Legal
Privacy Policy
This is the current privacy policy for Intella. It describes what the service collects, how that information is used, and how to reach the operator.
Who operates Intella
Intella is a personal workspace on the web. Michael Wagner operates the service under the name Intella. The operator is an individual.
You sign in with Google, claim a handle, and get a private Home. You can add workspaces, apps, and pages, and you choose who can open them.
Google user data
Sign-in uses Google OAuth with the OpenID Connect scopes openid, email, and profile. After you approve access, Intella reads the Google userinfo response and stores:
- your email address, when Google reports that address as verified;
- the name Google sends, when it sends one;
- the profile photo URL Google sends, when it sends one.
Intella uses the Google access token only to read that profile during sign-in. The token is not written to the account database. Intella does not request Gmail, Drive, Calendar, Contacts, or other Google products.
On a later sign-in, Intella updates the stored name and photo URL when Google sends a non-empty value. The email address is the account key.
By default, a verified Google account can create an Intella account on first sign-in. A deployment can instead run in allowlist mode. In that mode an unknown email is refused, and an administrator may store an email address before that person signs in so the address is allowed to create an account.
Intella uses Google account data to authenticate you, to show your name and photo in the interface, to match invitations and named-person access to your email, and to recognize an account request you send from that address. Intella does not sell Google user data, does not use it for advertising, and does not share it with an advertising network or a data broker.
Information you add in Intella
Intella stores what you and the people you work with put into the product:
- the handle you claim. Handles are permanent and are not given to someone else;
- your Home, and any shared workspaces you create or join, including the name, handle, visibility (open with the link, or invite-only), and the default access for content in that workspace;
- membership (admin or member) and invitations, which store the invited email address and the role;
- apps you add: title, the URL you choose, an optional path, optional HTML, an icon, and a site title. The URL can be a public site, a host on your local network, or a Tailscale address;
- whether an app should open right after you save it. That choice is stored on your account;
- pages you write: title and the HTML you save;
- data a page saves for a signed-in viewer (a server store used in place of browser storage inside that page);
- sharing on each app and page: only you, workspace admins, workspace members, named people, or anyone with the link. A named grant stores an Intella account or an email address;
- people, notes, tasks, workflows, and decisions, when those parts of the product are used. A hosted production database starts empty. Intella does not load demo content into production.
The browser may keep interface state on the device, such as a last-used app icon. That device storage is not the account database.
Cookies
After sign-in, Intella sets an HttpOnly, SameSite=Lax session cookie. On an https hosted deployment the name is __Host-intella_session and the cookie is marked Secure. Otherwise the name is intella_session. The cookie is a server-signed session for the account. It does not contain a Google password or a Google access token. On the hosted service it lasts 7 days. On a private install it lasts 30 days. Either way it is refreshed while you keep using Intella. The cookie is for the address in the browser bar. Another address, including loopback versus a Tailscale name, needs its own sign-in.
During the Google redirect, Intella sets a cookie named intella_oauth for about 10 minutes. It carries the sign-in state check and the return path.
Signing out clears the session cookie in that browser. Claiming a handle, and deleting an account, also invalidate other sessions for that account.
Server logs
The server writes request logs so the operator can run and protect the service. A log line includes the time, HTTP method, URL, status code, response time, and client IP address. Server errors are logged with the error. Intella does not add an analytics product or an advertising network. Logs stay with the host that runs Intella. They are not copied into the account record. This policy does not set a separate retention period for those host logs.
Public app-icon lookups are counted in memory, per IP address, for a few seconds, so one address cannot fetch icons without a limit. That count is not written to the database.
How information is used
Intella uses the information above to provide the product, authenticate you, enforce the access you set, deliver invitations, store and show the content you create, and operate and secure the service.
Intella does not sell personal information. Intella does not use it for advertising and does not share it with an advertising network or a data broker.
Sharing and public links
Home content starts private to you. You can mark an app or page for named people, or for anyone with the link. Anyone-with-the-link content can be opened with no Intella account and no Google sign-in. A link you treat as public is public.
A shared workspace is either invite-only or open with the link. Invite-only workspaces are limited to members. Anyone-with-the-link content is available only when the workspace itself is open with the link. Workspace admins can see the name, email, and profile photo of members, and the email address on a pending invite.
Your handle is part of the address for your home (/u/your-handle) and for a shared workspace (/your-handle).
Third-party sites and fonts
An app loads a URL you choose, including inside an embed. That site is not operated by Intella, and its privacy policy covers what it collects when your browser opens it. When Intella looks up an icon for an app, the server may request that URL. The site then sees a request from the server.
The profile photo is a URL from Google. When the interface shows it, your browser loads the image from Google.
Intella pages load typefaces from Google Fonts (fonts.googleapis.com and fonts.gstatic.com). Your browser contacts Google for those font files. Google’s privacy policy applies to that request. The font request does not include your apps, pages, or workspace contents.
Retention and deletion
Account and content data stay in the deployment’s database until they are deleted. Intella does not expire accounts on a timer.
You can delete your account in Settings. Open Settings and choose Delete account at the bottom of the page. Intella lists what will be removed, including the name of each shared workspace that will be deleted because you are the only admin and how many other members lose access. You confirm by typing your handle.
Deletion removes:
- your user record (email, name, and profile photo URL) and signs you out on every device;
- your private Home and everything in it, including apps, pages, page files, and page data stored for you;
- every shared workspace where you are the only admin, including its apps, pages, files, icons, members, invitations, and membership requests. Other members of those workspaces lose access;
- your membership in shared workspaces that have another admin. Content in those workspaces stays for the people who still have access. Your name is removed from creator and invitation attribution on what remains;
- pending invitations you sent, invitations addressed to your email, membership requests you made, and access grants tied to your account or email;
- your saved and visited workspace list;
- the choice of whether an app opens after you save it.
Your handle is removed and someone else can claim it. Deleting the account does not leave your email, name, or photo on that handle. A shared workspace deleted because you were the only admin has its handle removed the same way.
Backups are kept for a limited period. After that they roll off.
Server request logs may still contain the time, HTTP method, URL, status code, response time, and client IP address for requests that already happened, including the deletion request. Those lines do not add your email, name, handle, or profile photo. Intella does not copy logs into the account record.
You can also email support@myintella.com from the email on the account to ask for deletion, or for a copy of the account data Intella stores.
You can remove an app or a page, leave a workspace, or delete a shared workspace you administer, without deleting the whole account. Removing an app removes it from Intella. It does not delete the website the app pointed at.
Children
Intella is not directed at children under 13. The operator does not knowingly create accounts for children under 13. If a child under 13 has an account, delete it in Settings, or email support@myintella.com from that email and ask for the account to be deleted.
Where information is processed
The operator runs Intella as an individual. There is no separate European establishment and no data-protection officer. Account and content data are stored in the Postgres database configured for the deployment you use. That database and the server may be in a country other than yours. Google processes sign-in under Google’s terms and privacy policy.
Changes to this policy
If this policy changes, the updated version will be posted at https://docs.myintella.com/privacy-policy and the date below will change.
Contact
Operator: Michael Wagner, operating Intella.
For privacy questions, support, a copy of your account data, or a deletion request, email support@myintella.com.
Terms of use: https://docs.myintella.com/terms-of-use.
Effective date and last updated: 28 September 2026.