Legal
Privacy Policy
Last updated June 21, 2026
1. Who this policy covers
intentLM (intentlm.ai) provides real-time behavioural intent classification for software products. This policy describes how we process data when:
- End users interact with a customer's application that includes the intentLM browser SDK — intentLM acts as a data processor on behalf of that customer (the data controller).
- Customers use the intentLM dashboard, signup, and API — intentLM is the controller for account and billing data described in section 8.
- Visitors browse intentlm.ai — we collect standard web server logs. If you accept analytics cookies, we also collect anonymous page-view metrics via Vercel Web Analytics (see section 6a).
If you reached this page from another company's privacy policy, that company controls your personal data; intentLM processes tokenised behavioural sequences on their instructions under a Data Processing Agreement (DPA).
2. What we process (SDK / API)
The intentLM SDK converts in-app navigation into integer token IDs in the browser. Only those integers and timing metadata are sent to our inference API. We do not receive:
- Raw URLs, page titles, or DOM text
- Form field values, email addresses, or names
- IP addresses stored as part of session sequences (standard infrastructure logs may briefly exist at the edge)
Typical payload fields:
tokens— ordered list of global taxonomy integers (e.g. pricing view, checkout started)time_deltas_ms— milliseconds between eventssession_id— ephemeral browser session identifier- Optional opaque ids supplied by the customer app:
user_id,account_id(must not contain email or PII) - Optional
visitor_id— random UUID in first-party cookie_ilm_vidwhen the customer enables cross-session persistence
3. Purpose
We use token sequences to:
- Classify behavioural intent in real time (e.g. upgrade seeking, support needed)
- Return confidence scores to the customer's application or webhooks
- Improve intent classification models using pseudonymised, aggregated patterns
- Provide analytics summaries to the customer in the intentLM dashboard
Customers may use classifications to personalise in-product experiences (nudges, agent prompts). Those interventions are configured by the customer and governed by their privacy policy and consent framework.
4. Retention
Tokenised session sequences are retained for 90 days by default and deleted thereafter unless a customer's DPA specifies a shorter window.
Longitudinal visitor profiles (when enabled) use a customer-configurable window (30–365 days; default 90). Customers may request erasure of session or account data via the config API; deletions are completed within 72 hours and audit-logged.
5. Cross-customer model training
intentLM may use pseudonymised token sequences from multiple customers to train and improve shared intent models. Individual session sequences are not exposed to or recoverable by other customers. This processing supports service improvement and does not constitute a sale of personal information under applicable US privacy law.
6. Cookies
When a customer enables visitor persistence, the SDK may set a first-party cookie:
| Name | Purpose | Duration |
|---|---|---|
| _ilm_vid | Random UUID for anonymous cross-session sequencing. No PII or raw URLs. | Up to 1 year |
The cookie is set only when the customer's consent hook allows analytics / persistence.
6a. intentlm.ai site analytics
On intentlm.ai we show a cookie banner. Until you choose Accept analytics, we do not load Vercel Web Analytics. After acceptance, Vercel may set first-party analytics cookies / local storage for aggregated page views and referrers. Choosing Essential only keeps the site working without that analytics. We do not use advertising or cross-site tracking pixels on this site.
7. Infrastructure & subprocessors
Data is processed in the United States using industry-standard cloud providers (including Google Cloud Platform and Supabase/PostgreSQL). Redis may be used for caching. Customers receive subprocessor details in the DPA. We apply encryption in transit (TLS) and restrict access by role.
8. Customer account data
When you sign up for intentLM, we process account email, company name, API key metadata, webhook configuration, and usage metrics as controller. Authentication uses Supabase Auth. You may delete your account and associated session data through the dashboard or API.
9. Your rights
If intentLM processes your data on a customer's application, contact that customer (the controller) to exercise GDPR, CCPA, or other privacy rights. They will instruct us as processor where required.
For intentLM account or website matters, contact us at contact.intentlm@gmail.com. EU/UK representatives and Standard Contractual Clauses are available to customers under DPA version 2026-06-21.
10. Changes
We may update this policy. Material changes will be reflected in the "Last updated" date. Customers integrating the SDK should ensure their privacy policy disclosure remains accurate.
For customers. Copy the processor disclosure snippet from the setup wizard into your privacy policy and link to this page. Full DPA: contact.intentlm@gmail.com.