Privacy Policy
Irisen reads your life data so it can tell you the truth about it. That only works if you trust where the data goes. This page explains exactly what we collect, why, and what we will never do with it.
1
Who we are
Irisen is operated by Irisen Limited, a company registered in New Zealand under company number 9421412 (NZBN 9429053594211), with a registered office at 255 Royal Road, Massey, Auckland 0614, New Zealand.
Irisen Limited is the entity responsible for the personal data described in this policy: the data controller under the UK GDPR and the EU GDPR, and the agency holding your personal information under the New Zealand Privacy Act 2020. Irisen is available worldwide, so more than one of these may apply to you. You can reach us at privacy@irisen.ai.
2
What we collect
We collect three kinds of data, and you control the second and third.
We do not buy personal data about you from data brokers, and we do not build advertising profiles.
3
Why we use it
- To run Irisen. Storing your tasks, habits, goals and notes, and syncing them across your devices.
- To calculate your pillar scores. Physical, mental, financial and social scores are derived from the data you enter and the sources you connect.
- To let Iris answer questions about your own data. Iris is grounded in your account so its answers cite what actually happened.
- To keep the service secure and to detect abuse, fraud and outages.
- To bill you if you are on a paid plan.
- To contact you about service changes, security matters and, only if you opt in, product news.
Our legal bases are contract (running the service you signed up for), legitimate interests (security, abuse prevention, product improvement), consent (optional connections such as Gmail, health and financial data, and marketing email) and legal obligation (tax and accounting records).
Where a connection involves health data or other special category data, we rely on your explicit consent, which you can withdraw at any time by disconnecting the source.
4
Google user data
Irisen only accesses Google user data after you sign in with Google or connect a Google feature. We request the narrowest scopes needed for the feature you turned on.
- Sign in. Basic profile and email address, to create and authenticate your Irisen account.
- Google Calendar. To show your calendar inside Irisen and to measure how your time is actually spent against your pillars.
- Gmail. To let you read and send mail from Irisen when you ask it to. Iris does not send mail on your behalf without your confirmation.
Irisen's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, we do not use it for advertising, we do not transfer it to third parties except as needed to provide or improve the features you turned on, to comply with law, or as part of a merger or acquisition with your notice, and we do not allow humans to read it except with your explicit consent, for security or legal reasons, or on data that has been aggregated and de-identified.
You can disconnect Google at any time in Irisen's settings, or revoke access from your Google account permissions page. Once revoked, we delete the associated tokens and cached Google content within 30 days.
5
How Iris uses your data
Iris is the AI inside Irisen. When you ask Iris a question, the relevant parts of your Irisen data are sent to a model provider to generate the answer.
- We use enterprise model APIs with zero data retention or no-training terms where offered by the provider.
- Your data is not used to train third party foundation models.
- We do not use your personal content to train models for other Irisen users.
Our current model providers are listed at irisen.ai/subprocessors. We will update that list before adding a new one.
6
Who we share it with
We never sell your personal data. We share it only with service providers who help us run Irisen, under contract and only for that purpose:
- Cloud hosting and database providers
- AI model providers, for the Iris features described above
- Payment processing
- Error monitoring and product analytics
- Email delivery
A current list of subprocessors is at irisen.ai/subprocessors. We may also disclose data where required by law, or to protect the rights and safety of users and the public.
7
Where your data is stored
Irisen stores data on servers located in Sydney, Australia. Some of the companies that process data for us are based elsewhere, including in the United States, so your data does leave that region in the course of running the service. The full list is at irisen.ai/subprocessors.
Where data covered by the UK or EU GDPR leaves the UK or the EEA, we rely on adequacy decisions or on Standard Contractual Clauses together with appropriate additional safeguards. Where personal information covered by the New Zealand Privacy Act 2020 is disclosed to a provider overseas, we take reasonable steps to satisfy ourselves that comparable safeguards apply, as principle 12 requires.
8
How long we keep it
- Account and content data: for as long as your account is open.
- After you delete your account: erased from live systems within 30 days and from backups within 90 days.
- Connected source data: deleted within 30 days of disconnecting that source.
- Billing records: retained for as long as tax law requires, typically six years.
9
Security
Data is encrypted in transit with TLS and at rest. Access to production systems is limited to staff who need it, protected by multi factor authentication and logged. We review access regularly. No system is perfectly secure, and if a breach affects your data we will notify you and the relevant regulator as the law requires.
10
Your rights
Wherever you live, you can ask us for a copy of your data, ask us to correct it, and ask us to delete it. Export and deletion are available directly in Irisen's settings. For anything else, email privacy@irisen.ai and we will respond within one month.
Some places give you more, and you keep whichever rights apply to you:
- New Zealand — under the Privacy Act 2020 you can ask for access to the personal information we hold about you and ask us to correct it.
- United Kingdom and the EEA — under the UK and EU GDPR you can also ask us to restrict or object to how we use your data, ask for it in a portable form to send to another provider, and withdraw consent at any time, which does not affect processing that already happened.
- United States — depending on your state, you may have the right to know what personal information we collect and why, to have it deleted or corrected, and to opt out of its sale or sharing. We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
If you are unhappy with our response, you can complain to the regulator where you are. In New Zealand that is the Office of the Privacy Commissioner, privacy.org.nz. In the United Kingdom it is the Information Commissioner's Office, ico.org.uk. In the EEA it is your local supervisory authority. In the United States, residents of states with a privacy statute can contact their state Attorney General.
11
Children
Irisen is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has given us data, email privacy@irisen.ai and we will delete it.
12
Cookies
We use cookies that are strictly necessary to keep you signed in and to keep the service secure. We use limited analytics cookies to understand how the product is used; you can decline these without losing functionality. We do not use advertising or cross site tracking cookies.
13
Changes
If we make a material change to this policy we will tell you by email or in the product before it takes effect. The date at the top always reflects the current version.