IRIntellrise

Privacy Policy

Last updated: 15 June 2026

Intellrise provides an AI data-analysis platform that lets you ask questions about your own business data in plain English and get charts, dashboards and reports. This policy explains what we collect, how we use it, and the choices you have.

1. The short version

When you connect a database or Google Sheet, we keep no standing copy of it. PostgreSQL, MySQL and Redshift sources are attached read-only and queried in place; SQL Server, Snowflake, BigQuery and Databricks are read into memory for the session instead, and a Google Sheet is re-read from the Sheets API each session. That in-memory copy is dropped when the session ends. What we keep is what an answer returned, not your source tables.

Files you upload are different, and we want to be plain about it: if you upload a CSV or Excel file, we store that file so it can be queried later. It stays until you delete it, and deleting it in the app deletes the stored file.

We do store the account and configuration data needed to run the service for you (your login, your chat history, the reports and dashboards you choose to save, your connection settings and your AI provider key). Sensitive items (data-source credentials and AI keys) are encrypted at rest.

AI analysis runs on your own AI provider key (BYOK), so these requests go to the provider you chose, under that provider's terms, billed to your own account. Each question sends what you typed, the names and types of your tables and columns together with any saved descriptions, and the SQL. Query results are not sent to the model; it is told only whether the query ran and how many rows it returned. Two paths do send rows: AI Semantic Schema Learning, available on Pro, sends up to three sample rows per table when you connect a source or refresh its schema so that column meanings can be inferred, and it does not run on the free tier; and if a Gemini request fails part-way through answering, the retry includes up to ten rows of the result already produced so the reply can still be written.

We never sell your data and we do not use your business data to train any AI model.

2. Information we collect

Account data — name, email, password (stored only as a secure bcrypt hash), and your plan tier.

Content you create and save — conversations/messages in Chat, and any reports, dashboards and pinned charts you explicitly save. Saved items include the generated chart data and the SQL used to produce them.

Data-source connection settings — the details you enter to connect a database, Google Sheet or uploaded file. Connection strings/credentials are encrypted at rest (AES-256-GCM).

AI provider keys (BYOK) — the API key you add for your chosen provider, stored encrypted at rest (AES-256-GCM) and shown back to you only masked.

Your business data from a connected source — we keep no standing copy of your database or Google Sheet; PostgreSQL, MySQL and Redshift sources are attached read-only and queried in place; SQL Server, Snowflake, BigQuery and Databricks are read into memory for the session instead, and a Google Sheet is re-read from the Sheets API each session. The rows a query returns are stored twice over: with the message in your chat history, and again in any report or chart you choose to save. You can delete conversations, reports and dashboards at any time in the app.

Files you upload (stored) — when you add a CSV or Excel file as a data source, the file's full contents are stored in our database so it can be queried later, subject to a per-file and per-account size limit. This is the only case where we hold a complete copy of a source, rather than only the rows an answer returned. You can delete an uploaded file at any time in the app.

Technical & diagnostic data — error reports and performance data (via Sentry), product-usage analytics (pages viewed and features used, via PostHog), and standard server logs. We do not collect or store payment card details — payments are handled by Lemon Squeezy.

3. How we use it

To operate the service: authenticate you, run your queries, render charts/dashboards/reports, and deliver email/other channel features you enable.

To secure the service: prevent abuse, debug errors, and protect accounts.

To communicate: transactional emails (e.g. password reset, billing) via Resend.

We do not use your business data, questions, or saved content to train AI models, and we do not use your data for advertising.

4. AI processing (BYOK)

Intellrise does not provide the AI model. You connect your own API key for a provider you choose (e.g. Google Gemini, OpenAI, Anthropic). To answer a question we send that provider your question text and the relevant schema/metadata (table and column names, descriptions, and limited sample values where needed) so it can generate a query. Your provider processes this under its own terms and privacy policy.

5. Sub-processors

We rely on the following providers to run Intellrise: Neon (PostgreSQL database hosting), Render (application hosting), Resend (transactional email), Sentry (error & performance monitoring), PostHog (US — product analytics), Lemon Squeezy (payments / Merchant of Record), and your chosen AI provider (AI query generation, BYOK).

6. Security

Encryption in transit (HTTPS/TLS) for all traffic. Data-source credentials and AI keys encrypted at rest (AES-256-GCM). Passwords stored only as bcrypt hashes. Per-account isolation: one shared database in which every row carries the account it belongs to and every query filters on it — logical isolation in application code, not a separate database or schema per customer. No method is 100% secure, but we work to protect your information and will notify you of a material breach as required by law.

7. Data retention & deletion

We keep account and saved content while your account is active. You can delete saved reports, dashboards, conversations, connections, uploaded files and AI keys at any time in the app. If you close your account, we delete your account data, saved content and uploaded files within a reasonable period, except where we must retain limited records for legal/financial obligations. We keep no standing copy of a connected database or Google Sheet: PostgreSQL, MySQL and Redshift sources are attached read-only and queried in place; SQL Server, Snowflake, BigQuery and Databricks are read into memory for the session instead, and a Google Sheet is re-read from the Sheets API each session. That in-memory copy is dropped when the session ends. What an answer returned is a different thing and it does persist: those rows live with the message in your chat history and in any report or chart you saved, and they go when you delete those. Uploaded files are retained until you delete them or close your account.

8. Your rights

Depending on your location (e.g. Malaysia PDPA, EU/UK GDPR) you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise them, email contact@intellrise.com.

9. International transfers

Our providers may process data outside your country. Where required, transfers are covered by the providers' standard contractual clauses or equivalent safeguards.

10. Changes & contact

We may update this policy as the product evolves; we'll post the new date above and, for material changes, notify you. Questions or requests: contact@intellrise.com. Intellrise Technologies (SSM Reg. No. 202603145414 / LA0090055-W), Malaysia.