Policies

IAA Privacy Policy

Effective August 2026

IAA collects information submitted through its forms for application review, directory administration, communication, security, and platform operation. Public profile information is published only after approval and authorization. IAA does not sell submitted personal information.

When controlled IAA AI access is enabled, member text is sent to IAA's configured AI service provider. The Action Planner does not store its prompt or generated plan in IAA's application database; only an action the member individually reviews and adds to Today becomes an IAA record. The conversational workspace stores owner-scoped conversations, messages, sources, structured feedback, and limited usage metadata in IAA's database so members can resume their work.

When a member deletes a conversation, its messages, structured sources, and structured feedback are permanently deleted. IAA retains only a scrubbed conversation tombstone and sanitized non-content usage/security records for rate limiting, abuse prevention, cost controls, and operational auditing. Those retained records do not contain prompts, responses, sources, feedback prose, confidential data, or deleted conversation content. A sanitized record that deletion occurred may be retained.

IAA's current OpenAI runtime requests set store: false. This limits provider-side Responses storage but does not prevent request processing or override provider safety, legal, or account-level retention practices. Production AI remains disabled until server-side gates and founder-approved provider, privacy, access, and operational configuration are in place. IAA does not use saved conversations or feedback for automatic model training.

Questions may be submitted through the Contact page.