IRIS privacy
Last updated 13 September 2026
IRIS listens to conversations, so this page has to be specific rather than reassuring. It says what leaves your phone, who receives it, how long it is kept, and how to get rid of it.
Who we are
IRIS is made and sold by Sufi Plugins (Lucas Crowley), an independent developer based in Maryland, USA. We are the controller of the personal data described here. Contact: [email protected]. Postal address available on request at [email protected].
IRIS is an independent product and is not affiliated with Even Realities. The IRIS app runs on your phone; your Even G2 glasses are a display and a set of gestures — they do not process or store your conversations.
What IRIS handles, and why
Most of what IRIS makes stays on your phone. What leaves it does so to be transcribed, answered or backed up. This table is the whole picture; the sections after it explain the parts that need more than a line.
One switch. Four of the rows below are on by default and can be turned off: cloud backup, the 48-hour question log, diagnostics and session recordings. Settings → About & help → Privacy & legal → Private mode turns all four off in one tap (deleting the stored backup copy) and Off restores the defaults. It does not change how IRIS works: audio still goes to the speech-to-text provider and the transcript to the AI provider to be answered, and neither is stored by us.
| Data | Why | Where it goes | How long |
|---|---|---|---|
| Audio, while a session or Live captions is running | To turn speech into text | Streamed through our server to the speech-to-text provider (Soniox on Pro). On Basic it goes straight from your phone to the provider whose key you entered. With “Always use offline” captions (English), it never leaves the phone. | Not stored by us. Kept only if you switch on session recordings. |
| Recognition hints sent with that audio | So names and terms you use are not transcribed phonetically | Same speech-to-text provider. The names in your Voice ID library, the words listed under the mode you are recording in and distinctive terms in that mode’s files; when you dictate to Ask or Terminal, also your mode names, your agent’s name and the titles of your saved memories; with the teleprompter, the distinctive words of your own script. Never the notes inside a memory, your transcripts or your “About you” profile, and nothing from a private mode. | Not stored by us |
| Recent transcript, plus the relevant parts of your modes, prep files, documents and memories | To generate a cue, an answer or a summary | Passed through our server to the AI provider (Anthropic, or Google Gemini; or your own provider or agent if you set one up) | Not stored by us: passed through, not written to our database |
| Search queries built from what was said | To look something up | Anthropic’s web search, or Google (Gemini with Google Search) | Not stored by us |
| Transcripts, summaries, key points, action items | Your record of the conversation | Your phone. Copied to our cloud backup if backup is on (Pro) | On your phone until you delete it. In the backup until you switch backup off, delete it, or 2 years after the last backup |
| Memories, people, modes, to-dos, preferences, Ask chats | To run the features you use | Your phone, plus the cloud backup (Pro) | Same as above |
| Voiceprints: your own voice ID, voices you chose to remember, and the per-session speaker profiles | To tell speakers apart and label them | Your phone only. Not in the cloud backup | See Voiceprints |
| Session audio recordings (Pro, off by default) | Because you asked IRIS to keep the audio | Stored privately in IRIS’s cloud storage (Cloudflare R2), under an opaque per-user prefix | Until you delete the recording |
| Documents you add (Pro) | So IRIS can answer from your own files | Stored as text on IRIS’s server | Until you remove the document |
| “Hey Even” captures — notes, to-dos and events you dictate with the app closed | To hand them to the app | A queue on IRIS’s server, held for your licence | Until the app collects them; calendar items are dropped two weeks after the event |
| Your Ask and “Hey Even” questions and IRIS’s answers (Pro, since 13 September 2026) | Quality review — catching wrong answers | IRIS’s server, under a truncated licence id; emails, phone numbers and key-shaped strings removed first. See below | 48 hours, then deleted automatically. Switch it off in Settings → Privacy & legal |
| Reminders you set | To email you at the time | IRIS’s server, with your email address | Until it fires, plus 7 days |
| Computer audio and screenshots from the browser extension (Pro) | To transcribe a tab, or put a screen on your lens | Our server, then the speech-to-text provider | Text held at most ~15 minutes on the way to your phone; a screenshot until your glasses collect it, at most 10 minutes |
| Your licence and subscription: email address, PayPal subscription id, plan and status | To give you Pro, email your key, handle billing and support | IRIS’s server; PayPal handles the payment | While you are a customer, and afterwards as long as tax and accounting law requires |
| Monthly AI-cost counters per licence | The fair-use ceiling, and spotting abuse | IRIS’s server | 90 days |
| Free-session allowance, tied to an install id | So the 3 free sessions are given once per install | IRIS’s server | 365 days |
| The email address a free user types to receive a session summary | To send that one email | IRIS’s server and our email provider | 365 days |
| Repeat-trial record: the email address that started a trial | To stop one person taking the free trial over and over | IRIS’s server | 2 years |
| Diagnostics (on by default, switch off in Settings) | To find and fix faults | IRIS’s server | Raw records 30 days; daily totals longer |
| Your Home Assistant address and access token, if you connect it | To run your home commands, including with the app closed | IRIS’s server, stored against your licence and never inside the cloud backup | While the connection exists; the record’s 400-day expiry is renewed each time it is used. Remove the connection and it is deleted |
| Your own agent’s address and key, if you use one | To reach your agent | Sent with each request, through our relay | Not stored on our servers |
| Approximate location from your internet connection | Time and place context, weather, and the recording geoblock | Derived at Cloudflare’s edge, used for that request | Not stored against your account |
Things you connect yourself — Obsidian, Google Drive, Google Tasks, Todoist, Raindrop, Karakeep, calendar feeds — receive what you tell IRIS to send them, and what happens to it there is governed by that service. We do not sell your data, we do not share it for advertising, and we do not use your conversations to train or evaluate AI models.
