This policy covers IRIQ applications and connected services published by IRIQ AI, including IRIQ Capture, IRIQ Wearables, and other IRIQ experiences. A future IRIQ product is covered only when it links to this policy. The separate IRIQ AI website privacy policy covers iriqai.com, including website cookies and analytics.
Privacy questions: hello@iriqai.com
1. Scope and Products
- IRIQ Capture handles documents, photos, OCR text, local edits, exports, and optional cloud AI actions.
- IRIQ Wearables handles compatible wearable discovery, device sessions, user-initiated capture or transfer, local notes, optional health access, and optional cloud AI actions.
- Features differ by app version, device, region, and permissions. A disclosure below applies only when the described feature is available and you use it.
2. Local and On-Device Data
- We design core workflows to remain local where practical. Local files, settings, notes, charts, Bluetooth scan observations, and cached media stay in the app's private storage unless you export, share, sync, submit, or delete them.
- Uninstalling an app or clearing its storage normally removes its app-private data. Device backup or device-to-device transfer behavior can vary by app build, Android version, and device manufacturer.
- Locally displayed calculations and wellness trends are descriptive. They do not by themselves establish a medical diagnosis or a claim about what a nearby person or device is doing.
3. IRIQ Capture Data
- Camera capture, system-selected photo import, document detection, cropping, perspective correction, classical image enhancement, and local editing use only the image you capture or select.
- OCR runs on-device using bundled Google ML Kit recognition models. OCR text is not sent to IRIQ merely because recognition occurred.
- Face-landmark features in Beauty Studio use on-device ML Kit processing. Landmark and contour data is kept in memory for the active editing session and is not used to identify a person.
- Cloud AI receives document images or extracted text only when you explicitly start an AI action; Section 7 describes that processing.
4. IRIQ Wearables Data
- Nearby-device discovery processes Bluetooth names, addresses or masked identifiers, signal strength, advertised services, and manufacturer identifiers to find and classify compatible wearables.
- Bluetooth evidence may indicate that a possible glasses or camera-capable wearable is nearby. It cannot determine identity, ownership, field of view, or whether a camera is recording, and the app does not offer a command to disable another device's recording indicator.
- When you initiate capture or media sync, a compatible wearable may transfer photos or other media to your phone through Bluetooth, Wi-Fi, or a guarded local HTTP connection. Local-network transfer does not by itself upload that media to IRIQ.
- Hands-free notes save recognized text in app-private local storage. The app does not retain a voice recording for those notes.
- Vendor-specific integrations may be governed by the device maker's terms and privacy practices. IRIQ displays a capability only when the app has an implemented adapter and runtime evidence that the capability is available.
5. Health and Wellness Data
- Health access is optional. On supported Android devices, Health Connect lets you choose both the data categories and the apps that may read or write them. IRIQ reads only categories you authorize.
- Health Connect records and compatible sensor readings may be used locally for metric cards, charts, trends, variability, and other descriptive wellness summaries.
- Health data is not sent to IRIQ merely because you viewed a chart. If you enable Health context and explicitly submit a health or context-fusion AI request, the app sends only the permitted values and trends needed for that request.
- IRIQ health features provide wellness information, not emergency monitoring, medical diagnosis, treatment, or a substitute for professional care. Seek qualified medical help for symptoms or urgent concerns.
- You can withdraw Health Connect permissions in Android settings. Removing permission prevents new reads but does not automatically delete an already completed AI operation record or a file you previously exported.
6. Voice, Audio, and Speech
- Microphone access occurs only after Android permission and a user action, such as starting push-to-talk or dictating a note.
- IRIQ Wearables uses Android speech recognition to convert speech into text. Depending on your device and selected recognition service, Android or that service may process audio under its own terms.
- IRIQ sends the recognized transcript—not raw microphone audio—to its text AI endpoint when you explicitly submit a voice question. Empty, cancelled, or rejected recognition is not submitted as an AI request.
- Spoken replies use Android text-to-speech. The selected TTS engine's data practices apply to its processing.
7. Optional Cloud AI
- Cloud AI runs only after an explicit action such as Send, Analyze, Ask What I See, health analysis, or context fusion. Preparing a prompt, capturing a photo, viewing health data, or transferring media does not by itself start a billable AI request.
- A request may contain the prompt or recognized transcript and the specific content you selected, such as an image, OCR text, permitted health values or trends, and selected context labels.
- Requests go through IRIQ's authenticated backend. Provider credentials for services such as Anthropic, OpenAI, Google Gemini, or other configured providers remain server-side and are not packaged in the app.
- We may decline, safety-filter, rate-limit, cancel, or temporarily disable a request. Local device functions remain available where they do not depend on that cloud service.
- AI output can be inaccurate. Review it before relying on it, especially for health, safety, financial, legal, or purchasing decisions.
8. Authentication and App Integrity
- IRIQ uses Firebase Authentication for account sign-in, which can include email address, authentication-provider metadata, verification state, and a stable account identifier.
- Billable IRIQ Wearables AI features require a signed-in user. If another IRIQ app offers a clearly identified anonymous or free cloud path, Firebase may issue that installation a random anonymous identifier without an email address or name.
- The app sends a fresh Firebase ID token with authenticated requests. Where supported, Firebase App Check or Google Play Integrity evidence may also be sent so the backend can assess whether requests come from a genuine app installation.
- App-integrity evidence can include app/package identity, certificate or licensing signals, device-integrity verdicts, timestamps, and anti-abuse signals supplied by Google. The backend, not the client, decides whether protected operations are allowed.
