Skip to main content
IRISLIGHT WITHIN
Support Try Iris free

Privacy and data control

Privacy Policy

How Iris intends to collect, use, protect, retain, and give users control over personal information.

Last updated August 24, 2026Iris Light Within LLCPeople 18 and over

On this page

OverviewInformation we collectSensitive informationHow we use informationAI and service providersHow information is sharedSafety systemsMemory and personalizationRetention and deletionYour rights and choicesCookies and analyticsSecurityInternational processingAge requirementContact

1. Overview

This Privacy Policy explains how Iris Light Within LLC (“Iris,” “we,” “us,” or “our”) collects, uses, shares, stores, and protects information when you use the Iris website, web app, mobile apps, support channels, and related services (collectively, the “Services”).

Iris is an adult-focused artificial intelligence service for personal reflection and everyday support. Iris is not a human, therapist, medical provider, lawyer, financial adviser, or emergency service.

Plain-language promise: We intend to collect only what is needed to operate and protect Iris, provide features you choose to use, honor your settings, and meet legal obligations. We do not sell personal information or use private conversation content for behavioral advertising.

2. Information we collect

Account and contact information

Depending on the sign-in method and features you use, we may collect an email address, telephone number, login credentials or authentication tokens, age confirmation, country or region, subscription status, and information you send to support.

Conversation and feature content

We process the text you send to Iris and the responses generated for you. When offered and used, this may also include voice transcripts or recordings, photos, journal entries, saved reflections, reminders, and memories you expressly approve. Website story submissions may include a written account, images, and video links.

Technical and usage information

We may collect device type, operating system, browser, app version, IP address, approximate region derived from IP, session and feature activity, crash reports, security logs, anti-abuse signals, and diagnostic data.

Payment information

Apple, Google, Stripe, or another disclosed payment provider may process purchases. Iris generally receives transaction identifiers, subscription status, plan, renewal information, and limited billing metadata—not full payment-card or bank-account details.

3. Sensitive information you choose to provide

Conversations may involve health, grief, trauma, relationships, finances, religious or philosophical beliefs, sexuality, unusual experiences, or other deeply personal subjects. You decide what to share.

By using the Services, you acknowledge that you may voluntarily provide sensitive personal information and authorize its processing as described in this Policy so Iris can respond and provide the features you request.

Do not include information about another person unless you have the right to share it. Avoid sending information that is not necessary for the conversation.

4. How we use information

  • Provide conversations, accounts, saved history, user-approved memory, reminders, support, and other requested features.
  • Authenticate users, count free questions, manage subscriptions, and prevent duplicate or abusive trial use.
  • Secure the Services, investigate fraud or misuse, diagnose technical problems, and maintain reliability.
  • Respond to support, privacy, account-deletion, and legal requests.
  • Measure high-level product performance and improve design, safety, accessibility, and quality.
  • Comply with law, enforce our Terms of Use, and protect users, Iris, and others.

Iris does not make legal, medical, credit, employment, housing, insurance, or other consequential decisions about users.

5. AI systems and service providers

Iris uses automated systems and third-party infrastructure to generate responses and operate the Services. This may include AI model providers, cloud hosting, authentication, databases, analytics, crash reporting, payment processing, email, customer support, and security services.

Conversation content and related context may be transmitted to an AI provider so it can generate a response. The final published Policy must name the production processors, explain their purpose, and match the actual contracts and technical configuration.

Training direction: Iris does not use private conversations to train a general-purpose AI model by default. Any future program that asks users to contribute content for model improvement must be separate, optional, clearly explained, and based on explicit consent that can be withdrawn prospectively.

AI-generated outputs may reproduce details you included in your input or approved memory. Outputs can be inaccurate, incomplete, outdated, or inappropriate and should not be treated as verified facts.

6. How information is shared

We may share the minimum information reasonably necessary with service providers that help operate Iris, including AI, cloud, database, authentication, communications, analytics, safety, payment, and support providers.

