Ishiro
Back to the site
Legal

Privacy policy

Last updated 8 September 2026. Written in plain words on purpose; if anything here is unclear, write to hello@ishirohq.com and we will explain it.

This says what we hold, why we hold it, who can see it and what you can ask us to do. It covers the Ishiro website and the application.

What we hold

  • What you give us to work on: bank statements, invoices, company documents and the records Ishiro builds from them. These usually name people, so they contain personal data.
  • Who you are: the name, work email and password of the workspace login, and the names and roles of colleagues you add.
  • What was done: an audit trail of actions in the workspace, with who did them and when. This is the product, and it cannot be turned off.
  • Messages: support requests, and email sent to and from your workspace address.
  • Basic technical records: the requests our servers receive, kept briefly to keep the service running and secure.

Why

To provide the service you asked for, to keep it secure, to bill you, and to answer you when you write. We do not sell your data, we do not share it with advertisers, and we do not use one customer's records to serve another.

Do you train models on our data?

No. Your documents are not used to train models, ours or anyone else's. Reading a document uses a model provider under contract, on the basis that the content is processed to answer that one request and is not retained or used for training.

Who can see it

  • The people who sign in to your workspace.
  • Ishiro staff, only when you ask for help. A member of staff opens your workspace under a grant that names the reason and expires, and the grant and its use are on your audit trail where you can see them.
  • Providers we use to run the service: our hosting and database provider, our email provider, and the model provider that reads documents. Each is bound by contract and none may use your data for their own purposes.
  • Anyone else only if the law requires it, and we will tell you unless we are forbidden to.

Where it lives

On servers operated by our hosting provider. Some providers process data outside your country, including in the European Union and the United States, under contractual protections. Tell us if you have a requirement about where your data may be held and we will tell you honestly whether we can meet it today.

How long

For as long as your workspace exists. When you close it we keep the records for 30 days so that a mistake can be undone, then erase them. Invoices and the records we must keep for tax and accounting are kept for as long as the law requires.

Your rights

You can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, or object to what we do with it. Write to hello@ishirohq.com and we will answer within 30 days. If you are covered by the Nigeria Data Protection Act, the United Kingdom or European data protection law, or another regime with similar rights, those rights apply and we will honour them.

Where we handle your customers' data on your behalf, you are the controller and we are the processor: we act on your instructions, and we will sign a data processing agreement if you need one.

Security

Traffic is encrypted in transit, passwords are stored hashed and never in plain text, files are served only to a session that is entitled to them, and staff access to a customer workspace requires a grant that expires. More detail is on the security page. If you believe you have found a vulnerability, write to hello@ishirohq.com and we will answer quickly and thank you properly.

Cookies

The application sets one cookie, to keep you signed in. There are no advertising or tracking cookies, and no third-party analytics on the marketing site.

Changes

If we change this policy in a way that matters, we will email the workspace owner before it takes effect.

Contact

hello@ishirohq.com.

© 2026 IshiroTerms · Privacy · Security · hello@ishirohq.com