Privacy Policy
Last updated: July 1, 2026
This Privacy Policy explains how IDA ("IDA", "we") collects, uses, and protects your information when you use our AI chatbot service.
1. Data We Collect
Account data: When you sign in with Google, we receive basic profile information such as name, email address, profile picture, and user identifier (user ID) through Supabase Auth.
Conversation data: Messages you send and assistant responses, chat history, session titles, and UI preferences (theme, language, voice settings) are stored to provide the service and synchronize across devices.
Technical data: API request logs (model, provider, tokens, status), IP address for rate limiting, and session metadata for security and operational analytics.
File uploads: Images or PDFs you attach are processed for text extraction (OCR) and are not stored permanently unless they become part of your conversation history.
2. How We Use Data
- Provide, maintain, and improve the IDA chat service.
- Synchronize your chat history across devices.
- Process AI requests, knowledge base retrieval (RAG), and voice features.
- Prevent abuse, spam, and security violations.
- Comply with legal obligations and respond to valid requests.
3. Storage & Retention
Data is stored on Supabase infrastructure (database and authentication). Chat history is retained as long as the account is active or until you delete it. We may delete inactive data after a reasonable period according to internal policy.
4. Cookies & Local Storage
We use Supabase Auth session cookies and browser local storage (localStorage/sessionStorage) for theme, UI preferences, and configuration caching. Essential cookies are required for login and session functionality.
5. Third-Party Services
IDA integrates with the following providers that process data according to their own policies:
- Supabase — authentication, database, and session storage.
- Google — OAuth login and AI models (Gemini) for chat, embeddings, OCR, and transcription.
- Groq — speech transcription (optional, if configured).
- xAI / OpenAI / Hugging Face — alternative AI models or TTS (if enabled by administrators).
- Vercel — application hosting.
Conversation content may be sent to AI model providers to generate responses. Do not share sensitive information (passwords, OTPs, critical medical data) through chat.
6. Security
We implement reasonable measures to protect data, including encryption in transit (HTTPS), OAuth-based authentication, and database access limited to server-side. No system is 100% secure; use the service with awareness of the risks.
7. Your Rights
You can:
- Access and update your profile through the Account page.
- Delete chat history from within the application.
- Request account deletion by contacting the service administrator.
- Stop using the service at any time.
8. Policy Changes
We may update this policy at any time. Material changes will be noted on this page with the update date. Continued use after changes means you accept the updated policy.
9. Contact
For privacy questions, contact the IDA administrator through official organizational channels.