Legal
Privacy Policy
Last updated 22 July 2026
iolite Labs builds tools that measure whether AI systems are psychologically safe — including for children. A product like that has no business collecting more than it needs. This policy describes exactly what we collect, what we deliberately do not, and what you can make us delete.
Who this covers
This policy applies to iolitelabs.com, the iolite Labs portal at beta.iolitelabs.com, the ioLite Guardian browser extension, and the audit services we deliver to clients.
iolite Labs is the data controller for information collected through these products. Where we process data on behalf of a school, clinic, or employer, that organization is the controller and we act as a processor under our agreement with them.
The short version
- —We do not sell personal information. We never have and we will not.
- —We do not use your data, or anyone's conversations, to train AI models.
- —The Guardian extension analyzes conversations on the device. Conversations assessed as safe never leave it.
- —Monitoring is never covert: it requires an affirmative, revocable consent step, and the person being monitored is told.
- —You can ask us to delete your data, and we will.
Website
Visiting iolitelabs.com does not require an account. We keep aggregate, non-identifying traffic counts so we know which pages are read. We do not use advertising cookies, cross-site trackers, or third-party analytics that build a profile of you.
If you submit the contact form, we receive what you type — typically your name, email, organization, and message — and use it only to reply to you and to keep a record of the enquiry.
Portal accounts
Creating an account stores your name, email address, hashed password (or Google sign-in identifier), role, and the organization you belong to. We record ordinary operational logs: sign-ins, actions taken in the product, and errors.
Audit content you upload — target system details, probe sets, transcripts, and reports — is stored so the product can function, and is visible only to your organization and to iolite Labs staff who need it to run or support your audits.
ioLite Guardian browser extension
Guardian is a safety monitor installed by a parent, school, clinic, or employer on a device they are responsible for. It reads AI-chat conversations on that device and flags moments that suggest psychological harm. Because it collects browsing content, it is worth being precise about what happens to it.
Classification runs on the device first. A local classifier scores both what the person wrote and what the AI replied. If the exchange is assessed as safe, the content is counted and immediately discarded — it is never transmitted, stored, or seen by anyone, including us.
Only when an exchange is flagged as concerning does anything leave the device.
- —What is sent when a moment is flagged: the flagged excerpt (capped in length), up to five surrounding conversation turns, the page address with its query string removed, the page and conversation title, the site name, the severity and category, and how long the session had been running.
- —How the person is identified: by a pseudonym such as Child-K7QM, generated on the device. The person's real name exists only as a label a guardian typed into their own dashboard — it is never sent from the device and is never attached to the stored record.
- —What is never collected: safe conversations, full transcripts, passwords, form entries, browsing history, keystrokes, screenshots, location, or contacts.
- —Where it never runs: messaging apps and social direct messages, email, health, therapy and crisis services, and banking sites are excluded permanently and cannot be enabled. Human-to-human private conversation is outside the scope of this product.
Consent and disclosure
Guardian does not monitor anything until an affirmative consent step is completed in its settings, and it displays a standing, plainly-worded disclosure naming who is monitoring the device. Whoever installs it is responsible for having the lawful authority to monitor that person, and for telling them.
Consent can be withdrawn at any time by unchecking it, unlinking the device, or uninstalling the extension. Monitoring stops immediately.
Children's data
Guardian is designed to be installed by parents and schools to protect minors, so it will often process a child's data. We collect only what a guardian needs to respond to a flagged moment, we do not use it for advertising or profiling, and we do not disclose it to third parties for their own purposes.
In a school deployment, the school is the controller. Student data is processed only to provide the service under our agreement with the school, is never used commercially, and is deleted on request or at the end of the agreement, consistent with obligations including FERPA, COPPA, and state student-privacy laws such as New York Education Law § 2-d.
Limited use of data from Google APIs and the Chrome Web Store
Our use of information received from Google APIs, and any data the ioLite Guardian extension collects, adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. Specifically: data is used only to provide and improve the user-facing safety-monitoring features described here; it is not transferred except as necessary to provide those features, to comply with law, or in a merger with equivalent commitments; it is not sold; and it is not used for advertising, credit assessment, or lending. Humans do not read collected content except with your explicit permission, to investigate abuse or a security incident, to resolve a support request, or where required by law.
How we use what we collect
We do not use customer content, portal data, or conversations captured by Guardian to train machine-learning models.
- —To operate the products — running audits, delivering reports, and surfacing flagged moments to the right guardian.
- —To keep the products secure, diagnose failures, and prevent abuse.
- —To respond to you when you contact us.
- —To meet legal obligations.
Retention
Portal accounts and audit content are kept while your account is active and for a reasonable period afterwards for record-keeping. Flagged Guardian alerts are kept so a guardian can review a pattern over time; an organization may set a shorter retention period, and any alert or profile can be deleted from the dashboard at any time. Deleting a monitored person's profile stops all future collection for them.
Aggregate, non-identifying counts may be retained indefinitely.
Security
Data is encrypted in transit. Passwords are hashed and never stored in readable form. Sensitive credentials such as API keys are encrypted at rest. Device credentials for Guardian are stored only as one-way hashes, so a database leak cannot be replayed against us, and any device can be revoked individually without affecting others. Access to production data is limited to staff who need it.
No system is perfectly secure. If a breach affects your data we will notify you and any required regulator without undue delay.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to or restrict processing, and to withdraw consent. Residents of California, the EU, and the UK have these rights under the CCPA/CPRA and the GDPR respectively; we extend them to everyone.
To exercise any of them, contact us at the address below. We will not discriminate against you for asking. If your data is held on behalf of a school or employer, we will direct your request to them as the controller and support them in answering it.
International transfers
We operate from the United States, and data may be processed there. Where we transfer personal data out of the EEA or UK we rely on appropriate safeguards, including Standard Contractual Clauses.
Changes
We will post any change here and update the date at the top. If a change materially reduces the protection of data we already hold, we will give notice before it takes effect.
Contact
Questions, requests, or complaints: privacy@iolitelabs.com. You can also reach us through the contact page.