Contents
- 1. Who We Are and What This Policy Covers
- 2. Data We Handle for Our Customers
- 3. Information We Collect
- 4. How We Use Information
- 5. How Audits Use Your Data
- 6. How We Share Information
- 7. Usage Information from Our Open-Source Tool
- 8. Cookies and Similar Technologies
- 9. How Long We Keep Information
- 10. How We Protect Information
- 11. Your Choices and Rights
- 12. U.S. State Privacy Rights
- 13. Visitors and Customers in the EEA, UK and Switzerland
- 14. Children
- 15. Changes to This Policy
- 16. Contact Us
The short version
- iFixAi Inc. is a U.S. company. This policy covers our website, the iFixAi hosted platform and the usage information our open-source tool sends.
- We collect what we need to run the service: your contact and account details, billing information, and the data you connect for audits.
- When your organization audits an AI agent, we handle that data on its behalf and use it only to run your audits.
- We access AI models through OpenRouter, a SOC 2 compliant provider, to build simulation environments and review audit results. We do not use your data to train AI models.
- We do not sell personal information, and our website does not use tracking or advertising cookies.
- You can ask us to access, correct or delete your information at any time at privacy@ifixai.ai.
This summary is for convenience only. The full policy below is what applies.
1. Who We Are and What This Policy Covers
This Privacy Policy explains how iFixAi Inc. (“iFixAi,” “we,” “us” or “our”), a Delaware corporation at 2810 North Church Street, Wilmington, DE 19802, United States, collects, uses and shares personal information when you:
- visit ifixai.ai or contact us;
- use iFixAi OS (our web dashboard), our MCP connector or our API (together, the “Hosted Services”); or
- run our open-source iFixAi tool, which sends us limited usage information unless you switch it off.
Our services are built for businesses and professionals. Our Terms of Service explain the rules for using them, and terms such as “Agent,” “Audit” and “Report” have the meanings given there.
2. Data We Handle for Our Customers
When an organization uses iFixAi to audit an AI agent, it decides what data goes into the audit, such as the agent’s files and configuration, the credentials we use to reach it, and the agent’s replies. We process that data (“Customer Data”) on the organization’s behalf, as its service provider, and only to provide the Hosted Services to it. The organization’s own privacy policy applies to any personal information in that data.
If you believe your information is included in an agent audited on iFixAi, please contact the organization that runs the agent. If you contact us instead, we will pass your request on and help them respond. Section 5 explains how Customer Data moves through our service.
3. Information We Collect
3.1 Information you give us
- Contact requests: your name, company, work email, the reason you are getting in touch and your message, when you use the contact or demo form on our website.
- Account information: your name, work email address, organization and role in your Workspace.
- Billing information: billing contact details, company details, your package, invoices and payment records. We do not collect payment card numbers.
- Communications: emails, support requests and notes from calls with our team.
3.2 Information from sign-in and connected services
- Sign-in providers: when you sign in with Microsoft or Google, we receive your name, email address and an account identifier from that provider.
- GitHub: when you install our GitHub App, we receive your GitHub account or organization name, the repositories you select and branch and commit information, and we read the files you choose.
- AI tools: when you connect an AI assistant through our MCP connector, we receive the tool’s name and the permissions you approve.
3.3 Information collected automatically
- Technical and log data: IP address, browser and device type, pages requested and the date and time, recorded by our hosting and sign-in providers for security and reliability.
- Sign-in activity: sign-in attempts, including attempts by people whose organization does not yet have access, and administrative actions taken in Workspaces.
- Open-source usage information: see Section 7.
3.4 Business contact information from other sources. We may collect business contact details, such as name, job title, company and work email, from public professional sources, events we attend, referrals and business contact tools, to reach people at organizations that may be interested in iFixAi.
We do not ask for sensitive personal information such as government ID numbers, financial account numbers, or health or biometric data. Please do not include it in forms, messages or your agent’s test data.
4. How We Use Information
We use personal information to:
- respond to enquiries and arrange demos;
- provide the Hosted Services: create Workspaces, manage access, connect repositories and agents, run audits and produce reports;
- bill you and keep business and tax records;
- send service messages, such as sign-in emails, renewal reminders, invoices and security notices;
- protect our services, prevent fraud and abuse (including misuse of promotional offers) and enforce our Terms;
- understand how our services and open-source tool are used and improve them, mainly using aggregated or de-identified information;
- send business-to-business marketing about iFixAi, which you can opt out of at any time; and
- comply with the law and establish or defend legal claims.
We do not sell personal information, we do not share it for targeted advertising, and we do not use personal information or Customer Data to train AI models.
5. How Audits Use Your Data
When your organization runs an audit on the Hosted Services:
- Repositories. Our GitHub App has read-only access to the repositories you choose. We read the agent files you select (such as AGENTS.md or CLAUDE.md). We do not request write access and we do not store GitHub access tokens.
- Simulation environment. We send the selected files to an AI model to draft a simulation environment for your agent, which you can review before any audit runs.
- Agent credentials. We keep the endpoint and credentials needed to reach your agent in encrypted storage and use them only to run your audits. You can remove them at any time.
- Audit results. We send your agent test inputs, record its replies and actions, and send them to AI models for review. In-progress results are deleted as soon as the audit ends. Completed reports, with the evidence behind each finding, are stored in your Workspace.
- AI models. We access AI models through OpenRouter, a SOC 2 compliant provider that routes our requests to the AI model providers it works with. We configure OpenRouter so that our requests only go to providers that do not train on the data sent to them, and we use these models only to produce your audits.
6. How We Share Information
We share personal information only as follows:
- Service providers that help us run iFixAi, under contracts that limit how they can use it: cloud hosting and databases (Vercel, Render and Supabase), AI model access (OpenRouter), email delivery (Resend), sign-in (Microsoft and Google), repository access (GitHub), usage analytics for our open-source tool (PostHog), and business email, productivity and sales tools.
