Privacy Policy
Effective: July 27, 2026 · Last updated: July 27, 2026
In one line: we collect your email, the floor plans and photos you upload, and basic usage data — we use them to build and host your tours, we never see your card number, we don't sell your data or run ad trackers, and anyone holding a tour link can open that tour.
Who this covers
This policy explains how IVRIS, Inc. ("IVRIS", "we") handles personal information across ivris.ai — the marketing site, the free AI staging tool, the signed-in app, the done-for-you order forms, and the public tour pages we host.
Two different kinds of people show up here, and they're treated differently:
- Customers — photographers, agents and owners with an account or an order. We hold an account record for you.
- Tour viewers — home buyers and renters who open a link someone sent them. We don't ask viewers for anything. No sign-in, no email gate, no ad tracking. See §9 for the one small measurement we do.
What we collect
| What | When | Notes |
|---|---|---|
| Account email and display name | When you sign up or sign in | Handled by Google Firebase Authentication — email + password, or Google sign-in. If you use a password, IVRIS never sees or stores it; Firebase does. |
| Floor plans and room photos you upload | When you create a listing or order Remote Finalize | Plus what we generate from them: the 2D plan, the furnished 3D floor plan, staged photos and the AR files. Photos of an empty home can incidentally reveal the address or a person; please don't upload photos with people in them. |
| Listing details you type | When you set up a home | Home name, room names, layout choices. |
| Order details — name, email, phone, property address | Only when you order Remote Finalize ($175) or Full Capture ($350) | The property address is needed to price the region gate and, for Full Capture, to physically show up. |
| Billing status — Stripe customer and subscription references, plan, period dates | After a purchase | Never your card number. See §4. |
Session cookie (ivris_sid) |
While you're signed in | HttpOnly, expires after 7 days. Strictly necessary — it's how the app knows it's you. |
| Tour engagement counts | When someone opens a tour you published | Views, AR opens, layout switches, furniture taps — per home, aggregated. See §9 for exactly what is and isn't stored about the viewer. |
| Push notification token | Only if you use the mobile app and allow notifications | Used to tell you a listing finished processing. |
| Server logs | Automatically | Request paths, timestamps, error traces and IP addresses, for security and debugging. |
We don't ask for and don't want government IDs, financial account numbers, health data, precise geolocation, or biometric data. Please don't send them to us.
The free staging tool
The free AI staging tool on the home page asks for your email before it stages a photo. Here's the honest technical picture, which is probably not what you'd assume:
That email currently stays in your own browser. It is used as a counter
key in your browser's localStorage to meter the 10 free staged photos, and it
is not transmitted to our servers with the staging request. Clearing your
browser data clears it — and, incidentally, resets the counter.
The photo does reach our servers. It is sent to IVRIS and on to Google's Gemini API to be staged, and the staged result is returned to your browser. We don't attach it to an account or to your email.
If we later start storing that email — to send you the result, or to follow up — we'll update this policy and say so on the tool itself before we do it.
Payments
All payments are processed by Stripe. Card numbers, CVCs and expiry dates are entered into Stripe's own checkout and go to Stripe directly. They never touch IVRIS servers and we never store them. What Stripe hands back to us — and all we keep — is a customer reference, your subscription id, plan tier, status and billing-period dates. Stripe's own privacy policy governs what Stripe does with your payment data.
Updating a card, switching plans and cancelling all happen inside Stripe's customer portal, not on our servers.
Why we use it
- To build your tours — reading the plan, measuring it, staging the photos, generating the 3D and AR files. This is the core purpose.
- To host and serve your published tours, indefinitely, per the hosted-forever commitment in the Terms.
- To sign you in and keep your session going.
- To bill you and grant the right plan entitlements.
- To deliver a done-for-you order you placed.
- To show you buyer analytics for your own listings.
- To notify you when processing finishes, and to answer support email.
- To keep the service up and safe — debugging, abuse prevention, rate limits.
- To comply with the law when we're required to.
Not for advertising, ad targeting, profile-building, or resale. See §11.
Your images and AI — including training
Your floor plans and room photos are processed by Google's Gemini API. That is how the plan gets read, the rooms get measured and the furniture gets rendered into your photos. The images leave our server for Google's API and the result comes back.
IVRIS does not use your uploads to train any AI model. We don't build or fine-tune models on customer content, and we don't hand your images to anyone for that purpose.
Google acts as our processor, not as an independent recipient. Your plans and photos are sent to Google's Gemini API solely to produce your deliverable, and we don't authorise Google or anyone else to use them for their own purposes. What Google does on its side is governed by Google's own API terms rather than by this policy — how submitted content may be handled depends on the terms applying to the API tier the request is made under. If that distinction matters to you, read Google's Gemini API terms and Google's privacy policy, and write to support@ivris.ai if you need this in writing for your brokerage.
AI output is imperfect. That's a product caveat rather than a privacy one, but it's worth saying here too: check what the AI produced before you publish it.
Who else touches your data
We keep this list short on purpose and we'd rather name everyone than hide behind "trusted partners". These are the companies that actually receive data when you use IVRIS:
| Company | What it does for us | What it receives |
|---|---|---|
| Stripe | Payments, subscriptions, the billing portal | Your name, email, card details (directly from you), billing address, purchase history |
| Google Firebase (Authentication, Cloud Storage, Firestore) | Sign-in, file uploads for done-for-you orders, the order database | Email, password credential, Google account id, uploaded files, order records |
| Google Gemini API | Reading plans, measuring, AI staging | The floor plans and room photos you upload, plus our prompts |
| Render | Hosts the application server and its persistent disk | Everything the app stores server-side, and standard request logs |
| Shopify (shop.ivris.ai) | The furniture store behind "shop the look" | Only what a shopper enters there, if they buy something — a separate transaction under that store's policy |
| Google Fonts and unpkg (CDN) | Serve the brand fonts and the 3D library the viewer needs | Your IP address and browser user-agent, because your browser fetches those files directly |
| Apple / Google push services | Deliver app notifications | A device push token, only if you use the app and opt in |
We may also disclose information if the law requires it, to enforce our Terms, to protect someone's safety, or as part of a merger or acquisition — in which case we'll tell you before your information becomes subject to a different policy.
