IRIS← ACCOUNT
LEGAL // PRIVACY

Privacy Notice

Effective September 6, 2026 · revision 1

This Privacy Notice explains how HANS Society Foundation (“Undercover IRIS,” “IRIS,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information when you use app.undercoveriris.io, related websites, IRIS Accounts, identity and wallet tools, security reviews, subscriptions, and other IRIS services (collectively, the “Services”).

HANS Society Foundation is the business or controller responsible for the processing described here unless a separate written agreement identifies a different role. This Notice should be read with our Terms of Service.

1. Scope and data-minimization principles

This Notice applies to information handled by IRIS. It does not govern information independently collected by a third-party website, wallet, blockchain, authentication provider, payment processor, or review provider.

IRIS is designed to collect only information reasonably needed to authenticate Accounts, provide requested security features, manage access and billing, prevent abuse, and comply with law. We do not request your Google password, Gmail messages, Drive files, contacts, wallet seed phrase, or wallet private key. Never submit a password, seed phrase, or private key to IRIS.

2. Information we collect

2.1 Account and identity information

  • a Google-verified email address, basic Google profile name, and opaque provider identifier when you use Google authentication;
  • additional email addresses that you separately verify;
  • Account-linking, acceptance, session, authentication-generation, and security records; and
  • communications and rights requests you send to HANS Society Foundation.

Guardian companion plans

Official companion version 0.4 and later connects to your IRIS account to verify Free or Pro access. We store an account-associated hashed connection credential for up to 30 days, short-lived pairing and rate-limit records, and a Free scan attempt identifier and UTC month for up to 40 days. These plan checks do not include file contents, extension inventories, browser history, or wallet secrets. Disconnecting removes the credential; the scan allowance record remains until it expires.

With your choice to enable Pro monitoring, the Mac companion checks supported folder changes locally and the browser companion checks listed scam navigation and extension changes. Monitoring and local finding assessments have limits described in Guardian companion privacy and credits. The companion shows coverage gaps. Saved cleanup and recovery do not require Pro.

2.2 Wallet and public blockchain information

  • public EVM wallet addresses, the chain used for a signature-only ownership proof, linking timestamps, and proof-verification records;
  • public approvals, token and contract identifiers, transaction hashes, chain data, and other public blockchain information associated with a selected address; and
  • operation-safety records needed to prevent stale, duplicate, wrong-wallet, or wrong-chain actions.

IRIS does not receive or store your wallet seed phrase or private key. Your wallet provider—not IRIS—displays and submits any signature or transaction you approve.

2.3 Identity-review information

  • the verified email address selected for a review;
  • your Google-verified profile name, when available and used to improve a public-web search;
  • public search results and breach-intelligence results returned for the requested review; and
  • short-lived, single-use authorization and cancellation state for that review.

Public search results may incidentally contain information about other people. You must use review information only for lawful, authorized security and privacy purposes.

2.4 Subscription and transaction information

  • the selected plan, subscription status, billing period, entitlement, provider and customer references, Checkout or billing-intent references, and lifecycle timestamps;
  • for an offered cryptocurrency purchase, the public payer address, network, token, amount, recipient, transaction hash, confirmation status, and access period; and
  • for an offered paid wallet action, the disclosed fee type and operation-safety state.

Stripe—not IRIS—collects and processes full card details. IRIS receives limited billing and subscription records needed to provide and manage access.

2.5 Technical, security, and usage information

We and our infrastructure providers may process limited request metadata, timestamps, network and browser information, error and reliability events, abuse-prevention signals, rate-limit state, and audit information needed to operate and secure the Services. We do not use third-party behavioral-advertising trackers in the IRIS Account application.

3. Sources of information

We obtain information:

  • directly from you and your browser when you create an Account, select a feature, communicate with us, or approve a wallet request;
  • from Google when you choose Google authentication;
  • from public blockchains, RPC providers, indexers, and public-web sources;
  • from Firecrawl and Have I Been Pwned when you authorize a specific identity review;
  • from Stripe or a blockchain when you purchase or manage paid access; and
  • from security, hosting, storage, and abuse-prevention providers that support the Services.

