Privacy Policy · Version 1.0 · Effective September 1, 2026

Privacy Policy

We collect the information needed to run and secure Infinite Ocean services, including Spyglass. We do not sell personal information, use it for cross-context behavioral advertising, or share SMS consent for marketing.

Who this policy covers

This Privacy Policy applies to Infinite Ocean, LLC websites, applications and services that link to it, including infiniteocean.net, its subdomains and Spyglass (together, the “Services”). Infinite Ocean, LLC, a North Carolina limited liability company, is responsible for the personal information described here. Contact us at privacy@infiniteocean.net.

When a business customer puts information about its employees, customers or other people into Spyglass, that customer controls why the information is used and Infinite Ocean generally processes it for the customer. Requests about that Customer Content should normally be directed to the customer that provided it. We remain responsible for account, billing, security, support and website information we control directly.

Information we collect

We collect account and contact information; authentication and security information such as passkey public credentials, phone number when SMS is selected, Google sign-in identifiers and login events; Customer Content deliberately submitted to the Services; usage and diagnostic records; Stripe-linked billing, tax and Affiliate records; support communications and audited support-inspection records; and public-site consent choices.

We receive information from you and your team, browsers and devices, integrations you authorize, identity and communications providers, payment providers, and sources you deliberately ask the Services to retrieve.

How we use information

We use information to provide and secure the Services; administer accounts and teams; deliver authentication codes and service messages; process subscriptions, taxes and Affiliate credits; run requested integrations and AI features; provide support; detect abuse and reliability problems; maintain audit evidence; comply with law; and improve the Services.

For people in the European Economic Area, United Kingdom or similar jurisdictions, our legal bases are performance of a contract, compliance with law, consent where requested, and our legitimate interests in securing, supporting and improving a business service. Consent may be withdrawn at any time without affecting earlier lawful processing.

AI features and analytics

Requested AI work may send relevant instructions and Customer Content to the configured model provider to produce a result, enforce limits, meter AI Token use and investigate failures. Models and providers may change as configurations evolve. Important legal, financial, employment, safety or regulatory decisions require qualified human review.

Necessary storage keeps the Services secure and makes signup and checkout work. Optional public-site analytics stays off until accepted. Raw analytics does not contain names, emails, user or team IDs, payment details, prompts, answers, documents, evidence, task content, full URLs, query strings or referring pages. Marketing tracking is not currently used.

How we disclose information

We disclose information only as needed to provide the Services: to hosting providers; Stripe for payments and taxes; identity providers such as Google when selected; communications and telecommunications providers; configured model providers; integrations authorized by the customer; professional advisers; and authorities when lawfully required. Information may also transfer in a merger, financing, reorganization or sale subject to appropriate protections.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising or disclose it to third parties or affiliates for their own promotional or marketing purposes.

SMS and mobile information

Your mobile information will not be sold or shared with third parties or affiliates for promotional or marketing purposes. Text messaging originator opt-in data and consent will not be shared with any third parties for purposes unrelated to providing the SMS service.

We may share a phone number, SMS opt-in or consent status with telecommunications carriers, messaging platforms and vendors that help deliver and secure requested text messages. They may use it only to provide those services, prevent abuse, comply with carrier rules or satisfy law.

Retention and deletion

Raw public-site analytics events are kept for up to 395 days. After an Account is closed, ordinary Customer Content enters a 30-day recovery period and is then scheduled for deletion. Limited billing, tax, Affiliate, security, fraud-prevention, consent and audit records may remain longer when required by law or needed for legal claims. Affiliate financial and audit records may be retained for seven years after the later of closure or final relevant activity. Backups expire on their protected schedule and are not restored to ordinary use except for disaster recovery.

Security and privacy rights

We use safeguards including encryption in transit, access controls, strong authentication, least-privilege roles and audit trails. No service can guarantee absolute security. Report concerns to security@infiniteocean.net.

Depending on location, you may have rights to know, access, correct, export or delete information; restrict or object to processing; withdraw consent; and complain to a regulator. We do not discriminate for exercising a privacy right. California residents may exercise applicable CCPA rights. We have not sold or shared personal information as defined by the CCPA in the preceding 12 months and do not use sensitive information to infer characteristics.

Submit an available request inside Spyglass or email privacy@infiniteocean.net. We may verify identity and authority. Requests about Customer Content may be directed to the business customer that controls it.

International processing, children and changes

Information may be processed in the United States and other provider locations. Where required, we use a lawful transfer safeguard such as standard contractual clauses. The Services are for businesses and not directed to children under 18.

We may update this policy as services or law changes. We will post the effective date and give additional notice when a material change requires it. Questions may be sent to privacy@infiniteocean.net.