INFABODE
ANYWHERE
Overview
Our Data
AI Connectors
Pricing
Sign In
Get Started
Privacy
Terms
Contents
1. Who We Are
2. Services Covered
3. Information We Collect
4. How We Use Information
5. Legal Bases
6. Profile Visibility & Partner Analytics
7. Extraction, AI & Human Review
8. When Information Is Shared
9. International Processing
10. Retention and Deletion
11. Cookies
12. Security
13. Individual Rights
14. Professional Audience & Children
15. Changes to this Policy
16. Contact
Privacy Policy
Effective date: 2 September 2026
1. Who we are
This Privacy Policy explains how Infabode Ltd collects, uses, shares and retains personal information when people use Infabode, receive Infabode communications, contribute content, or access Infabode through an API, Model Context Protocol (MCP) connection or Data Lake service.
Infabode Ltd is a company registered in England and Wales under company number 07961698. Its registered address is 15 Wood Wharf, Horseferry Place, Greenwich, London, SE10 9BB.
For the personal information described in this Policy, Infabode generally acts as the controller. An enterprise agreement may allocate responsibilities differently for particular API, MCP or Data Lake services.
Privacy questions and requests may be sent to hello@infabode.com.
2. Services covered by this Policy
This Policy covers Infabode's professional information platform and related services, including:
the Infabode website and logged-in platform;
digest emails and service communications;
Infabode Anywhere and the remote, client-agnostic Infabode MCP service;
Infabode APIs and customer integrations;
Data Lake access and licensed data deliveries; and
content-partner publishing, ingestion, extraction and analytics services.
API, MCP and Data Lake customers normally enter into separate commercial agreements. This Policy and Infabode's Terms of Service apply alongside those agreements unless the relevant agreement states otherwise.
Security information for the Infabode Anywhere MCP service is available in the MCP Security Q&A.
3. Information we collect
3.1 Account and profile information
When an account is created, Infabode may collect a user's first and last name, email address, password credential, location and job sector. The service may also request a job title, company, biography and social links. Some fields are required to complete registration; other fields are optional.
Email addresses are used for account administration and communications and are not displayed publicly or shared with content partners. Passwords are stored as cryptographic password hashes rather than readable passwords.
Users choose how much of their non-contact profile information to complete and display. Profile information made available by a user may be visible to other Infabode members and content partners. Contact details are excluded.
3.2 Direct platform activity
When a person uses Infabode directly, Infabode may record activity such as logins, article views and clicks, digest opens, advert views and clicks, interests, saved feeds, markets, locations, assets, companies or funds followed, general activity level and, where introduced, time spent using parts of the service.
Approximate location may be inferred from an IP address for security, service operation and geographically appropriate marketing-page pricing. Logged-in profile location is selected by the user.
3.3 MCP information
The remote MCP service receives the authentication and structured MCP calls sent by the customer-selected MCP client. This may include a bearer token, session headers, IP address, user agent, tool or resource identifiers, structured tool arguments, an API-user reference, organisation and user identifiers, and timestamps.
Infabode's MCP analytics are deliberately limited. Infabode records which MCP tools or resources are used and limited identity and timing information needed to authenticate, operate, secure and understand the service. Infabode does not intentionally store the user's complete natural-language prompt, conversation history or successful MCP response body for analytics. The connected MCP client determines what information it sends in a tool call and how returned Infabode data is presented to the user.
More detail on authentication, encryption, logging, retention and infrastructure for the MCP service is available in the MCP Security Q&A.
3.4 API information
API access is authenticated using the customer's API key. Customers may use a company name or other label to identify API activity and may optionally pass user details such as name, job title, company, location and job sector. Infabode does not require those additional end-user fields for ordinary API access.
Infabode tracks request volumes and the number of articles or data points returned. Filters submitted and the articles or data returned may appear temporarily in technical or application logs but are not retained as a separate user-analytics dataset. API customers are responsible for having an appropriate basis to provide any personal information they choose to pass to Infabode.
3.5 Data Lake information
Data Lake access provides licensed Infabode content and data rather than personal information about Infabode users. Infabode records customer access entitlements, permitted data buckets and operational information necessary to deliver and secure the service. The content scope, sectors, locations and update frequency depend on the customer agreement.
3.6 Content and partner information
Infabode records content submitted directly by partners or collected from partner-approved websites and portals, together with source, publisher, contributor, ingestion, edit and update information. Infabode may also collect and summarise posts from publicly accessible sources that are marked as external.