4. How we use information

We use personal information to:

  • create, authenticate, secure, and recover the correct IRIS Account;
  • verify and link email addresses and wallets without silently merging unrelated Accounts;
  • perform the identity, public-exposure, wallet, monitoring, assessment, remediation, or investigation feature you request;
  • present results, warnings, and recommended next steps;
  • create and manage subscriptions, entitlements, billing, payment recovery, cancellation, and support;
  • prevent fraud, unauthorized access, duplicate operations, abuse, security incidents, and violations of our Terms;
  • debug, maintain, measure, and improve the reliability and safety of the Services;
  • communicate about the Services, material policy changes, security, and support; and
  • comply with legal obligations and protect users, HANS Society Foundation, providers, and the public.

5. Fresh authorization for identity reviews

Accepting the Terms and creating an Account is not treated as blanket authorization to send a verified identity to downstream review providers. Before each identity review, IRIS identifies the applicable provider and requires an affirmative action to start the check. Identity footprint uses Firecrawl; Breach exposure uses Have I Been Pwned. These modules share your verified Google identity but run separately. You may remember the provider permission on this browser for 30 days; returning to saved results does not start a new check.

The authorization is short-lived, bound to the current Account, session, verified email, and disclosure version, and designed for a single review. You can decline. If you withdraw while the browser request remains active, IRIS will attempt to cancel pending processing and clear the active browser result. Already saved identity-footprint findings can be deleted using Delete saved workspace. Information already transmitted cannot be retracted from a provider, and provider-side processing or retention remains subject to that provider’s practices.

6. Identity-review providers

  • Firecrawl. IRIS sends public-footprint search queries derived from the selected verified email and, when available, the Google-verified profile name to search publicly indexed webpages. IRIS does not currently use Firecrawl’s Enterprise Zero Data Retention option. Firecrawl may retain queries, results, or operational logs under its terms. Firecrawl’s current policy is available at firecrawl.dev/privacy-policy.
  • Have I Been Pwned (HIBP). IRIS sends only the selected verified email address to check it against breach intelligence. HIBP may maintain operational request logs under its practices. HIBP’s current policy is available at haveibeenpwned.com/Privacy.

IRIS does not send Gmail messages, Drive files, contacts, Google access tokens, passwords, seed phrases, or wallet private keys to either provider.

Removal requests and AgentMail: when you approve a batch, IRIS sends your verified name, email, selected listing URLs, and a limited authorization record through AgentMail from iris.app@agentmail.to to the listed privacy contacts. AgentMail processes outgoing messages and incoming replies. IRIS retrieves only the conversations bound to your saved requests. This authorization covers sending the selected requests and receiving their replies; it does not cover account closure, additional messages, or new recipients. A source may require direct identity verification or its own authorization form. See Identity cleanup privacy and authorization and AgentMail’s privacy policy.

Photo privacy: selected photos are inspected and re-encoded locally in your browser. IRIS does not upload them, create a stored face template, or run an internet face search.

7. Other disclosures and service providers

We disclose personal information only as reasonably necessary for the purposes described in this Notice:

  • Authentication: Google processes Google sign-in information under its Privacy Policy.
  • Payments: Stripe processes card and billing information under its Privacy Policy.
  • Email delivery: AgentMail processes an additional email address and a private, expiring verification link when IRIS sends the verification email you request. If a deployment uses Resend as its configured fallback, Resend performs that delivery instead.
  • Infrastructure: Vercel and Redis/Upstash hosting, serverless-compute, storage, database, network, and security services process encrypted Account records, opaque indexes, request and security metadata, sessions, authorization state, legal acknowledgments, quotas, and billing metadata needed to run and protect IRIS.
  • Blockchain and wallet services: RPC providers, public indexers, wallet software, and blockchain networks process public addresses, requests, signatures, or transactions as needed for the feature you choose.
  • Professional advisers and business transfers: lawyers, auditors, insurers, advisers, or a successor may receive information subject to appropriate duties where reasonably necessary.
  • Legal and safety disclosures: we may disclose information if reasonably necessary to comply with law or valid legal process, enforce our Terms, investigate abuse, respond to an emergency, or protect rights, safety, systems, or users.

