Privacy Policy
Last updated: March 21, 2026
1. Introduction
iAvatr ("we", "our", or "us") is operated by Crypken Sdn Bhd. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, dashboard, APIs, and AI avatar services (collectively, the "Service").
By accessing or using the Service, you agree to this Privacy Policy. If you do not agree, please do not use the Service.
2. Information We Collect
We collect information in the following ways:
a) Information You Provide
- Account registration details (name, email, phone number, organization)
- Payment and billing information (processed by Stripe)
- Content you upload (knowledge base documents, avatar configurations)
- Communications with us (support requests, feedback)
b) Information Collected Automatically
- Usage data (pages visited, features used, interactions with avatars)
- Device information (browser type, operating system, IP address)
- Cookies and similar tracking technologies
- Conversation logs between end users and your AI avatars
c) Third-Party Services
- OAuth tokens when you connect third-party apps (Google Calendar, Slack, Notion, etc.) — we store encrypted tokens, never your third-party passwords
- Analytics data from Google Analytics
3. How We Use Your Information
- Provide, maintain, and improve the Service
- Process transactions and send related information
- Power AI avatar conversations and knowledge base searches
- Execute actions on connected third-party services on your behalf (e.g., creating calendar events)
- Send administrative notifications and product updates
- Respond to support inquiries
- Monitor usage patterns to improve performance and security
- Comply with legal obligations
4. Data Sharing and Disclosure
We do not sell your personal information. We may share data with:
- Service providers — hosting (AWS), payment processing (Stripe), email delivery, and analytics
- AI model providers — conversation content is sent to LLM providers (Anthropic, OpenAI) to generate avatar responses
- Connected apps — data is sent to third-party APIs you explicitly connect (Google, Slack, etc.)
- Legal requirements — when required by law, regulation, or legal process
5. Data Security
We implement industry-standard security measures including:
- Encryption of data in transit (TLS) and at rest
- OAuth tokens encrypted with AES before storage
- Role-based access controls and multi-tenancy isolation
- Regular security reviews and monitoring
No method of transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
6. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. Conversation logs are retained based on your organization's configuration. You may request deletion of your data at any time by contacting us.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict processing
- Data portability
- Withdraw consent at any time
To exercise these rights, contact us at privacy@iavatr.com.
8. Cookies
We use essential cookies for authentication and session management, and analytics cookies (Google Analytics) to understand usage patterns. You can control cookie preferences through your browser settings.
9. Third-Party Links
The Service may contain links to third-party websites or services. We are not responsible for their privacy practices. We encourage you to review their privacy policies.
10. Children's Privacy
The Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If you believe we have collected such information, please contact us.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. Continued use of the Service after changes constitutes acceptance.
12. Contact Us
If you have questions about this Privacy Policy, contact us at: