Legal · Privacy

Privacy Policy

How iDharma collects, uses, and protects your data.

📅 Effective 2 July 2026 Last updated 2 July 2026 v2.0
In brief

iDharma is an independent AI-audit company. We collect only what an audit needs — your account details, the audit inputs you choose to submit, billing information, and basic usage data — and we use it to deliver your audit. We disclose every third party that can touch your data, including that your audit content is sent to Anthropic to generate a draft report. We don't sell your data, and we never use it to train products. You can access, correct, delete, or export your data any time — email connect@idharma.us and we respond within 30 days.

01 Who We Are & Scope

This Privacy Policy explains how iDharma LLC (“iDharma,” “we,” “us”) collects, uses, and protects personal data when you visit idharma.us or engage us for an AI audit. iDharma is an independent, standards-based AI-audit company based in Greenwood, Indiana, USA — we assess other organizations' AI systems and deliver a written report.

This policy covers our website and our audit service. It does not cover third-party websites we link to, which have their own privacy policies. Our customers are primarily organizations; where you interact with us on behalf of a company, a separate engagement or data-processing agreement between that company and iDharma may add detail and, where it conflicts, govern. This policy forms part of our Terms of Use.

02 Information We Collect

  • Account information — name, work email, phone (optional), a hashed password if you create an account, company, country, and language.
  • Audit inputs & materials — the documentation, system details, logs, and other materials you choose to submit for an audit. You control what you send us.
  • Engagement & billing information — the scope you approve, invoices, and payment details. Card details are entered directly with Stripe; we don't store full card numbers.
  • Communications — emails, support requests, and metadata from meetings you schedule with us (such as name, email, and time).
  • Technical & usage data — IP address, browser and device type, pages visited, referral source, and timestamps.
  • Cookies — see Cookies & Tracking below.

We collect no more than the work requires. We don't ask for government ID or special-category (“sensitive”) personal data to run an audit; if an engagement ever needs more, we'll agree it with you in writing first.

Free tools. Interactive tools on our site — such as the AI ROI Calculator — run entirely in your browser. Anything you enter into them is used only to show you a result on your own screen; it is not sent to us, stored, or logged.

03 How We Use Your Information

  • Deliver and scope your audit — plan the engagement, perform the assessment, and produce your report.
  • Generate the draft report — audit content you submit is processed by our AI provider (Anthropic) to generate a draft, which our team reviews. See Sharing & Subprocessors.
  • Process payment — via Stripe, once you approve a scope.
  • Operate and secure the service — authentication, fraud and abuse prevention, and troubleshooting.
  • Communicate with you — engagement updates, security notices, and service changes.
  • Marketing — only with your consent; every marketing email has an unsubscribe link.
  • Improve the product — using de-identified, aggregated analytics that don't identify you.

05 Sharing & Subprocessors

We share personal data only with the providers that help us run the audit service, when the law requires it, or in a business transfer. We disclose every provider that can process your data.

  • Service providers (subprocessors) — the vetted providers in the table below, each bound by contract to protect your data and use it only to provide their service to us.
  • Legal authorities — only when required by law, such as a valid subpoena or court order, or to prevent imminent harm.
  • Successor entity — if iDharma is involved in a merger, acquisition, or sale of assets, data may transfer to the successor; we'll give notice before it becomes subject to a materially different policy.
ProviderWhat it doesWhat it can touch
HostingerCloud hosting (our virtual server, US)Application data at rest on our server
StripePayment processing (PCI-DSS Level 1)Billing details; card data handled entirely by Stripe
Anthropic (Claude) Audit contentGenerates draft audit contentThe audit inputs you submit for a report
ResendTransactional email deliveryYour email address and message content
GoogleSign-in, reCAPTCHA, MapsAuth identifiers; form / bot-protection signals
MicrosoftSign-in, calendar, off-site backups (OneDrive)Auth identifiers; encrypted database backups
DocuSignE-signature for agreementsSigner name, email, and the document signed
ZoomScheduled video meetingsName, email, and meeting metadata
SentryApplication error monitoringTechnical diagnostic data from errors

This mirrors the subprocessor list on our Security & Compliance page. If you need a Data Processing Agreement or a formal, versioned subprocessor list for procurement, email security@idharma.us.