Service providers may process information in the United States and other countries. Their independent services and websites are governed by their own policies.

8. No sale or behavioral-advertising sharing

HANS Society Foundation does not sell personal information for money. IRIS does not share personal information for cross-context behavioral advertising and does not use personal information from the IRIS Account application for targeted advertising. Because we do not engage in those practices, IRIS does not presently offer a “sale” or “sharing” opt-out link. If this practice changes, we will update this Notice and provide legally required controls, including recognition of applicable opt-out preference signals.

9. Legal bases for processing

Where laws such as the GDPR or UK GDPR apply, our legal bases depend on the context and may include:

  • Contract: providing the Account, review, wallet, subscription, or service you request and enforcing our Terms;
  • Legitimate interests: securing IRIS, preventing abuse and Account conflicts, maintaining reliability, understanding service performance, and protecting users and HANS Society Foundation, balanced against your rights;
  • Consent: where we specifically request consent and applicable law requires it; you may withdraw consent prospectively;
  • Legal obligation: complying with tax, accounting, sanctions, legal-process, and other requirements; and
  • Vital interests or legal claims: responding to emergencies and establishing, exercising, or defending legal rights.

The feature-specific identity-review authorization described in Section 5 is an additional product safeguard and instruction; it does not by itself define every legal basis that may apply.

10. Retention

We retain information only for as long as reasonably necessary for the purposes described here, considering the sensitivity of the information, Account status, security and abuse risks, provider constraints, and legal obligations.

  • Account records: verified identity records, linked wallets, provider bindings, legal acknowledgments, review-usage markers, and billing references are retained while the Account remains open or as needed for security, fraud prevention, billing, disputes, and legal obligations.
  • Sessions and capabilities: a remembered Account session is limited to 30 days. Authentication, linking, candidate, and review capabilities expire much sooner, generally within minutes.
  • Identity footprint and cleanup: normalized public search findings, your match decisions, listing URLs, request drafts, scoped authorization receipts, sending status, limited reply excerpts, and your progress notes are saved encrypted on your authenticated Account for 90 days after the last workspace update. You can export or delete this workspace in Identity footprint. Reading saved results alone does not extend retention; saving a search, decision, request, or reply check does. Raw HIBP breach result payloads remain transient and are not stored in the saved workspace. Responses are marked private and no-store. Firecrawl, HIBP, AgentMail, Vercel, and other providers may independently retain queries, correspondence, results, or operational records under their practices. Deleting the IRIS workspace does not recall an email or delete records independently held by those recipients and providers.
  • Legal acceptance and security records: versioned acceptance, Account-security, fraud-prevention, and audit records may be retained as needed to establish the agreement, protect Accounts, enforce limits, and resolve disputes.
  • Billing records: subscription, entitlement, provider-reference, transaction, tax, and accounting records may be retained for the subscription lifecycle and any period required for payment recovery, disputes, accounting, or law.
  • Public blockchain data: HANS Society Foundation cannot alter or delete information recorded on a public blockchain.

We may retain de-identified information that cannot reasonably be linked to you.

11. Cookies and browser storage

IRIS uses secure, HttpOnly, same-site cookies for Account sessions and short-lived authorization, activation, and security state. These cookies are necessary to authenticate the correct Account and prevent cross-site and cross-Account operations.

Wallet and billing features may use narrowly scoped browser memory or local storage for selection state, transaction-safety locks, payment recovery, or duplicate-operation prevention. Browser storage is not treated as Account authentication. We do not use third-party advertising cookies in the IRIS Account application.

12. Wallet and blockchain privacy

Wallet addresses, token approvals, transaction hashes, and blockchain transactions are public or publicly inferable. Linking a public address to an Account can associate it with other Account information within IRIS. A passive Wallet Exposure scan does not require connection to an injected wallet, but an approved signature or transaction is handled by your wallet provider and may become observable to the provider, network, RPC services, and the public.

