Privacy Policy
Last updated: Sep 9, 2026
This policy covers three separate things, which collect very different amounts of data: this website, the IVYX account, and IVYX Studio on your machine. It is written to be checked rather than skimmed, so each item below names the data, why we have it, the legal basis for it, and how long it stays.
Contents
- 1. Who we are
- 2. The short version
- 3. What we collect, and why
- 4. What we do not do
- 5. Cookies and browser storage
- 6. Who else processes your data
- 7. Where your data goes
- 8. How long we keep it
- 9. Your rights
- 10. Security
- 11. Children
- 12. Changes to this policy
- 13. Contact and complaints
1. Who we are
The controller of the personal data described here is [[TBD: full registered company name]], registered in [[TBD: country]] under company number [[TBD: number]], with its registered office at [[TBD: registered address]]. This is the same entity you contract with under the terms of service.
Reach us about data protection at privacy@ivyx.io. [[TBD: if an Article 27 EU/UK representative or a KVKK data controllers' registry (VERBIS) entry is required, name it here.]]
2. The short version
IVYX Studio is a local-first desktop application. Your code, datasets and models stay on your machine: the app makes no network call on launch, and it does not send your files, your notebooks or your run contents to us, neither by default nor on request. There is no product telemetry.
Three things do involve us. You sign in once, so we hold an account: an email address, a password hash and your tier. Downloading the app and browsing the marketplace hits our servers, which keep standard web logs. And this website can load Google Analytics, but only after you choose to allow it.
If you connect a hosted model or AI service yourself, your requests go to that provider, not through us.
3. What we collect, and why
-
Account. Your email address, a hash of your password, your tier and the date the account was created.
- Why we have it: to hold your licence, so signing in licenses the app and a paid tier switches on without a reinstall.
- Legal basis: performance of the contract in the terms.
- Kept for: until you delete the account, then see section 8.
-
Licence records. The licence key, the plan, the seat count and how many are used, and the dates of issue and revocation.
- Why we have it: to issue, verify and revoke licences, and to enforce seat counts.
- Legal basis: performance of the contract.
- Kept for: term of the licence, then as required for tax and accounting records.
-
Sign-in and session. The bearer token issued to your browser or app, and the timestamp.
- Why we have it: to keep you signed in and to license the machine.
- Legal basis: performance of the contract.
- Kept for: token lifetime; see section 5 for what is stored in your browser.
-
Server logs for downloads, the marketplace and the account API. Each entry holds an IP address, a user agent, a timestamp, the requested path and the response status.
- Why we have it: to serve the request, keep the service available, and investigate abuse and attacks.
- Legal basis: our legitimate interest in running and defending the service.
- Kept for: [[TBD: log retention, e.g. 30 or 90 days]].
-
Extension ratings. A rating value and a random per-browser identifier.
- Why we have it: to show an aggregate rating without asking anyone to sign in.
- Legal basis: our legitimate interest in useful listings, with no identity attached.
- Kept for: life of the listing.
-
Support and sales email. Your message, your address, and what we reply.
- Why we have it: to answer you, and to keep a record of what was agreed.
- Legal basis: legitimate interests, or performance of the contract for a customer.
- Kept for: [[TBD: e.g. 2 years after the last message; longer where it forms part of a contract]].
-
Billing records. A company name, a billing contact, an address, tax identifiers and invoices.
- Why we have it: to invoice a paid licence and meet our tax obligations.
- Legal basis: performance of the contract, and legal obligation.
- Kept for: as required by tax and commercial law [[TBD: confirm the statutory period for the jurisdiction in section 1]].
-
Website analytics, collected only if you allow it. Page views, referrer, approximate location, device and browser, and the identifiers Google Analytics sets.
- Why we have it: to see which pages are worth keeping.
- Legal basis: consent, which you give and can withdraw.
- Kept for: [[TBD: confirm the GA4 data-retention setting on the property, e.g. 14 months]].
Two notes on the analytics row, because "we ask for consent" is often less than it sounds:
Analytics is off until you choose "Allow analytics", and off means off: until then the analytics library is never downloaded, so no request reaches Google, no cookie is written and no measurement identifier is stored. Allowing it lets Google set _ga cookies in your browser and process your IP address and page views on our behalf. Advertising and personalisation signals stay switched off in all cases.
4. What we do not do
- We do not sell your data, and we do not share it for advertising.
- We do not read your workspace files, and no part of IVYX Studio sends them to us.
- We do not collect product telemetry or usage analytics from the desktop app.
- We do not use advertising or cross-site tracking cookies.
- We do not measure your company's size. Whether you need a paid licence is a term of the contract, not something the app checks.
- We do not make decisions about you by automated means, and we do not profile you.
5. Cookies and browser storage
This website sets no cookie of its own. What it stores, it stores in your browser's local storage, where it is readable only by this site:
ivyx.consent.analyticsholds your analytics choice, "allowed" or "denied". It is written when you answer the consent banner.ivyx-sessionholds your sign-in token. It is written when you sign in.ivyx-accountholds your email and display name, cached so the header can draw your avatar without a request. It is written when you sign in.ivyx-installation-idholds a random identifier, so one browser cannot rate the same extension twice. It is written when you rate an extension.
