Privacy Policy
Last updated: August 10, 2026
With Iris ("Iris", "we", "us") is operated by withirishq LLC. Iris helps event businesses close the loop on the questions that land in their inbox: it reads the business conversations you connect, drafts replies for your review, and tracks open questions until they are answered. This policy explains what information we handle to do that, and the choices you have.
The short version. Iris processes only the business conversations and account data needed to provide the features you choose. Your data stays inside your account. We do not sell, license, purchase, exchange, or use it for advertising, and we do not pool it across customers. We do not use it for discrimination, decisions about eligibility for employment, housing, credit, insurance, education, or other regulated services, or for surveillance. Every outbound message requires your approval before it is sent. You can access or export your data, disconnect a channel, or delete your account and its data.
1. Who this policy covers
This policy covers account holders (the business owner and team members who sign in) and, indirectly, the people whose messages appear in the conversations you connect, such as your clients and vendors. You choose which conversations Iris can see. You are responsible for handling your own clients' information lawfully, including any notice or consent your local law requires. We process those conversations on your behalf and on your instructions.
2. Information we collect
Your account
- Name, business name, email address, phone number, city, and timezone.
- Sign-in and session records, including IP address and browser information, kept for security.
- Device registrations for push notifications and for approving outbound messages.
Connected conversations
- Messages from the channels you connect: WhatsApp Business Platform, Instagram messaging, Gmail, and Outlook. A limited Android pilot can also read incoming SMS from senders you have approved.
- This includes message text, sender and recipient identifiers (phone numbers, email addresses, Instagram IDs), subject lines, timestamps, and delivery status.
- For email, Iris works allowlist first: it reads full content only from senders you have approved or messages you have labeled for Iris. For everything else it sees only routing headers, and it keeps a content-free record of what was skipped.
- Attachments are recorded by file name and type only. Iris does not download or store attachment files.
Contacts and events
- Contact profiles for the people you do business with: names, phone numbers, email addresses, category (for example caterer or client), and notes you add.
- Learned interaction patterns per contact, such as typical response time, used to time follow-ups.
- Event details you enter: event names, dates, venues, participants, tasks, and decisions.
Drafts, edits, and memory
- The replies Iris drafts, the version you actually send, and the difference between them. This is how Iris learns your voice. It stays inside your account.
- Facts Iris remembers from your conversations (for example a confirmed guest count), stored with their source.
- De-identified interaction records inside your account, with phone numbers, emails, and amounts masked, used to improve how Iris works for you.
- WhatsApp and Instagram message text, drafts, and sender identifiers are never copied into a shared or general model-training corpus. Iris may process them to provide the connected account's requested features, but the training capture path blocks Meta-derived data.
Voice notes
- When you speak to Iris, the audio is streamed for transcription and then discarded. We store the transcript only. Audio recordings are never saved.
Calendar
- If you connect a calendar, Iris reads busy windows only: start and end times. Event titles, attendee lists, and locations are excluded by design. Calendar events Iris helps create are made only with your approval.
Billing
- Payments are processed by Razorpay. We store your subscription status and invoices. We never see or store card numbers.
3. How we use information
- To run Iris for you. We classify incoming messages, prepare replies for your review, answer questions from your own records with the source attached, track open questions, maintain the event workspace, and carry out an action only when you request or approve it.
- To improve your own Iris. Voice learning, memory, and account-level preferences are built from your account's data and apply only to your account.
- To keep the service secure and running. We use limited security and delivery records for authentication, abuse prevention, debugging, reliability, and support.
- To bill you and comply with law. We maintain subscription and invoice records needed to operate the service and meet legal obligations.
We do not sell, license, purchase, or exchange personal information or Platform Data. We do not use it for targeted or behavioral advertising. We do not use it to discriminate or to determine a person's eligibility for employment, housing, credit, insurance, education, immigration, health care, or another regulated service. We do not use it for surveillance, law-enforcement profiling, or to build or enrich profiles unrelated to the service the account holder requested.
We request and process only the Meta permissions and data needed for the visible WhatsApp and Instagram features the account holder enables. Meta-derived WhatsApp and Instagram message bodies, drafts, and sender identifiers are not placed in a shared or general training corpus.
4. AI processing
Iris uses Anthropic's Claude models to classify messages and prepare drafts. Message content and relevant context from your account are sent to Anthropic's API only to provide those features. Under Anthropic's commercial API terms, API data is not used to train Anthropic's models.
