Privacy Policy
Last updated 3 August 2026
IA is a platform that venture capital firms use to receive and evaluate startup applications. This policy explains what personal data we handle, why, and what control you have over it.
1. Two different roles
Which rights you have, and who you exercise them against, depends on how your data reached us. There are two distinct cases, and we are careful not to conflate them.
- We are the controller for the accounts of the firms that use IA — the details of the people who sign in, the organizations they belong to, billing records, and anyone who contacts us through this website or joins the waitlist. We decide how that data is used, and this policy governs it.
- We are a processor for everything a firm collects through the application portal it publishes — the founder submissions, pitch decks, notes, and the evaluations produced from them. The firm decides what to collect and why; we only act on its instructions. If you applied to a fund and want your data corrected or deleted, contact that fund first. Its agreement with us governs that data, and where this policy conflicts with it, the agreement wins.
2. What we collect
- Account data. Name, email address, the organization and role you hold, and your authentication credentials. Passwords are stored only as scrypt hashes — we cannot read them. If you enable two-factor authentication we store the secret needed to verify your codes.
- Session and technical data. IP address, browser user agent, session timestamps, and a record of sign-in attempts, used to keep accounts secure and to detect abuse.
- Audit records. Actions taken in the dashboard — who changed a setting, who overrode a decision, when an evaluation ran — retained so firms can reconstruct how a decision was reached.
- Application content. What founders submit through a firm’s portal: contact details, company information, answers to the firm’s questions, and uploaded documents such as pitch decks.
- Billing data. Subscription status and invoice history. Card numbers are entered directly with Stripe and never reach our servers.
- Website enquiries. What you tell us through the contact or waitlist forms on this site.
3. Where uploaded documents are stored
4. Automated evaluation
The core of the service is an evaluation pipeline that reads an application and produces a structured assessment and a recommendation. To do this, application content — the submitted answers and the text of uploaded documents — is sent to the large language model providers listed below, chosen by the customer organization in its own settings.
We use these providers’ business APIs, whose terms exclude the content sent to them from being used to train their models. We do not use application content to train models of our own.
5. Why we use it, and on what basis
- To provide the service. Running evaluations, delivering notifications, and operating the dashboard, on the basis of our contract with the customer.
- To keep it secure. Authentication, abuse detection, and audit logging, on the basis of our legitimate interest in a service that is not compromised.
- To bill for it. Managing subscriptions and payments, on the basis of our contract and our legal obligations to keep financial records.
- To improve it. Aggregate usage and error diagnostics, on the basis of our legitimate interest in a product that works. We do not need to read your deal flow to do this.
- To reply to you. Responding to contact and waitlist submissions, on the basis of your request.
6. Who else processes it
We do not sell personal data, and we do not share it for advertising. We use the following processors, each bound to handle data only on our instructions:
- Google (Gemini API), OpenAI, Anthropic. Running the evaluation pipeline. Which of these is used, and in what order, is chosen by each customer organization in its own settings.
- Stripe. Subscription billing and payment processing. Card details are collected and held by Stripe; we never receive them.
- Sentry. Error and performance monitoring, which may incidentally capture request metadata.
- Google Firebase. Remote configuration of application content and settings.
- Resend. Delivery of email sent from our marketing site, such as contact and waitlist replies.
We may also disclose data where the law requires it, or to establish or defend legal claims. If we are ever party to a merger or acquisition, data may transfer with the business; we will say so before it does.
7. International transfers
Our processors operate internationally, so your data may be handled outside the country you are in, including in the United States. Where data leaves the UK or EEA we rely on the transfer mechanisms those regimes provide, such as the Standard Contractual Clauses.
8. How long we keep it
- Account data. For as long as the account is open, and for a short period afterwards so it can be restored if closed in error.
- Application content. For as long as the customer firm keeps it. Retention is the firm’s decision, not ours, and deletion requests go to the firm.
- Audit and billing records. Longer, where we are required to retain them — typically for the period set by tax and accounting law.
- Uploaded documents. Held in the customer’s own storage under that customer’s retention rules.
9. How we protect it
- Isolation between firms. Every record carries the organization that owns it, and isolation is enforced in the database itself rather than left to application code to remember. One firm’s deal flow is not reachable from another firm’s session.
- Encryption. Data is encrypted in transit. Credentials we hold on a customer’s behalf — storage keys, provider API keys, OAuth tokens — are encrypted at rest.
- Access control. Permissions are role-based, two-factor authentication is required for administrators, and every mutating action is recorded in an audit log.
No system is perfectly secure, and we do not claim otherwise. If a breach affects your personal data we will notify you and the relevant regulator as the law requires.
10. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to have it deleted, to restrict or object to how we use it, to receive it in a portable form, and to withdraw consent where our use rests on consent. You also have the right to complain to your data protection authority.
To exercise any of these, write to [email protected]. We will respond within the period the law allows. If your data reached us through a fund’s application portal, we will pass your request to that fund, since it is the party that decides.
11. Cookies
The platform sets the cookies it needs to keep you signed in and to protect the sign-in flow against cross-site request forgery. There are no advertising or cross-site tracking cookies. Blocking the essential cookies will prevent you from signing in.
12. Children
IA is a tool for investment professionals and is not directed at children. We do not knowingly collect data from anyone under 16, and we delete it if we discover we have.
13. Changes
We will update this policy as the product changes. The date at the top always reflects the current version, and we will tell account holders directly before a change that materially affects their rights takes effect.
14. Contact
Questions about this policy, or about data we hold, go to [email protected].
Investment Analyst AI, Ltd., 98/6/1 Rehab - Cairo, Egypt.