Privacy Policy

Last updated: July 24, 2026.

This policy explains how Palette, a product of Isotropic, Inc., handles personal information across its website and application. We control account, website, billing, support, security, and optional Library contribution data.

Information we handle

Accounts and communication

We handle names, email addresses, authentication details, workspace membership and role information, support messages, and waitlist or other messages you send us. We receive this information from you, workspace members who invite you, and services you use to sign in.

Workspaces and connected services

We handle the content you and other members place in a workspace, including customer evidence, files, messages, designs, product data, prompts, outputs, and workspace-specific memories. If you connect another service, we receive the content and account information that you direct that service to provide.

Research studies

Study data can include screening and demographic answers, consent records, participant identifiers such as a Prolific ID, responses, recordings, audio, video, transcripts, and research synthesis. Depending on the study, answers may include sensitive traits such as health, ethnicity, beliefs, political views, gender identity, or sexual orientation.

Billing

Stripe hosts payment entry. We receive billing contact details, Stripe identifiers, amounts, currency, and subscription, invoice, payment, and refund status. We do not receive full payment card details.

Technical data

We handle device, browser, network, diagnostic, usage, and security information, including IP addresses where needed. We also use essential cookies and browser storage for authentication, preferences, security, and requested features. If you separately opt in to optional public-site measurement, the additional information described below can include page URLs, referring pages, timestamps, interactions, diagnostic events, device and browser information, and identifiers associated with a Palette ad click.

How we use information

Provide Palette

We use information to authenticate people, administer workspaces, connect requested services, run research, generate requested analysis and outputs, personalize a workspace for its members, process billing, provide support, communicate, secure the service, prevent abuse, troubleshoot, and comply with law.

Optional public-site measurement

Optional technologies are off by default for every visitor worldwide. Usercentrics' Cookiebot consent-management platform presents the choices and tells optional services which categories you allowed. You can review or change those categories through the Cookiebot privacy trigger shown in the lower-left corner on reviewed public, privacy, and eligible clean authentication or onboarding pages. Refusing optional categories does not affect the essential site.

The browser requests Cookiebot from consent.cookiebot.com only on reviewed public and privacy routes and limited clean authentication or onboarding documents where the consent interface or optional services are available. It is not loaded on Palette's dashboards, general product routes, participant experiences, previews, tokenized documents, APIs, or unknown routes. This necessary request can include ordinary connection and device information. Cookiebot stores the current domain's consent state in the necessary first-party CookieConsent cookie for up to 12 months. A consent log records an encrypted consent ID, timestamp, consent state, submission URL, browser user agent, and a shortened form of the IP address so the choice can be documented.

Where data protection law requires a legal basis, Palette relies on your consent for optional technologies. We apply the same prior-choice standard worldwide as a product rule, even where local law may permit another approach. Cookiebot uses four standard categories: Necessary, Preferences, Statistics, and Marketing. Necessary cannot be switched off in the consent interface. Preferences, Statistics, and Marketing remain off until allowed. Refusing or withdrawing an optional category does not affect the lawfulness of processing completed before withdrawal.

Even with consent, optional measurement is limited to the canonical https://palettelabs.ai origin. Public-site Google Ads, LinkedIn Ads, and first-touch attribution are limited to the home page (/), Research (/research), Build (/build), Pricing (/pricing), the Changelog index (/changelog), the published Palette begins public rollout entry (/changelog/palette-begins-public-rollout), the Blog index (/blog), each published Blog guide listed there, the waitlist (/waitlist), and Docs (/docs). First-touch attribution can also be captured locally on a clean login (/login), sign-in alias (/signin), or signup (/signup) entry document. Clarity can also run on this policy (/privacy) and the Terms (/legal/terms). Unknown Blog URLs remain excluded. The waitlist notice (/waitlist/privacy) can load Cookiebot so a visitor can manage a choice, but remains ineligible for optional measurement.

