Iris Code
FeaturesPlaygroundMCPTeamsPricingDocs
Get Iris Code Free
Sign inGet Iris Code Free
Privacy

Privacy Policy

What Iris Code collects, why it is needed, and which workflows can process source. Local analysis stays on your machine; cloud scans are separately disclosed and opt-in. Last updated June 9, 2026.

On this pageIntroductionInformation We CollectThe VS Code Extension & Your CodeIris Code Cloud (opt-in)How We Use Your InformationThird-Party ServicesData Storage & RetentionYour RightsCookies & TrackingChildren's PrivacyChanges to This PolicyContact

Introduction

Iris Code ("we", "our", or "us") is a set of editor extensions for VS Code and JetBrains IDEs, a command-line interface, and an accompanying web service built by David Jaja. This Privacy Policy explains what information we collect, why we collect it, how we use it, and your rights regarding your data.

By using Iris Code — including the VS Code extension, the JetBrains plugin, the iris command-line interface, this website, or your account dashboard — you agree to the practices described in this policy. If you do not agree, please discontinue use of the service.

Information We Collect

Account information: When you sign in, Clerk (our authentication provider) collects your name, email address, and profile picture from your Google account. We sync this information to our backend database to create and maintain your Iris Code account.

Payment information: When you upgrade to Pro, Paystack processes your payment. We receive confirmation of payment and your subscription status, but we never see or store your card number, bank details, or other raw payment credentials — these stay with Paystack.

License and subscription data: We store your subscription plan (Free or Pro), license key, and activation status on our servers.

Product-use events: We may store limited usage events such as extension activation, workspace or folder scans, feature-gate hits, and related lifecycle actions so we can operate licensing, account surfaces, admin support, and notification features. These events are product telemetry, but they do not include your source code or file contents.

Team audit evidence is separate from personal product-use events. When a Team owner or admin explicitly enables it for a connected project, Iris Code records bounded operational evidence: audit outcome, aggregate finding counts, health score, execution surface, timestamp, commit SHA, branch, and configuration version. It never stores source, file paths, repository URLs, finding text, or code snippets. Detailed Team evidence is retained for 365 days, after which the detail is pruned and only the aggregate record remains. Team admins can disable collection or purge a project record at any time.

Technical data: Our infrastructure may log standard server-side information such as request timestamps and error traces for debugging purposes. We do not log IP addresses for marketing or tracking.

The VS Code Extension & Your Code

Iris Code analyses your source code entirely on your local machine. No source code, file contents, or project data is ever transmitted to our servers.

The extension reads files in your workspace to compute health scores, complexity metrics, TypeScript-specific checks, and code smell detections. All of this processing happens locally, offline, and privately.

The extension does make limited network calls for account and product operation, including license validation, sign-in flows, config sync, and bounded product-use event logging. These payloads are for account, billing, and lifecycle features and do not include your source code or project contents.

Iris Code Cloud (opt-in)

Cloud scanning is a separate feature you have to connect deliberately. It is not part of the editor extension or the CLI, and nothing described in this section happens unless you install our GitHub app and confirm consent for a specific repository.

What happens during a scan: the connected repository is cloned onto our infrastructure, analysed there, and the working copy is discarded when the scan finishes. File contents are not retained.

What we store afterwards: the report. That contains file paths and per-file health scores, aggregate finding counts, the commit SHA, the branch, what triggered the scan, and the policy and engine versions used. Detected secret locations are removed from the report before it is stored. Note that file paths are retained, so a path that itself reveals something sensitive will be stored.

Who can see it: everyone with access to the workspace the project belongs to. For a team, that means your teammates.

Your controls: disconnecting a repository stops future scans, and deleting a project removes its stored reports. Revoking the GitHub app installation stops our access to the repository entirely.

GitHub (github.com) is a processor for this feature: we use the GitHub API and webhooks under the installation you grant, and repository access is limited to the repositories you select. See docs.github.com/privacy.

How We Use Your Information

To provide the service: your name, email, and account status are used to authenticate you, display your account information, and manage your subscription.

To process payments: your subscription details are passed to Paystack to initiate and confirm billing.

To manage your license: your Clerk user ID is used to validate extension activation and gate Pro features.

To communicate with you: we may send transactional and operational emails needed for account security, billing, and service operation, plus optional product updates or tips when those categories are enabled in your notification preferences. We do not sell your data or send unrelated marketing blasts.

Third-Party Services

Clerk (clerk.com): handles authentication. Clerk may collect device and session information as part of their fraud-prevention and session-management features. See clerk.com/privacy.

Paystack (paystack.com): handles payment processing. Paystack is PCI-DSS compliant. See paystack.com/privacy.

GitHub (github.com): only if you opt in to Cloud scanning. See the Iris Code Cloud section above.

Brevo (brevo.com): sends transactional and product-update email, and therefore processes your email address and delivery events such as opens and bounces. See brevo.com/legal/privacypolicy.

PostHog (posthog.com): website analytics on our public marketing pages. It records page views, referrer, and coarse device and browser information, and stores an identifier in your browser's local storage. It is deliberately not loaded on your account pages, the licence page, the CLI and editor sign-in handoffs, or payment return pages, and URLs are stripped of tokens and references before being sent. See posthog.com/privacy.

Sentry (sentry.io): receives application error reports so we can diagnose faults. See sentry.io/privacy.

We do not sell or rent your personal information, and we do not share it with third parties for advertising purposes.

Data Storage & Retention

Your account data is stored on our backend servers hosted in a secured environment. We retain your data for as long as your account is active.

If you delete your account, we delete your personal data (name, email, avatar URL) from our database. Anonymised billing records may be retained for legal and accounting purposes.

Deleting your account also revokes your licence key and removes your saved configurations, your personal Cloud projects and their reports, and your membership of any team. If you own a team, you will be asked to transfer ownership or close that workspace first, because deleting the owner would leave a paying workspace with nobody able to manage it.

Cloud scan reports are retained until you delete the project they belong to. Detailed Team audit evidence is retained for 365 days, after which the detail is pruned and only the aggregate record remains.

Your Rights

You may request access to, correction of, or deletion of your personal data at any time by contacting us at the email below.

If you are in the EU or UK, you have rights under the GDPR including the right to data portability and the right to lodge a complaint with your local supervisory authority.

If you are in California, you have rights under the CCPA including the right to know what personal information is collected and the right to opt out of sale (we do not sell personal information).

Cookies & Tracking

This website uses cookies set by Clerk to maintain your authentication session. These are strictly necessary cookies and cannot be disabled without breaking sign-in functionality.

We do not use advertising cookies, tracking pixels, or third-party analytics scripts that fingerprint individual users. Separately, Iris Code may store first-party product-use events needed for licensing, support, lifecycle, and notification features.

Children's Privacy

Iris Code is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the 'Last updated' date at the top of this page. Continued use of Iris Code after changes constitutes acceptance of the updated policy.

Contact

If you have questions or requests regarding this Privacy Policy or your personal data, please contact us at: hello@iriscode.co

Iris Code

Score every file. Stop the bad ones shipping.

Product
FeaturesPricingTeamsPlaygroundCompare
Surfaces
CLIMCP for agentsLanguagesDownloadVS Code MarketplaceOpen VSXJetBrains Marketplace
Learn
DocsGetting startedHealth scoreGit hooks.irisconfig.jsonCLI reference
Company
AboutBlogChangelogExtended trialsContactSupportX / Twitter
Legal
SecurityPrivacy PolicyTerms of ServiceJetBrains Plugin EULA
© 2026 Iris Code — built by David Jaja.v1.28.0