Privacy in the private beta
This is a technical privacy overview, not the final legal notice. Exact retention periods, legal bases and hold rules still require the dedicated operations and legal review before beta release.
What Iris needs
The platform processes account identity, tenant runtime and conversation state, structured notes and tasks, short-lived device delivery records, connection credentials, security audit records, rollback generations and protected backups only for their declared service or operational purpose.
What stays out of application logs
User prompts, message payloads and model responses are excluded from system application logs. Credentials remain in their owning service and are not placed in prompts or tenant containers.
Export and deletion
Iris is designed for authenticated export and account deletion across active state, queued delivery, integrations and backups. Export implementation has synthetic evidence; a complete real-tenant deletion and restore exercise is still a Gate 4 requirement.
Operator trust
Transport and storage use available industry protections, but Iris does not claim zero-knowledge operation or confidentiality from a privileged platform operator. Those claims would require a different architecture.