Legal · Privacy Policy

Privacy Policy

Last updated: April 17, 2026

1. Summary

IBHQ is software for introducing brokers. We store what you put into IBHQ (leads, signals, activity logs), some metadata about how you use the app (page views, feature clicks), and payment records. We don't sell this, we don't share it with advertisers, and we don't train AI models on it. Everything below is the detail.

2. Data we collect

  • Account data — your email, display name, workspace slug, bcrypt password hash, last login time.
  • Tenant content — leads, activities, onboarding conversations, outreach messages, signal drafts, publish history, website content. This is your data; you own it.
  • Telegram session material — API ID, API hash, and Telethon session string, encrypted at rest with Fernet before insertion.
  • Usage telemetry — page navigation, module activation, feature usage counts. Aggregated per tenant, retained 90 days.
  • Payment records — USDT transaction hashes, wallet addresses, amounts, confirmation blocks. Required for accounting and audit.

3. What we don't collect

  • Credit card or bank account data (we only accept USDT).
  • Identity verification documents, passports, or KYC material.
  • Biometric data of any kind.
  • Device fingerprints, IP-based geolocation beyond what's inferred for timezone.

4. Third parties

We use: DigitalOcean (hosting), Groq + Anthropic + Google Gemini (AI inference, with zero retention on training), TronGrid (on-chain USDT monitoring), and Twilio (SMS, if your tenant enables it). These are processors, not data brokers. We've reviewed each for GDPR / data-residency compatibility.

5. Your rights

You can: export all your data at any time (JSON or CSV from the dashboard), delete your workspace and force hard-delete within 30 days, request we restrict specific processing, request correction of inaccurate records. Email privacy@ibhq.io and we respond within 72 hours.

6. Data residency

Primary region: EU (Frankfurt). Backups remain in EU. US residency available for enterprise tenants. Nothing is stored in jurisdictions with weaker privacy law than the stricter of EU GDPR or California CCPA.

7. Cookies

We set one cookie: the authentication session cookie. No analytics cookies, no ad cookies, no cross-site trackers. Your marketing-site visits are logged in aggregate server-side without personal identifiers.

8. Changes to this policy

Material changes are announced via email to all workspace owners 30 days before taking effect. Minor edits (typos, clarifications) ship immediately and are listed in our public changelog.

Questions? Email privacy@ibhq.io.