We do not sell your personal data — ever. And we do not use your data, or the materials you submit for an audit, to train AI models or build other products. What you share for an audit is used for that audit.

06 Cookies & Tracking

We use cookies and similar technologies to run the site and understand how it's used:

  • Strictly necessary — required for the site to work (security and sessions). These can't be switched off.
  • Functional & analytics — remember your preferences and help us improve the site.
  • Marketing — used only if you consent.

You can review and change your choices any time from our cookie settings. Public forms are protected by Google reCAPTCHA.

07 Data Retention

We keep personal data only as long as we need it for the purpose we collected it, or as the law requires.

  • Account information — while your account is active, plus a limited period afterward.
  • Audit materials & reports — for the engagement and a limited period after delivery, then deleted or returned as set out in your engagement agreement.
  • Billing & tax records — as required by applicable tax and accounting law (generally up to 7 years).
  • Communications — as long as needed to support you and maintain our records.
  • Marketing data — until you unsubscribe.
  • Logs — a limited period, unless a longer period is needed for a security investigation.

08 Your Rights

You have rights over your personal data. Depending on where you live, these include:

  • Access — request a copy of the data we hold about you.
  • Correction — ask us to fix inaccurate or incomplete data.
  • Deletion — ask us to delete your data; we keep only what we must for legal and tax reasons.
  • Portability — receive your data in a portable, machine-readable format.
  • Opt out of marketing — unsubscribe at any time.
  • California (CCPA/CPRA) — the right to know, delete, and correct, to opt out of the “sale” or “sharing” of personal information (we do not sell or share your data for cross-context behavioral advertising), and not to be discriminated against for exercising these rights.
  • EU / UK (GDPR) — in addition to the above, the right to object to or restrict processing, to withdraw consent, and to lodge a complaint with your supervisory authority.

To exercise any right, email connect@idharma.us. We verify your request and respond within 30 days. You may use an authorized agent where the law allows.

09 Security

We protect your data with the controls we actually run today — described in full, and honestly, on our Security & Compliance page. In summary:

  • Data travels over HTTPS/TLS in transit; HTTPS is enforced with HSTS.
  • Passwords are one-way hashed with bcrypt; sensitive tokens and signing keys are encrypted at the application layer.
  • Two-factor authentication is required for administrative access, with role-based access control and audit logging.
  • Databases are backed up nightly — retained 14 days locally, plus an off-site copy to encrypted cloud storage.
  • Payments are handled by Stripe (PCI-DSS Level 1); we never store full card numbers.

No method of transmission or storage is ever completely secure, and we don't claim certifications we haven't earned — iDharma is not currently SOC 2, ISO 27001, or HIPAA certified. Found a vulnerability? Email security@idharma.us and we'll acknowledge your good-faith report promptly.

10 International Transfers

iDharma operates from the United States, and our providers may process data in the US and elsewhere. If you access the service from outside the US, your data is transferred to the US and handled under safeguards recognized by applicable law — such as the Standard Contractual Clauses — together with the contractual protections we require of our providers.

11 Children's Privacy

iDharma is a business service and is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a minor has given us data, email connect@idharma.us and we'll delete it promptly.

12 Changes to This Policy

We may update this Privacy Policy as our practices or the law change. For material changes we'll give reasonable notice by email or on-site notice; the version and date at the top of this page always reflect the current edition. Continued use after the effective date means you accept the update.

13 Contact Us

Questions, requests, or concerns about your privacy? For data and privacy requests — access, deletion, and the rest — email connect@idharma.us. For security matters or a Data Processing Agreement, email security@idharma.us. You can also write to us at iDharma LLC, Greenwood, Indiana, USA.

Questions about your privacy?

We read every request and respond within 30 days.

Email connect@idharma.us
Privacy requests
Security & DPAs
Mailing address
iDharma LLC
Greenwood, Indiana, USA

This Privacy Policy explains how iDharma LLC handles personal data as of 2 July 2026 and forms part of our Terms of Use. It describes our current practices, which evolve as the product does; the version and date above reflect the current edition. For binding data-protection terms, request a Data Processing Agreement at security@idharma.us. iDharma LLC, Greenwood, Indiana.