3.7 Emails, payments and website analytics
Infabode records opted-in digest delivery, opens and interactions. Digest emails may contain a tracking pixel that records when an email is opened. Users may disable a digest, and image blocking in an email client may prevent open tracking.
Stripe processes payment and billing information. Infabode receives transaction and subscription status information but does not store complete payment-card details.
Infabode uses Google Analytics 4 to understand website use. Analytics data may include pages visited, interactions, approximate location, referral source, device, browser and technical identifiers. Infabode does not enable Google Signals, demographic reporting or Google Analytics advertising features.
4. How we use information
provide, authenticate, administer and secure Infabode accounts and services;
deliver content, searches, feeds, digests, API results, MCP tool results and Data Lake access;
personalise feeds and alerts based on interests selected by the user;
measure service use, content reach and engagement;
provide aggregated and limited identifiable analytics to content partners;
process payments, subscriptions, renewals and account communications;
extract, classify, connect, summarise, correct and improve content and data;
monitor reliability, investigate incidents, enforce usage limits and prevent misuse;
comply with legal obligations and establish, exercise or defend legal claims; and
improve and develop Infabode products, without training an Infabode-owned AI model on customer prompts.
5. Legal bases
Depending on the activity and applicable law, Infabode relies on one or more of the following legal bases:
Contract
to create accounts, provide subscribed services, deliver requested content and administer payments.
Legitimate interests
to operate a professional information platform, secure and improve services, measure content engagement, provide proportionate partner analytics and develop commercial data products, balanced against the rights and expectations of individuals.
Consent
for optional email communications, analytics cookies where consent is required, and other activities presented as optional. Consent may be withdrawn at any time.
Legal obligation
where information must be processed to comply with law, regulation, tax, accounting or lawful authority requests.
6. Profile visibility and content-partner analytics
Direct platform users agree during registration that non-contact profile information they choose to provide may be visible to other members and content partners. Users may limit their visible profile to their name, but cannot use the direct platform while opting out of all profile visibility. Email addresses are never shared through these analytics.
Most content analytics are aggregated. Content partners may receive high-level totals and trends, recent viewers or the individuals most actively engaging with their own content. Identifiable analytics may include name, job title, company, job sector and location, together with the relevant article and an engagement measure, but only where those profile fields were supplied by the user and the activity occurred through direct use of Infabode.
Content partners can access analytics only for their own content. Infabode does not provide them with downloadable datasets of user analytics, although partners are not prohibited from retaining their own lawful business records of information displayed to them.
MCP, API and Data Lake services use different and generally more limited tracking arrangements, as described above.
7. Content extraction, AI and human review
Infabode aggregates content from content partners and publicly accessible sources, extracts key information, adds metadata and connects related records — for example, combining multiple stories about the same transaction into a connected transaction record.
Content may be processed by authorised Infabode employees, authorised contractors and selected third-party AI services for extraction, classification, summarisation and quality review. Employees and contractors are subject to confidentiality, access-control and data-protection obligations. Infabode may change AI provider or model depending on the task. Provider API arrangements are configured so submitted Infabode content is not used to train the provider's general-purpose models.
Infabode does not develop or train its own foundation AI models using customer questions. Extracted fields are used to organise, filter and deliver Infabode data products. A combination of human and technical review supports quality, and reported mistakes may be hidden or removed while they are reviewed.
8. When information is shared
Infabode may share information with:
other members and content partners, to the limited extent described in section 6;
Google Cloud Platform for hosting, databases, BigQuery analytics, technical logging and backups;
Auth0 for MCP authentication and OAuth services;
Amazon Web Services for sending opted-in emails and service communications;
Stripe for subscription and payment processing;
Google Analytics for website statistics, subject to applicable cookie choices;
selected AI providers and authorised contractors for content extraction and review;
professional advisers, insurers, auditors, prospective purchasers and finance providers under appropriate confidentiality obligations; and
courts, regulators, law-enforcement bodies or other recipients where disclosure is legally required or reasonably necessary to protect rights, safety and service integrity.
A customer-selected MCP client — including ChatGPT, Claude, Copilot, Cursor, Grok or another compatible client — is selected and controlled by the customer rather than Infabode. Its own privacy terms apply to the information it receives and sends. Infabode does not sell user contact details or make them available to content partners. Customers may separately license Infabode content and data products under commercial agreements.