Clarity, LinkedIn, and public-site advertising measurement are excluded from authentication, verification, identity, and workspace-creation documents. Cookiebot can appear by itself on the reviewed clean documents, and the distinct direct-signup Google conversion described below can run only on the clean completion page (/signup/complete). Optional measurement is also excluded from the leave-waitlist page (/waitlist/leave), the Palette application and dashboards, other workspace routes, participant and study experiences, previews, APIs, and other sensitive or product routes. Preview, local, staging, and other noncanonical origins remain excluded from optional vendors even where a reviewed staging route can load Cookiebot for testing. An unrecognized URL query parameter disables optional measurement; approved campaign values can be captured locally where permitted, while those parameters and all URL fragments are removed before any optional vendor is requested. The sole exception is the validated, consented LI_FAT_ID exposure to LinkedIn described below. Optional measurement also stays off for a document when its incoming referrer contains anything more detailed than an origin.

AI and model training

We do not use your personal information, workspace content, connected-service data, or participant data to train models or improve Palette's algorithms. Outside the optional Library described below, results and personalization remain workspace-scoped and benefit that workspace only.

The Library

The Library is the only way study content is used across workspaces. A workspace must opt in. Palette contributes only scrubbed, de-identified written summaries, never raw recordings, audio, transcripts, verbatim quotes, names, or direct identifiers. Contributions already made ordinarily remain after the Library is disabled or the source workspace is deleted. They may be removed to honor a participant erasure request, satisfy a legal obligation, or respond to a valid takedown. The Library terms explain the contribution rules.

AI-assisted results

Palette can use AI to summarize evidence, rank research themes, and give answer-quality feedback.

Cookies and similar technologies

The declaration below is supplied by Cookiebot and reflects its current scan of the cookies and similar technologies used on this site, including their category, provider, purpose, and duration. You can also use it to change or withdraw an optional choice.

Sharing and transfers

Members and integrations

Information is available to workspace members according to their access. We send information to connected services when a member directs Palette to do so. A study organizer receives the participant information and results collected for its study.

Service providers

Providers process information for cloud hosting and storage, authentication, AI inference, search and content retrieval, security and observability, participant recruitment, billing, email delivery, and public-site advertising measurement. Their roles and terms depend on the service. We require them to protect information and limit their use where we act as controller or processor. Some, including payment, identity, and advertising measurement providers, may also process information independently under their own policies and legal duties.

Legal and business events

We may disclose information when reasonably necessary to comply with law, protect people or the service, investigate abuse, or establish or defend legal claims. Information may also transfer as part of a merger, financing, acquisition, reorganization, or sale of assets, subject to this policy and applicable law.

Microsoft Clarity analytics and replay

With Statistics consent, Microsoft Clarity helps us understand how people use the eligible public pages through heatmaps, behavioral analytics, diagnostics, and reconstructed session replays. Clarity can receive the cleaned eligible page URL and, when present, an origin-only referrer; clicks, pointer movement, selections, scrolling, resizing, and page visibility; DOM structure and mutations; timing, performance, script, image, and other diagnostic events; and browser, device, operating system, screen, network, and IP address information from which approximate location can be derived.

Before this optional feature is enabled, Palette's release gate requires Clarity's Strict masking mode. The waitlist form is additionally marked with Clarity's data-clarity-mask control, so its contents, including the submitted email address, are excluded from replay. Masking is not a complete privacy boundary: page and referring URLs, and link text and destination URLs associated with clicks, can remain available to Clarity. We therefore clean approved campaign parameters and fragments before Clarity starts, require any incoming referrer to be empty or origin-only, and do not run it on a URL with an unknown query parameter.

Cookiebot's built-in Microsoft consent mapping uses Statistics to control Clarity analytics storage and Marketing to control Clarity advertising storage. Palette does not request the Clarity tag before the relevant optional consent or on an ineligible route. Once Statistics is allowed, Clarity can use first- and third-party analytics cookies to maintain session continuity. Cookiebot sends later category changes to Clarity through the provider's supported consent interface. With Marketing allowed, Clarity may share data with Microsoft Advertising for advertising measurement and optimization. If you later withdraw Statistics after the Clarity tag has loaded, Cookiebot sends a denied analytics-storage signal. Clarity then stops cookie-based analytics and full features such as session replay, but Microsoft states that the loaded tag can continue sending limited cookieless data. Denying Marketing prevents Clarity from sharing data with Microsoft Advertising.

Under the Microsoft Clarity Terms, Palette and Microsoft are independent controllers for information processed through Clarity. Microsoft may use that information under its own terms and Microsoft Privacy Statement, including to provide and improve its products and services and for advertising. Microsoft may process Clarity information in the United States. Microsoft states that transfers from the European Economic Area, United Kingdom, and Switzerland to its United States affiliate are covered by contractual safeguards, including standard contractual clauses.