We may also disclose information when required by valid legal process; to investigate fraud, abuse, or security incidents; to protect rights or safety; in a business transaction subject to appropriate safeguards; or with your direction or consent.

We do not sell personal information. We do not disclose private conversations to advertising partners for behavioral advertising.

7. Automated safety systems are not monitoring

We may use automated systems to detect possible safety, abuse, fraud, or policy concerns. Iris does not provide continuous human monitoring, real-time intervention, or emergency response. Automated detection may be incomplete or wrong.

If you are in immediate danger in the United States, call 911. If you or someone else may be at risk of suicide or self-harm, call or text 988. Outside the United States, contact local emergency or crisis services.

8. Memory and personalization

Memory is intended to be permission-based. Iris should ask before saving information for future conversations. Saved memories must remain tied to the correct account and should be viewable, correctable, and deletable by the user.

Turning off or deleting a memory is different from deleting the conversation in which it appeared. The product must explain that relationship and prevent deleted information from reappearing through stale summaries or retrieval.

We do not intend to silently infer or save diagnoses, suicidality, trauma labels, religious identity, sexuality, financial problems, legal problems, or belief in a particular unusual cause. Sensitive memory, if offered at all, requires explicit confirmation and stricter controls.

9. Retention and deletion

We retain information only as long as reasonably necessary for the purposes described here, including providing requested history and memory, securing the Services, resolving disputes, keeping required financial or consent records, and meeting legal obligations.

The current product direction is that a free user who chooses to save a conversation can return to it for up to 12 months after the user’s last activity, unless it is deleted sooner. This schedule must be confirmed against the production database and disclosed consistently before launch.

When you delete content or an account, it may disappear from the visible product before all copies are removed from active systems and routine backups. We make reasonable efforts to delete or de-identify verified requests within a commercially reasonable period, subject to technical limitations, fraud prevention, legal obligations, backup cycles, and dispute preservation. We will not claim deletion is complete until the responsible system confirms it.

See Delete an Account for the intended in-app and web-request process.

10. Your rights and choices

Depending on your location, you may have rights to request access, correction, export, deletion, restriction, objection, or information about how data is used and shared. You may also have the right to appeal a denied request and use an authorized agent.

  • Control or remove saved memories.
  • Delete individual conversations or the entire account where available.
  • Opt out of marketing communications.
  • Decline optional analytics or cookies where required.
  • Decline any optional content-contribution or training program.

Use the Privacy Choices page or email app@irislightwithin.com. We may need to verify identity before fulfilling a request. We will not discriminate against you for exercising an applicable privacy right.

11. Cookies and analytics

The website and web app may use essential cookies or similar storage for login, security, preferences, trial continuity, and basic operation. Optional analytics or marketing technologies, if added, must be disclosed and presented with consent controls where required.

Browser “Do Not Track” signals are not universally standardized. The final product should describe whether it responds to Global Privacy Control or other legally recognized opt-out signals.

12. Security

We use administrative, technical, and organizational safeguards designed to protect information, such as encrypted transmission, access controls, authentication, logging, vendor review, and data minimization. No system is completely secure.

Users are responsible for protecting their credentials and devices. Iris may offer Face ID, Touch ID, device-passcode protection, or similar features where supported.

13. International processing

Information may be processed in the United States and other locations where Iris or its providers operate. Where required, Iris will use appropriate contractual and legal safeguards for international transfers.

14. People 18 and over

The Services are intended only for people 18 and over. We do not knowingly offer Iris to children. If we learn that a person under 18 provided personal information, we will take appropriate steps to restrict the account and delete information as required.

15. Contact

Iris Light Within LLC
4235 SE 20th Place, Suite 401A
Cape Coral, Florida 33904
United States

Email: app@irislightwithin.com

Privacy, access, correction, export, and deletion requests may be submitted through the Privacy Choices or Account Deletion pages.

© 2026 Iris Light Within LLC. For people 18 and over.

Home Privacy Terms Disclosures Safety Privacy Choices Delete an Account Support