Privacy Policy
Last updated: June 30, 2026
At Irabu, your privacy is not an afterthought — it is the foundation of how we build. This policy explains exactly what data we collect, why we collect it, and how we protect it. We believe in plain language, not legal fog.
1. Who We Are
Irabu is the Enterprise Intelligence Platform — the AI operating system that connects your organization's knowledge, people, applications, and workflows. We operate at https://chiron-umber.vercel.app. When this policy says "we," "us," or "our," it means Irabu. When it says "you" or "your," it means you — the person using our platform.
If you have any questions about this policy, email us at williamfranklyn2020@gmail.com. We respond within 72 hours.
2. Our Core Commitment
3. What Data We Collect
We collect only what is necessary to provide the service. Here is a full breakdown:
3.1 Account Information
- Email address — to create your account, send you product updates, and allow password recovery.
- Full name — to personalise your workspace and identify you to teammates.
- Password — stored as a one-way cryptographic hash (we never see your actual password).
- Role — whether you are an admin or member, used to control workspace permissions.
3.2 Workspace Data
- Tasks, lists, and spaces — the work you create and organise inside Irabu.
- Documents and spreadsheets — files you create or upload to your workspace.
- Goals and key results — your OKRs and progress tracking data.
- Team chat messages — messages sent between members of your workspace.
- Time logs and comments — time entries and task discussions.
- Notifications — activity alerts generated by your workspace activity.
3.3 Integration Data
- Google Calendar — if you connect your Google account, we store an OAuth access token and refresh token to read and write your calendar events on your behalf. We only access calendar data when you explicitly request it inside Irabu. You can disconnect this at any time from Settings.
- API keys — if you generate API keys for third-party integrations, we store a one-way hash of the key (not the key itself) for authentication purposes.
3.4 Usage and Technical Data
- Log data — IP address, browser type, pages visited, and timestamps, used for security monitoring and debugging.
- Device information — operating system and browser version, used to ensure compatibility.
- Feature usage patterns — which features you use and how often, used to improve the product (see Section 4).
4. How We Use Your Data
We use your data for three purposes — and only these three:
To provide the service
Authenticating your account, saving your work, syncing your data across devices, and enabling collaboration with your team. Without this, Irabu cannot function.
To improve the product
We analyse aggregated, anonymised usage patterns to understand which features are valuable and which need work. For example: if 80% of users never open the Gantt view, we investigate why. This data is never linked back to individual users in our analysis.
To communicate with you
We may send you product announcements, new feature updates, tips, and occasional promotional offers about Irabu. Every marketing email includes a one-click unsubscribe link. We do not share your email with third-party marketers.
5. What We Never Do
Sell your personal data or workspace content to any third party
Share your data with advertisers
Use your workspace content to train AI models — your content is processed in real-time by the Irabu Agent to answer your queries (inference), but never used to update or fine-tune any model's weights
Access your workspace data except when required to provide support (with your permission) or to comply with a valid legal order
Send you marketing emails if you have unsubscribed
6. Data Storage and Security
Your data is stored on Supabase (PostgreSQL), hosted on AWS infrastructure with encryption at rest and in transit (TLS 1.2+). We implement the following security controls:
- Row-level security (RLS) — database-enforced rules ensure users can only access their own organisation's data.
- API key hashing — API keys are stored as SHA-256 hashes; the raw key is never stored.
- Password hashing — passwords are hashed using bcrypt via Supabase Auth.
- HTTPS everywhere — all data in transit is encrypted.
- Access controls — internal access to production data is restricted to essential personnel only.
Despite these measures, no system is 100% secure. If you discover a security vulnerability, please report it immediately to williamfranklyn2020@gmail.com before disclosing it publicly. We take security reports seriously and respond within 24 hours.
7. Data Retention
- Active accounts — your data is retained for as long as your account exists.
- Deleted accounts — when you delete your account, your personal data and workspace content are permanently deleted within 30 days.
- Backups — encrypted backups may retain deleted data for up to 90 days before being purged.
- Log data — server logs are retained for 90 days for security and debugging purposes.
8. Third-Party Services
We use a small number of trusted third-party services to operate Irabu:
| Service | Purpose | Data shared |
|---|---|---|
| Supabase | Database and authentication | All workspace data (stored, not shared) |
| Vercel | Hosting and deployment | Server logs, IP addresses |
| Anthropic | AI assistant responses | Your messages and any workspace content retrieved during an AI query (tasks, docs, etc.) |
| Voyage AI / OpenAI | Semantic search embeddings | Text content of documents you upload or connect, converted to vector representations |
| Calendar integration (optional) | Calendar events (only if you connect) |
We select providers whose published terms prohibit using API data for their own training or advertising purposes. We cannot guarantee third-party behaviour beyond our contractual agreements — we encourage you to review each provider's privacy policy directly. We do not use any advertising networks or tracking pixels.
9. Your Rights
You have the following rights regarding your data. To exercise any of them, email williamfranklyn2020@gmail.com.
Request a full export of all data we hold about you.
Ask us to correct inaccurate or incomplete data.
Request permanent deletion of your account and all associated data.
Receive your data in a structured, machine-readable format (JSON/CSV).
Opt out of marketing communications at any time via the unsubscribe link or by emailing us.
Request that we limit processing of your data in certain circumstances.
We will respond to all data rights requests within 30 days. If you are in the EU or UK, you also have the right to lodge a complaint with your local data protection authority.
10. Cookies
Irabu uses only essential cookies — session tokens required to keep you logged in. We do not use advertising cookies, tracking cookies, or any third-party analytics cookies. You can clear cookies at any time through your browser settings, which will log you out of Irabu.
11. Children's Privacy
Irabu is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has created an account, contact us at williamfranklyn2020@gmail.com and we will delete the account promptly.
12. Changes to This Policy
We will notify you by email and with an in-app banner at least 14 days before any material changes to this policy take effect. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of Irabu after the effective date constitutes acceptance of the updated policy.
13. Contact Us
For any privacy-related questions, data requests, or concerns: