Privacy policy
What Ihsan collects, why, where it goes, and how to get it deleted. Written to be read.
Effective 19 September 2026
Who we are
This policy covers the Ihsan service and the website at ihsanone.com (“Ihsan”, “we”, “us”). For anything about privacy, write to privacy@ihsanone.com.
When your company uses Ihsan, your company decides what Ihsan reads and is responsible for that content. We process it on your company’s behalf, in order to provide the service.
What Ihsan collects
- Workspace details. Your Slack workspace name and identifier, and the access token Slack issues when an admin installs Ihsan. Tokens are encrypted before they are stored.
- Messages sent to Ihsan. Messages that mention Ihsan or are sent to it directly, and Ihsan’s replies.
- Knowledge sources. The content of channels, documents and other sources that your admins choose to connect, plus a searchable index and a map of the people, projects and decisions found in them.
- Basic profile details. Names and Slack user identifiers of people who talk to Ihsan or appear in connected sources, so Ihsan can say who said or owns what.
- Admin console accounts. Sign-in details for admins who use the console.
- Technical logs. Records of requests and errors, kept to run and secure the service.
Ihsan does not read channels, files or systems that have not been connected to it.
What we use it for
- To answer your people’s questions and carry out the tasks they give Ihsan.
- To keep Ihsan’s knowledge of your company current.
- To keep the service secure, find faults and fix them.
We do not sell your data. We do not use your company’s content to train AI models. We do not use it for advertising.
Who else processes it
We use a small number of carefully chosen service providers to run Ihsan. They fall into these groups:
- Hosting and database providers, which run the application and store your data.
- AI model providers, which receive a question together with the passages needed to answer it, and return the answer.
- Web search providers, which receive a search query when an answer needs information from the web.
- Your workplace tools, such as your chat platform, which carry messages between your people and Ihsan.
Each provider is bound by a written agreement that requires it to protect your data, to use it only to provide its service to us, and not to use it to train its own models. A current list of providers is available to customers on request.
We may also disclose information when the law requires it, or to a successor if the Ihsan business is reorganised or transferred, in which case this policy continues to apply to your data.
Where it is stored
Ihsan’s application and database are hosted in the United States. If you are outside the United States, your data is transferred there. Where the law requires a safeguard for such a transfer, we rely on standard contractual clauses or an equivalent recognised mechanism.
How long we keep it
We keep your workspace’s data while your company uses Ihsan. When a source is removed, its content is removed from Ihsan’s knowledge. When your company stops using Ihsan, or asks us to, we delete its stored data within 30 days. Copies held in routine backups are overwritten within a further 30 days. Technical logs are kept for up to 90 days.
Your choices and rights
Depending on where you live, you may have the right to see, correct, export or delete personal information about you, and to object to how it is used. Because Ihsan holds this information on behalf of your company, the quickest route is usually your company’s Ihsan admin. You can also write to privacy@ihsanone.com and we will work with your company to respond within 30 days. If you are not satisfied with our response, you have the right to complain to the data protection authority where you live.
Security
Each company’s data is stored apart from every other company’s. Credentials are encrypted before storage. Every request from Slack is verified. More on the security page.
Children
Ihsan is a workplace product and is not intended for anyone under 16.
Changes
If we change this policy in a way that matters, we will tell workspace admins before the change takes effect and update the date above.