Investment Recovery Association
Privacy Policy
Last updated 16 August 2026
In short: your uploads and your conversations are yours. Colleagues at your company see only what you or your organization's administrator deliberately share. We use no advertising or analytics trackers of any kind, we never sell your data, and you can ask us to delete your account and everything in it at any time.
Note for the association — remove before publishing. This draft is accurate to how the application actually works, but it has not been reviewed by a lawyer. Have counsel check it, and confirm in particular the governing-law, data-transfer and AI-provider sections against your obligations and your agreements with IRA members.
This policy explains what the Investment Recovery Association (“IRA”, “we”) collects when you use the IRA member application, why we collect it, who can see it, and what you can ask us to do with it. It covers the application only, not the main association website.
What we collect
Information you give us
- Your account. Email address, name, and optionally your job title, industry and experience level. We do not store passwords — signing in uses a one-time link sent to your email, or your Google or LinkedIn account.
- Your organization. The company you belong to, and whether you administer it. For most members this arrives from the association's own membership records rather than from you.
- Content you create. Documents you upload, conversations with the assistant, success stories, campaigns, brand settings, and your answers and scores in training quizzes.
Information we generate
- Search indexes. Uploaded documents are split into passages and converted into numerical representations so the assistant can find relevant material. These are stored alongside your document.
- Usage records. Counts of assistant requests and the number of words processed, used for capacity planning and cost control. These records deliberately contain no message or document text — only counts, identifiers and timestamps.
- Operational logs. Standard server logs and an audit trail of administrative actions.
What we do not collect
We use no advertising networks, no analytics services and no third-party tracking of any kind. The application sets one cookie, which keeps you signed in, and stores one preference in your browser recording that you dismissed a setup prompt. There is nothing to opt out of because there is nothing collecting you.
Who can see what
This is the part most members care about, so it is set out precisely. Access is enforced by the database itself, not only by the application.
| What | Who can see it |
|---|---|
| Documents you upload to My Documents | You, and IRA staff for support and moderation. Not your colleagues, and not your organization's administrator. |
| Documents published to your company | Everyone at your company. Only an organization administrator can publish them, and they are clearly marked as shared. |
| Your conversations with the assistant | You alone, unless you deliberately share a thread with your company — which you can undo at any time. There are no administrator overrides for conversations; not even IRA staff can read an unshared thread. |
| Success stories | You while drafting. Once complete, IRA staff can read them, which is how stories are reviewed and featured. Your organization's administrator can also add a completed story to your company's shared training material. |
| Training results | You, and your organization's administrator, who sees their team's progress in order to manage certification. IRA staff see association-wide averages, not individual results. |
| Anything at all | Never another member company. Sharing reaches your company and stops there. |
The same summary is available inside the application under Profile → Security & Privacy, and it is kept in step with this page.
How your content is used with AI
The assistant answers using material you or your company have given it, together with the association's published library. To do that, the text of your question and the relevant passages of the documents it draws on are sent to our AI providers to generate a response, and uploaded documents are sent once to be converted into search indexes.
- We use these providers through their business APIs and do not permit your content to be used to train their models.
- We do not use your documents or conversations to train any model of our own.
- Answers can be wrong. The assistant is a research aid, not professional advice, and it shows you its sources so you can check them.
Who processes your data
We keep this list short on purpose. Each of these is a processor acting on our instructions, not a party we sell or rent data to — we do not sell your data, and never will.
| Provider | What it handles |
|---|---|
| Supabase | Database, file storage and sign-in. This is where your account and your content live. |
| Vercel | Application hosting and delivery. |
| OpenAI | Generating the assistant's replies. |
| Converting documents and questions into search indexes, and some assistant features. | |
| Resend | Sending email, such as sign-in links and notifications. |
| Sentry | Error monitoring, so we find out when something breaks. See below. |
These providers operate in the United States. If you are outside the United States, using the application means your information is transferred there.
When something goes wrong
We use an error-monitoring service so that failures reach us rather than being silently endured. When an error happens in your browser, it records a short replay of the moments around it, which is how we work out what actually broke.
Because those screens can contain your documents and questions, the replay is deliberately blunted: all text is masked, all form inputs are masked, and images and document previews are not recorded at all. It captures the shape of what happened, not the content it happened to. We do not record ordinary sessions — only errors — and we do not attach your IP address to error reports.
How we protect it
- Encrypted in transit with TLS, and at rest with AES-256 by our database provider.
- Access rules enforced at the database level, so a mistake in application code cannot hand your rows to someone who should not have them.
- Sign-in without stored passwords, using one-time links or a provider you already trust.
- Administrative actions are recorded to an audit trail. Your personal content is not written to that trail.
No system is perfectly secure, and we do not claim otherwise. If you believe you have found a vulnerability, please write to team@group365.com before disclosing it publicly.
How long we keep it
- Your account and content — for as long as your account is open.
- If you ask us to delete your account — we remove your profile, documents and their indexes, conversations, stories, campaigns, training results and uploaded images. Documents your organization's administrator published to your company belong to the company and remain with it.
- Operational logs and audit records — kept for a limited period for security and accounting, then discarded.
Your choices
- See it. Everything the application holds about you is visible in the application itself.
- Correct it. Profile details are editable at any time.
- Delete it. Individual documents, conversations and stories can be deleted by you. For your whole account, write to us.
- Stop the email. Notification preferences are under Profile → Notifications, and every non-essential message carries an unsubscribe link. Sign-in links are not marketing and cannot be switched off.
Depending on where you live you may have further rights over your personal information, including access, correction, deletion and portability. Write to us and we will honour them.
Children
This is a professional application for association members. It is not directed at anyone under 16, and we do not knowingly collect their information.
Changes
If we change this policy we will update the date at the top, and for anything significant we will tell members inside the application.
Contact
Investment Recovery Association — team@group365.com. See also our Terms of Service.
