1. Scope
This Privacy Policy applies to the iriz application for macOS (the “App”) and the iriz marketing website (the “Website”). iriz is a local-first contextual memory: it can observe meaningful changes on the active screen, optionally process audio, preserve useful events, create Actions from commitments and unfinished work, and answer questions from sourced memory.
This policy describes the current product implementation. Distribution platforms may process purchase, download, update, or diagnostic information under their own terms and privacy policies.
2. Information stored and processed on your Mac
Depending on the features and permissions you enable, iriz may process and store:
- screen observations, including screenshots, visible text found through OCR, active application name, window title, and browser URL;
- microphone audio and, during recognized meetings, system audio;
- structured memory entries, summaries, entities, URLs, timestamps, and confidence information;
- Actions, subjects, completion evidence, and state history;
- Ask iriz conversations, including pinned state and recent answers;
- your settings, exclusions, and retention choices; and
- an optional short voice reference used to identify you as “You” in diarized meeting transcripts.
Before an AI request, iriz performs local frame comparison, Apple Vision OCR, silence detection, exclusions, sensitive-text filtering, and session grouping. Local search uses SQLite full-text search and, where supported, Apple Natural Language embeddings to rank relevant memories before an assistant request is composed.
Structured memory, Actions, conversations, and the full-text search database are maintained locally and serialized to an AES-GCM encrypted file. Raw screenshot and audio files are encrypted locally and expire automatically after 24 hours. Encryption keys, your OpenAI API key, and any optional voice reference are stored in macOS Keychain.
3. Information iriz does not capture
iriz does not capture keystrokes, clipboard contents, or camera video. It pauses when the Mac is locked, excludes its own interface and known password managers, and avoids secure text fields and recognized authentication windows. You can add excluded applications, domains, and window-title keywords.
4. Information sent to OpenAI
AI features require an OpenAI API key that you provide. The key is stored in macOS Keychain, and requests are sent directly from your Mac to OpenAI. There is no iriz server in the middle. Depending on the feature you use, a request may include a relevant screenshot, OCR text, application or URL context, an audio segment, a question, a bounded set of locally selected memory entries, or a small amount of recent context from the active Ask iriz conversation.
On supported Macs, Apple Foundation Models may receive only the OCR or transcript and app, window, domain, and audio-source metadata that iriz supplies. It does not automatically receive personal Siri context or read Calendar, Reminders, Contacts, Mail, Messages, or personal files. Exact capabilities are qualified independently: an approved gate may discard only clearly empty, low-risk observations, while a separately approved local-event capability may create only an observed context, research, document, or note event. Until the exact Apple model, prompt, schema, and capability pass qualification, and whenever content is uncertain or high-risk, iriz falls back to task-specific OpenAI models. OpenAI handles observation classification, meaningful refinement, assistant answers, standard transcription, and multi-speaker transcription when required.
An unchanged screen or silence does not produce an OpenAI call. When you use Ask iriz, memory is searched and ranked locally first; only a limited set of the best-matching events is included in the answer request. If the network or API key is unavailable, eligible observations remain in an encrypted local queue and may be retried before the raw evidence expires.
iriz sends store: false with Responses API analysis requests and does not intentionally create server-side conversation history. OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer opts in. OpenAI may still retain abuse-monitoring logs, including customer content, for up to 30 days by default, unless the API organization has approved data controls. Audio transcription is governed by OpenAI’s API data controls as well.
Your use of OpenAI is also subject to the terms, privacy policy, and data controls associated with your OpenAI API account. Review OpenAI’s API data controls before enabling AI features.
5. Information sent to the iriz developer
The current App does not require an iriz account and does not include developer-operated analytics, advertising, tracking, or crash-reporting services. The iriz developer does not receive your memory, Actions, conversations, screenshots, audio, API key, or queries through the App.
If you contact support, the information you choose to include in your message is used to respond to your request. Do not send private memory content, screenshots, audio, or API keys unless support specifically asks for a safe diagnostic item.
6. Website data
This Website is static and does not use cookies, analytics, advertising pixels, forms or user accounts in its current version. The hosting provider may process ordinary request information such as IP address, browser type, requested page, timestamp and security events to deliver and protect the Website. That processing is governed by the hosting provider’s terms and configuration.
7. Your controls and choices
You can control iriz at any time by:
- pausing or resuming observation;
- enabling or disabling screen and audio features;
- opening the relevant macOS Privacy setting from a permission message;
- revoking Screen Recording, Accessibility, Microphone, or Notification permission in macOS System Settings;
- adding excluded applications, domains, or window-title keywords;
- changing structured-data retention;
- removing your OpenAI API key or optional voice reference;
- editing, completing, dismissing, or resetting Actions;
- pinning or removing Ask iriz conversations;
- deleting individual memory events; or
- deleting the App and its local data from your Mac.
Exports are created only when you request them. JSON and Markdown exports are not encrypted and may contain private memory details and URLs; raw screenshots, raw audio, and API keys are excluded.
8. Retention and deletion
Encrypted raw screenshots and audio expire after 24 hours. Structured memory is kept according to the retention setting you choose. Removing an item or clearing local application data deletes it from the App’s local store. Information already transmitted to OpenAI is subject to OpenAI’s retention and deletion practices and any data controls configured for your API organization.
9. Audio and participant notice
Audio capture is optional. Laws governing recording and transcription vary by location. You are responsible for obtaining any required consent, informing meeting participants when appropriate, and using audio features in compliance with applicable law and workplace policy.
10. Children
iriz is a professional productivity tool and is not directed to children. Do not use the App to intentionally collect information from children where doing so would violate applicable law.
11. Security
iriz uses native macOS security features, local AES-GCM encryption, macOS Keychain, and file-protection options to reduce risk. No method of storage or transmission is completely secure. Keep your Mac account, OpenAI API key, and unencrypted exports protected.
12. Changes to this policy
This policy may be updated when iriz features, distribution methods, or service providers change. The “Last updated” date above will identify the latest version. Material changes should be reviewed before you continue using a new App version.
13. Contact
For privacy questions or support, use the contact method provided on the Support page or by the store or distribution channel from which you obtained iriz.
This policy is a product-facing draft based on the current implementation. The final publisher identity, contact details, hosting configuration and App Store privacy disclosures should be reviewed before public release.