Privacy Policy
Last updated: 5 September 2026.
This Privacy Policy explains how Ultima AI, Inc., a Delaware corporation (United States) ("Ultima," "we," "us"), handles information in connection with Infinite Growth OS, the Infinite desktop application, infinite.fast, and related hosted services (together, "Infinite" or the "Service"). Infinite is local-first, but some features use Infinite-hosted cloud infrastructure. This policy identifies those boundaries instead of treating every workflow as device-only.
1. Who we are
Ultima AI, Inc., a Delaware corporation (United States).
Contact: support@ultima.inc
2. Local and hosted processing
The Infinite desktop application performs substantial work on your device and can keep local project and execution data there. Account, workspace, collaboration, connector, analytics, and other hosted features may also send data to or store data in Infinite's cloud services when you enable or use them. The product surface should identify whether a feature is local or hosted before you connect data or run an action.
- Local data remains under your device and operating-system controls.
- Hosted workspace data is processed to provide the features you request, enforce workspace access, synchronize supported providers, and operate the Service.
- Credentials and tokens are limited to the connection and feature you authorize and are protected in transit and at rest. Bring-your-own credentials may remain local where the product explicitly says so; hosted connections necessarily send credentials or delegated tokens to the hosted execution boundary.
- We do not sell connected-source or website analytics data.
3. Google user data
Google Analytics 4
If you connect Google Analytics, Infinite uses the Google authorization mode shown in the product. A device-only connection reads authorized data to your device. A hosted connector processes the authorized metrics and credentials in Infinite's cloud so it can synchronize the workspace and provide the hosted feature you requested.
- Scopes requested: the hosted Google Analytics connection requests read access (
analytics.readonly) and edit access (analytics.edit) during connection. Infinite uses read access for reports and edit access to provision the workspace's declared conversion events as GA4 key events. - How it is used: to read authorized Google Analytics metrics, compute the summaries and insights you request, synchronize a hosted workspace when enabled, and perform setup changes you explicitly initiate. We do not use Google user data for advertising, and we do not sell it.
Connection modes
You may use your own Google app or Infinite's Google app where those choices are offered. The product must identify whether token exchange and subsequent API calls are device-only or hosted. Hosted credentials are encrypted and access-controlled; local credentials remain under your device controls.
- Use your own Google app. API usage is associated with your Google Cloud project. Storage and execution follow the local or hosted mode shown when you connect it.
- Use Infinite's Google app. Google's consent screen identifies Infinite and API usage may use Infinite's shared quota. The authorized scope is still limited to the connection and features you request.
- Where it is stored: in the local store for device-only connections and in the protected hosted workspace store for hosted connections, according to the mode you enable.
- Sharing: hosted connections use service providers to store and process authorized data on our behalf. When you request AI assistance using connected data, relevant context may be sent to your selected model provider, as described in section 6. We do not sell Google user data or use Google Analytics data for advertising.
- Limited Use: Infinite's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Revoking access: you can disconnect Google Analytics at any time inside Infinite, and you can revoke access directly at https://myaccount.google.com/permissions.
Other Google connections
Google sign-in and each optional integration serve different purposes. Connecting one service does not automatically connect the others.
- Google sign-in: account identity information is used to authenticate you and associate your Infinite account and workspace.
- Google Search Console: read-only access (
webmasters.readonly) reads your authorized sites and search performance for SEO reporting and recommendations. - YouTube:
youtube.readonlyidentifies your connected channel;youtube.uploaduploads videos you approve;youtube.force-sslsupports adding captions and comments as part of publishing. These permissions are requested when you connect YouTube. - Google Ads:
adwordssupports reading advertising performance and managing campaigns through the connected account. It is requested when you connect Google Ads.
Storage and protection: hosted integrations store connection identifiers, encrypted OAuth credentials, and the data and results needed to provide your connected workspace features. Access is restricted to authorized workspace and service operations. Local workflows use the local storage boundary described above.
Retention and deletion: connected data is retained while needed to provide your workspace, subject to the retention and backup limits in section 7. Revoke future Google access at Google Account permissions. Revoking access does not by itself erase previously stored records; contact support@ultima.inc to request deletion of Google connection data and credentials held by Infinite.
4. Other connected sources
For PostHog, Stripe, Shopify, Meta, X, and other sources, the product identifies the requested scopes and whether execution is local or hosted. Connected data is used to provide the analysis or action you request. Hosted credentials and data are workspace-scoped and access-controlled; device-only credentials remain under your device controls.
5. Website visitor analytics
On infinite.fast, Infinite first-party analytics, Google Analytics 4, and PostHog measure website use by default. Optional X or Meta campaign pixels also initialize when configured. The browser destinations are independent: disabling or blocking one provider does not imply that the others are disabled.
- Browser events: Infinite receives page views, structural CTA clicks, and clicks on the same-origin download route. Google Analytics and PostHog receive page views and interaction events under their configured terms. Infinite's public event envelope does not contain query strings, link text, DOM text, workspace identity, source authority, or environment choice.
- Browser storage: Infinite uses a random visitor identifier in local storage and a random session identifier in session storage. PostHog, Google Analytics, and configured campaign pixels may use their own cookies or browser storage under their published terms.
- Privacy signals: when the browser exposes Do Not Track or Global Privacy Control, the Infinite first-party browser runtime suppresses its browser events, and Google Analytics, PostHog, and any configured campaign pixels do not initialize unless you grant analytics through the on-site prompt. A saved denial keeps all of them off. Providers may additionally be blocked by browser settings or extensions.
