Privacy Policy
Last updated: July 24, 2026.
This policy explains how Palette, a product of Isotropic, Inc., handles personal information across its website and application. We control account, website, billing, support, security, and optional Library contribution data.
Information we handle
Accounts and communication
We handle names, email addresses, authentication details, workspace membership and role information, support messages, and waitlist or other messages you send us. We receive this information from you, workspace members who invite you, and services you use to sign in.
Workspaces and connected services
We handle the content you and other members place in a workspace, including customer evidence, files, messages, designs, product data, prompts, outputs, and workspace-specific memories. If you connect another service, we receive the content and account information that you direct that service to provide.
Research studies
Study data can include screening and demographic answers, consent records, participant identifiers such as a Prolific ID, responses, recordings, audio, video, transcripts, and research synthesis. Depending on the study, answers may include sensitive traits such as health, ethnicity, beliefs, political views, gender identity, or sexual orientation.
Billing
Stripe hosts payment entry. We receive billing contact details, Stripe identifiers, amounts, currency, and subscription, invoice, payment, and refund status. We do not receive full payment card details.
Technical data
We handle device, browser, network, diagnostic, usage, and security information, including IP addresses where needed. We also use essential cookies and browser storage for authentication, preferences, security, and requested features. If you separately opt in to optional public-site measurement, the additional information described below can include page URLs, referring pages, timestamps, interactions, diagnostic events, device and browser information, and identifiers associated with a Palette ad click.
How we use information
Provide Palette
We use information to authenticate people, administer workspaces, connect requested services, run research, generate requested analysis and outputs, personalize a workspace for its members, process billing, provide support, communicate, secure the service, prevent abuse, troubleshoot, and comply with law.
Optional public-site measurement
Optional technologies are off by default for every visitor worldwide. Usercentrics' Cookiebot consent-management platform presents the choices and tells optional services which categories you allowed. You can review or change those categories through the Cookiebot privacy trigger shown in the lower-left corner on reviewed public, privacy, and eligible clean authentication or onboarding pages. Refusing optional categories does not affect the essential site.
The browser requests Cookiebot from consent.cookiebot.com only on reviewed public and privacy routes and limited clean authentication or onboarding documents where the consent interface or optional services are available. It is not loaded on Palette's dashboards, general product routes, participant experiences, previews, tokenized documents, APIs, or unknown routes. This necessary request can include ordinary connection and device information. Cookiebot stores the current domain's consent state in the necessary first-party CookieConsent cookie for up to 12 months. A consent log records an encrypted consent ID, timestamp, consent state, submission URL, browser user agent, and a shortened form of the IP address so the choice can be documented.
Where data protection law requires a legal basis, Palette relies on your consent for optional technologies. We apply the same prior-choice standard worldwide as a product rule, even where local law may permit another approach. Cookiebot uses four standard categories: Necessary, Preferences, Statistics, and Marketing. Necessary cannot be switched off in the consent interface. Preferences, Statistics, and Marketing remain off until allowed. Refusing or withdrawing an optional category does not affect the lawfulness of processing completed before withdrawal.
Even with consent, optional measurement is limited to the canonical https://palettelabs.ai origin. Public-site Google Ads, LinkedIn Ads, and first-touch attribution are limited to the home page (/), Research (/research), Build (/build), Pricing (/pricing), the Changelog index (/changelog), the published Palette begins public rollout entry (/changelog/palette-begins-public-rollout), the Blog index (/blog), each published Blog guide listed there, the waitlist (/waitlist), and Docs (/docs). First-touch attribution can also be captured locally on a clean login (/login), sign-in alias (/signin), or signup (/signup) entry document. Clarity can also run on this policy (/privacy) and the Terms (/legal/terms). Unknown Blog URLs remain excluded. The waitlist notice (/waitlist/privacy) can load Cookiebot so a visitor can manage a choice, but remains ineligible for optional measurement.
Clarity, LinkedIn, and public-site advertising measurement are excluded from authentication, verification, identity, and workspace-creation documents. Cookiebot can appear by itself on the reviewed clean documents, and the distinct direct-signup Google conversion described below can run only on the clean completion page (/signup/complete). Optional measurement is also excluded from the leave-waitlist page (/waitlist/leave), the Palette application and dashboards, other workspace routes, participant and study experiences, previews, APIs, and other sensitive or product routes. Preview, local, staging, and other noncanonical origins remain excluded from optional vendors even where a reviewed staging route can load Cookiebot for testing. An unrecognized URL query parameter disables optional measurement; approved campaign values can be captured locally where permitted, while those parameters and all URL fragments are removed before any optional vendor is requested. The sole exception is the validated, consented LI_FAT_ID exposure to LinkedIn described below. Optional measurement also stays off for a document when its incoming referrer contains anything more detailed than an origin.
