Privacy Policy
Infrared Project Inc. ("Infrared Project," "we," "us," or "our") builds and operates software products, currently Badger and callZone. This Policy explains what information we collect, how we use and protect it, what happens when you connect an outside account, and the choices you have. We do not sell personal data, and we never will.
1. Information we collect
We collect information in three ways.
Information you give us directly.
- Contact details, such as name, email address, phone number, and company name, submitted through our website, a booking link, a waitlist form, or the course of setting up an account.
- Information you provide while setting up a product, including how your business works, what you sell, who you sell to, and the way you want messages and calls handled. This is what makes the products useful to you specifically.
- Billing information. Payment card details are handled by our payment processor and are never stored on our systems.
Information collected automatically.
- Standard web analytics on this website, including pages viewed, device and browser type, approximate location derived from IP address, referring URL, and session recordings of how the page was used. See Cookies and analytics below.
- Usage and diagnostic logs generated by the products, such as timestamps, error logs, and performance metrics, used to keep the system running and secure.
Information from accounts you connect.
- If you authorize a product to connect to an outside account, such as your email, calendar, phone number, CRM, or social account, we process the data that connection provides, strictly as needed to perform the function you authorized.
2. Connected account data
Some features request ongoing access to an account you control so the product can act on your behalf when you are not signed in, for example triaging inbound email, drafting replies, or booking a calendar event.
- Email. Read, send, draft, label, or organize messages, depending on the permissions you grant. Used only to perform the workflow you asked for.
- Calendar. Read, create, or update events, depending on the permissions you grant. Used to schedule, reschedule, or surface meetings as part of your workflow.
Limited use. In practice, this means:
- Connected account data is used only to provide or improve the specific feature you asked for. Never for advertising. Never for an unrelated Infrared Project product.
- We do not allow people to read it, except: (a) with your explicit consent for a specific issue, such as debugging something you reported; (b) where necessary for security, such as investigating abuse; (c) to comply with the law; or (d) where the data has been aggregated and stripped of anything identifying.
- We do not transfer it to third parties except as needed to deliver the feature you authorized, for example to our hosting provider or to an AI model provider acting strictly as a processor under contract.
- Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Revoking access. You can disconnect an account at any time, from inside the product or from the security settings of the platform itself. Revoking access stops the related automation from working until it is reconnected.
3. Message and call data
Where a product sends text messages or places and answers calls, we work with infrastructure providers for message delivery, telephony, speech, and conversational voice. They act as processors on our behalf, under contract, solely to deliver the service.
- Phone numbers, message content, call audio, and transcripts are processed only to operate, debug, and improve the specific workflow running for your business.
- Consent and opt-out. Message recipients can opt out at any time by replying STOP, and get help by replying HELP. Message and data rates may apply. Message frequency varies by workflow. For AI voice calls, callers are told they may be speaking with an automated system where the law requires it, and recording disclosures are given where applicable.
- No marketing use of opt-in data. No mobile phone number, text messaging opt-in data, or call data is shared with, or sold to, any third party or affiliate for their own marketing or promotional purposes. Text messaging originator opt-in data and consent are never shared with third parties for any purpose other than providing the messaging or voice service itself.
- If you use a product to message or call your own contacts, you remain responsible for obtaining proper consent from them and for complying with applicable law, recording consent rules, and carrier requirements. We build the product to help you do that correctly.
The Badger messaging program has its own SMS Privacy Policy and SMS Terms, published alongside this document.
4. How we use information
We use the information described above to:
- Respond to inquiries, schedule calls, and set up accounts;
- Operate, monitor, secure, and troubleshoot the products;
- Personalize how a product works for your business, which is the core of what you are paying for;
- Maintain accurate billing and business records;
- Improve our own products and internal tooling, using aggregated or de-identified data only; and
- Comply with legal obligations.
We do not use customer data, connected account data, or messaging and call data to serve ads, build advertising profiles, or train general-purpose AI models.
5. How we share information
We do not sell personal data or customer data. Period. We share information only in these limited circumstances:
- Service providers who process data on our behalf under contract and only as we direct: cloud infrastructure and hosting, messaging and telephony delivery, speech and conversational voice, AI model providers used to power reasoning and drafting, payment processing, website analytics, and standard business tools such as email and accounting. We keep a current list of these providers and will give it to you on request.
