Privacy Policy
Last updated October 3, 2026
This Privacy Policy explains what personal information Brandon P, operating as ISO Space (“ISO Space,” “we,” “us”) collects when you use the ISO Space website and app (the “Service”), why we collect it, who we share it with, how long we keep it, and the rights and choices you have. We are the controller of the personal information described here.
1. Summary
- Your files are private to your account. Only you, and people you choose to share a file with, can open them.
- We do not sell or rent your personal information, share it for cross-context behavioral advertising, show ads, or use your content to train AI models.
- We collect only what we need to run the Service, and you can ask us to access, correct, export, or delete your data at any time.
2. Information we collect
Information you give us
- Account information: name, email address, and password. Your password is stored only as a salted cryptographic hash by our authentication provider; we never see it in plain text.
- Your content: notes, documents, spreadsheets, presentations, uploaded files and images, drawings, folders, calendar events, reminders, page settings, your desk pet’s artwork, and the Sheets add-ons you install.
- Payment information: if you subscribe, your plan, billing interval, subscription status, and billing history. Your card details go directly to our payment processor, Stripe; we never receive or store your full card number.
- Social information: your username and permanent public ID, friend requests and connections, blocks, messages, message reactions, event invitations, and the files you share and with whom.
- AI requests: the text you select when you use an AI action, and a record of the action type and time (used to enforce usage limits).
- Communications: anything you send us, such as support requests or legal notices.
Age confirmation
At sign-up we ask for your birth month and year only to confirm you meet the minimum age. We do not store your birth month or year. We store only that you passed the check, when, and which version of the check you completed. If you do not meet the minimum age, your browser remembers that for 30 days so the check cannot simply be repeated.
Information collected automatically
- Presence: while you have a shared file open, the other people on that file can see your name and avatar.
- Error reports: if the app crashes, a report with technical details about the error (such as the page, browser, and stack trace) is sent to our error-monitoring provider so we can fix it.
- Technical data: IP address, browser type, device and operating-system information, and request times, which our hosting and authentication providers process to deliver and secure the Service, including limiting repeated sign-in or AI requests.
- Browser storage: we use local storage for sign-in sessions and preferences. See the Cookie and Storage Policy. We do not use advertising or cross-site tracking cookies or third-party analytics.
3. How and why we use information (and our legal bases)
- To provide the Service (store and sync your content, deliver messages and invitations, run reminders): necessary to perform our contract with you.
- To secure the Service (authentication, rate limiting, abuse prevention, fraud detection, enforcing our terms): our legitimate interests in keeping the Service and its users safe, and to comply with law.
- To communicate with you (verification codes, password resets, important changes, replies to support): contract performance and legitimate interests.
- To run AI features you request: contract performance, only when you choose to use them.
- To comply with law and respond to lawful requests, and to establish, exercise, or defend legal claims.
We do not use automated decision-making that produces legal or similarly significant effects about you.
4. Who we share information with
We share personal information only as described here:
- Supabase — database, file storage, authentication, and real-time messaging.
- Cloudflare — website hosting, delivery, and network security.
- Groq — generates AI responses from the text you select, only when you use an AI action.
- Stripe — processes subscription payments, trials, and billing, and receives your email address and payment details.
- Sentry — receives technical error reports when something breaks, so we can diagnose and fix it.
- Google Fonts — when you choose an editor font, your browser downloads it from Google, which receives your IP address.
- People you choose: friends see your handle, messages you send them, and events you invite them to after they accept. People you share a file with can see and, if you allow it, edit that file, and see when you are viewing it.
- Legal and safety: when we believe in good faith that disclosure is required by law, subpoena, or court order, or is necessary to protect the rights, property, or safety of you, other users, us, or the public.
- Business transfers: if we are involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction, subject to this Policy, and we will notify you before it becomes subject to a different policy.
Our service providers may process personal information only on our instructions and are contractually required to protect it.
5. International transfers
Our providers may store and process information in the United States and other countries whose data-protection laws may differ from yours. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses to protect information transferred internationally.
6. How long we keep information
- Account information and content: while your account is active.
- Items in Trash: until you delete them permanently or delete your account.
- AI request records: up to 90 days, for enforcing usage limits and preventing abuse.
- After you delete your account, we delete or anonymize your personal information within 30 days, except for information we must keep for legal, security, or dispute-resolution purposes, and copies in encrypted backups, which are overwritten within their normal rotation (up to 90 days).
- Your public ID is permanently retired, not reused, so no one else can ever take your handle. The retired ID is kept without any link to your personal information.
- Messages you sent remain visible to the recipients who already received them until they delete them or their accounts.
7. Security
We use industry-standard safeguards, including encryption in transit (HTTPS), hashed passwords, per-user database access rules that stop any account from reading another account’s private data, and rate limiting. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a data breach affecting your personal information occurs, we will notify you and the relevant authorities as required by law.
8. Your rights and choices
Depending on where you live, you may have the right to:
- access the personal information we hold about you and receive a copy in a portable format;
- correct inaccurate information;
- delete your information and account;
- restrict or object to certain processing, including processing based on legitimate interests;
- withdraw consent where processing relies on consent, without affecting earlier processing;
- not be discriminated against for exercising your rights; and
- complain to your local data-protection authority.
To make a request, email [contact email] from the address on your account. We may need to verify your identity before acting, and we will respond within the time required by law (generally 30 days, or 45 days for California residents, extendable where the law permits). You may use an authorized agent where the law allows; we may ask for proof of their authority. If we deny your request, you may appeal by replying to our decision, and we will respond to the appeal within the time the law requires.
9. Additional information for specific regions
- European Economic Area, United Kingdom, and Switzerland: our legal bases are listed in section 3. You may complain to the supervisory authority where you live or work.
- California and other U.S. states with privacy laws: in the last 12 months we collected identifiers, account and customer records, commercial information (subscription and billing history), internet or network activity, and the content of your files and messages, for the purposes in section 3, and disclosed them to the service providers in section 4. We have not sold or shared personal information for cross-context behavioral advertising, and we do not knowingly sell or share the personal information of anyone under 16. We do not use or disclose sensitive personal information for purposes that would require offering a right to limit.
10. Children
The Service is not directed to children under 13 (or the higher minimum age in your country), and we do not knowingly collect their personal information. If we learn we have collected such information, we will delete it promptly. If you believe a child has provided us information, contact [contact email].
11. Do Not Track and Global Privacy Control
We do not track you across other websites, so there is no cross-site tracking for Do Not Track to disable. Where required by law, we treat a Global Privacy Control signal as a valid request to opt out of sale or sharing, which we do not do in any case.
12. Changes to this Policy
We will post any changes here with a new “Last updated” date. For material changes, we will give reasonable advance notice in the app or by email. We will not use personal information in a materially different way from what we described when it was collected without your consent where the law requires it.
13. Contact
Questions or requests about privacy: [contact email]. Controller: Brandon P, operating as ISO Space.