<< Back

Privacy Policy

Effective date: 24 March 2026  ·  Last updated: 24 March 2026

1 - Overview

iTeri Pty Ltd ("iTeri", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the iTeri Chrome extension and related services (the "Service").

We designed iTeri with a privacy-first architecture. We do not store your website credentials, we do not sell your data, and we minimise the information we collect to what is necessary to provide the Service.

By using the Service, you consent to the practices described in this Privacy Policy. This Policy should be read alongside our Terms & Conditions.

2 - Who We Are

iTeri Pty Ltd (ABN 57 662 920 238) is a company registered in New South Wales, Australia. We are the data controller for the personal information collected through the Service.

For privacy-related enquiries, contact us at info@iteri.ai.

3 - Information We Collect

3.1 Information You Provide

Data Type Details Purpose
Account information Name, email address, authentication credentials (via Google OAuth / AWS Cognito) Account creation & authentication
Payment information Processed and stored exclusively by Stripe; we receive only a transaction reference and last four digits of your card Credit purchases & billing
User preferences Configuration settings, notification preferences, confirmation gate preferences Personalising the Service
Support communications Emails, feedback, and support requests you send us Responding to enquiries & improving the Service

3.2 Information Collected Automatically

Data Type Details Purpose
Usage data Feature usage, credit consumption, session duration, action types Service operation, billing & analytics
Device & browser info Browser version, operating system, screen resolution, extension version Compatibility, debugging & support
Error & diagnostic data Crash reports, error logs, performance metrics Maintaining & improving reliability

3.3 Information We Do NOT Collect

We do not collect or store: your website login credentials or passwords; the full content of web pages you visit (only compressed, ephemeral representations as described in Section 5); your browsing history; or your payment card numbers.

4 - How We Use Your Information

We use the information we collect for the following purposes:

  • Providing the Service — Operating, maintaining, and delivering iTeri's core functionality including AI-powered browser automation.
  • Authentication & security — Verifying your identity, protecting your account, and preventing fraud or abuse.
  • Billing & credits — Processing credit purchases, tracking credit consumption, and managing your subscription.
  • Communication — Sending service-related notifications, responding to support requests, and providing product updates.
  • Improvement & analytics — Understanding how the Service is used to improve features, performance, and reliability. We use aggregated, de-identified data for this purpose where possible.
  • Legal compliance — Meeting our obligations under applicable laws and regulations.

We will not use your personal information for purposes materially different from those described here without your consent.

5 - Browser & Page Data

This section is important. Because iTeri is a browser-based AI agent, it processes web page content in order to function. Please read this section carefully to understand how page data is handled.

5.1 How Page Data Is Processed

When you instruct iTeri to interact with a web page, the extension processes the page's DOM (Document Object Model) — the structured content of the page. This processing occurs as follows:

  • Local compression — The extension applies significant compression and transformation to the page content locally within your browser, reducing it to a compact semantic representation. This typically reduces the data by 90% or more compared to the raw page content.
  • Ephemeral transmission — The compressed representation is transmitted to our servers and/or to third-party AI providers for interpretation. This data is used only to process your current request and is not persistently stored by us.
  • No browsing history — We do not track, log, or store which websites you visit. Page data is processed only when you actively direct iTeri to interact with a page.

5.2 What Page Data May Contain

The compressed page representations may include text content visible on the page, form field labels and structure, link text and navigation elements, and page layout information. If a page you direct iTeri to interact with contains personal information (for example, your bank account dashboard or a social media profile), elements of that information may be included in the compressed representation sent for AI processing.

5.3 Sensitive Pages

You should exercise caution when directing iTeri to interact with pages containing highly sensitive information such as banking portals, medical records, or confidential documents. While the data is compressed and transmitted securely, it is processed by third-party AI providers as described in Section 6.

5.4 WhatsApp & Messaging Integrations

If you use iTeri's messaging integrations (such as WhatsApp relay or Slack integration), message content is processed to enable iTeri to understand and respond to your requests. Message content is transmitted to our servers and to AI providers for processing, but is not persistently stored beyond what is necessary to complete the current interaction. Message relay is provided by Twilio, Inc.; see Section 6.4 for details.

6 - Third-Party Services & AI Providers

6.1 AI Model Providers

iTeri uses third-party large language model (LLM) providers to power its AI capabilities. When you use the Service, compressed page content and your instructions are sent to these providers for processing. Our current AI providers include:

We may add or change AI providers over time. We will update this section accordingly. We select providers that offer appropriate data handling commitments, but we cannot guarantee how these third parties process data once it leaves our systems. We encourage you to review their privacy policies.

6.1.1 Bring Your Own Key (BYO Key)

iTeri allows you to connect directly to AI providers using your own API key. When you use this option, your instructions and compressed page data are sent directly from the extension to the AI provider under your own account and agreement — they do not pass through our servers.

In this configuration, iTeri acts solely as the interface facilitating your interaction with the provider. We have no visibility into, and accept no responsibility for, the data processed under your API key. Your use of the provider's services is governed entirely by your own agreement with that provider, and we encourage you to review their data handling and retention policies.