AI and model training
We do not use your personal information, workspace content, connected-service data, or participant data to train models or improve Palette's algorithms. Outside the optional Library described below, results and personalization remain workspace-scoped and benefit that workspace only.
The Library
The Library is the only way study content is used across workspaces. A workspace must opt in. Palette contributes only scrubbed, de-identified written summaries, never raw recordings, audio, transcripts, verbatim quotes, names, or direct identifiers. Contributions already made ordinarily remain after the Library is disabled or the source workspace is deleted. They may be removed to honor a participant erasure request, satisfy a legal obligation, or respond to a valid takedown. The Library terms explain the contribution rules.
AI-assisted results
Palette can use AI to summarize evidence, rank research themes, and give answer-quality feedback.
Retention and security
How long we keep data
We keep information while an account or workspace is active and as needed to provide Palette. After that, retention depends on the information's purpose, legal and billing duties, dispute needs, security, backup cycles, and provider deletion schedules. The waitlist notice explains the narrower rules for waitlist data.
Optional measurement retention
Microsoft's published Clarity schedule keeps ordinary session playback data for 30 days. Labeled or favorited sessions, a limited sample of recordings, and click and heatmap aggregates can remain for up to nine months. Microsoft states that a specific visitor's Clarity data cannot be deleted without deleting the entire project. Palette retains historical public-site measurements already held in its current Clarity project and lets them expire under that schedule. Withdrawing Statistics stops future cookie-based analytics and full Clarity features, including session replay, but an already-loaded tag can continue limited cookieless measurement under the denied state. Withdrawal does not retroactively remove provider history.
Browser-session attribution ends with the browser-tab session or is cleared sooner when Marketing is no longer allowed. A copy already submitted with a waitlist signup stays with the waitlist record until that record is deleted under the waitlist notice; withdrawing optional measurement does not retroactively delete the submitted copy. Google retains information already received according to its own retention practices, legal obligations, and privacy controls. LinkedIn likewise retains information already received under its own policies and controls.
Deletion
Deleting a workspace removes the workspace from Palette's active product. Associated content may remain temporarily in provider systems, security logs, backups, and other systems with separate deletion schedules. Deleting an account replaces the person's displayed identity with a deleted-user placeholder where shared or transferred workspace history must remain coherent. We may retain other records required for billing, security, legal compliance, or dispute resolution.
Library contributions
De-identified Library summaries ordinarily remain after the original study or workspace is deleted. They may be removed to honor a participant erasure request, satisfy a legal obligation, or respond to a valid takedown. Other workspaces receive no direct source link or workspace identifier through the Library.
Security
We use reasonable technical and organizational safeguards designed to protect information. No storage or transmission method is completely secure.
Your choices and rights
Account controls
Depending on your role, Palette settings let you update account details, manage connected services, control workspace-specific memories, disable the Library, delete a workspace, or delete your account.
Website measurement choices
Use the Cookiebot privacy trigger shown in the lower-left corner on reviewed public, privacy, and eligible clean authentication or onboarding pages to review, allow, refuse, or withdraw the Preferences, Statistics, and Marketing categories. Necessary technologies remain active because they are required to operate the site and remember your choice. A change applies to future optional processing; providers may retain information already received under their published retention practices.
Privacy rights
Depending on where you live, you may ask to access, correct, delete, restrict, or obtain a portable copy of personal information, or object to processing. You may also withdraw consent and complain to your local data protection authority. We may need to verify your identity and may deny or limit a request where law permits.
Adults only
Palette is for people aged 18 and older. We do not knowingly collect personal information from anyone under 18. Contact us if you believe a minor has provided information so we can investigate and delete it where appropriate.
Changes and contact
Policy changes
We will update the effective date when this policy changes. We will give appropriate advance notice before a material change takes effect, especially before using information for a new, incompatible purpose.
Contact us
Send privacy questions or requests to privacy@palettelabs.ai.
Isotropic, Inc.2810 N Church St STE 88937
Wilmington, DE 19802
United States