Collab OS · Legal

Privacy Policy

Last updated September 11, 2026 · See also the Terms of Service

Collab OS is a shared workspace built by Iris Cocreative for the studio, its clients and its collaborators. This page says what we collect when you use it, why, who else handles it on our behalf, and what you can ask of us. We have tried to write it the way we would explain it to you across a table.

1. Who we are

The service is provided by Iris Cocreative, LLC, a Delaware limited liability company, United States (“Iris”, “we”, “us”). We are the controller of the personal data described here. For anything in this policy, write to hello@iriscocreative.com.

This policy covers collab-os.com and the Collab OS application (together, the “Service”). It does not cover other Iris websites or tools, which have their own notices.

2. What we collect

Account and profile

When you are invited and sign in: your email address, your name, and a password or sign-in link (passwords are hashed by our authentication provider and never visible to us). Your profile can also hold a photo, a display color, a job title, an organization and a website, all of which you set yourself. Your account carries a role (admin, team, collaborator or client) that decides what you can see.

The work itself

Collab OS exists to hold collaborative work, so it stores what you and the people you work with put into it: collaborations, initiatives, actions, documents, comments, notes, files and assets, time entries, notifications, and who is connected to what. Some of this names people — an action assigned to you, a comment you wrote, a person on a team roster. We treat all of it as your content and the content of the organization you work within (see the Terms).

Meetings and their artifacts

Some collaborations record meetings. When they do, the recording and its transcript are produced by a meeting-recording service (currently Fireflies.ai), the video may be hosted for playback by SproutVideo, and the transcript is processed by AI models (currently from Anthropic, Google and OpenAI) to draft a summary, key quotes, decisions and follow-up actions. Those drafts are reviewed by a person before they become part of a collaboration. A meeting is only recorded with the knowledge of the people in it; you will be told at the start, and you can ask for a meeting not to be recorded.

Usage and device information

We measure how the Service is used so we can improve it. What is measured depends on the cookie choice you make (section 6):

  • With your consent, PostHog records pages you visit, elements you click, errors your browser reports, and the session they belong to, tied to your account once you are signed in, so we can see how the people who use Collab OS actually use it.
  • Without it, PostHog counts visits without cookies or any storage on your device; you appear as a hash computed on their servers from your IP address and browser, which resets daily and cannot be used to follow you.
  • Independently of that choice, our hosting provider (Vercel) collects aggregate, cookieless page-view and performance statistics. These are not tied to you.

Like every website, our servers and providers keep short-lived technical logs: IP address, browser and device type, the pages requested and when. We use these to keep the Service secure and running.

Fonts

Our typefaces are served by Adobe Fonts and, on the marketing page, Google Fonts. When your browser fetches them it sends those services your IP address and browser details; neither sets cookies for us.

3. Why we use it, and on what basis

For people in the European Economic Area, the United Kingdom and Switzerland, the law asks us to name a legal basis for each purpose. For everyone, it is a fair summary of why we do what we do.

  • To provide the Service— accounts, the shared workspace, the meeting artifacts, notifications. Basis: performance of a contract (the Terms, and the engagement between Iris and the organization you work within).
  • To keep it secure and working— technical logs, abuse prevention, error reports. Basis: our legitimate interest in running a safe service.
  • To understand how it is used and improve it— analytics. Basis: your consent for the cookie-based measurement; our legitimate interest for the cookieless, aggregate counts.
  • To communicate with you about the Service— invitations, sign-in links, notifications about work you are part of. Basis: performance of a contract. We do not send marketing email from Collab OS.
  • To meet legal obligations and to establish or defend legal claims. Basis: legal obligation, legitimate interest.

4. Who handles data on our behalf

We do not sell personal data, and we do not share it with anyone for their own advertising. We use a small number of service providers who process it under contract and only on our instructions:

ProviderWhat forWhere
SupabaseDatabase, authentication and file storage — where the work livesUnited States
VercelHosting, delivery, aggregate analytics and performance measurementUnited States (edge network worldwide)
PostHogProduct analytics (section 2, section 6)United States
Fireflies.aiMeeting recording and transcription, where a collaboration records meetingsUnited States
SproutVideoHosting and playback of meeting recordingsUnited States
Anthropic, Google, OpenAIAI models that draft summaries, quotes and actions from meeting transcripts. Used through their business APIs, which do not train on the data sent.United States
n8nThe automation that moves a meeting transcript through the steps aboveIris-operated
Adobe Fonts, Google FontsTypefaces (your IP address and browser details are sent when they load)United States (worldwide delivery)

Beyond providers, data is shared the way the Service is designed to share it: with the other people in a collaboration you are part of, according to their role. A client sees the client-facing side of their own collaboration; the studio team sees the collaborations they are on. We may also disclose data if the law requires it, or to protect the rights and safety of Iris, our users or others.