Iris does not use your data or your contacts' data to train a model shared across customers. Account memory and voice learning stay tenant-specific. WhatsApp and Instagram message bodies, drafts, and sender identifiers are also blocked at the code boundary from Iris's training-capture corpus. We do not permit a processor to use personal information or Platform Data for its own advertising, profiling, model training, or any other independent purpose.
5. Google user data and Limited Use
Iris's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Gmail read access is used to poll for new mail and read full content only from senders you approved or messages you labeled for Iris.
- Gmail compose access is used only to keep a copy of Iris's draft in your Gmail Drafts. That code path cannot send.
- Gmail send access is used only after you explicitly approve a specific reply.
- Calendar access reads availability windows and creates or edits events only with your approval, on the calendar you chose.
- Google user data is shared with a third party only as needed to provide these visible features (processing by Anthropic as described above). It is never used for advertising, never sold, and never used to train generalized AI or machine learning models.
- No human reads your Google data except with your explicit permission for support, for security investigation, or where the law requires it.
6. WhatsApp and Instagram
Iris connects to WhatsApp through the official WhatsApp Business Platform and to Instagram through Meta's official messaging APIs, under the account holder's own business accounts and Meta's terms. Incoming webhooks are cryptographically verified. Messaging through these channels is also governed by Meta's policies, including WhatsApp's customer-service-window rules.
We request the minimum Meta permissions and data needed for the features the account holder turns on:
- Instagram basic account identity, limited to the connected professional account's ID and username, so the account holder can verify and disconnect the right account.
- Instagram messaging, limited to receiving direct messages and sending the specific reply the account holder approved.
- WhatsApp messaging, limited to receiving messages and sending a reply or approved template after the account holder approves it.
- WhatsApp business management, limited to the connected business account and phone-number information needed to operate messaging and to create or read the status of message templates used by Iris.
We do not request followers, media libraries, insights, advertising data, or unconnected accounts for these features. We do not sell, license, purchase, exchange, advertise with, discriminate with, surveil with, or train shared or general models on WhatsApp or Instagram message bodies, drafts, or sender identifiers.
Disconnecting WhatsApp or Instagram stops future collection through that connection and removes Iris's stored connection credentials. It does not, by itself, erase messages already imported into the account; the account holder can retain them as business records or delete the account as described in section 11. The account holder can also remove Iris in Meta Business or Instagram settings to terminate Meta-side access.
7. Who we share information with
We disclose personal information only to a direct provider that is necessary to provide, secure, support, or bill for the feature the account holder requested, or where law requires disclosure. Each provider may process the data only for that necessary service. We do not authorize independent advertising, sale, licensing, profiling, shared-model training, or other independent use.
| Direct provider | Necessary purpose | Processing or access location |
|---|---|---|
| Microsoft Azure | Iris application hosting and secret storage | Central India |
| Supabase | Database, authentication, and live updates | Primary data region: Mumbai, India; limited corporate or support access may occur from Singapore or the United States |
| Anthropic | AI classification and drafting | United States |
| Sarvam AI | Voice transcription, only with the account holder's consent | India; Sarvam's policy permits some processing or support from the United States |
| Meta Platforms | WhatsApp and Instagram messaging, only when connected | Global, including the United States |
| Gmail and Google Calendar, only when connected | Global, including the United States | |
| Firebase Cloud Messaging | Push notifications to an enrolled device | Global, including the United States |
| Microsoft | Outlook and Microsoft Calendar, only when connected | Global, including the United States |
| Razorpay | Payments and invoicing | India |
| Sentry | Error monitoring, with message content excluded; pseudonymous account/request identifiers may be retained, only if configured | United States or European Union |
| Netlify | Hosting the public withirishq.com website | United States |
Push notifications can include a short preview and sender identifier so the account holder can decide whether to open Iris. The account holder can disable notifications at the device level. Sentry is conditional: if it is not configured, no data is sent to Sentry.
8. Where your data lives
Iris's application servers run in Azure Central India. The primary Supabase database and authentication region is Mumbai, India. Supabase may provide limited corporate or support access from Singapore or the United States. Anthropic processes AI requests in the United States. Sarvam primarily processes voice transcription in India and may involve the United States as described in its policy. Meta, Google, Firebase Cloud Messaging, and Microsoft operate global networks, including in the United States. Sentry, if configured, operates in the United States or European Union.
Where data crosses borders, it does so only to provide, secure, support, or bill for the feature described in this policy. Cross-border access does not change the restrictions in sections 3, 4, and 7.