9. Shared Credits and Entitlements
- The same signed-in IRIQ account may share its authoritative credit balance, transaction history, subscription entitlement, and eligible purchases across participating IRIQ apps.
- The backend determines an operation's current price and eligibility. It reserves credits before provider execution, commits a charge only for usable output, and releases or refunds the reservation on eligible failure, timeout, rejection, or cancellation.
- Unique operation and idempotency identifiers prevent the same logical retry from being charged twice. Ledger records can include operation type, status, price version, credits reserved, charged or refunded, timestamps, and non-content diagnostic metadata.
- The app does not determine its own balance, premium status, price, debit, or refund. If the server price changes from the price displayed for confirmation, the app requires reconfirmation before execution.
- Bluetooth discovery, device pairing, supported capture and local transfer, Health Connect viewing, local charts, Android speech recognition, and device TTS are not themselves credit-consuming cloud AI operations.
10. Cloud Processing and Retention
- Submitted text, images, and selected context are processed to fulfill the requested AI operation. IRIQ services are designed not to place raw request content in application logs or analytics.
- Unless a feature clearly offers cloud saving, synchronization, or history, IRIQ does not intentionally retain raw submitted content after the operation is delivered. Short-lived processing, queues, caches, security logs, and provider-side retention may still apply.
- Operational records such as the credit ledger, entitlement, operation status, provider category, duration, cost, failure reason, and idempotency identifier may be retained while the account is active to maintain balance, history, refunds, reliability, and abuse prevention.
- Third-party AI providers process the portion of content sent to them under their own API data-handling terms. Their retention and international-processing practices are outside IRIQ's direct control.
11. Analytics and Crash Reporting
An IRIQ app may use Firebase Analytics and Firebase Crashlytics. These services can receive app events, device model, OS version, app version, crash traces, and non-content technical outcomes. IRIQ does not intentionally place document text, health values, raw photos, voice recordings, provider credentials, or authentication tokens in analytics or crash reports. Availability and consent controls vary by app, build, and region.
12. Advertising, Purchases, and Payments
- Where an app offers rewarded ads, Google AdMob is requested only after you choose the rewarded action. Consent and privacy-choice controls are shown where required.
- Purchases and subscriptions use Google Play Billing where offered. Google processes payment credentials; IRIQ receives purchase and entitlement information needed to validate and provide the purchase.
- Google Play retains its own transaction records under Google's terms. Deleting an IRIQ account does not delete Google's records or automatically cancel a Play subscription.
13. Permissions by Feature
- Camera and selected photos — Capture documents or media, or import only the item selected through Android's picker.
- Nearby devices/Bluetooth — Discover, identify, connect to, and communicate with compatible wearables. Older Android versions may associate Bluetooth discovery with location permission even when IRIQ does not request or use precise location.
- Local network, Wi-Fi, and internet — Transfer media from a compatible wearable on the local network and access sign-in, protected AI, integrity, billing, ads, and other online services.
- Microphone — User-initiated speech recognition for voice questions or dictated notes.
- Health Connect — Read only health categories you grant; write access is requested only if a released feature clearly requires it.
- Notifications — Show transfer, device, health, or operation status where a released feature requests notification permission.
IRIQ requests permissions at runtime when a feature needs them. You can deny or later revoke a permission, although the related feature may stop working.
14. Service Providers and Connected Devices
Depending on the app and feature, service providers can include Google Firebase, Google Play, Health Connect, Android speech recognition and TTS services, Google AdMob, and configured AI providers. Connected wearable manufacturers and their SDKs or companion services may separately process device data. IRIQ does not claim that every discovered device is supported; the app identifies when a validated vendor adapter or companion-app setup is required.
15. Security
- Release apps must not contain reusable backend shared secrets or third-party AI provider keys. Protected AI requests use user authentication and backend-side credential management.
- Network requests to IRIQ and supported platform services use HTTPS/TLS. A guarded local-network transfer may use a device-local HTTP connection and is limited to the user-initiated wearable transfer workflow.
- We use access controls, app-integrity checks where supported, server-authoritative pricing and credits, secret management, and minimized logging. No system can guarantee absolute security.
16. Account and Data Deletion
- Deleting the shared IRIQ account removes the Firebase Authentication account after applicable backend cleanup succeeds. It can affect access, balance, history, and entitlements across participating IRIQ apps.
- Backend credit-ledger and entitlement records associated with the account are deleted where the deletion flow states; non-content reliability records may instead be irreversibly anonymized when needed for aggregate operations.
- Account deletion does not automatically remove app-private files already stored on each device, exported files, media retained by a connected device, or Google Play records. Delete local content in the app where available, clear that app's storage, or uninstall it.
- Use the account and data deletion page or email hello@iriqai.com if you cannot use an in-app deletion path.
17. International Processing
Firebase, Google Play, AdMob, speech or TTS providers, connected-device services, and AI providers may process data outside your country, including in the United States, under their own terms and applicable data-transfer safeguards.
18. Your Choices and Rights
You can choose whether to grant optional permissions, connect a wearable, select Health Connect categories, submit content to cloud AI, enable spoken replies, view an ad, or make a purchase. Depending on your location, you may also have rights to access, correct, delete, restrict, or object to processing. Contact hello@iriqai.com to exercise a right that is not available in the app.
19. Children's Privacy
IRIQ apps are not directed at children and IRIQ does not knowingly collect personal data from children.
We may update this policy when products, data practices, or legal requirements change. The date at the top shows the latest revision. For privacy questions, requests, or deletion help, contact hello@iriqai.com.