Privacy Policy
Your privacy matters. This policy explains how IronhausAI collects, uses, and protects data when you interact with our platform, website, and Instagram DM automation services.
Introduction
IronhausAI (“we,” “our,” or “us”) operates an AI-powered automation platform designed for independent gyms and fitness facilities. Our services include website and Instagram assistants, lead capture tools, pending intro-session request capture, and email notifications for gym owners.
This Privacy Policy applies to all users who interact with our platform, including visitors to our website at www.ironhausai.com, individuals who send messages through Instagram to gym pages powered by our AI, and gym owners who use our dashboard and notification services.
Information We Collect
We collect the following categories of information:
Chat and Instagram Interaction Information
- A website session identifier or Instagram-scoped sender ID
- Message content sent through website chat or to a connected gym's Instagram account
- Message IDs (used for deduplication and delivery confirmation)
- Timestamps of interactions
Owner Account and Workspace Information
- Account name and email address
- Gym profile information, including approved knowledge, notification address, website, phone, address, and timezone
- Connected Instagram profile identifiers, connection status, permission metadata, and encrypted provider access tokens
Information You Voluntarily Provide
- Full name, email address, and phone number (when you express interest in a gym membership or booking)
- Preferred session dates and fitness goals
- Any additional notes or messages shared during conversation
Automatically Collected Data
- Session identifiers (randomly generated UUIDs for conversation continuity)
- Basic analytics data via Vercel Analytics and Google Analytics (page views, device type, country)
How We Use Your Information
We use the information we collect to:
- Provide automated, AI-powered responses to your Instagram DM inquiries about gym memberships, pricing, and class schedules
- Capture and store lead information (name, email, phone) so the gym owner can follow up with you personally
- Record intro-session requests for gym staff to review and confirm; the assistant does not confirm calendar availability
- Send instant email notifications to gym staff when a new lead or booking is captured
- Maintain conversation context within a single session for coherent, helpful interactions
- Prevent abuse through rate limiting (maximum 10 messages per sender per minute)
- Diagnose failures and maintain platform reliability
Data Retention
- Lead and intro-request records currently have no automatic expiry and are retained until a valid deletion request or operational removal.
- Conversation records are stored in PostgreSQL and automatically deleted after 90 days.
- Agent session context may contain a separate copy of message history used to maintain conversation continuity. These records currently have no automatic expiry and are retained until a valid deletion request or operational removal.
- Webhook delivery records are stored in PostgreSQL and automatically deleted after 30 days.
- Agent session data is stored in PostgreSQL for conversation continuity and does not currently have an automatic expiry.
- Rate-limiting state is short-lived according to the applicable one-minute or one-hour rate-limit window.
Your Rights & Choices
You have the right to:
- Access — Request a copy of the personal data we hold about you.
- Correction — Request correction of inaccurate or incomplete data.
- Deletion — Request that we delete your personal data from our systems.
- Opt-out — Stop interacting with the AI-powered Instagram DM assistant at any time by simply not sending further messages. The AI will not proactively message you.
- Withdraw consent — Where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, contact us at the email address listed in the Contact Us section below. We will respond to your request within 30 days.
Data Security
We implement industry-standard security measures to protect your data:
- HMAC-SHA256 signature verification on all incoming Meta webhooks to prevent forged requests
- HTTPS encryption for all data in transit between your browser, Instagram, and our servers
- Timing-safe authentication using cryptographic comparison for API keys
- Per-sender rate limiting to prevent automated abuse
- Message deduplication and persistent reply state to reduce duplicate processing and replies
- Encrypted provider tokens using authenticated AES-256-GCM encryption
- Parameterized database queries to prevent SQL injection attacks
While no system can guarantee absolute security, we take reasonable and appropriate measures to safeguard your personal information against unauthorized access, alteration, disclosure, or destruction.
Children's Privacy
Our services are not directed at individuals under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected data from a child under 13, we will take steps to delete that information as promptly as possible.
If you are a parent or guardian and believe your child has provided personal data to us, please contact us immediately.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the “Last updated” date at the top of this page.
We encourage you to review this page periodically to stay informed about how we protect your data. Your continued use of our services after any changes constitutes acceptance of the updated policy.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or the handling of your personal data, please contact us:
We aim to respond to all privacy-related inquiries within 30 calendar days.