Insay privacy policy
Last updated October 9, 2026 · Insay by Indraft
Insay is a browser extension that drafts replies on Gmail, X, Reddit and LinkedIn. It is built to read as little as possible, keep nothing, and never act without you.
What Insay reads
Only when you tap the Insay button (or press Alt+I) in a reply box, Insay reads the message you are replying to, up to two earlier messages in the same thread, the post title or email subject, and anything you already typed in that box. On Reddit it also reads the subreddit's name and up to five other comments in the same thread (shortened), so the reply fits the thread and does not repeat what others said. On LinkedIn it also compares your name, as shown on the page, with the post's author, only to tell whether the post is yours; your name itself is never sent. It never reads profiles, post history or other pages. Nothing is read before you tap. On a site you switch off in Insay's settings, Insay does nothing at all: no button, and nothing on the page is read.
Where it goes
Insay writes in one of two ways, chosen in its settings.
With an Insay account (the default when you have not added an API key): the text is sent to Insay's server, run by Alpstack on Amazon Web Services in the United States, which passes it to Anthropic's Claude to write the draft and streams the draft back. The server does not store the text or the draft, and its logs record only your account or device id, the site, how long the request took and how many words the model used, never the content. Anthropic does not train its models on API data; see Anthropic's privacy policy for how long it keeps API requests.
With your own API key: the text is sent directly from your browser to the AI provider you chose (Anthropic Claude, Google Gemini, DeepSeek, OpenAI or your own OpenAI-compatible endpoint), using your key. Alpstack's server is not involved and never receives your messages, drafts or key. If the first provider fails before writing anything, and backup models are on, the same text is sent to the next provider in your list that has a key.
The provider's own privacy policy applies to what you send them. Please read it, especially for email. For example, DeepSeek states that it processes and stores data in the People's Republic of China and may use it to train its models unless you opt out in your DeepSeek account.
Gmail and InboxSDK
On Gmail, Insay uses InboxSDK (by Streak) to attach to compose and reply windows. Insay turns off InboxSDK's usage analytics. If InboxSDK itself hits an internal error, it sends an error report to InboxSDK's servers containing the error message, the extension ID and a one-way hash of your Gmail address. It is not sent your emails, the replies you draft, or your API keys. See the InboxSDK terms.
What Insay stores
On this device:
- Your API key, if you use one: stored only on this device (
chrome.storage.local), never synced, readable only by the extension's background worker. - Your Insay sign-in: short-lived tokens and a random device id, stored the same way, never synced.
- Your preferences (provider, model, default tone, reply language, your "about me" note, X length limit, which sites are on): stored on this device (
chrome.storage.local). If you turn on "Sync settings across my devices", they and your saved actions are kept inchrome.storage.sync, your browser's own sync, so they follow your browser profile. Insay's servers are not involved, and API keys, edit history and recent takes are never synced. - A small settings file (
alpstack.com/insay/config.json) with page selectors and links, downloaded every few hours. It contains no user data and the request carries none.
On Insay's server, for the Insay account only:
- Your account: when you sign in with Google, your email address, your Google account id, what you have bought (Plus, BYOK), when your Plus trial started and ends, and when you joined. Insay asks Google only for your basic profile and does not store your name or photo.
- Your browsers: each browser you sign in on gets a random id, kept with a label such as "Chrome on macOS" and when it was last used, so the BYOK plan can be used on up to 2 browsers. You can see and deactivate them in settings.
- Usage counts: how many drafts you used today and this month, to apply the plan's limits. They hold numbers only and delete themselves after the period ends.
- The Plus trial: the random id of the browser that started it, so each browser gets one trial, deleted after a year; and a count of trials started from your network, kept under a one-way keyed hash of your IP address (never the address itself) and deleted when the month ends.
- Before you sign in: the random device id and, to stop abuse of the free tries, a one-way keyed hash of your IP address. The IP address itself is never stored, and the hash is deleted after two days.
On this device, unless you turn it off:
- Your edits: when you insert a draft, Insay keeps it, and when you post, what you actually posted (the last 200). This is how Insay will learn how you write. It stays in
chrome.storage.local, is never synced and never sent. Settings, Privacy, "Remember my edits on this device" turns it off, and "Clear my edit history" deletes it. - Your voices: if you create a custom voice, the writing you paste is sent once to write its style rules (to Insay's server with Plus, or straight to your AI provider with your own key) and is not stored anywhere, by Insay or on your device. Only the resulting rules and a few short examples, with names, emails and links removed, are kept on this device, and synced only if you turn on settings sync. They are sent with each draft you write in that voice.
- What you typed into Insay: your last 10 takes and refinements, so the up arrow can bring one back. Never kept on Gmail. It stays in
chrome.storage.local, is never synced and never sent. Settings, Privacy, "Remember what I type, for the up arrow" turns it off and deletes them.
Apart from these, page text, drafts and generated replies are never stored, on your device or on the server. They live in memory while the panel is open and are gone when you close it.
Payments
Plus and BYOK are sold through Polar, which handles checkout, tax and receipts as the merchant of record. You pay on Polar's checkout page; Insay never sees your card. Polar tells Insay's server what you bought, linked to your Insay account id, so your plan works wherever you sign in. Insay keeps only what you own, when you bought it and the price paid, never payment details.
With BYOK, your API key stays in this browser and is never sent to Insay. A signed note from Insay's server, valid for 7 days, lets BYOK keep working if Insay's server is briefly unreachable.
Usage statistics
To learn what to improve, Insay sends anonymous usage events to PostHog (US), which stores them for us. An event says what happened, never what was written: for example that a draft was written or inserted, which action it was (Answer, Push back...), on which site, how long it took, whether you changed it before posting (as yes or no and a number), whether you use an Insay account or your own key, and the extension version. When you mark a draft as not good, the reason you picked (such as "Too generic") is sent with the names of the writing rules the draft broke, never the draft. Each install gets a random id that is not linked to your account, your email or your trial.
Never sent: page text, drafts, your edits, your take, your API key, your email. PostHog is told not to look up your location from your IP address. Turn usage statistics off in Settings, Privacy, "Share anonymous usage data"; anything not yet sent is dropped.
What Insay never does
- It never clicks Post or Send. You always post yourself.
- It has no ads, no session recording and no tracking across sites, and it does not sell or share your data. Its only usage statistics are the anonymous ones above, which you can turn off.
- It only runs on mail.google.com, x.com, www.reddit.com and www.linkedin.com.
Removing your data
Uninstalling Insay deletes your key, sign-in, preferences and edit history from this browser. To revoke a key, delete it in your provider's dashboard. To delete your Insay account, its browsers and usage counts from the server, use Delete my Insay account in settings, or email insay@alpstack.com from the address you signed in with. Deleting the account ends any Plus subscription first. Polar keeps its own records of past payments, as the law requires for tax.
Contact
Questions: insay@alpstack.com