Privacy Policy
Irisen builds Iris, a personal AI that works from the life data you choose to share. We do not sell your personal data. We do not run ads against it. This page explains what we collect, why, who helps us process it, and the controls you have.
1. Who we are
Irisen Ltd (“Irisen”, “we”, “us”) operates irisen.ai, the Iris web app at app.irisen.ai, optional desktop software (Irisen), and related services (together, the “Services”). Contact: hello@irisen.ai.
2. Scope
This policy covers:
- the marketing site and waitlist;
- accounts on the Iris web app and desktop app;
- optional connectors and out-of-app delivery channels you enable (for example Gmail, Google Calendar, Telegram, or web push).
In-product Help under Data and Privacy summarises the same practices in shorter form. If anything conflicts, this Privacy Policy controls for legal purposes.
3. What we collect
Depending on how you use Irisen, we may process:
- Account data. Email address, authentication identifiers, and profile details you provide (including Google sign-in if you choose it).
- Irisen content you create. Notes, tasks, habits, goals, scores, preferences, Iris chat messages, and similar records stored in your account.
- Optional ambient signals. Structured observations you enable in Settings (for example environment or in-app navigation). Sensitive scopes such as browser history stay off until you opt in and, where required, install the browser extension.
- Optional connectors. Data from services you connect on purpose. Examples of live connectors include Google Calendar (schedule and attendee metadata, not private event notes), Gmail (inbox sync including subjects, snippets, and message bodies used for search you request; Iris does not send mail without your confirmation), Instagram export uploads you provide (including message threads you export), and desktop activity metadata when you run Irisen capture. We only request the access needed for the features you turn on.
- Desktop capture (when enabled). Activity and focus-oriented signals such as app usage patterns and related metadata you allow. Long-term storage is oriented around aggregated or derived activity metadata rather than keeping full screenshots as a permanent archive. Continuous screen video recording and always-on ambient microphone capture are not offered as live product features.
- Reach channels. If you enable Web Push or Telegram, we store the channel details needed to deliver messages you asked for (and inbound Telegram text may be stored for triage as untrusted inbox content).
- Usage and diagnostics. Technical logs, approximate activity timestamps, error reports, and billing or token usage metadata needed to run and secure the service.
- Waitlist. Email address (and optional campaign tags) submitted on irisen.ai.
Bank account connectors and wearable device connectors may appear in our codebase or docs as future options. They are not live product surfaces unless we clearly enable them and you connect them yourself.
4. How we use data
We use personal data to:
- provide, sync, and secure your Iris account and content;
- generate Iris responses and personalised guidance from context you store or connect;
- run optional features you enable (connectors, capture, reach, exports);
- send waitlist or account-related email;
- measure product health, prevent abuse, and meet legal obligations;
- support you when you ask for help (with access limited by role; private life content is not treated as a staff browsing dump).
5. How we do not use data
- We do not sell your personal data.
- We do not share it with advertisers, data brokers, or researchers for their own use.
- We do not use your private life content to train public foundation models for unrelated third parties.
- We do not show advertising inside Iris funded by mining your account.
Irisen’s business model is paid access for people who use the product, not monetising a secondary market in your data.
6. AI processing
To generate Iris replies and related AI features, we send relevant prompts and context to language-model providers that process data on our instructions as service providers (currently Anthropic’s Claude API is the primary backbone). That processing is for providing the feature to you. It is not a sale of your data, and it is not sharing with advertisers.
You control much of what enters that context by what you store, connect, and enable in Settings.
7. Service providers
We use infrastructure and vendors to operate the Services. They process data only to provide their service to us (or as otherwise required by law), not to sell your data. Categories include:
- Hosting and app delivery (for example Vercel for web hosting).
- Database, auth, storage, and edge compute (Supabase).
- AI inference (Anthropic and any successor providers we disclose in product or this policy).
- Auth and optional Google connectors (Google, when you use Google sign-in, Calendar, or Gmail).
- Waitlist forms (Formspree on the marketing site).
- Optional messaging (for example Telegram or browser push services when you enable Reach).
When you connect a third-party account, that provider’s own privacy terms also apply to data held in their systems.
8. Staff access
Irisen staff tools are built around business operations and support (account identity, adoption, cost, and ticket metadata), not open browsing of capture frames, health portals, or full chat archives. Break-glass access to act as a user, if ever used, is restricted, audited, and time-boxed.
9. Retention, export, and deletion
- Retention. We keep account data while your account is active and as needed for backups, security, and legal duties. Some desktop or observation data may also follow retention settings you configure in the product.
- Export. You can download a full account snapshot from Settings → Data Safety.
- Deletion. You can delete your account from Settings → Danger Zone. By default Irisen schedules removal after a grace period (typically 30 days) so you can cancel if you change your mind; you may also choose immediate deletion where offered. After completion, server data under your account is wiped and login stops working. Clearing only local browser or device copies does not delete the server account.
For access, correction, or deletion requests you cannot complete in-product, email hello@irisen.ai.
10. Security
We use industry-standard controls appropriate to a cloud personal-data product, including encrypted transport (HTTPS), authentication, and row-level access controls so other customers cannot read your account. No method of transmission or storage is perfectly secure; please use a strong unique password and protect your devices.
11. International transfers
Irisen is based in New Zealand. Our providers may process data in other countries (including the United States). Where we transfer personal data internationally, we take steps designed to keep it protected in line with this policy and applicable law.
12. Children
The Services are not directed at children under 16. We do not knowingly create accounts for children under 16. If you believe a child has provided personal data, contact us and we will take appropriate steps to delete it.
13. Your choices
- Do not create an account, or delete it when you are done.
- Leave optional collection scopes and connectors off; connect only what you want Iris to use.
- Disconnect Google, Gmail, Telegram, or other channels from Settings when you no longer want them linked.
- Pause or configure desktop capture in Capture settings on Irisen.
- Export your data before major changes or deletion.
14. Changes
We may update this policy as the product or law changes. We will post the updated version at https://irisen.ai/privacy with a new effective date. Material changes may also be called out in-product or by email when appropriate.
15. Contact
Privacy questions: hello@irisen.ai
Irisen Ltd, Auckland, New Zealand