9. International processing
Infabode's principal production infrastructure and analytics datasets are hosted in London and European regions. Some technical logs and service providers may process information in other countries, including the United States.
Where required, Infabode and its providers use recognised safeguards for international transfers, such as adequacy regulations, the UK International Data Transfer Addendum, Standard Contractual Clauses and applicable Data Privacy Framework certifications. Google states that its advertising and analytics services use applicable adequacy mechanisms, the EU–US Data Privacy Framework and its UK and Swiss extensions, and Standard Contractual Clauses where required.
10. Retention and deletion
Infabode keeps information for as long as reasonably needed for the purposes described in this Policy, the applicable customer agreement and legal requirements. The principal working retention rules are:
Information Typical retention approach
Accounts and profiles Kept while the account remains active. Inactive accounts may be deleted after at least 12 months of inactivity. Users must contact Infabode to request deletion.
Direct engagement analytics May remain identifiable for up to one year, after which engagement is aggregated by content item and the aggregated records are retained indefinitely.
MCP analytics Limited tool/resource, identity and timing records are retained while the account remains active. On account deletion, granular user-linked MCP records are deleted and historic usage may remain only in aggregated, unassigned form.
API and technical logs Kept according to operational logging requirements and then deleted or overwritten. Filters or returned records appearing in logs are not retained as a separate analytics dataset.
Content and extracted data Partner content, public-source summaries, provenance records, metadata and extracted or connected industry data may be retained indefinitely, including after prospective content distribution ends.
Aggregated statistics Retained indefinitely because they no longer identify an individual user.
Backups Production backups operate on a rolling seven-day basis. Deleted granular user data should therefore expire from routine backups within approximately seven days.
Payment and legal records Kept for the period required for accounting, tax, dispute and legal-compliance purposes.
When an account is deleted, granular user-linked data is removed from active systems, subject to backup expiry and any limited information that must be retained for legal or security reasons. Aggregated historic records that are no longer assigned to a user may remain.
11. Cookies and similar technologies
Infabode uses essential cookies or similar browser storage where necessary to operate, secure and authenticate its services. It also uses Google Analytics 4, whose standard JavaScript tags use first-party cookies commonly named _ga and _ga_<container-id> to distinguish visitors and sessions.
Where consent is required, analytics cookies will be activated only after consent. Visitors can reject or withdraw consent without losing access to essential website functionality. Blocking images in an email client may prevent Infabode's digest tracking pixel from recording an open.
12. Security
Infabode applies technical and organisational measures appropriate to the nature of the information it handles. These include HTTPS using TLS 1.2 or later, encrypted cloud storage, cryptographic password hashing, signed and validated OAuth tokens, permission checks, limited production-data access, monitoring and rolling backups.
A small number of authorised personnel have access to user data. Infabode monitors its services around the clock and investigates operational and security issues promptly. If a personal-data breach is likely to affect a client, Infabode aims to consult or notify the client within 24 hours of confirming the relevant incident, subject to applicable law and contractual arrangements.
Infabode is working towards ISO 27001 certification but is not currently certified. No internet service can be guaranteed completely secure.
For MCP-specific security information, see the MCP Security Q&A.
13. Individual rights
Depending on location and applicable law, individuals may have rights to request access, correction, deletion, restriction or portability of personal information, object to certain processing, withdraw consent, and complain to a supervisory authority.
Requests should be sent to hello@infabode.com. Infabode may ask for information needed to verify identity and may retain or refuse to delete information where permitted or required by law, including information necessary to establish or defend legal claims. Users must contact Infabode to close and delete an account.
UK users may complain to the Information Commissioner's Office at ico.org.uk, although Infabode asks that concerns first be raised with hello@infabode.com so they can be investigated.
14. Professional audience and children
Infabode is designed for professional and business users and is not directed at children. Infabode does not knowingly seek to collect personal information from children. A parent or guardian who believes a child has provided personal information should contact hello@infabode.com.
15. Changes to this Policy
Infabode may update this Policy to reflect changes in its services, technology, providers or legal obligations. The updated version will be published with a revised effective date. Where a change materially affects registered users, Infabode may also provide notice through the service or by email.
Contact
Infabode Ltd
Company number 07961698
15 Wood Wharf, Horseferry Place
Greenwich, London SE10 9BB
hello@infabode.com
Back to Top
Privacy & Terms
Connect
Real Estate MCP
API Docs
Data Lake
Integrations
Advertising
Use Cases
Contribute
Recruitment
Events