Iris

Privacy policy

What we collect when you use Iris or visit this site, why, who we share it with, how long we keep it, and your rights.

Last updated 5 October 2026

Iris is provided by Crown Student Consultancy (CSC) UK Ltd, trading as Ferrolo (company number 14324057, registered in England and Wales, registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, registered with the Information Commissioner’s Office under ZC265399).

We refer to ourselves as “we”, “us” and “our”. We are the controller of the personal data described here. Questions, and requests to use any of your rights, go to iris@ferrolo.com.

1. What this policy covers

This policy explains how we handle personal data about people who use Iris on the web or in our apps, ask for access, visit this website or contact us.

2. What we collect

Account details. Your name, email address, a scrambled copy of your password and any sign-in or security settings you turn on.

Your conversations. What you write or say to Iris, files you share with it, and what Iris replies. This includes background work you set up, such as goals and automations, and what they find.

Voice. When you use voice, your audio is turned into text so Iris can understand and reply. The transcript becomes part of your conversation. Audio is kept only as long as needed to transcribe it and reply.

Memory. The notes Iris saves about you from your conversations, such as people, dates, preferences and commitments, together with where each note came from.

Connected accounts. If you connect a service such as Gmail, Google Calendar or Google Drive, the access permissions you grant and the information Iris reads from it to do what you ask, such as an email thread, a calendar event or a document.

Device and usage information. Sign-ins, actions in the app, IP addresses, device and browser details, push notification tokens, crash reports and error logs.

Access requests and messages. Your email address when you ask for access, anything you write to us, and the IP address it was sent from.

Website analytics. Only if you allow it, how you use this website, collected by Mixpanel. See our cookie notice.

Payments. If you buy a plan, your plan, invoices and billing contact. Card details go directly to our payment provider or to the app store you paid through, and never reach us.

3. How we use it, and why we are allowed to

To provide Iris to you: to answer you, remember what matters, act on your instructions, run background work, send notifications and support you. This is necessary for our contract with you.

To keep Iris safe and working: to secure accounts, prevent abuse, investigate problems and fix bugs. We have a legitimate interest in running a safe and reliable service.

To improve Iris: using information about how the service is used, such as which features are used and where errors happen. We have a legitimate interest in making the product better. This does not involve training AI models on your conversations.

To send you access, if you ask for it. We rely on your request, which is a step towards a contract with you. We don’t use that email for anything else.

To measure this website, only if you consent. You can withdraw consent at any time from “Cookie settings” in the footer.

To meet legal duties: keeping tax and accounting records and responding to lawful requests.

We do not make decisions about you that have legal or similarly significant effects based only on automated processing.

4. Your conversations and AI

To reply to you, Iris sends the relevant parts of your conversation, memory and connected information to the AI providers that run its models. We only use providers that are not allowed to train their models on your data or keep it for longer than needed to provide the service to us.

We do not use your conversations to train AI models. We do not sell them, and we do not share them for advertising.

Access within our team is limited to the few people who need it, and only to keep the service running, investigate a problem you have reported, deal with abuse, or where the law requires it.

5. Google user data

Iris’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:

  • We only use Google user data to provide and improve the features you use in Iris, such as finding an email, drafting a reply, checking your calendar or reading a document you ask about.
  • We do not use Google user data for advertising, and we do not sell it.
  • We do not transfer it to others except as needed to provide those features (for example, to the AI providers described above), for security, to comply with the law, or as part of a merger or acquisition with your consent.
  • People on our team do not read it unless you ask us to for specific items, it is needed for security purposes such as investigating abuse, it is required by law, or it has been aggregated and anonymised for internal operations.
  • We do not use Google Workspace data to develop, improve or train generalised AI or machine learning models.

You can remove Iris’s access at any time from your Google account settings or by disconnecting the service in Iris.

6. Who we share it with

We share personal data only with organisations that help us run Iris, under contracts that require them to protect it, and only as much as they need:

  • providers that host the service and store its data;
  • AI providers that generate Iris’s replies, and speech providers that turn voice into text and text into speech;
  • email delivery, and the push notification services run by mobile platforms;
  • Mixpanel, for website analytics, only if you consent;
  • our payment provider, or the app store you paid through, if you buy a plan.

We may also share personal data with professional advisers, with authorities where the law requires, to protect our rights or the safety of others, and with a buyer or successor if our business, or part of it, is sold or reorganised.

7. Where it is kept

Personal data may be stored and processed in the United Kingdom, the European Economic Area, the United States or other countries where we and our providers operate. When it is transferred outside the UK or the EEA, we rely on adequacy decisions or on approved safeguards such as the UK International Data Transfer Addendum and the EU standard contractual clauses.

8. How long we keep it

Conversations and memory: until you delete them or close your account. After your account closes we delete them within 90 days.

Connected account data: read when a request needs it. Anything Iris quotes back becomes part of your conversation. Access tokens are deleted when you disconnect the service.

Account details: while your account exists, then up to six years for our tax and business records.

Usage and security logs: up to 12 months, unless needed longer to investigate a problem.

Access requests and messages: up to 24 months after our last contact, or until you ask us to remove them.

Website analytics: up to 24 months.

Copies in backups are deleted as the backups expire. Aggregated or de-identified data that no longer identifies anyone may be kept indefinitely.

9. Your rights

Under UK data protection law you can ask to see the personal data we hold about you, correct it, delete it, restrict or object to how we use it, and receive a copy to take elsewhere. Where we rely on your consent, you can withdraw it at any time. Some rights have limits, for example where we must keep records by law.

Email iris@ferrolo.com and we will answer within one month. If you live in the European Economic Area, you have the same rights under the EU GDPR.

If you are unhappy with how we have handled your data, please tell us first. You can also complain to the Information Commissioner’s Office at ico.org.uk, or to your local data protection authority. Crown Student Consultancy (CSC) UK Ltd is registered with the ICO under ZC265399.

10. Security

We encrypt data in transit, keep each account’s data separate, limit who on our team can reach it, and monitor for misuse. No system is perfectly secure. If a breach affects you, we will tell you as the law requires.

11. Children

Iris is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.

12. Changes to this policy

We may update this policy. If a change is significant, we will tell you by email or in the app before it takes effect. The date at the top of this page shows when it last changed.