- At your direction: when a workflow you configured sends data to another system you use, such as your CRM or a spreadsheet, that is the product doing what you told it to do.
- Legal and safety: where required by law or legal process, or to protect the rights, property, or safety of Infrared Project, our customers, or others.
- Business transfers: in a merger, acquisition, or asset sale, customer data would transfer only subject to the same protections described here, with notice to affected customers.
6. Data security
- Encryption in transit. All data moving between your systems, our infrastructure, and outside APIs is encrypted using TLS 1.2 or better.
- Encryption at rest. Databases, file storage, and backups are encrypted at rest using industry-standard encryption.
- Credential handling. Access tokens, API keys, and secrets are held in a dedicated secrets manager, never hard-coded or stored in plaintext, and scoped to the minimum permissions the workflow requires.
- Least-privilege access. Internal access to customer systems and data is limited to the people actively working on the issue at hand, and is logged.
- Vulnerability management. Dependencies and infrastructure are kept current with security patches as part of our normal release process.
No method of transmission or storage is completely secure. We design every system to minimize what is collected, where it lives, and who can reach it, and we will tell you plainly if something does not meet this bar.
7. Isolation: your data is not pooled
Each customer's environment is provisioned so that its data, credentials, and configuration are isolated from every other customer's. We do not pool customer data into shared databases or shared vector stores.
This matters most for what the products learn. Badger and callZone get better at your business by observing how you review, edit, and approve their work. Everything learned that way belongs to your account and is used for your account. It is not transferred to another customer, not used to give a competitor of yours a head start, and not folded into a general model. If you leave, it leaves with you.
8. Retention and deletion
- We retain contact and business information for as long as needed to provide the Services and to meet legal, accounting, or contractual obligations.
- Operational data, such as logs, message history, call recordings and transcripts, and processed email or calendar items, is retained only as long as the workflow needs it, or as otherwise agreed with you, then deleted or anonymized.
- When an account closes, we will delete or return customer data within a reasonable period, typically 30 days, on written request, except where the law requires us to keep it. Consent and opt-out records are kept longer where carrier or legal requirements demand it, precisely so that an opt-out is never lost.
9. Research use of data
From time to time, with your explicit opt-in consent, we may use anonymized or aggregated data for internal research and development, or to publish general, non-attributable observations about how businesses use automation.
- This is always opt-in, never a condition of receiving the Services, and can be withdrawn at any time.
- We do not use connected account content, message content, or call content for research, consistent with the limited use commitments described above.
- Anything used for research is stripped of information that could reasonably identify you, your business, or your customers before it is used or shared.
10. Your rights and choices
Depending on where you are located, including under the GDPR, UK GDPR, and U.S. state privacy laws such as the CCPA and CPRA, you may have the right to:
- Access a copy of the personal data we hold about you;
- Correct inaccurate data or have it updated;
- Request deletion of your personal data, subject to legal and contractual exceptions;
- Request a portable export of your data;
- Object to or restrict certain processing, and withdraw consent at any time;
- Opt out of the "sale" or "sharing" of personal data, though to be clear, we do not sell or share personal data for cross-context advertising in the first place.
To exercise any of these, contact us using the details at the bottom of this page. We will respond within the time the applicable law requires.
11. Cookies and analytics
This website uses a third-party product analytics service to understand which pages people read and where they get stuck, so we can improve the site. It sets cookies and collects device and browser information, pages viewed, referring URL, approximate location derived from IP address, and session recordings of how the page was used.
Session recordings are configured to mask text typed into form fields. We can see that a form was used. We cannot see what was typed into it.
We do not use this data to identify individual visitors for marketing, and we do not sell it. You can control cookies through your browser settings. Blocking them will not affect your ability to read anything on this site.
12. Children's privacy
The Services are intended for businesses and for individuals over the age of 18. We do not knowingly collect personal information from children. If you believe a child has given us personal information, contact us and we will delete it.
13. International data transfers
Infrared Project is based in the United States. If you are located elsewhere, information you provide may be transferred to, stored, and processed in the U.S. or in other countries where we or our service providers operate. Where required, we rely on appropriate safeguards, such as standard contractual clauses, for these transfers.
14. Changes to this Policy
We may update this Policy from time to time to reflect changes in our practices, products, or legal requirements. We will update the "Last updated" date above and, for material changes, tell active customers directly.
See also the Terms of Use.