- Your organization: administrators of your Workspace can see its members, activity and reports.
- Legal and safety reasons: when required by law or legal process, or to protect the rights, property or safety of iFixAi, our customers or others.
- Business transfers: to a buyer or successor as part of a merger, acquisition, financing or sale of assets, who will be bound by this Policy.
- With your consent or at your direction.
7. Usage Information from Our Open-Source Tool
The open-source iFixAi tool (the command-line tool, plugin and agent skills) runs on your own machine with your own AI model keys. Your code, prompts, findings and reports stay on your machine.
By default, the tool sends limited usage information so we can understand how it is used: a random install ID, whether a run started or finished, the tool version, your operating system name, how the tool was run (CLI, plugin or skill), how it was installed, and a timestamp. It never sends file contents, findings, prompts, file or repository paths, hostnames, usernames or environment values. Our analytics provider, PostHog, is set up to discard your IP address, and usage information is switched off automatically in CI environments.
To switch it off, run the tool with --no-telemetry, set IFIXAI_TELEMETRY=0 or DO_NOT_TRACK=1, or create a file at ~/.config/ifixai/telemetry-opt-out. To delete information already sent, run ifixai run --show-id and email your install ID to privacy@ifixai.ai.
8. Cookies and Similar Technologies
Our website does not use advertising, analytics or social media tracking cookies or pixels. It saves your display preferences, such as your chosen theme, in your browser, and our product demo keeps temporary progress in your browser session. The Hosted Services use cookies that are strictly necessary to keep you signed in.
We do not track you across other websites and we do not sell or share personal information, so there is nothing to opt out of. We still honor Global Privacy Control signals as an opt-out request. If we ever add analytics or other non-essential cookies, we will update this Policy first.
9. How Long We Keep Information
- Contact requests and business contact information: up to 24 months after our last interaction, unless you become a customer or ask us to delete it sooner.
- Account information: while your account is active and for 90 days after it closes.
- Customer Data and reports: until your organization deletes them or its subscription ends. After that, your organization has 30 days to export its reports, and we delete the data from our active systems within a further 30 days.
- In-progress audit results: deleted when the audit ends.
- Agent credentials: until your organization removes the connection or its subscription ends.
- Billing records: as long as tax and accounting laws require, generally seven years.
- Security and sign-in logs: up to 12 months.
- Open-source usage information: up to 24 months.
We may keep information longer where the law requires it or to resolve disputes.
10. How We Protect Information
- Encrypted connections (TLS) for our website, dashboard, API and MCP connector.
- Each organization’s data is kept separate at the database level.
- Read-only GitHub access, with access tokens created for each request and never stored.
- Agent credentials and API keys kept in encrypted storage.
- Access to production systems limited to the people who need it, with administrative actions logged.
No system is perfectly secure. If a security incident affects your personal information, we will notify you as required by law. To report a security issue, email support@ifixai.ai.
11. Your Choices and Rights
- Marketing emails: every marketing email has an unsubscribe link, and you can also opt out by emailing privacy@ifixai.ai. We will still send service messages while you have an account.
- Access, correction and deletion: you can ask for a copy of your personal information, or ask us to correct or delete it, by emailing privacy@ifixai.ai. We will verify your request and respond within 45 days, or tell you if we need more time where the law allows. You can use an authorized agent to make a request for you. If we decline your request, you can appeal by replying to our response.
- Open-source usage information: see Section 7.
- Customer Data: if your request concerns data an organization put through an audit, we will pass it to that organization and help it respond.
We will not discriminate against you for exercising any of these rights.
12. U.S. State Privacy Rights
Depending on where you live, such as California, Virginia, Colorado, Connecticut or another state with a privacy law, you may have the right to know what personal information we collect and how we use and disclose it; to access, correct and delete it; to receive a copy in a portable format; and to opt out of the sale of personal information, targeted advertising and certain profiling. We do not sell or share personal information, use it for targeted advertising, or use it for profiling that has legal or similarly significant effects.
In the terms used by California law, in the past 12 months we have collected identifiers (such as name, email address and IP address), commercial information (such as your package and billing records), internet or network activity (such as log data) and professional information (such as your company and job title). We collect them from the sources in Section 3, use them for the purposes in Section 4 and disclose them only as described in Section 6. We do not use sensitive personal information to infer characteristics about you. To make a request, follow Section 11.
13. Visitors and Customers in the EEA, UK and Switzerland
If you are in the European Economic Area, the United Kingdom or Switzerland, local data protection laws apply to our handling of your personal information. We rely on these legal bases: performing our contract with you or your organization; our legitimate interests in running, securing and promoting our business, which we balance against your rights; complying with legal obligations; and your consent, where we ask for it.
You can ask us to access, correct, delete, restrict or transfer your personal information, object to our use of it (including for marketing, at any time), and withdraw any consent you have given. We will respond within one month. You also have the right to complain to your local data protection authority.
We are based in the United States, and your information is processed in the U.S. and in other countries where our service providers operate. Where the law requires, we protect these transfers with safeguards such as the European Commission’s Standard Contractual Clauses.
14. Children
Our services are for businesses and for people aged 18 and over. We do not knowingly collect personal information from children. If you believe a child has given us personal information, contact us and we will delete it.
15. Changes to This Policy
We will post any changes here and update the “Last updated” date. If we make material changes, we will tell account holders by email or in the Hosted Services before the changes take effect.
16. Contact Us
iFixAi Inc., 2810 North Church Street, Wilmington, DE 19802, United States
Privacy questions and requests: privacy@ifixai.ai · Phone: (929) 810-4610