Public policy

Privacy Policy

Last updated September 1, 2026

Iris (“we”, “us”) is a personal assistant you use over iMessage. This policy explains what we collect, how we use Google account data, and how you can revoke access or request deletion.

1. Who this is for

Iris is a consumer product. You text our phone number and can start getting help in that same thread immediately. Connecting Google (or other apps) is optional and unlocks deeper inbox/calendar context when you choose. There is no separate mobile app to install for core use.

2. Information we collect

  • Phone / messaging identity — the number and conversation identifiers we need to reply over iMessage.
  • Assistant mailbox — we provision a unique agent email address for you (for example on mail.ihermes.co). Mail you send or forward to that address is processed so the assistant can acknowledge it over iMessage, extract short memory, and act when you ask. This is not access to your personal Gmail until you connect Google.
  • Google account email — to identify which Google account you connected (userinfo.email), when you link Gmail via our first-party Google connect.
  • Gmail (read-only) — message content and metadata needed to summarize email and surface what needs your attention (gmail.readonly). We do not send, delete, or modify mail via first-party Google.
  • Google Calendar (via optional Calendar connect) — when you connect Google Calendar for reminders and scheduling, we may read event titles, times, and locations, and create or update events you ask for (including reminder holds). This uses a separate Calendar connect flow with read and write access.
  • Optional integrations — if you connect other tools (for example Linear, Slack, or Google Calendar), we store the tokens and data required for those features under the same principles.
  • Derived memory — short facts we extract to make the assistant useful over time (preferences, recurring context). These are stored in our database, encrypted at rest where secrets are involved.
  • Scheduled reminders — when you ask to be reminded, we store the reminder text and fire time so we can text you over iMessage (and optionally email from your assistant address) at that time.
  • Advertising measurement — when a new user first messages Iris, we may send Meta a one-way hashed phone identifier and a Contact event to measure whether an advertisement led to the conversation. We do not send message contents, internal account identifiers, or Google user data for this measurement.
  • Technical logs — basic operational logs (errors, request health) to keep the service running. We do not sell advertising profiles.

3. How we use Google user data

We use Google user data solely to provide and improve the Iris personal assistant features you request, including:

  • Answering questions about your calendar and upcoming schedule
  • Proactive reminders over iMessage, and calendar events for those reminders when Calendar is connected
  • Reading email context so we can summarize inbox items and priorities you ask about
  • Maintaining a private per-user agent profile so answers stay specific to you

OAuth tokens are stored encrypted on our servers. Access tokens are refreshed as needed to keep the assistant working. We do not use Google user data for advertising, credit decisions, or unrelated AI training sold to third parties.

4. Google API Services User Data Policy — Limited Use

Iris’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • We only use Google user data to provide user-facing features that are prominent in the app’s user interface (iMessage conversations with your agent).
  • We do not transfer Google user data to third parties except as necessary to provide or improve user-facing features, for security, or as required by law — and not for serving ads.
  • We do not allow humans to read Google user data unless you give us permission, it is needed for security/compliance, or the data is aggregated and anonymized for internal operations.
  • We do not use Google Workspace APIs to develop, improve, or train generalized/non-personalized AI or ML models.

5. Sharing

We use infrastructure providers (for example hosting and database) to run the product. They process data only to provide those services to us. We may also use Meta as an advertising measurement provider, using a hashed phone identifier and conversion metadata as described above. Message contents, internal account identifiers, and Google user data are not included. We do not sell your personal information. We may disclose information if required by law or to protect the security of the service or our users.

6. Retention

We keep your connection tokens and assistant memory while your account is active. If you disconnect Google or ask us to delete your data, we remove or irreversibly anonymize associated tokens and personal memory immediately, except where we must retain limited records for security, fraud prevention, or legal obligations.

7. Your choices — revoke and delete

  • Revoke Google access anytime at Google Account → Third-party access. After revocation we can no longer read Gmail (or Calendar, if that app was authorized).
  • Delete your Iris data by emailing support@ihermes.co from the phone number or Google email associated with your account. We will confirm when deletion is complete.
  • You can also stop using the product by ceasing to message the Iris number.

8. Security

We use encryption for OAuth secrets at rest, HTTPS in transit, and access controls on our systems. No method of transmission or storage is 100% secure; we work to protect your information using industry-standard practices appropriate to the sensitivity of the data.

9. Children

Iris is not directed to children under 13, and we do not knowingly collect data from them.

10. Changes

We may update this policy from time to time. The “Last updated” date at the top will change when we do. Continued use after an update means you accept the revised policy.

11. Contact

Iris — privacy and support:
support@ihermes.co
Website: https://iris-agent.co

Questions: support@ihermes.co. Public policy for Google OAuth verification and everyday users.