Your information
Privacy Policy
Last updated September 9, 2026
What we collect
When you create a Discovery session, IBAT may collect your name, company, work email, mobile number, answers, uploaded materials, session progress and the choices you make during the experience. Growth workflows may also store brand guidance, research questions and cited findings, audience and campaign details, drafts and versions, creative briefs, approvals, notes, and the identity and time associated with authorized actions.
How we use it
We use this information to provide and continue your Discovery, prepare requested recommendations and pilot materials, plan and govern Growth work, coordinate appointments and callbacks, improve and protect the service, and maintain appropriate business and audit records.
Session communications
IBAT may contact you about the Discovery you started, requested meetings, reminders, missing information and related next steps. This permission does not enroll you in unrelated promotional marketing.
AI, voice and content assistance
Microphone access is optional and requested separately. When voice is enabled, spoken input may be transcribed and processed to operate the guided session. For Growth planning or content assistance, IBAT may send a user's direction together with selected brand rules, research summaries and citations, campaign context, draft content, and aggregate event information to an AI service provider. Current requests to OpenAI are configured with provider-side storage disabled. See the AI & Voice Notice for additional details.
First-party measurement
IBAT may record first-party event and session identifiers, event types and times, campaign parameters, landing paths, referrer origins, privacy-mode metadata, and links to internal client, opportunity or deal records. Supported advertising click identifiers are hashed before storage. A Global Privacy Control signal suppresses those click-identifier hashes, but does not disable all first-party event recording or internal record linkage.
LinkedIn connections
The LinkedIn connection is currently being configured and is not yet an active publishing or analytics service. If an authorized administrator connects a LinkedIn Page, IBAT may receive a short-lived authorization code, access and refresh tokens, granted permissions and expiration, the administrator's approved organization roles, organization identifiers, and Page names or vanity URLs. IBAT stores the selected Page identifier and name, connection status, granted permissions and expiration, the connecting administrator's IBAT account email, and related connection metadata. The planned connection requests organization-administration and organization-social permissions; no external posting endpoint is currently active.
Security and tenant restrictions
Stored LinkedIn access and refresh tokens are encrypted using AES-256-GCM with workspace-bound authenticated data. Tokens are not returned in ordinary browser responses. Growth records are scoped by workspace in a shared service database, and access depends on authenticated administrative permissions and tenant restrictions. This does not mean every IBAT record or provider backup is encrypted by the same application control.
Sharing and service providers
We may use contracted providers to host, secure, transcribe, analyze or deliver the service. LinkedIn receives authorization and authorized organization-lookup requests when its connection is used. OpenAI receives the selected information described above when AI assistance is requested. The reviewed LinkedIn connection does not send Growth prompts, research, applicant financial answers or campaign qualification events to LinkedIn. We do not sell the personal information collected through these services.
Disconnecting LinkedIn
Disconnecting through IBAT removes stored LinkedIn token ciphertext, clears the selected Page and cancels pending connection attempts for that workspace. Connection metadata and governed audit records may remain. This action does not revoke access at LinkedIn, erase unrelated Growth records, or remove provider backups or logs. An administrator can separately revoke the application through LinkedIn's connected-app settings.
Retention and your choices
IBAT retains information only as reasonably needed for the purposes described here, security, recordkeeping and applicable obligations; no general fixed retention period is promised by this policy. To request access, correction or deletion, email info@ibat.ai. IBAT will verify the requester's identity and authority, identify records within scope, apply the approved process, and explain any information that must be retained.
Contact
For privacy questions or requests, contact info@ibat.ai.