Say this plainly: if you record a confidential conversation, its audio and text are transmitted to and processed by third-party speech and AI providers. That is how the product works. Live captions skip the cues and save nothing, but the speech is still sent to the speech-to-text provider unless you turn on “Always use offline” (English only), which keeps the audio on your phone. If a conversation must never leave the room, use offline captions or do not start a session.
The same applies to the browser extension. A call, a lecture, a video or a screen you send is audio and text leaving your computer for the same providers.
Voiceprints and biometric data
What it is. To tell speakers apart, IRIS turns short pieces of speech into a mathematical voice profile — a voiceprint. There are three kinds: the one you record for yourself in Voice ID, the ones you deliberately record or save for other people so IRIS can name them, and a short profile IRIS derives for each unnamed speaker in a session so you can correct a label afterwards. A voiceprint is biometric data in several places, including the EU and a number of US states, and it is treated here as such.
They stay on your phone. Voiceprints are made and matched on your device. They are not included in the cloud backup, and any copies that earlier backups had contained on our server were deleted on 11 September 2026. They are included in the portable export you make yourself (Settings → Backup → “Your data, as a file”), which stays on your device unless you move it somewhere.
Someone else’s voice needs their permission. Remembering another person’s voice is off by default. When you turn it on for someone, IRIS asks you to confirm that you have that person’s permission. Get it before you do it — a voiceprint carries stricter rules than an ordinary recording, and in some places a written release is required.
How long they are kept, and when they are destroyed.
- The profile of an unnamed speaker is removed from a session after 30 days.
- A voiceprint you named or saved is kept until you delete that person or that voice in the app.
- Your own voiceprint is kept until you delete it; you can do that in Settings.
- Everything goes when you uninstall the app, because it lives in the app’s storage.
- In any case, we do not keep voiceprints beyond 24 months after you last use IRIS: if the app is not opened again, the data goes with the install, and any record on our side is deleted on that schedule.
We never sell voiceprints, never share them for advertising, never use them to train anything, and never disclose them to anyone except where the law requires it. If you want confirmation that nothing of yours remains on our side, email [email protected] and we will check and tell you.
Recording other people
IRIS transcribes people who have not agreed to anything. That is your responsibility, and in many places it is a legal one: recording and eavesdropping laws differ by country and by US state, and several require every participant’s consent. Tell people that IRIS is transcribing, and stop if they object.
Storing session audio is blocked entirely in Germany, Austria, Switzerland, France, Portugal and Australia, and in the US states that require all-party consent: California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, Nevada, New Hampshire, Oregon, Pennsylvania and Washington. The block is based on where your connection is, and it applies to recordings only — transcription, cues and summaries work everywhere. It does not make recording lawful where you are, and it does not move your responsibility to us.
Location
IRIS does not ask your phone for GPS. Our server works out an approximate location from your internet connection — country, region and city level, plus your time zone — and uses it to set time and place context for AI answers, to show local weather on the lens, and to apply the recording block above. It is used for the request and is not stored against your account. It can be wrong: a phone roaming abroad often appears to be at home.
Diagnostics
Diagnostics are on by default; you can switch them off in Settings, and the choice survives a reboot. They are pseudonymous: each record carries an install identifier, and, while the app is open, your licence key, so support can see what happened on your account when you write to us. They contain event names, counts, timings, model names and error types — never transcript, cue or chat text, never your email address. Raw records are deleted after 30 days; the daily totals we keep beyond that are counts, not records about you.