Privacy rights requests cannot require HANS Society Foundation to modify or erase a public blockchain. We can assess requests concerning off-chain Account records under Section 15.

13. International data transfers

HANS Society Foundation and its providers may process information in countries other than where you live, including the United States. Those countries may have different data-protection laws. Where required, we rely on lawful transfer mechanisms or provider safeguards, such as contractual protections, adequacy decisions, or recognized transfer frameworks.

14. Security

IRIS uses administrative, technical, and organizational safeguards appropriate to the service and information involved. IRIS encrypts verified email/name records and linked-wallet records at the application layer before storage. It separately stores opaque keyed indexes and operational metadata such as session and authorization state, legal acknowledgments, usage markers, and billing references; IRIS does not claim that all Account metadata is end-to-end encrypted. Other safeguards include secure cookies, short-lived capabilities, same-origin checks, rate limits, conflict-safe Account linking, server-side authorization, reauthorization before consequential operations, provider-response validation, and fail-closed behavior.

No system, provider, transmission, wallet, or storage method is perfectly secure. You are responsible for securing your Google Account, wallet, devices, browser, and authentication methods and for reviewing every wallet prompt. Notify us promptly if you suspect unauthorized IRIS Account activity.

15. Your choices and privacy rights

You can decline an identity review, withdraw an active browser review, remove eligible non-primary verified emails, choose which linked wallet to scan, sign out, cancel recurring Stripe billing through Account, and stop using IRIS. IRIS does not currently provide self-service deletion of the whole Account; removing an additional email or wallet is not whole-Account deletion.

Depending on where you live and subject to legal exceptions, you may have rights to:

  • know whether and how we process your personal information;
  • access or receive a portable copy of certain information;
  • correct inaccurate information;
  • delete certain information;
  • restrict or object to certain processing;
  • withdraw consent prospectively where processing relies on consent;
  • opt out of legally defined sale, sharing, targeted advertising, or certain profiling if those practices apply;
  • appeal a denied request where local law provides an appeal; and
  • complain to a data-protection authority.

To exercise a right, email support@joinhans.io with “Undercover IRIS privacy request” in the subject. You may also contact the official @UndercoverIRIS account to request the current privacy-contact channel. We may verify your identity and Account authority before acting. An authorized agent may submit a request where permitted, but we may require proof of authority and direct identity verification.

We will not discriminate against you for exercising an applicable privacy right. We may deny or limit a request where permitted by law, including when we cannot verify it, another person’s rights would be affected, an exception applies, or retention is required for security, fraud prevention, legal claims, billing, or compliance.

16. California disclosures

For California residents and to the extent the California Consumer Privacy Act applies, the categories collected during the preceding 12 months may include identifiers; customer-record and commercial information; internet or other electronic-network activity; geolocation inferred from network information; professional information you provide in a service engagement; and inferences generated from review or security information. The sources, business purposes, and recipient categories are described in Sections 2 through 7.

HANS Society Foundation does not sell personal information or share it for cross-context behavioral advertising. We do not use or disclose legally defined sensitive personal information to infer characteristics or for purposes outside those permitted by applicable law. California residents may request access, deletion, or correction and may exercise applicable rights without discriminatory treatment as described in Section 15.

17. Children

The Services are not directed to children under 18, and we do not knowingly collect personal information from children under 18. If you believe a child has provided personal information, contact us so we can assess and delete it where appropriate.

18. Changes to this Notice

We may update this Notice prospectively to reflect changes in the Services, providers, or law. Material changes will carry a new effective date and may be presented in Account. When current policy acceptance is required, IRIS will request it before protected features continue.

19. Contact

Privacy questions and rights requests may be sent to HANS Society Foundation at support@joinhans.io with “Undercover IRIS privacy” in the subject, or through the official @UndercoverIRIS account.

© 2026 HANS Society Foundation All rights reserved.

ACCOUNTTERMS@UNDERCOVERIRIS ↗