9. Security
- Channel credentials and access tokens are encrypted at rest with AES-256-GCM.
- Every customer's data is isolated with database row-level security. Access to one account can never return another account's rows.
- All connections use TLS. Our database connections additionally pin the provider's certificate authority.
- Every outbound send requires a cryptographic signature from a device you enrolled. Without it, nothing sends.
- Message content is excluded from operational logs, and phone numbers in logs are masked.
- Every state-changing action is recorded in an audit log you can export.
10. Retention
We keep account content while the account is active so Iris's memory and event workspace can do their job. Voice audio is not retained after transcription; the transcript is kept as an account note. Webhook delivery diagnostics are deleted after seven days, including diagnostics received before Iris could resolve them to an account. Processed operational queue records have separate reliability retention. Pending or terminal-failure queue records remain only for delivery recovery and operator investigation, and every tenant-linked queue payload is removed during permanent account erasure.
When an account holder deletes the account, active access stops immediately and the deletion schedule in section 11 applies.
11. Deleting your data
The account holder can disconnect a channel at any time in Settings. Iris stops future collection through that connection and removes the stored credentials. For Google, Iris also revokes its own Google access token. For Microsoft and Meta channels, the account holder can additionally remove Iris in Microsoft account or Meta Business/Instagram settings. Disconnecting a channel does not automatically erase messages already imported into the Iris account.
The owner can request account deletion by following the steps on our data deletion page. We confirm an emailed request within 2 business days. Access is blocked when the request is accepted, and the 30-day recovery window begins at that moment. After that window, the account enters the permanent-erasure process. Iris ordinarily targets completion of active-system erasure within 30 days after the recovery window closes.
Before Iris removes the local user and account rows, it deletes every associated Supabase Auth identity. If a provider outage, provider rejection, or privacy-system configuration issue blocks safe completion, Iris leaves the local account inaccessible but intact, alerts its operator, and retries after the issue is resolved; it does not report the local purge as complete first. Permanent erasure removes messages, contacts, events and workspace data, drafts, voice transcripts, memory, consents, stored channel credentials, durable queued-job payloads, webhook diagnostics, and other tenant-linked records. If provider identity deletion succeeds but a later active-system database step fails, the account remains inaccessible and its local rows remain isolated and soft-deleted. Iris alerts the operator and retries the local purge; it does not report erasure as complete until that purge succeeds.
The retained Iris security record is deliberately narrow: the audit action, timestamp, and a one-way tenant tombstone used to correlate security events. The actor, email, IP address, user agent, target, and payload content are removed or replaced with a redaction marker. Payment providers or tax records may be retained separately where law requires them.
Backups are isolated from the active service and are not used to provide the product after deletion. They cannot be edited one record at a time. Deleted data can remain in encrypted point-in-time recovery or backup copies until those copies expire under the provider schedules configured for Iris. If a backup is restored for disaster recovery, valid deletion requests must be reapplied before the restored data is returned to service. Contact us for the currently verified maximum recovery-copy retention period.
12. Your rights
You can access, correct, export, or delete your information and withdraw consent for optional processing such as voice transcription. The owner can request a machine-readable JSON export by emailing divya@withirishq.com. Iris produces the export through its owner-only, tenant-scoped export process. It includes account metadata, users, connected-channel status, messages, drafts, contacts, events and workspace records, memory, consent history, billing metadata, and relevant security activity. It excludes passwords, session and device credentials, access or refresh tokens, app secrets, encrypted ciphertext, service-role material, internal queue/sync/routing/rate-limit state, retired provider-specific configuration or diagnostics, and cross-customer or global reference data.
The export process refuses with a clear error rather than silently truncating if it exceeds its published record or response-size safety limit. We then provide a secure assisted export.
Account holders in India have the rights provided by the Digital Personal Data Protection Act, including grievance redressal. To exercise a right or ask a privacy question, email divya@withirishq.com. We will respond within 30 days.
13. Cookies and tracking
This website sets no advertising or analytics cookies and runs no trackers. The application stores only what sign-in requires: your session, kept on your own device. We use Sentry for error monitoring with personal identifiers masked, and both the website and the application load fonts from Google Fonts, which involves a standard web request to Google's servers.
14. Children
Iris is a business product for adults. It is not directed to anyone under 18, and we do not knowingly collect information from minors.
15. Changes to this policy
When this policy changes materially, we will notify account holders by email or inside the product before the change takes effect, and update the date at the top of this page.
16. Contact
withirishq LLC · divya@withirishq.com