If Iris is ever merged, acquired or sells the Service, your data may transfer to the successor, who will be bound by this policy until they tell you otherwise.

5. Where data goes

Iris is a US company and the Service is hosted in the United States, so if you use it from elsewhere your data is transferred there. For people in the EEA, UK and Switzerland, we rely on the European Commission’s Standard Contractual Clauses (and the UK addendum) with our providers, or on their certification under the EU–US Data Privacy Framework where they hold it. You can ask us for a copy of the safeguards in place.

6. Cookies and storage on your device

We keep this short because the list is short. Nothing here is used for advertising.

NameKindWhat it doesLasts
sb-…-auth-tokenNecessaryKeeps you signed in. Set only when you sign in.Your session
collabos-consentNecessaryRemembers the choice you made on the cookie bar, so we don’t ask again.12 months
collabos-view-asNecessaryAdmin only: which role you are previewing the app as.Your session
collabos-themeFunctional (local storage)Light or dark, if you chose one.Until cleared
__ph_opt_in_out_…Necessary (local storage)PostHog’s own record of the same choice, so it obeys it before we can tell it to.Until cleared
ph_…_posthogAnalytics (consent)PostHog’s visitor and session id, so visits from the same browser count as the same person. A cookie plus a local-storage copy. Set only if you accept.12 months

If you decline, PostHog runs without cookies or storage and can only count, not recognize. If you accept, you can change your mind at any time here; the cookie is then no longer read and expires on its own.

Your browser can also block or delete cookies on its own. Blocking the necessary ones will stop sign-in from working.

7. How long we keep it

  • Your account and profile: for as long as it is active. When an account is closed we remove the profile; your name stays on the things you did inside a collaboration (a comment you wrote, an action you completed) because the record of the work belongs to that collaboration.
  • Work content: for as long as the collaboration and the engagement behind it. Collab OS archives rather than deletes inside a live collaboration, so things can be recovered; when an engagement ends, its data is retained according to the agreement with that client and then deleted or returned.
  • Meeting recordings and transcripts: as above, unless a participant asks for one to be removed, in which case we remove it.
  • Analytics: PostHog event data for as long as we run the analytics project, which we review yearly; Vercel’s aggregate statistics for as long as the hosting account exists.
  • Technical logs: a few weeks at most, on our providers’ default schedules.

8. What you can ask of us

Wherever you are, you can ask us to tell you what we hold about you, to correct it, to delete it, to give you a copy, or to stop a particular use. Write to hello@iriscocreative.com; we answer within 30 days and will ask you to confirm it is really you. Some things we cannot delete on request — a comment in a client’s collaboration, a record we must keep by law — and if so we will say which and why.

If you are in the EEA, UK or Switzerland, these are your rights of access, rectification, erasure, restriction, portability and objection under the GDPR (and its UK and Swiss counterparts). Where we rely on consent you can withdraw it at any time, without affecting what was done before. You can also complain to your local data-protection authority; we would rather you talked to us first, but that is your right either way.

If you are in California, the CCPA gives you the rights to know, to delete, to correct, and to not be discriminated against for exercising them. We do not sell or share personal information as those words are defined there, and we do not use it for cross-context behavioral advertising, so there is nothing to opt out of. Other US states with privacy laws give similar rights; the same email address works for all of them.

9. Security

Data is encrypted in transit and at rest with our providers. Access inside the Service is enforced row by row in the database, so an account only ever receives the data its role and its collaborations entitle it to. Only the people at Iris who need to operate the Service can reach the underlying data. No system is perfect; if a breach ever affects you we will tell you, and any regulator we must, without undue delay.

10. Children

Collab OS is a workplace tool and is not directed at anyone under 16. We do not knowingly collect data from children; if you believe we have, tell us and we will remove it.

11. Changes to this policy

When we change this policy we update the date at the top. If a change matters — a new kind of data, a new purpose, a new provider that sees your content — we will also tell signed-in users inside the Service or by email before it takes effect.

12. Contact

Iris Cocreative, LLC · hello@iriscocreative.com