Google Ads campaign measurement

We advertise Palette, including through Google Search. With Marketing consent, Google Ads helps us understand whether an ad visit results in a waitlist signup. Palette uses Google's Basic Consent Mode: the Google Ads tag is withheld until consent rather than sending cookieless advertising pings before your choice. Cookiebot's built-in Google consent mapping uses Marketing to control ad storage, advertising user-data processing, and ad personalization signals. Statistics controls analytics storage. Palette currently uses Google Ads for campaign conversion measurement, not remarketing audiences or personalized advertising.

If you later withdraw Marketing after the Google tag has loaded, Cookiebot sends denied ad-storage, advertising user-data, and ad-personalization signals. Palette does not send another waitlist conversion, and Google may not use advertising cookies, advertising user data, or personalized advertising under those denied states. Google states that an already-loaded tag can still send the consent state and limited measurements without cookies.

Google can receive the eligible public page visited, device, browser, network, timestamp, consent state, a validated GCLID when present, and a conversion event for a backend-confirmed new waitlist signup. We do not send the waitlist email address, workspace content, or participant data to Google Ads, and we do not send a conversion later if Marketing was not allowed when the signup completed. We do not use this tag for remarketing or personalized advertising.

After consent, Palette can save the first approved campaign or ad-click identifiers, landing path, and external referring host in session storage for attribution within that browser tab. We do not put the submitted email in that browser record. If you join the waitlist while Marketing is allowed, the approved attribution values are submitted to Palette with the signup and retained with the waitlist record under the waitlist-specific privacy notice. A validated Google Click ID (GCLID) can be passed separately through Google's documented tag field after the visible page URL is clean; other approved click IDs remain in Palette's first-party attribution record for supported backend attribution and are not sent through undocumented tag fields. Campaign-copy values remain out of vendor request URLs. We clear the browser-session attribution record when Marketing is refused or withdrawn, or when the master switch or all advertising-provider switches disable campaign measurement.

Direct-signup conversion

Separately from waitlist measurement, after Palette's backend confirms an eligible new direct signup and first workspace creation, Palette may make one Google Ads conversion attempt only on the exact clean /signup/complete page and only while Cookiebot currently reports Marketing consent. The event uses a stable opaque transaction ID that does not contain an email address, user ID, workspace ID, or workspace content.

Palette carries that backend confirmation to the completion page in a short-lived signed HttpOnly receipt. The page consumes the receipt before making its one optional delivery attempt, so a reload or repeated visit cannot reuse it. If the receipt is absent, invalid, expired, or already consumed, or if Marketing is absent or withdrawn when delivery would occur, Palette does not send that conversion then or later. Consent and vendor delivery are independent of product access; the workspace remains available whether or not a conversion is attempted or delivered.

Learn more in the Google Privacy Policy and Google's explanation of how it uses information from sites that use its services.

LinkedIn Ads campaign measurement

We also advertise Palette through LinkedIn. After you allow Marketing, LinkedIn's Insight Tag helps us understand whether an eligible ad visit results in a waitlist signup. Palette withholds the tag before that affirmative choice, does not use it on excluded or sensitive routes, and stops making new LinkedIn tag or conversion calls if Marketing is withdrawn. If the tag has already executed, withdrawal reloads the current page so the vendor runtime is removed; the fresh document does not load it unless Marketing remains allowed.

LinkedIn can receive the eligible public page URL and referrer, device and browser characteristics, network and IP address, timestamp, and a LinkedIn ad-click identifier such as LI_FAT_ID when present. The tag creates cookies and, in supported regions, a first-party pseudonymous LinkedIn Ads ID (LI_ADSID). Website Actions can classify page visits, button clicks, and form submissions using limited page structure such as page or button names, button click-or-view state, and a session-unique action hash. LinkedIn states that this classification data does not include form-field values.

For first-party click attribution, after Marketing consent Palette briefly restores only a validated LI_FAT_ID to the already-cleaned page URL while the tag executes, then removes it again. Campaign copy and other URL parameters remain removed. Palette sends the selected conversion event only for a backend-confirmed new waitlist signup completed while Marketing is allowed. We do not send the waitlist email address, workspace content, or participant data to LinkedIn, and this implementation does not use Enhanced Matching or LinkedIn's user-data API.