Cloud backup
Cloud backup is a Pro feature and is on by default. It copies your sessions and summaries, memories, modes, preferences, to-dos and Ask chats to our server, retrievable only with your licence key. It does not contain voiceprints, and API keys and integration credentials are stripped out before upload.
Switch backup off in Settings and the server copy is deleted. Otherwise it is kept while you keep using IRIS: each new backup renews a two-year expiry, so a backup that is not touched for 2 years expires on its own. You can also ask us to delete it at any time, including after your subscription has ended.
Documents, captures and reminders
Documents you add on Pro are stored as text on our server so IRIS can answer from them; they stay until you remove the document, and removing it deletes the text. “Hey Even” captures sit in a queue for your licence until the app collects them; calendar items are dropped two weeks after the event. Reminders are held with your email address until they fire, plus 7 days.
Questions kept for quality review
Since 13 September 2026, on Pro only: the questions you put to IRIS in the Ask tab and to “Hey Even”, and the answers IRIS gave, are kept on our server for 48 hours and then deleted automatically. We keep them so we can review the quality of the answers — a wrong fact, a menu path that does not exist — without waiting for someone to write in. Until now the relay kept nothing of what was said; this is the one exception, and it is deliberately narrow.
- What is kept: the question and the answer, as text, with the model and timing of the call, under the first twelve characters of your licence key. Email addresses, phone numbers and anything that looks like a key or token are removed before storage.
- What is not kept: audio or recordings, session transcripts, cues, summaries, your documents, your memories, or anything from the free tier or from calls made with your own keys. Cloud backup is unchanged and governed by the section above.
- Who sees it: the developer’s own review tooling and, when it flags something, the developer. Nobody else, and it is never used to train AI models.
- How to opt out: Settings → About & help → Privacy & legal → “Share recent questions with IRIS support (48 hours)” → Off. That stops it for Ask and for “Hey Even” alike, and nothing else about IRIS changes.
- Deletion: every row expires 48 hours after it was written. A deletion request to [email protected] removes any rows still within that window along with the rest of your data.
Audience Q&A
If you run an audience Q&A, the people in the room open eveniris.com/j and type a question, optionally with a name. Those questions, names and votes are held only for the event: the room is wiped automatically 12 hours after its last activity, and there is no account and no sign-in. Do not put anything sensitive in a question — the presenter sees every one of them.
We use your email address for two kinds of mail:
- Account mail you cannot opt out of while you are a customer: your licence key, billing and trial notices, fair-use warnings, reminders you asked for, and replies to your support messages.
- Product news — occasional emails about what has changed. Every one carries an unsubscribe link, and you can also reply “unsubscribe” or email us. Unsubscribing stops all marketing mail, not just one kind.
Our email provider records whether a message was delivered or bounced. Open and click tracking are switched off for our domain, so no tracking pixel is added to IRIS email. We do not build profiles from it.
Service providers
These are the companies that process data for IRIS. Each receives only what the request it answers needs — a search provider gets a query, not your transcript — and each is bound by its own terms; we use business rather than consumer tiers.
| Provider | What it does for IRIS | Privacy policy |
|---|---|---|
| Cloudflare | Hosts this website, runs the IRIS server, and stores backups, documents and recordings | cloudflare.com/privacypolicy |
| Anthropic | The AI behind cues, answers and summaries, and its web search | anthropic.com/legal/privacy |
| Gemini models for some AI work, and Google Search behind them | policies.google.com/privacy | |
| Soniox | Speech-to-text on Pro | soniox.com/privacy |
| ElevenLabs | IRIS’s spoken voice, only when “IRIS speaks” is on | elevenlabs.io/privacy |
| Open-Meteo | The weather line on the lens home screen; the phone sends the approximate city of your connection, never a precise position | open-meteo.com/en/terms |
| PayPal | Takes the payment and manages the subscription. PayPal is an independent controller of what you give it | paypal.com privacy |
| Resend | Sends our email | resend.com/legal/privacy-policy |
If you bring your own API keys (Basic, or Pro with your own provider), your audio and text go straight from your device to the provider you chose — Deepgram, OpenAI, Google, Anthropic, your own agent or anything OpenAI-compatible — under their terms, and we never receive it. If you use our Discord bot, Discord receives what you type there.
International transfers
We are in the United States and our servers and providers are mostly in the United States, so if you are outside it your data is transferred there. Where that transfer needs a legal mechanism, our providers offer the European Commission’s standard contractual clauses (and the UK addendum) in their data processing terms, and several are certified under the EU–US Data Privacy Framework. Ask us and we will tell you what applies to a particular provider.
