Last updated — September 2, 2026

Privacy Policy

Your privacy matters. This policy explains how IronhausAI collects, uses, and protects data when you interact with our platform, website, and Instagram DM automation services.

01

Introduction

IronhausAI (“we,” “our,” or “us”) operates an AI-powered automation platform designed for independent gyms and fitness facilities. Our services include website and Instagram assistants, lead capture tools, pending intro-session request capture, and email notifications for gym owners.

This Privacy Policy applies to all users who interact with our platform, including visitors to our website at www.ironhausai.com, individuals who send messages through Instagram to gym pages powered by our AI, and gym owners who use our dashboard and notification services.

02

Information We Collect

We collect the following categories of information:

Chat and Instagram Interaction Information

  • A website session identifier or Instagram-scoped sender ID
  • Message content sent through website chat or to a connected gym's Instagram account
  • Message IDs (used for deduplication and delivery confirmation)
  • Timestamps of interactions

Owner Account and Workspace Information

  • Account name and email address
  • Gym profile information, including approved knowledge, notification address, website, phone, address, and timezone
  • Connected Instagram profile identifiers, connection status, permission metadata, and encrypted provider access tokens

Information You Voluntarily Provide

  • Full name, email address, and phone number (when you express interest in a gym membership or booking)
  • Preferred session dates and fitness goals
  • Any additional notes or messages shared during conversation

Automatically Collected Data

  • Session identifiers (randomly generated UUIDs for conversation continuity)
  • Basic analytics data via Vercel Analytics and Google Analytics (page views, device type, country)
03

How We Use Your Information

We use the information we collect to:

  • Provide automated, AI-powered responses to your Instagram DM inquiries about gym memberships, pricing, and class schedules
  • Capture and store lead information (name, email, phone) so the gym owner can follow up with you personally
  • Record intro-session requests for gym staff to review and confirm; the assistant does not confirm calendar availability
  • Send instant email notifications to gym staff when a new lead or booking is captured
  • Maintain conversation context within a single session for coherent, helpful interactions
  • Prevent abuse through rate limiting (maximum 10 messages per sender per minute)
  • Diagnose failures and maintain platform reliability
04

Information Sharing & Disclosure

We do not sell, rent, or trade your personal information to any third party. We share data only with the following service providers who are essential to operating our platform:

Meta / FacebookWebhook infrastructure for receiving and sending Instagram DMs
OpenAIProcessing message content through our AI agent to generate responses
ResendDispatching email notifications to gym owners when leads or bookings are captured
Neon (PostgreSQL)Storing accounts, gym profiles, connections, conversations, webhook state, agent sessions, leads, and intro requests
VercelHosting the frontend website and providing analytics
FastAPI CloudHosting the AI and Instagram-processing backend
UpstashWebsite rate limiting and durable webhook dispatch through Redis and QStash
Google AnalyticsOptional production website analytics when configured

We may also disclose information if required by law, court order, or governmental authority, or to protect the rights, property, or safety of our users and the public.

05

Data Retention

  • Lead and intro-request records currently have no automatic expiry and are retained until a valid deletion request or operational removal.
  • Conversation records are stored in PostgreSQL and automatically deleted after 90 days.
  • Agent session context may contain a separate copy of message history used to maintain conversation continuity. These records currently have no automatic expiry and are retained until a valid deletion request or operational removal.
  • Webhook delivery records are stored in PostgreSQL and automatically deleted after 30 days.
  • Agent session data is stored in PostgreSQL for conversation continuity and does not currently have an automatic expiry.
  • Rate-limiting state is short-lived according to the applicable one-minute or one-hour rate-limit window.
06

Your Rights & Choices

You have the right to:

  • Access — Request a copy of the personal data we hold about you.
  • Correction — Request correction of inaccurate or incomplete data.
  • Deletion — Request that we delete your personal data from our systems.
  • Opt-out — Stop interacting with the AI-powered Instagram DM assistant at any time by simply not sending further messages. The AI will not proactively message you.
  • Withdraw consent — Where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, contact us at the email address listed in the Contact Us section below. We will respond to your request within 30 days.

07

Data Security

We implement industry-standard security measures to protect your data:

  • HMAC-SHA256 signature verification on all incoming Meta webhooks to prevent forged requests
  • HTTPS encryption for all data in transit between your browser, Instagram, and our servers
  • Timing-safe authentication using cryptographic comparison for API keys
  • Per-sender rate limiting to prevent automated abuse
  • Message deduplication and persistent reply state to reduce duplicate processing and replies
  • Encrypted provider tokens using authenticated AES-256-GCM encryption
  • Parameterized database queries to prevent SQL injection attacks

While no system can guarantee absolute security, we take reasonable and appropriate measures to safeguard your personal information against unauthorized access, alteration, disclosure, or destruction.

08

Children's Privacy

Our services are not directed at individuals under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected data from a child under 13, we will take steps to delete that information as promptly as possible.

If you are a parent or guardian and believe your child has provided personal data to us, please contact us immediately.

09

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the “Last updated” date at the top of this page.

We encourage you to review this page periodically to stay informed about how we protect your data. Your continued use of our services after any changes constitutes acceptance of the updated policy.

10

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or the handling of your personal data, please contact us:

We aim to respond to all privacy-related inquiries within 30 calendar days.