Iris

Privacy policy

Last updated: 12 August 2026

This privacy policy explains how we collect, use, store, and protect your personal data when you use Iris (the “Service”), and the rights you have in relation to that data. It applies to the Iris website and to the Briefings we generate and deliver to you.

1. Who we are

The Service is operated by Iris Technology Development Ltd, a company registered in England and Wales under company number 17375272, with its registered office at 82A James Carter Road, Mildenhall, IP28 7DE, United Kingdom. For the purposes of the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018, we are the data controller of the personal data described in this policy.

If you have any questions about this policy or how we handle your data, contact us at support@irisbriefings.com.

2. Personal data we collect

We collect only the data we need to provide the Service. We do not build advertising profiles and we do not use third-party tracking pixels.

CategoryWhat it includesWhy we collect it
Account dataYour email address and display name.To create and secure your Account, sign you in, and address you in your Briefings.
Briefing profileThe role, focus areas, preferences, and other details you enter during onboarding and in your preferences.To personalise and generate your Briefings.
BriefingsThe reports, transcripts, audio files, and topics we generate for you.To deliver the Service and maintain your briefing library.
FeedbackNotes and ratings you leave on individual Briefings.To calibrate and improve the Briefings we generate for you.
Billing dataYour Stripe customer ID and Subscription status. Card details never reach our servers.To take payment, manage your Subscription, and keep required records.
Technical dataData needed to keep you signed in and to operate and secure the Service (for example, your authentication session).To run the Service securely and reliably.

3. Our lawful bases for processing

Under UK GDPR we must have a lawful basis for processing your personal data. We rely on the following:

  • Performance of a contract. To provide the Service you have subscribed to — creating your Account, generating and delivering Briefings, and taking payment.
  • Legitimate interests. To secure, maintain, and improve the Service and to prevent misuse, provided our interests are not overridden by your rights.
  • Legal obligation. To comply with our legal and regulatory duties, including keeping certain billing and tax records.
  • Consent. Where we ask for it — for example, before introducing any optional, non-essential cookies or communications. You can withdraw consent at any time.

4. How we use your data

We use your personal data to:

  • register, authenticate, and secure your Account;
  • generate personalised Briefings and deliver them on your schedule;
  • process payments and manage your Subscription;
  • respond to your enquiries and provide support;
  • maintain, protect, and improve the Service; and
  • comply with our legal obligations.

5. What we do not do

  • We do not sell your personal data.
  • We do not run advertising cookies, pixels, or tracking scripts on the Service.
  • We do not ship your data to marketing tools.
  • We do not permit our AI providers to use your content to train their models. We do send your briefing profile and source excerpts to those providers at generation time so that a Briefing can be produced; they process that data on our behalf and under their own terms.

6. Sub-processors

We rely on a small number of trusted providers to operate the Service. They process your personal data only on our behalf, only to provide the Service, and under contractual terms that prohibit them from using it for any other purpose. We group them here by function. If our sub-processors change materially, we will update this policy and notify registered users.

FunctionWhat they process
Infrastructure and data storageYour Account, briefing profile, and Briefings, held in a database and file storage hosted in the EU. The website is served from a global edge network.
PaymentsSubscriptions and card details, handled entirely by our payment processor, Stripe. Card details never reach our servers.
Email deliverySign-in links and Briefing emails, sent through our email delivery provider.
AI processingYour briefing profile and relevant source material, processed by third-party AI model and search providers at generation time to produce a Briefing.

For the specific providers behind any of these functions, or a copy of our processor agreements, email support@irisbriefings.com.

7. Where your data is stored and international transfers

Your Account data, briefing profile, and Briefings are stored in the EU. Website requests are served from a global edge network, from the region closest to you. Some of our sub-processors may process data outside the UK and EU; where they do, we rely on appropriate safeguards recognised under UK GDPR (such as the UK International Data Transfer Agreement or an adequacy decision) to protect your data.

8. How long we keep your data

We keep your personal data only for as long as we need it:

  • Account, briefing profile, Briefings, and feedback — until you delete the relevant item, or delete your Account, at which point the data is permanently removed from our systems.
  • Billing records — Stripe retains invoice and payment records on its side for the period required by law, which we cannot shorten, even after your Account is deleted.

9. Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate data. You can correct most of it yourself in Preferences.
  • Erase your Account and associated data. Deletion is available immediately in Settings and is a permanent hard delete — there is no recovery.
  • Data portability — receive a machine-readable copy of your data. Email us and we will provide an export.
  • Object to or restrict certain processing. Email us.
  • Withdraw consent at any time where we rely on it.

For anything other than deletion (which is in Settings), email support@irisbriefings.com. We will respond within one calendar month, the statutory maximum under UK GDPR.

You also have the right to lodge a complaint with the UK’s Information Commissioner’s Office at ico.org.uk.

10. Cookies and local storage

Iris uses only strictly-necessary cookies and local storage: the authentication session that keeps you signed in. We do not run analytics cookies, marketing cookies, or advertising trackers. Stripe sets its own cookies on its own domains during payment; those are Stripe’s cookies, not ours, and are strictly necessary for the payment flow.

If we ever introduce analytics or any non-essential tracking, we will present a consent banner and will not activate the tracker until you have accepted it.

11. Data security

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse, including using reputable infrastructure providers and encrypting data in transit. No system can be guaranteed to be completely secure, but we work to protect your data and will notify you and the relevant authorities of any breach where we are legally required to do so.

12. AI-generated content and its limits

Every Briefing is generated by AI systems on our behalf. Briefings are calibrated but not infallible and may contain errors. We cite sources so that you can verify the content, and you should verify any decision-critical claim (medical, legal, financial, or safety-related) against its source before acting on it.

13. Sharing your Briefings

Your Briefings are prepared for you and licensed for your own use. You are free to quote from one, or discuss what is in it with a colleague, in the ordinary course of your work. Distributing Briefings on a standing basis to a group, a mailing list, or a shared channel is not covered by a personal subscription. That is what Iris for Teams is for.

This is a licensing matter rather than a data-protection one, and it is noted here only so it is easy to find. The operative wording is clause 9 of our Terms of service, which is what applies if this summary and those Terms ever differ.

14. Children

The Service is not intended for anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

15. Changes to this policy

We may update this policy as the Service evolves. Where a change is material, we will notify registered users by email. The date at the top of this page reflects the most recent update.

16. Contact

For any question about this policy or your personal data, contact us at support@irisbriefings.com.