ijr.ai · Effective July 22, 2026
Privacy Policy
We built IJR.ai to sharpen thinking, not to harvest data. This policy explains what we collect, why, and the controls you have over it. It applies to every IJR product and surface — ijr.ai, open.ijr.ai, the product subdomains (inbox, drive, focus, projects, studio, circles, pulse, earn), and the sub-products they serve: Chat, Pulse, Inbox, Drive, Focus, Projects, Studio, Channels, Games, Journals, and Earn (together, the “Services”). The Services are operated by IJR AI, Inc.
1. Information We Collect
- ·Account information — your name, email address, and profile details, collected when you register. Authentication is handled by our identity provider, Clerk, which processes your sign-in credentials on our behalf; we never see your password.
- ·Content you create — chat conversations, questions and answers, documents and files you upload, journal posts, comments and reactions, games and characters you build, project boards, calendar entries and tasks you create in the Services.
- ·Connected-account data — if you connect a third-party account (see Section 3), the data that service makes available under the permissions you grant, such as emails, calendar events, contacts, files, or messages.
- ·Payment information — processed by Stripe. We receive subscription status, plan, and billing metadata; we never store your full card number.
- ·Usage and device data — pages visited, features used, approximate location derived from IP address, device and browser type, collected through server logs and the analytics described in Section 8.
- ·Attribution data — if you arrive via a marketing link or an Earn partner link, we record the campaign parameters (UTM tags, referrer, landing page) that brought you here.
2. How We Use Your Information
We use the information we collect to:
- ·Provide, operate, personalize, and improve the Services.
- ·Authenticate your identity and maintain your session.
- ·Send transactional emails such as sign-in codes, invites, notifications, and account notices.
- ·Process payments, subscriptions, and Earn program payouts.
- ·Detect and prevent abuse, fraud, and security incidents, including automated moderation of submitted content.
- ·Comply with legal obligations.
- ·Conduct internal research to improve product features and answer quality.
We do not sell your personal information. We do not use your conversation content or connected-account data to train our own models without your explicit opt-in.
3. Connected Accounts
Several Services work by connecting accounts you already use — for example Gmail and Google Calendar, Google Drive, Google Contacts, Microsoft 365, Slack, Notion, GitHub, Dropbox, Facebook, Instagram, TikTok, and X. Connections are made through OAuth: you grant permissions on the provider’s own consent screen, and access tokens are held and refreshed by our secure connection infrastructure (Nango and Unipile) — encrypted, never exposed to your browser. You can disconnect any account at any time from Settings, which revokes our access and deletes associated tokens.
Google user data — Limited Use. IJR.ai’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the features you request (for example, triaging your inbox or scheduling on your calendar), is not used for advertising, and is not transferred to third parties except as necessary to provide those features, for security, or to comply with law.
4. AI Processing
The Services are built on large language models and related AI systems. When you use an AI feature, the relevant content — your prompt, and where the feature requires it, context such as the email or document being worked on — is sent to the model provider that powers that feature (for example Anthropic, OpenAI, Google, or xAI, routed through Vercel’s AI Gateway). These providers process the data to generate the response and are bound by agreements that restrict use of your data for their own purposes. Submitted content may also be screened by automated moderation systems to enforce our acceptable-use rules and safety protections.
5. Information Sharing
We share your information only in the following circumstances:
- ·Service providers — vendors who help us operate the Services under data processing agreements: hosting and file storage (Vercel), authentication (Clerk), connection infrastructure (Nango, Unipile), payments (Stripe), product analytics (PostHog), error monitoring (Sentry), transactional email (Resend), and the AI model providers described in Section 4.
- ·Legal requirements — when required by law, regulation, or valid legal process, or to protect the rights, property, or safety of IJR AI, our users, or the public.
- ·Business transfers — in connection with a merger, acquisition, or asset sale, with notice provided to you.
6. Content You Make Public
Some Services are public by design. Journal posts you publish, community answers you contribute, characters and games you share to the community shelves, comments and reactions on Pulse stories, your reader profile, and chat threads you explicitly share by link are visible to anyone — including on open.ijr.ai, where public content is indexable by search engines. Your private account details are never included; only the content you chose to publish. Think before you post: content you make public may be copied or redistributed by others.
7. Children and Family Accounts
The Services are not directed to children under 13, and we do not knowingly collect personal information from them outside a parent-managed family account. Family features let a parent or guardian link a child’s account to their own, apply parental controls and a safe-content baseline, and manage the child’s experience across the Services (including Games). Parental-control settings are protected by a PIN held only in hashed form. If you believe a child under 13 is using the Services without a managing parent, contact us at hello@ijr.ai and we will take appropriate action.
8. Cookies and Analytics
We use a small set of first-party cookies for sign-in, guest rate limiting, and marketing/Earn attribution, plus privacy-respecting product analytics. The full list of cookies, what each one does, and how long it lasts is in our Cookie Policy.
9. Data Retention and Deletion
We retain your account data and content for as long as your account is active or as needed to provide the Services. Connected-account data is generally fetched at the time you use a feature rather than copied into our systems; where any of it is stored, disconnecting the account deletes it. If you delete your account, we will delete or anonymize your personal information within 30 days, except where retention is required by law (e.g. billing and payout records) or needed to prevent abuse. Content you published publicly may remain visible where others have interacted with it (for example, remixes of a game you shared), but is disassociated from your identity. Anonymized, aggregated data that cannot be linked back to you may be retained indefinitely.
10. Security
We implement industry-standard security measures including encryption in transit (TLS) and at rest, AES-256-GCM encryption for stored connection tokens, least-privilege access controls, and continuous automated security scanning of our code and dependencies. No system is perfectly secure. In the event of a data breach affecting your information, we will notify you as required by applicable law.
11. Your Rights and Choices
Depending on your jurisdiction, you may have the right to:
- ·Access a copy of the personal data we hold about you.
- ·Correct inaccurate or incomplete information.
- ·Request deletion of your personal data.
- ·Object to or restrict certain processing activities.
- ·Data portability — receive your data in a machine-readable format.
- ·Withdraw consent where processing is based on consent, including disconnecting any connected account at any time.
To exercise any of these rights, email us at hello@ijr.ai. We will respond within 30 days.
12. International Users
The Services are operated from the United States, and your information is processed and stored there. If you access the Services from outside the U.S., you understand that your information will be transferred to and processed in the United States, where data protection laws may differ from those of your jurisdiction. Where required, we rely on appropriate safeguards for such transfers.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by a prominent notice within the Services before the change takes effect. The “Effective date” at the top of this page will always reflect the most recent revision. Continued use of the Services after the effective date constitutes acceptance of the updated policy.