1. Scope and who is responsible
This Privacy Policy explains how Iterel collects and uses personal data when you use the website, web application, macOS application, collaborative projects, public review links, billing, and support. Iterel is the controller for account, billing, website, hosted-project administration, security, and support data described here. Contact support@iterel.com for privacy questions or requests.
A customer organization is normally the controller for personal data it chooses to place in a project, and Iterel acts as its processor when providing hosted services under the customer’s instructions. Business and Team customers may request a data processing addendum. This policy does not govern providers you connect directly when they act under their own terms.
2. Local and cloud data boundary
Normal machine-local projects store their project state, source, memories, logs, credentials, and local Asset bytes on the Mac. Opening a local project does not by itself send its content to Iterel cloud storage, hosted analytics, or Iterel-funded models.
Data leaves the Mac only when you choose an operation that requires it—for example, signing in, creating a collaborative cloud copy, uploading a file, using a hosted integration, contacting support, starting a remote session, selecting Iterel Cloud generation, or instructing a connected engine or provider to process selected context. The interface is designed to identify those boundaries.
3. Personal data we collect and its sources
Please do not place special-category personal data, government identifiers, health data, payment-card data, passwords, or provider keys in prompts or projects unless it is necessary, lawful, and covered by an appropriate agreement and security configuration.
Data you provide
This includes email address, name and avatar if provided, account preferences, support messages and attachments, billing details other than full card data, project content you upload to cloud services, comments, invitations, and instructions sent to a capability, agent, engine, or integration.
Data generated through the Service
This includes authentication identifiers, locale, plan, team membership, roles, tasks, rounds, Chats, artifacts, files, Design and Whiteboard data, Project Map information, provenance, receipts, consent choices, transaction references, credit and usage records, guest-session identifiers, security events, IP address, browser or device information, app version, crashes, and performance information.
Data from other people and providers
Project administrators and collaborators may provide your email, role, comments, or project content. Authentication providers provide the profile information you authorize. Payment, repository, model, integration, hosting, and security providers return transaction status, output, usage, connection, or diagnostic information needed for the requested service.
4. Purposes and legal bases
We use personal data only for the purposes below. Where we rely on legitimate interests, we balance those interests against your rights and reasonable expectations.
We do not sell personal data. We do not use project content to train Iterel or third-party foundation models, and normal local-project content is not used for hosted analytics. We do not use personal data for solely automated decisions that produce legal or similarly significant effects about you.
| Purpose | Typical data | GDPR legal basis |
|---|---|---|
| Provide accounts, cloud projects, collaboration, requested generation, integrations, remote sessions, and support | Account, project, instruction, collaboration, device, and support data | Performance of a contract or steps requested before a contract |
| Administer subscriptions, credits, payments, and Team billing | Account, plan, usage ledger, transaction, and invoice data | Performance of a contract and compliance with tax and accounting law |
| Authenticate users, secure the Service, prevent fraud and abuse, enforce access controls, and diagnose incidents | Identifiers, IP address, device, access, security, and diagnostic records | Legitimate interests in operating a safe service; legal obligation where applicable |
| Send service, security, billing, invitation, and account messages | Identity, contact, account, project, and transaction data | Performance of a contract; legitimate interests; legal obligation |
| Measure and improve website and product usability with optional analytics | Consent choice, pseudonymous device and interaction events | Consent where required; otherwise legitimate interests only where lawful |
| Establish, exercise, or defend legal claims and respond to lawful authorities | Relevant account, transaction, security, support, or project records | Legitimate interests and legal obligation |
5. Engines, model providers, and integrations
When you request an operation, the prompts, selected context, files, and instructions needed for that operation may be sent to the connected engine, model provider, repository host, integration, or other service you selected. The interface identifies the applicable capability, agent, engine, or provider and records available provenance.
Some connected providers act as independent controllers under their own terms and privacy policies. When Iterel selects a provider to deliver Iterel Cloud generation on our behalf, we contractually restrict that provider as appropriate. Provider keys configured for local use are stored using machine protections and are supplied only to compatible local child engines.
6. Recipients and service providers
Personal data is disclosed only as needed to authorized Iterel personnel; project members and reviewers according to the access you choose; infrastructure, authentication, hosting, storage, payment, email, observability, analytics, support, model, and integration providers; professional advisers and transaction counterparties subject to confidentiality; public authorities where legally required; or a successor in a merger, financing, reorganization, or sale.
Current provider categories include Supabase for authentication and cloud data, Vercel for web delivery and performance measurement, Stripe for billing, Resend for transactional email, Sentry for error monitoring, Amplitude and Google tools for consented analytics, and the model or integration providers you select. We review provider access and disclose material category changes through this policy.
7. Collaboration and public review links
Members of a collaborative cloud project can see account identity, activity, comments, and project content according to their role. Public Share for review links expose only the saved artifact, Design target, or Whiteboard target and the View or Comment permission selected by the owner.