Legal bases (UK and EU)
- Performance of a contract — running IRIS for you: transcription, cues, summaries, backup, documents, your licence and billing.
- Legitimate interests — keeping the service secure and working, preventing abuse of the managed AI, understanding which features are used, and telling existing customers about changes to the product. You can object at any time.
- Consent — voiceprints (biometric data, Art 9), session audio recordings, and diagnostics where local law requires consent for them. You can withdraw consent by switching the feature off, which stops the processing from then on.
- Legal obligation — keeping tax and accounting records of what you paid.
Where you are recording other people, you are the one deciding to do that; we process what you send us in order to run the product for you. That does not relieve you of your own obligations to the people in the room.
Your rights
Wherever you live, you can ask us to:
- Tell you what we hold about you, and give you a copy.
- Correct anything wrong.
- Delete it: your backup, your recordings, your documents, your Home Assistant connection, your licence record. Sessions, memories and recordings can also be deleted in the app yourself. You can ask even if your subscription has ended — a lapsed licence is no reason for us to refuse.
- Export it: Settings → Backup → “Your data, as a file” gives you a portable copy of everything on the device, voiceprints included; ask us and we will also send what is on our side.
- Object to processing based on legitimate interests, and withdraw consent for anything you switched on.
Email [email protected]. You do not need to cite a law and we will not charge you or make it difficult. We answer within 30 days, usually much sooner. If you are in the UK or EU you can complain to your national data protection authority; in the EU you may also contact the authority where you live. If you are in California, you may ask what we collect and ask us to delete it, and we do not sell or share personal information for cross-context behavioural advertising. If you are in Brazil, the LGPD gives you equivalent rights.
Consumer health data
IRIS is not a health product and does not seek out health information. But a conversation can contain anything, so a transcript, a summary or a memory may end up holding something about your health — and a voice recording from which a voiceprint can be derived is treated as consumer health data under Washington’s My Health My Data Act.
We handle it the same way as everything else on this page: it stays on your phone unless you turned on backup or recordings; it is not sold, not shared for advertising, and not used to train anything; voiceprints stay on your device. We do not sell consumer health data, and we would not do so without your separate written authorisation. You can delete it in the app, or ask us to delete our copy — see Your rights, or write to [email protected], and we will confirm when it is done.
IRIS is not for patient records or other confidential professional material. If you are a clinician, do not use it for consultations: we have no business associate agreement, and the Even Realities platform does not permit health-consultation use.
Children
IRIS is for adults. You must be 18 or older to use it, we do not knowingly collect data from anyone under 18, and if we learn that we have, we delete it. If you believe a child has used IRIS, email [email protected].
Security
Everything travels over HTTPS. Server-side data sits in Cloudflare’s storage and is reachable only with your licence key, which works like a password — keep it to yourself, and tell us if you think it has leaked and we will issue a new one. Recording files are stored under an opaque per-user prefix, so no licence key appears in a file path and one user cannot address another’s audio. Your API keys and integration credentials are stripped out of the cloud backup. No system is perfect; if you find a security problem, email [email protected] and we will treat it as urgent.
Changes to this policy
If this page changes in a way that affects what we do with your data, we update the date at the top and email subscribers. We will not quietly widen it. What has changed so far:
- 24 August 2026 — first published.
- 25 August 2026 — disclosed the vocabulary hints that travel with the audio, and what the computer-audio bridge sends.
- 26 August 2026 — corrected the backup default (on for Pro) and disclosed the per-session speaker voice profiles.
- 10 September 2026 — recognition hints extended to a mode’s “Words to expect” list and the distinctive terms in its files.
- 13 September 2026 — new section: on Pro, Ask and “Hey Even” questions and answers are kept for 48 hours for quality review, with an opt-out in Settings. Added to the table.
- 11 September 2026 — rewritten. Voiceprints taken out of the cloud backup and given their own section with a retention schedule, and the server copies deleted; who we are and where; every retention period stated; named service providers; diagnostics correctly described as on by default; location explained; legal bases, your rights, consumer health data; the age limit raised to 18; and corrections to what we had said about Live captions, recording storage and backup expiry.
Contact
Questions, a deletion request, or anything unclear: [email protected]. We answer within 30 days and usually the same week.
IRIS is made and sold by Sufi Plugins (Lucas Crowley), an independent developer based in Maryland, USA. Postal address available on request at [email protected]. IRIS is not affiliated with Even Realities. · Terms · Fair use · IRIS