, and have not shared it for cross-context behavioural advertising, in the preceding 12 months or ever. We therefore offer no “Do Not Sell or Share My Personal Information” link, because there is nothing to opt out of.
- Sensitive personal information. We do not collect it, do not infer characteristics from it, and do not use or disclose it beyond what the law permits without a right to limit.
- Your rights. To know, access and receive a portable copy; to correct; to delete; to limit use of sensitive information (not applicable, as above); to opt out of sale or sharing (not applicable); and not to be discriminated against for exercising any of them.
- How to exercise them. Email legal@imitationengine.com. We verify requests against your account email. An authorised agent may act for you with written permission we can verify.
- Shine the Light. We do not disclose personal information to third parties for their direct marketing purposes.
Data you process yourself
When the plugin crawls a target site, it may encounter personal data on those pages — names in testimonials, avatars, comments, an author byline, data behind a login you used. That processing happens on your machine, under your control, for your purposes.
Important
For that data you are the controller and we are not a processor of it, because we never receive it. You alone are responsible for having a lawful basis, for honouring the rights of those individuals, for minimising and deleting what you do not need, and for any notification obligation if it leaks from your systems. Your indemnity in the Terms of Service covers claims arising from it.
Practical advice: crawl staging or seeded environments where you can, strip personal data from the output before it enters a training pipeline, and never point the plugin at a page showing someone else’s account.
Children
The service is for professional developers and is not directed to anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, write to legal@imitationengine.com and we will delete it. Do not use the plugin to clone services aimed at children — see the Acceptable Use Policy.
Breach notification
If a personal data breach affecting you occurs in our systems, we will notify the relevant authority and affected individuals within the timeframes the applicable law requires — including the Data Protection Board of India under the DPDP Act, CERT-In where its directions apply, and supervisory authorities within 72 hours under the GDPR where the threshold is met. Notification is not an admission of fault or liability.
Changes to this policy
We update this page as the product and our providers change. The current version and its effective date are always at the top. For a change that materially reduces your protections or expands our use of your data, we will give notice by email or in the dashboard at least 14 days beforehand and, where consent is required, ask for it. Continued use after the effective date is acceptance of the updated policy.
Contact and grievances
- Privacy, data requests, grievances and security reports: legal@imitationengine.com — begin your message with the subject so it is triaged correctly
- Grievance Officer and Data Protection contact: [YOUR FULL LEGAL NAME], [STREET ADDRESS], [AREA], [CITY], [STATE] [PIN], India
Include the email address on your account and enough detail to identify the request. Acknowledgement within 72 hours, substantive response within 30 days. Escalation routes: the Data Protection Board of India, your EEA or UK supervisory authority, or your state Attorney General, as applicable to you. For requests about the plugin’s local behaviour, note the constraint in What never reaches us — we cannot return data we never received.
Questions about this document? Write to legal@imitationengine.com. This page is provided for transparency and does not constitute legal advice.