Privacy policy

This policy covers the Irada application at app.irada.io, Irada Studio at studio.irada.io, the Irada Capture browser extension and the public website at irada.io, including the checklist library. Questions and requests about your data: privacy@irada.io. Help with the product: support@irada.io.

Your organization's data in the application

When your organization uses Irada, it stores the records you create so you can run, review and report on your work: sites, people and roles, templates, inspections and audits with their answers, photos, videos and documents, signatures, corrective actions, and the history of who did what and when.

It is your data

  • Your organization owns its records. Irada processes them only to provide the service to you.
  • We do not sell your data, use it for advertising, share it with other customers, or use it to train AI models.
  • Irada staff do not look at your organization's records. We access them only when you ask us for help and give permission, when needed to keep the service secure and running (for example to investigate a fault or an attack), or when the law requires it.

Who can see it

  • Only people your organization invites, according to the roles and sites you give them. Contractors you invite see only what relates to their own company.
  • Each organization's records are kept apart in the database by row-level security, so one organization can never read another's.

How it is protected

  • All traffic is encrypted in transit (HTTPS). Stored data and files are encrypted at rest by our hosting providers.
  • Uploaded files are held privately and scanned for malware before anyone can open them. Checklist photos are limited to 5 MB each and larger photos are compressed on your device before upload.
  • Records such as inspection answers are versioned rather than overwritten, and every change is written to an audit log.
  • Your organization can require multi-factor authentication for its members.

Where it is stored

  • The database, sign-in and file storage are provided by Supabase, hosted on Amazon Web Services in the United States (us-east-1).
  • The application runs on a server in the United States.
  • Email notifications (for example invitations and reminders) are sent through Resend. When paid plans open, payments will be handled by Dodo Payments; Irada will not store card details.

How long we keep it

  • While your subscription is active, your records are kept until your organization deletes them.
  • After a subscription ends, we keep your organization's data for 90 days so you can export it or come back. After 90 days, it is deleted. Copies inside encrypted backups expire on the backup schedule, normally within a further 30 days.
  • You can download inspection reports and evidence packages at any time. For a full export of your organization's data, or to have it deleted sooner, email privacy@irada.io.

Cookies in the application

The application uses only the cookies needed to keep you signed in and protect your session, set for app.irada.io alone. It loads no analytics or advertising scripts.

Irada Studio and Irada Capture

Irada Studio is part of the application. The standard operating procedures your organization writes there, with their images, reviews, sign-offs, quiz answers and checklist runs, are your organization's records and are handled exactly as described above.

What Irada Capture sends, and when

  • The extension does nothing until you connect it to your Irada account and start a recording. It stops when you finish or discard the recording.
  • While you record, in the tab where you started and in another tab of the same window if you switch to it, it sends to your organization's Irada Studio only: a screenshot of each step, the label of the element you used (for example a button name, or the name of an option you chose from a list), the page title, the page address without its query string or fragment, and the SOP title and any notes you type into the extension.
  • By default, before each screenshot is taken, the extension looks for and covers text typed into fields, email addresses, phone numbers, card numbers and long numbers with solid boxes, on your device. Owners and administrators of your organization can turn these defaults off, and can add their own patterns and page elements to hide. You can hide any other area while recording. Automatic detection can miss things, so review the screenshots before you publish.
  • It ignores password, payment-card, one-time-code, banking and identity-number fields completely: no step is recorded for them, their contents and the keys pressed in them are never read, and they are always covered in screenshots. Embedded frames, such as a payment provider's card form, are always covered too.
  • It never sends what you type into web pages as text, and it does not send cookies or anything about pages you visit when you are not recording. It keeps its sign-in token and any unsent steps in the extension's storage on your device. Choosing Disconnect this browser in the extension, or Disconnect under Settings › Connected browsers in Irada Studio, revokes the token.
  • Screenshots are stored privately with your organization's other files and scanned for malware before anyone can open them.

Optional AI suggestions

Irada Studio can suggest clearer wording, a purpose and scope, quiz questions and checklist wording. This is off unless an owner or administrator of your organization turns on “Allow AI assistance”.

  • When an author asks for a suggestion, the text needed for it (the procedure's title and the text of its steps, checklist items or pasted text) is sent to OpenRouter, which passes it to a language model provider. Images and screenshots are never sent, and nothing else from your organization's records (such as people, sign-offs or checklist answers) is included.
  • Each request tells OpenRouter to use only providers that do not store the text and do not use it for training. The provider may process the text outside the United States.
  • A suggestion changes nothing until an author reviews it and accepts it. We record which suggestion was accepted, by whom and with which model, in your organization's audit log.

The public website

What this website does not collect

  • It sets no cookies and loads no analytics, advertising or tracking scripts.
  • Answers you type into a checklist are stored only in your browser, on your device. They are never sent to Irada, never placed in a web address, and never shared. Use “Clear” on a checklist to remove them, or clear this site's data in your browser.
  • The library search runs in your browser. What you type is not sent anywhere.
  • Comments and photos you add to a checklist also stay on your device: comments in this browser's storage, and photos (compressed first, 5 MB at most) in this site's browser database, only so they can appear on screen and in your printout. They are never uploaded. “Clear” on a checklist removes its answers, comments and photos from this device.
  • Other files, electronic signatures and names of people from your organization are not collected on public pages. Those questions ask you to sign in to the application instead.

USDOT number lookup

The USDOT number lookup is the one place on this website where something you type leaves your browser. The number is sent to this website in the body of the request, never in the web address, and passed to the Federal Motor Carrier Safety Administration (FMCSA) to fetch that carrier's public record. The answer is kept in the server's memory for up to six hours so repeat lookups are fast, then discarded. The number is not written to the access log, stored on disk or linked to you. To limit misuse, the web server counts lookups per visitor address in memory for a few minutes; the address is not logged.

What the web server records

The web server's access log for this website records only the time, the page address, the response status, whether the browser described itself as an automated crawler (yes or no) and whether the request was a background prefetch by the page (yes or no). It does not record IP addresses, browser details or anything you type. Server error logs, kept for fault diagnosis, can include the requesting address; they are rotated and deleted after 14 days. From that log we count, per checklist and per day, page views, prints (a printed checklist requests a one-pixel image with the checklist's name) and clicks on “Use this checklist in Irada”. The counts are never linked to a person or to an account in the application.

Moving to the application

“Use this checklist in Irada” opens the sign-up page with only the checklist's public name and version in the link. After you sign in, the checklist template is copied into your organization. Answers from this website are not transferred.

Your requests

To ask what we hold about you, correct it, export it or delete it, email privacy@irada.io. If your organization manages your account, we may pass the request to your organization's administrator, who controls its records. We reply within 30 days.

Changes to this policy

We update this page when our practices change and change the date below. Material changes to how we handle organization data are also announced to account owners by email before they take effect.

Last updated: September 28, 2026.