- Get-started sign-in handoff: when you verify with Google or verify your email code on
/get-startedbefore downloading, we create a one-time sign-in grant (a "claim") for that account. Google sign-in via Supabase Auth uses same-tab session storage for the PKCE redirect exchange; OAuth tokens may live there only for the few seconds needed to mint the one-time claim, then the page signs out locally and purges every Supabase auth key. The site never writes Google tokens to local storage. The claim expires after 48 hours, can be redeemed once, and only lets the Infinite desktop app open already signed in to the account you just verified; it authorizes nothing else. We store the claim identifier, a one-way hash of the claim secret (never the secret itself), the verified email and account identifier, the button you started from, and the timestamps; the record is removed after 90 days. A claim is created only after Google verifies server-side or the emailed code verifies - typing an email alone creates nothing. If analytics is permitted, the claim carries the same rotating visitor and session identifiers the ledger uses so we can count how many verified visitors open the app; under Do Not Track, Global Privacy Control without a site grant, a saved denial, blocked storage, an unverified host, or a dormant site source those ids are omitted, and we never fill the gap from IP address or timing. Before Google redirects, the page stores only the originating button, UTM source / medium / campaign values, click-id presence booleans (not raw click-id values), the Google gate method marker, and Supabase's same-tab PKCE state in session storage. Downloading the app never opens it; the app is opened only by your own click on Open Infinite (on the page or in the confirmation email). - Advertising conversion measurement: when we run Meta or Google advertising, we tell those platforms which ad clicks led to a verified sign-up so their bidding stops optimising for clicks alone. A Meta pixel is present on
infinite.fastonly when we have configured it, and like every other campaign pixel it initializes only if analytics is permitted. When you complete/get-startedwith analytics permitted, the page reads the values of Meta's own_fbcand_fbpcookies (and a Google click identifier only if one is present on the/get-startedaddress at that moment - it normally is not) and sends them to our server inside the same request that creates your sign-in claim; our server forwards them to Meta or Google in that same moment and does not store, log, or queue them, and the page never writes them to browser storage or to any analytics provider. Separately, our server reports the verified sign-up (and later a first paid subscription) to Meta and Google Ads as a conversion using a one-way hash of the verified email address - never the address itself - together with the claim identifier as a duplicate-suppression key; the browser fires the same Meta event with the same key so the two are counted once. We keep only a record that a conversion was reported (platform, event, identifier, status): no email, no hash, and no click identifier. Under Do Not Track or Global Privacy Control without a site grant, or a saved denial, the page reads and forwards none of these identifiers. - Server observations: server collection uses Vercel production document-request and
/downloadredirect logs. This request/redirect collection is not controlled by browser settings because the server necessarily receives a request in order to serve or redirect it. Known bots and previews are filtered, and this lane remains separate from browser views. - Purpose: site reliability, aggregate audience measurement, conversion analysis, and comparison of the three browser providers during the shadow period.
- Accuracy: no analytics system captures mathematically 100% of people. Browser blocking, privacy signals, bots, network delivery, and provider processing can produce different totals.
Sign-in claim records - the claim identifier, the one-way hash of the claim secret (never the secret itself), the Google-verified or email-code-verified email and account identifier, the starting button, any consent-qualified visitor and session identifiers, and the issue, expiry and redemption timestamps - are retained for 90 days and then removed. They are readable only by our own service role.
Raw website ledger events are retained for 90 days and daily first-party aggregates for 25 months. Provider-side Google Analytics and PostHog data follows the retention configured for those services and their processor terms. Current website processors include Vercel for hosting and Drain delivery, our database/cloud infrastructure providers for the first-party ledger, PostHog, and Google Analytics. X and Meta are additional processors only when their optional pixels are configured; Meta and Google Ads also receive the server-side conversion reports described above when that reporting is configured.
You can review or change a saved analytics decision for this website at any time:
6. Hosted features and AI sub-processors
Account information, hosted workspace context, requested action inputs, and saved results may reach our servers when you use hosted features. When you run a hosted AI action, the data needed for that action may be processed by model providers acting as our sub-processors — currently Anthropic and/or OpenAI — under the applicable business/API terms and configured data controls. When you bring your own model or key, your data goes to the endpoint you configure, under that provider's terms.
7. Data retention and deletion
- Local data: controlled entirely by you; delete it by removing the local store or disconnecting sources.
- Hosted workspace data: retained while needed to provide the workspace or until you delete it, subject to legal, security, backup, and fraud-prevention obligations.
- Website analytics: raw Infinite events are deleted after 90 days and daily first-party aggregates after 25 months. Browser controls or extensions may block future browser events; they do not rewrite already aggregated statistics or prevent the server from receiving a request you make.
- Provider data: use Google Analytics, PostHog, X, or Meta controls to manage data those processors hold, and contact us for records under our control.
- Requests: to exercise access, correction, or deletion rights, contact support@ultima.inc.
8. Security
We use administrative, technical, and organizational measures appropriate to the Service, including encryption in transit and protection of credentials and tokens at rest. No method of storage or transmission is 100% secure.
To protect the website, browsers may send Content Security Policy violation reports to us. We log only the sanitized document origin and path, blocked origin and path (or inline, eval, or self), effective or violated directive, and disposition. Query strings, script samples, full policies, account identifiers, and workspace identifiers are not logged. These bounded reports are used only for security diagnostics in Vercel function logs; the exact platform retention receipt remains pending.
9. Children's privacy
Infinite is a business tool not directed to children under 16, and we do not knowingly collect their personal data.
10. International users
If you use the Service outside the United States, you understand that any data sent to our hosted features may be processed in the United States, where Ultima AI, Inc. is incorporated (Delaware).
11. Changes to this policy
We may update this policy; we will post the updated version and, for material changes, provide reasonable notice.
12. Contact
Questions or requests: support@ultima.inc (Ultima AI, Inc.).