Irisen Home Log in
Legal

Privacy Policy

Effective 9 August 2026 · Irisen Ltd · Auckland, New Zealand

Irisen builds Iris, a personal AI that works from the life data you choose to share. We do not sell your personal data. We do not run ads against it. This page explains what we collect, why, who helps us process it, and the controls you have.

1. Who we are

Irisen Ltd (“Irisen”, “we”, “us”) operates irisen.ai, the Iris web app at app.irisen.ai, optional desktop software (Irisen), and related services (together, the “Services”). Contact: hello@irisen.ai.

2. Scope

This policy covers:

In-product Help under Data and Privacy summarises the same practices in shorter form. If anything conflicts, this Privacy Policy controls for legal purposes.

3. What we collect

Depending on how you use Irisen, we may process:

Bank account connectors and wearable device connectors may appear in our codebase or docs as future options. They are not live product surfaces unless we clearly enable them and you connect them yourself.

4. How we use data

We use personal data to:

5. How we do not use data

Irisen’s business model is paid access for people who use the product, not monetising a secondary market in your data.

6. AI processing

To generate Iris replies and related AI features, we send relevant prompts and context to language-model providers that process data on our instructions as service providers (currently Anthropic’s Claude API is the primary backbone). That processing is for providing the feature to you. It is not a sale of your data, and it is not sharing with advertisers.

You control much of what enters that context by what you store, connect, and enable in Settings.

7. Service providers

We use infrastructure and vendors to operate the Services. They process data only to provide their service to us (or as otherwise required by law), not to sell your data. Categories include:

When you connect a third-party account, that provider’s own privacy terms also apply to data held in their systems.

8. Staff access

Irisen staff tools are built around business operations and support (account identity, adoption, cost, and ticket metadata), not open browsing of capture frames, health portals, or full chat archives. Break-glass access to act as a user, if ever used, is restricted, audited, and time-boxed.

9. Retention, export, and deletion

For access, correction, or deletion requests you cannot complete in-product, email hello@irisen.ai.

10. Security

We use industry-standard controls appropriate to a cloud personal-data product, including encrypted transport (HTTPS), authentication, and row-level access controls so other customers cannot read your account. No method of transmission or storage is perfectly secure; please use a strong unique password and protect your devices.

11. International transfers

Irisen is based in New Zealand. Our providers may process data in other countries (including the United States). Where we transfer personal data internationally, we take steps designed to keep it protected in line with this policy and applicable law.

12. Children

The Services are not directed at children under 16. We do not knowingly create accounts for children under 16. If you believe a child has provided personal data, contact us and we will take appropriate steps to delete it.

13. Your choices

14. Changes

We may update this policy as the product or law changes. We will post the updated version at https://irisen.ai/privacy with a new effective date. Material changes may also be called out in-product or by email when appropriate.

15. Contact

Privacy questions: hello@irisen.ai
Irisen Ltd, Auckland, New Zealand