Legal
Privacy Policy
Our full Privacy Policy is being finalised with our attorney and will replace this page when it is approved. Until then, this page sets out the facts we can already state about the service as it is built today. For any privacy question or request, write to legal@itaibot.io.
This website
The site's own code sets no cookies and runs no analytics or advertising code. Its pages, images and video are all served from itaibot.io and it uses your own device's fonts, so a visit sends nothing to another website.
What the service collects
- About each enrolled PC or server: its name, Windows version, hardware, manufacturer, model and serial number, domain details, network adapters with their IP and MAC addresses, the roles it plays (such as domain controller, DNS, DHCP, file or print server) with its share and printer names, the public IP address it enrolled from, and the names of the people signed in to it (at most five).
- About other devices on your network: passively, from the PC's own address and name caches and from a DHCP server's leases: their private IP address, MAC address, a vendor guess and, where known, their host name. ITAI sends no network probes to find them.
- During a diagnosis: the problem description, each read-only command ITAI ran and its output, the findings, the proposed fix, who approved what, and notes. Command output can include event log lines, file names, installed software and user names.
- About people who use the dashboard: email address, name if given, role, a hashed password and two-step sign-in data. Also the IP address and time of each agreement to these terms, of wrong-password attempts (kept only while they can still lock an account) and of each browser kept signed in, and a log of every ITAI staff request that reaches your organization. Card and bank details are held by our payment processor, Stripe, not by ITAI.
Diagnosis data is sent to our AI model provider so that it can run the diagnosis. ITAI does not use your tickets or device data to train AI models.
How long we keep it
- Tickets and their transcripts: deleted 90 days after the ticket's last activity, unless they are under a legal hold.
- A slim audit record of each ticket (who did what and when, the commands run, and fingerprints of their output rather than the output itself): kept for 7 years, including after a customer's data is deleted.
- Billing records: kept as tax law requires.
The Security page has more detail.
Your choices
Your organization's admins can export its data from the Data & privacy page in the dashboard. Your account owner can ask there for the account's data to be deleted, and ITAI staff then carry out the deletion.