Anyone who receives an active public link may be able to open its target. Project owners should limit the target, avoid secrets, and revoke links when they are no longer needed. Guest comments and abuse-prevention records may be associated with a pseudonymous guest session.
8. International transfers
Iterel and its providers may process personal data outside the European Economic Area. Where the receiving country is not covered by an adequacy decision, we use an applicable safeguard such as the European Commission’s Standard Contractual Clauses and supplementary technical or organizational measures. You may request information about the relevant safeguard from support@iterel.com.
Data sent directly to a provider you connect is also subject to the transfer arrangements and locations offered by that provider.
9. How long we keep data
We retain personal data for no longer than needed for the purpose collected, then delete or irreversibly de-identify it unless law, a legal hold, security, or the establishment or defense of claims requires longer retention. The principal periods or criteria are below.
Local project files remain on the Mac until the device user deletes them. Iterel cannot delete local files from a device it cannot access.
| Data | Normal retention |
|---|---|
| Account and membership data | For the account or membership lifetime, followed by the period needed to complete deletion and preserve narrowly required security, billing, or legal records |
| Cloud project content and collaboration history | Until the project owner deletes it, the account closes, or the plan’s disclosed history limit applies; residual backup copies age out under the backup cycle and are isolated from normal use |
| Invoices and legally required accounting records | 10 years from the end of the relevant accounting period where French law applies |
| Security and access logs | Normally 6 to 12 months, unless an incident, legal duty, or claim requires a longer period |
| Support correspondence | For the time needed to resolve the request and then for the applicable limitation period where necessary to document the response or defend a claim |
| Consent record and locale preference | The consent preference and locale cookies expire after 12 months unless refreshed or deleted sooner |
| Guest review session and short-lived connection state | Guest session: 24 hours; Figma OAuth state: 10 minutes; beta invitation handoff: 1 hour |
| Optional analytics identifiers | For the configured provider period necessary for audience and product measurement; the settings are reviewed against applicable regulator guidance, and consent is requested again no later than the consent-choice expiry |
10. Security and incident response
We use risk-appropriate technical and organizational measures, including encryption in transit, access controls, row-level cloud-data policies, scoped tokens, machine-encrypted provider keys, signed desktop updates, logging, and provider review. No system is completely secure. You should protect credentials, review project access, revoke unused links and integrations, and maintain local backups.
We assess personal-data incidents and notify the competent supervisory authority and affected people when the GDPR or another applicable law requires it.
11. Cookies and similar technologies
Strictly necessary cookies or storage support authentication, security, guest review sessions, locale, and consent preferences. Optional analytics and marketing technologies are off until you make an affirmative choice where consent is required. You can reject them as easily as accepting them, select categories, and change or withdraw your choice at any time through Cookie settings in the footer.
Optional tools may include Amplitude and Google Analytics or Tag Manager. Sentry may receive essential error and security diagnostics needed to operate the Service; optional product analytics or session replay remain consent-controlled. Vercel may provide aggregate, cookieless performance measurement. Withdrawing consent does not affect processing that was lawful before withdrawal.
During the open beta, if you consent to analytics, product sessions may be recorded with Amplitude Session Replay — up to all consented sessions — to diagnose usability and reliability issues. Recordings capture on-screen interactions with the web and desktop application interface; text inputs are masked by default, replay data is processed in the EU, and internal Iterel accounts are excluded. You can decline or withdraw at any time through Cookie settings in the footer, which stops recording for future sessions.
12. Your data-protection rights
Under the GDPR, you may have rights to access, correct, erase, restrict, or receive a portable copy of personal data; object to processing based on legitimate interests or direct marketing; withdraw consent at any time; and obtain information about applicable international-transfer safeguards. These rights may be limited by law in specific circumstances.
Use available account controls or email support@iterel.com. State the right you wish to exercise and enough information for us to identify the relevant account or data. We may verify your identity and authority. We normally respond within one month under the GDPR, subject to a permitted extension for complex or numerous requests.
You may complain to the supervisory authority where you live, work, or believe an infringement occurred. In France, the authority is the Commission nationale de l’informatique et des libertés (CNIL), available at cnil.fr.
13. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data without legally valid authorization. Contact support@iterel.com if you believe a child provided personal data improperly.
14. Changes and contact
We may update this Privacy Policy as the Service, providers, or law changes. We will change the effective date and provide reasonable advance notice of material changes where required. An update will not retroactively change the legal basis for processing already performed.
Contact support@iterel.com to ask a privacy question, exercise a right, request a data processing addendum, or raise a concern. Please do not send passwords, payment-card details, provider keys, or other credentials by email.
Questions or requests
Contact Iterel
Email support@iterel.com for legal notices, billing questions, withdrawal requests, privacy rights, or support. Please do not email passwords, provider keys, or other credentials.
Read the product documentation