Iridium — Privacy Policy
This Privacy Policy explains how Progress Labs LLC, a California limited liability company doing business as Iridium ("Iridium," "we," "us," or "our"), collects, uses, shares, and retains information when you use the Iridium service (the "Service"). By using the Service, you agree to this Policy.
1. Who We Are
Iridium is a hosted LinkedIn automation tool provided through a Model Context Protocol (MCP) interface, operated by Progress Labs LLC. For any privacy-related request, contact support@iridiumhqmcp.com.
2. Information We Collect
Account and identity information. When you sign in, we receive identity and authentication information through Supabase (our authentication provider), such as your name and email address.
LinkedIn connection data. To operate the Service, we connect to your LinkedIn account through Unipile, a third-party provider. We do not store your LinkedIn password or login credentials. Unipile holds a session token that maintains the connection; if that session is invalidated, the remedy is to reconnect and regenerate the session, not account loss.
Content and activity data. We process the drafts, comments, messages, prospect lists, and configuration (such as goals, topics, and connection caps) that you create or that the Service generates for your review. We also process data about the LinkedIn profiles and posts you interact with through the Service.
LinkedIn messages and conversations. The Service includes a messaging feature. With your LinkedIn account connected, we synchronise your LinkedIn conversations — including messages you received from other people — so the Service can display your inbox, summarise threads, classify which conversations need a reply, and draft replies for your review. Message content is sent to our AI sub-processors for those purposes. Incoming messages also reach us through a webhook from Unipile so your inbox stays current. As with every other action, a drafted reply is only sent after you approve it, or at a time you schedule.
Voice and style data. To write in your voice, we analyse your own LinkedIn profile, posts, and comments, plus any example messages you provide, and store a derived summary of your writing style and interests.
Payment information. If you purchase a paid plan, payments are processed by Stripe. We do not store full card numbers; Stripe handles payment data under its own terms.
Usage and diagnostic data. We collect logs and analytics about how the Service is used, including through PostHog, to operate, secure, and improve the Service.
3. How We Use Information
We use information to: operate and provide the Service; authenticate you; generate and schedule the activity you direct; process payments; secure the Service and detect abuse; comply with legal obligations; and communicate with you about the Service.
4. Legal Bases (EU/EEA/UK Users)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Contract — to provide the Service to you, our registered user.
- Legitimate interests — to secure the Service, prevent abuse, maintain logs, and operate the Service. Where we process the personal data of third parties (for example, LinkedIn profiles that our users discover, comment on, or reach out to through the Service), we rely on legitimate interests, subject to a Legitimate Interest Assessment we maintain on file.
- Legal obligation — to comply with applicable law.
- Consent — where required, for example for non-essential cookies or trackers.
5. Notice to Individuals Whose Data Is Processed Through the Service (GDPR Article 14)
If you are located in the EU/EEA or UK and your personal data was collected through the Service by one of our users (rather than provided by you directly), we provide notice consistent with GDPR Article 14. That notice describes the categories of data processed (such as your public LinkedIn profile information), the purposes and legal basis (legitimate interests), the source (LinkedIn, via our user's activity), your rights, and how to object or request deletion. We maintain an append-only log of such processing, which is what allows us to identify the data we hold about you and to honor a request. Notices are currently issued on request rather than automatically. To exercise your rights or object to processing, contact support@iridiumhqmcp.com.
6. How We Share Information
We share information only with the service providers necessary to operate the Service, each acting as a processor or sub-processor on our behalf:
| Provider | Purpose |
|---|---|
| Unipile | LinkedIn connectivity, activity, and message synchronisation |
| Supabase | Authentication (sign-in only — not the application database) |
| Anthropic | AI generation of drafts, comments, posts, and replies |
| Cerebras | AI classification, ranking, and quality scoring. Processed in the United States with zero data retention. |
| Stripe | Payment processing |
| PostHog | Product analytics |
| Resend | Transactional and notice email |
| Hetzner | Hosting and database (all application data) |
| Cloudflare (incl. R2) | Content delivery and object storage |
We do not sell your personal information. We may disclose information if required by law or to protect our rights, users, or the Service.
7. International Transfers
Some providers process data outside your country, including in the United States. Where required, such transfers are made under an appropriate transfer mechanism, such as the EU-U.S. Data Privacy Framework certification or Standard Contractual Clauses with supplementary measures.
8. Data Retention
We retain account and activity data for as long as your account is active and as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. In practice:
- Discovered LinkedIn profile and post data is retained for up to seven (7) days and then deleted on the next processing cycle.
- Comment drafts you do not action expire after 24 hours; outreach drafts expire after 3 days.
- Synchronised LinkedIn conversations and messages are retained while your LinkedIn account is connected, so the inbox and reply features can work, and are erased on account deletion under the same 30-day window described below.
- If you do not use the Service for thirty (30) days, we disconnect your LinkedIn account from Unipile so we are not maintaining an unused connection. We email you before this happens. Your Iridium account and data are not deleted — only the LinkedIn connection is dropped, and you can reconnect at any time.
- When you delete your account, access is revoked and your LinkedIn session is destroyed immediately, and your personal data — profiles, drafts, scheduled messages, conversations, replies, and identity records — is permanently erased within thirty (30) days.
Audit and activity logs are retained after account deletion and are not erased. These records document actions taken through the Service — excluding credentials and secrets — and are kept for security, abuse investigation, to issue and honor notices to third parties whose data is processed, and to establish, exercise, or defend legal claims. You may request deletion of your data as described below, subject to this log-retention exception.
9. Your Rights
Depending on your location, you may have rights to access, correct, delete, port, or restrict the processing of your personal data, to object to processing, and to withdraw consent. EU/EEA/UK users have these rights under the GDPR; California residents have rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of sale/sharing (we do not sell), and the right to be free from discrimination for exercising these rights. We honor Global Privacy Control signals where applicable. To exercise any right, contact support@iridiumhqmcp.com. We will not discriminate against you for exercising your rights.
10. Cookies and Tracking
The Service uses cookies and similar technologies, including for analytics via PostHog. Where required, we obtain consent for non-essential cookies. You can control cookies through your browser settings.
11. Security
We use reasonable technical and organizational measures to protect information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Children
The Service is not directed to anyone under 18, and we do not knowingly collect their personal data. This matches the minimum age in our Terms of Service.
13. Changes to This Policy
We may update this Policy from time to time. Material changes will be posted here with an updated "Last updated" date.
14. Contact
Progress Labs LLC (dba Iridium)
Privacy requests:
support@iridiumhqmcp.com.