The Insight Tag is capable of supporting audience insights, website retargeting, and auto-created Website Actions conversions. Palette uses the integration for campaign measurement and conversion optimization only. We do not create or activate LinkedIn Matched Audiences from these signals, and our campaign selects only the explicit backend-confirmed waitlist conversion.

LinkedIn processes information under its LinkedIn Privacy Policy and Cookie Policy.

We do not sell personal information. With Marketing consent, we disclose the public-site signals described above to LinkedIn for Palette campaign measurement and optimization. We do not use workspace content, connected-service data, participant data, or submitted waitlist information to target advertising.

International processing

Isotropic, Inc. is based in the United States, and we and our providers may process information in the United States and other countries. Where law requires, we rely on recognized safeguards such as adequacy decisions or contractual protections. Contact us to ask about the safeguards that apply.

Retention and security

How long we keep data

We keep information while an account or workspace is active and as needed to provide Palette. After that, retention depends on the information's purpose, legal and billing duties, dispute needs, security, backup cycles, and provider deletion schedules. The waitlist notice explains the narrower rules for waitlist data.

Optional measurement retention

Microsoft's published Clarity schedule keeps ordinary session playback data for 30 days. Labeled or favorited sessions, a limited sample of recordings, and click and heatmap aggregates can remain for up to nine months. Microsoft states that a specific visitor's Clarity data cannot be deleted without deleting the entire project. Palette retains historical public-site measurements already held in its current Clarity project and lets them expire under that schedule. Withdrawing Statistics stops future cookie-based analytics and full Clarity features, including session replay, but an already-loaded tag can continue limited cookieless measurement under the denied state. Withdrawal does not retroactively remove provider history.

Browser-session attribution ends with the browser-tab session or is cleared sooner when Marketing is no longer allowed. A copy already submitted with a waitlist signup stays with the waitlist record until that record is deleted under the waitlist notice; withdrawing optional measurement does not retroactively delete the submitted copy. Google retains information already received according to its own retention practices, legal obligations, and privacy controls. LinkedIn likewise retains information already received under its own policies and controls.

Deletion

Deleting a workspace removes the workspace from Palette's active product. Associated content may remain temporarily in provider systems, security logs, backups, and other systems with separate deletion schedules. Deleting an account replaces the person's displayed identity with a deleted-user placeholder where shared or transferred workspace history must remain coherent. We may retain other records required for billing, security, legal compliance, or dispute resolution.

Library contributions

De-identified Library summaries ordinarily remain after the original study or workspace is deleted. They may be removed to honor a participant erasure request, satisfy a legal obligation, or respond to a valid takedown. Other workspaces receive no direct source link or workspace identifier through the Library.

Security

We use reasonable technical and organizational safeguards designed to protect information. No storage or transmission method is completely secure.

Your choices and rights

Account controls

Depending on your role, Palette settings let you update account details, manage connected services, control workspace-specific memories, disable the Library, delete a workspace, or delete your account.

Website measurement choices

Use the Cookiebot privacy trigger shown in the lower-left corner on reviewed public, privacy, and eligible clean authentication or onboarding pages to review, allow, refuse, or withdraw the Preferences, Statistics, and Marketing categories. Necessary technologies remain active because they are required to operate the site and remember your choice. A change applies to future optional processing; providers may retain information already received under their published retention practices.

Privacy rights

Depending on where you live, you may ask to access, correct, delete, restrict, or obtain a portable copy of personal information, or object to processing. You may also withdraw consent and complain to your local data protection authority. We may need to verify your identity and may deny or limit a request where law permits.

Adults only

Palette is for people aged 18 and older. We do not knowingly collect personal information from anyone under 18. Contact us if you believe a minor has provided information so we can investigate and delete it where appropriate.

Changes and contact

Policy changes

We will update the effective date when this policy changes. We will give appropriate advance notice before a material change takes effect, especially before using information for a new, incompatible purpose.

Contact us

Send privacy questions or requests to privacy@palettelabs.ai.

Isotropic, Inc.
2810 N Church St STE 88937
Wilmington, DE 19802
United States