There are no advertising trackers, ad pixels, tag managers or third-party analytics products anywhere on ivris.ai.
Who can see your tour
This is the one thing we most want you to actually read.
A published tour page is public. There is no password and no
sign-in on it — that's the point: a buyer taps a link and the home opens. Anyone who
has the link (ivris.ai/view?id=…) can open the tour, and anyone can forward it
to anyone else.
Treat a published tour link as public information. We don't promise it is hidden, hard to find, or reachable only by people you sent it to. If you post a tour link on a website or a social profile, search engines can find and index it. Publish a home only if its owner has agreed to it being public, and don't put anything in a home you publish that you wouldn't want a stranger to see — that includes photos of documents, keys, alarm panels, personal effects, or anything else in frame that shouldn't be shared.
Files uploaded through the Remote Finalize order form are likewise stored in Firebase Storage at URLs that are readable by anyone who has the URL.
You can take a tour down at any time by deleting that home from your dashboard. Deletion is permanent and immediate — the project and its assets are removed and the link stops working. There is no undo.
How long we keep things
- Your listings, uploads and tours: for as long as they're published. That is intentionally indefinite — the hosted-forever commitment means we don't delete your delivered work. Delete a home yourself and it's gone permanently, including its assets.
- Account records: while your account exists, plus what we need afterwards for tax, accounting and legal-claim reasons.
- Sign-in sessions: 7 days, then they expire.
- Tour analytics events: kept as an append-only record; dashboards show a rolling 30-day window. Each record holds only the day-salted hash described in §9.
- Done-for-you order records: kept as business records after delivery.
- Payment records: retained by Stripe under its own schedule; we keep the references and receipts we need for accounting.
- Server logs: kept for a short operational window for debugging and abuse prevention.
California privacy rights
If you're a California resident, the CCPA (as amended by the CPRA) gives you rights over your personal information. This section is for you; we're happy to extend the same handling to anyone who asks.
What we collect, in CCPA's categories
| Category | Do we collect it? | Where it comes from |
|---|---|---|
| Identifiers — name, email, phone, IP address, account id | Yes | You, and automatically from your browser |
| Customer records — billing contact, property address on an order | Yes | You |
| Commercial information — plans bought, orders placed | Yes | You, via Stripe |
| Internet activity — pages used, feature usage, tour engagement counts | Yes | Automatically |
| Visual information — the photos and floor plans you upload | Yes | You |
| Precise geolocation | No | — |
| Biometric information | No | — |
| Sensitive personal information (as defined by the CPRA) | No | — |
| Inferences / profiles about you | No | — |
Selling and sharing
IVRIS does not sell your personal information, and does not share it for cross-context behavioural advertising, as those terms are defined by California law — and we have not done so in the preceding 12 months. We run no advertising trackers. There is nothing for you to opt out of, because we don't do it.
Your rights
- Know what we've collected about you and get a copy.
- Delete what we hold, subject to the exceptions the law allows (we may need to keep records for tax, security or legal reasons).
- Correct inaccurate personal information.
- Opt out of sale or sharing — not applicable, as above.
- Limit use of sensitive personal information — not applicable; we don't collect it.
- Not be discriminated against for exercising any of these. We won't change your price or degrade your service because you asked.
How to exercise them
Email support@ivris.ai from the address on your account, with what you'd like done. We'll confirm receipt within 10 business days and respond within 45 days, extending once if we genuinely need more time and telling you if we do. We verify requests by confirming control of the account email; for anything sensitive we may ask for more. An authorised agent can act for you with written permission we can verify.
A note on deleting a tour: deletion requests covering a published listing may affect the tour's public link. If both you and your client expect it to stay live, tell us which you want. And remember you can delete any individual home yourself from the dashboard.
We don't currently respond to browser "Do Not Track" signals, as there's no agreed standard. Since we don't sell or share personal information, an opt-out preference signal has nothing to act on.
Children
IVRIS is a professional tool for adults. Our Terms require you to be at least 18, the Service isn't directed at children, and we don't knowingly collect personal information from anyone under 13. If you believe a child has given us information, email support@ivris.ai and we'll delete it.
Security
Traffic to ivris.ai is served over HTTPS. Sign-in sessions use an HttpOnly cookie and expire after 7 days. Passwords are held by Google Firebase Authentication, not by us. Card data never reaches our servers. Firebase Storage is default-deny except for the narrow upload and catalog paths the product needs. Per-project data is access-checked against the owning account on every request.
All that said: no system is perfectly secure. We can't guarantee that data transmitted to us is safe from every possible interception, and a published tour link is public — see §8. If you find a security problem, please tell us at support@ivris.ai before telling anyone else.
IVRIS is operated from the United States and your information is stored and processed there.
Changes
When we change this policy we'll update the "last updated" date at the top. If a change materially affects how we handle your information, we'll tell you by email or in the app before it takes effect.
Contact
Questions, requests or complaints — a person reads this address.
IVRIS, Inc.
Fremont, California, USA
support@ivris.ai
See also the Terms of Service.