The only cookies are the _ga cookies Google Analytics sets, and only after you allow analytics.
Withdrawing consent. Your analytics choice lives in your browser, not in your account, so it is per-browser and per-device. To withdraw it, clear this site's data in your browser settings: the choice is the single ivyx.consent.analytics entry above, and clearing it makes the site ask again.
6. Who else processes your data
- [[TBD: hosting and CDN provider]] hosts this website, the registry and the account API, so it sees server logs and anything in transit through them.
- Google (Google Analytics 4) runs website analytics as our processor. It sees page views and IP addresses, and only for visitors who allowed analytics.
- [[TBD: email provider]] delivers and stores support and sales email, so it sees the contents of your messages to us.
- [[TBD: accounting or invoicing provider, if any]] handles invoicing and bookkeeping, so it sees billing records.
We do not use any other processor for the data in section 3. We may share data where we are legally required to, meaning a valid court order or a lawful request from an authority. If the business is ever sold or merged we may share it with the acquirer, under this same policy. We will tell you before that happens where we are permitted to.
Not processors, and worth separating out: a hosted model or AI service you connect from IVYX Studio, and a third-party extension you install. Those act for themselves under their own terms, and what you send them is outside this policy. Section 10 of the terms covers that relationship.
7. Where your data goes
Our servers are in [[TBD: hosting region]]. Google Analytics involves a transfer to the United States; where that transfer is subject to the GDPR, it relies on [[TBD: transfer mechanism, being the EU-US Data Privacy Framework and/or Standard Contractual Clauses, whichever Google's current terms provide]], and IP addresses are processed for a visitor who has allowed analytics only.
Nothing about your local work is transferred anywhere, because it never leaves your machine.
8. How long we keep it
The retention column in section 3 is the rule for each item. Beyond that:
- When you delete your account, we delete the account record and its licence assignments within 30 days, apart from what we must keep for tax and accounting, and any record of a serious breach of the terms.
- Backups are cycled out within [[TBD: backup retention, e.g. 35 days]], so a deleted record can persist in a backup until that window passes.
- Server logs age out on the schedule in section 3, except a log preserved for an open security or abuse investigation.
9. Your rights
If the GDPR, the UK GDPR or the Turkish KVKK applies to you, you have the right to:
- know whether we hold data about you and get a copy of it;
- correct it if it is wrong or incomplete;
- delete it, where we have no overriding obligation or ground to keep it;
- restrict or object to processing based on legitimate interests;
- take it with you in a portable format, for data you gave us under the contract or by consent;
- withdraw consent at any time, which affects analytics only and does not undo processing already carried out lawfully;
- not be subject to a decision made solely by automated means, of which we make none;
- under the KVKK, additionally to ask that data processed unlawfully be corrected, deleted or destroyed and that third parties we passed it to be notified, and to claim compensation for damage caused by unlawful processing.
To exercise any of these, write to privacy@ivyx.io from the address on your account. We will respond within 30 days, and we will not charge you or ask you to justify the request. If we need to verify who you are, we will ask for the minimum that establishes it.
10. Security
Passwords are stored as hashes, never in plain text. Traffic to this website, the registry and the account API is served over HTTPS. Access to account and billing data is limited to the people who need it to do their job. Session tokens expire and can be revoked.
We keep the attack surface small by design rather than by policy: the desktop app holds no credential of ours, sends no telemetry, and its signing key is sealed in the operating system keychain in a separate process, where the command-line tool cannot read it. There is no copy of your work on our servers to lose.
If a breach affects your personal data and is likely to present a risk to you, we will notify you and the relevant supervisory authority within the deadlines the law sets, which is 72 hours under the GDPR. To report a vulnerability, write to security@ivyx.io [[TBD: confirm this mailbox exists, or use privacy@ivyx.io]].
11. Children
IVYX Studio is a professional tool and is not directed at children. You must be at least 16, or the minimum age for digital consent where you live if that is higher, to create an account. We do not knowingly collect data from anyone below that age; if you believe a child has created an account, write to privacy@ivyx.io and we will delete it.
The education tier is for students and teachers using the app for coursework, and it changes the licence, not the data: an account is still an email address, a password hash and a tier.
12. Changes to this policy
We may update this policy. The date at the top is the date the wording last changed, and previous versions are available on request.
If a change materially affects how we handle your data, we will give at least 30 days' notice by email to the address on your account before it takes effect. A change that would need your consent will ask for it rather than assume it.
13. Contact and complaints
Questions, requests and complaints about your data: privacy@ivyx.io. We would rather hear from you first, and will try to resolve it directly.
You can also complain to a supervisory authority. In the EU that is the authority where you live, work or where the issue arose; in the UK it is the Information Commissioner's Office; in Türkiye it is the Kişisel Verileri Koruma Kurumu (KVKK).
Business customers who need a data processing agreement, a sub-processor list under contract, or a security questionnaire completed should write to sales@ivyx.io.
This policy describes our practices and is not legal advice. It has not yet been reviewed by counsel; the bracketed items above are open.