Privacy policy

This notice explains how Iosis uses information when you create an account, join the waitlist, authenticate, or use the product. Last updated 24 July 2026.

Controller

Iosis is the controller for the personal information described here. Questions, objections and rights requests can be sent to cz07business+iosis@gmail.com.

Information we collect

  • email address;
  • name and profile image when supplied by you or an authentication provider;
  • the authentication method and provider account identifier used to sign in;
  • account, session and security information needed to authenticate you;
  • an access status used to determine whether your account can enter the product;
  • strategy YAML, graph layout, revision hashes and related project information you save in the product;
  • page views and product events described below; and
  • billing records such as Stripe customer, subscription, checkout, invoice and payment status identifiers.

Our providers may also process sign-in time, IP address, browser or device information, referrer, page path, approximate location and performance measurements.

Product events record waitlist CTA clicks, workbench entry, node additions, connections and deletions, structurally valid graph revisions that are successfully saved, new strategy starts, strategy loads, branches and exports, and successful opening of Stripe checkout or the billing portal. Event properties are limited to operation types, coarse graph-size bands, revision numbers and action categories. When you are signed in, PostHog receives your stable Clerk user ID and access state so these events can be grouped across visits for funnels, retention analysis and behavioral cohorts. Signed-out page views and landing-page actions are anonymous. We do not send strategy names, YAML, graph parameters, strategy or workspace IDs, email addresses, datasets or research outputs.

Stripe collects and processes payment details directly. Iosis does not receive or store your complete card number or card security code.

How we use it

  • authenticate users, maintain sessions and prevent unauthorised access;
  • review and administer access to the Iosis application;
  • validate the product, conduct user research and organise testing;
  • measure activation, saved graph edits, returning workflows, feature use and billing intent;
  • create and manage subscriptions, process payments, maintain billing records and handle refunds or disputes;
  • operate, secure and diagnose the website and application; and
  • comply with legal obligations and protect legal rights.

We rely on steps requested before entering a contract and performance of our contract with you to provide accounts and paid services. We rely on our legitimate interests to secure, validate and develop Iosis, and on legal obligations where billing, tax, accounting or fraud-prevention records must be kept. You can object to processing based on legitimate interests.

Service providers

We do not sell personal information. The services that process information for this workflow are:

  • Clerk for authentication, account management, session security and the account access flag;
  • Vercel for hosting and performance monitoring;
  • PostHog for page and product-event analytics. Iosis configures PostHog without DOM autocapture, session recording, cookies, local storage or session storage. Signed-in events use the Clerk user ID as a pseudonymous account identifier so product use can be analysed across visits. PostHog is configured in its EU region and the project should discard client IP data;
  • Supabase for database hosting and durable product state;
  • Stripe for checkout, payment processing, subscription management, invoices, refunds and payment-fraud prevention;
  • Google or GitHub when you choose that provider to authenticate.

Google and GitHub also process your interaction under their own privacy notices and your settings with those providers.

International processing

Clerk, Google, GitHub, PostHog, Stripe, Supabase and Vercel operate internationally, so information may be processed outside the United Kingdom. Where required, we rely on an applicable UK adequacy regulation or contractual safeguards made available by the provider. Contact us for more information about safeguards relevant to your account.

Retention

Waitlisted accounts are kept for up to 24 months after the last meaningful interaction unless they are no longer needed or a valid deletion request is made sooner. Approved account information is kept while the account is active and for up to 24 months afterwards where needed for security, dispute resolution or legal obligations. Saved strategies and project state are kept while the account is active and removed following account deletion, subject to a limited backup-retention period. Billing, transaction and invoice records may be kept for longer where required for tax, accounting, fraud prevention or legal claims. We retain access to identified and aggregate product analytics for no more than 24 months and allow shorter reporting windows to expire when the information is no longer needed. Providers may retain payment, security, analytics and backup records under their documented schedules.

Your choices and rights

Creating an account is optional. An email address and supported authentication method are required because we cannot authenticate or approve access without them. Google and GitHub are optional alternatives to email-based authentication.

Depending on the circumstances, you may ask us to:

  • provide access to your personal information;
  • correct inaccurate or incomplete information;
  • delete or restrict the use of your information;
  • provide information you supplied in a portable format; or
  • stop processing based on legitimate interests.

We do not make solely automated decisions that produce legal or similarly significant effects.

To request account deletion, email cz07business+iosis@gmail.com.

Complaints

Contact us first if you have a concern. You can also complain to the UK Information Commissioner's Office through its data-protection complaints service, by calling 0303 123 1113, or at ico.org.uk.