We do not store, log, or transmit your API key to our servers. Your key is held in your browser's local extension storage and is used only to authenticate requests made directly from the extension to the provider.

6.2 Payment Processing

Stripe, Inc. processes all payments. Your payment card details are collected and stored exclusively by Stripe — they never pass through or reside on our servers. See Stripe's Privacy Policy.

6.3 Authentication

AWS Cognito (Amazon Web Services) provides our authentication infrastructure, including Google OAuth federation. See AWS's Privacy Policy.

6.4 Messaging & Communication Providers

If you use iTeri's WhatsApp integration, message relay is provided by Twilio, Inc. Messages sent and received through this integration are transmitted via Twilio's infrastructure. Twilio may retain message metadata and content in accordance with their own policies. See Twilio's Privacy Policy.

We use the Twilio integration solely to relay messages between you and iTeri. We do not persistently store message content on our servers beyond what is necessary to process your current request. However, Twilio's own data retention policies apply to data processed through their platform.

6.5 Other Third Parties

We may use additional third-party services for analytics, error tracking, or communication. We will not share your personal information with third parties for their own marketing purposes.

7 - Data Storage & Security

7.1 Where Your Data Is Stored

Our servers are hosted on Amazon Web Services (AWS). Account data and service infrastructure are primarily hosted in the Asia Pacific (Sydney) ap-southeast-2 region. However, data sent to third-party AI providers may be processed in other jurisdictions (see Section 12).

7.2 Security Measures

We implement appropriate technical and organisational measures to protect your information, including:

  • Encryption in transit — All communications between the Chrome extension, our servers, and third-party providers are encrypted using TLS. Application-layer encryption (AES-256-GCM) is applied to sensitive API traffic.
  • No credential storage — We do not store your website passwords or login credentials on our servers at any time.
  • Authentication security — Account access is managed through OAuth-based authentication via AWS Cognito.
  • Access controls — Access to production systems and user data is restricted to authorised personnel on a need-to-know basis.

While we take reasonable steps to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.

8 - Data Retention

We retain your personal information only for as long as necessary to fulfil the purposes described in this Policy:

  • Account data — Retained for the duration of your account and for a reasonable period after deletion to comply with legal obligations.
  • Billing records — Retained for a minimum of 7 years as required by Australian tax law.
  • Usage & analytics data — Aggregated and de-identified data may be retained indefinitely. Identifiable usage data is retained for up to 24 months.
  • Page content & AI interactions — Compressed page representations and AI interaction data are ephemeral and are not persistently stored by us beyond the duration of the request. Note that third-party AI providers may have their own retention policies.
  • Support communications — Retained for up to 3 years after the last interaction.

When data is no longer required, it is securely deleted or de-identified.

9 - Your Rights

Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), you have the following rights in relation to your personal information:

  • Access — You may request access to the personal information we hold about you.
  • Correction — You may request that we correct inaccurate or incomplete personal information.
  • Deletion — You may request deletion of your account and associated personal information, subject to our legal obligations to retain certain records.
  • Complaint — If you believe we have breached your privacy, you may lodge a complaint with us. If you are unsatisfied with our response, you may escalate the complaint to the Office of the Australian Information Commissioner (OAIC).

To exercise any of these rights, contact us at privacy@iteri.ai. We will respond within 30 days.

9.1 Additional Rights for EU/UK Residents

If you are located in the European Economic Area or the United Kingdom, you may also have rights under the GDPR / UK GDPR including the right to data portability, the right to restrict processing, and the right to object to processing. If these rights apply to you and you wish to exercise them, please contact us.

10 - Cookies & Local Storage

The iTeri Chrome extension uses browser local storage and Chrome's extension storage APIs to save your preferences, authentication tokens, and session state. This data is stored locally on your device and is necessary for the Service to function.

Our website (iteri.ai) may use cookies for:

  • Essential cookies — Required for authentication, security, and basic website functionality.
  • Analytics cookies — Used to understand how visitors interact with our website. These may be provided by third-party analytics services.

We do not use advertising or tracking cookies. You can control cookie preferences through your browser settings.

11 - Children's Privacy

The Service is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected information from a child under 18, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us at privacy@iteri.ai.

12 - International Data Transfers

While our primary infrastructure is hosted in Australia, your information may be transferred to and processed in other countries when it is sent to third-party AI providers (such as Anthropic and OpenAI, whose infrastructure is primarily located in the United States).

Where personal information is transferred outside Australia, we take reasonable steps to ensure that the recipients of your information comply with privacy obligations that are at least substantially similar to the Australian Privacy Principles, in accordance with APP 8.

By using the Service, you acknowledge and consent to the transfer and processing of your information in jurisdictions outside Australia as described in this Policy.

13 - Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will notify you by email or through the Service at least 14 days before the changes take effect.

We encourage you to review this Policy periodically. The "Last updated" date at the top of this page indicates when the Policy was most recently revised.

14 - Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

iTeri Pty Ltd
Privacy Officer
Email: privacy@iteri.ai
Sydney, New South Wales, Australia

If you are not satisfied with our response to a privacy concern, you may contact the Office of the Australian Information Commissioner.