Privacy notice
How Itera collects, uses, and protects your personal information, and what your report is and is not used for.
Last updated · Jul 16, 2026
Written to the California Consumer Privacy Act, as amended by the CPRA, and to the California Privacy Protection Agency's rules on automated decisionmaking technology. We apply it as the baseline for every participant, in every state.
Who we are
Itera, operating through [LEGAL_ENTITY_TBD], is the business that collects your personal information and decides how it is used. The legal entity is being formed and will be named here before Itera sells in the United States.
Information we collect
Identifiers: your name, work email, and browser IP address. Professional or employment information: your employer, your role, and your team. Product activity: your responses inside a case, transcripts of your interactions with the AI, and the scores the model assigns them. Commercial information: your organization's subscription and billing records. We collect this from you directly, from your employer when they set up your seat, and automatically from your browser.
Sensitive personal information
We do not ask for sensitive personal information as California defines it, meaning government IDs, financial account numbers, precise geolocation, race or ethnicity, religion, union membership, health, sex life, sexual orientation, or the contents of your private messages. We do not use or disclose any of it for purposes that would give you a right to limit. If you paste sensitive data into a case, we process it only to score that case, and we ask you to use synthetic data instead.
Why we collect it
To create and maintain your account. To assign and run assessments. To generate reports for your authorized manager. To capture evidence of judgment under pressure. To recommend the targeted practice that closes a gap. Nothing else.
How we use AI, and what it decides
Itera uses a language model to score your responses against a published rubric, and that score sets which practice you get next. California's rules on automated decisionmaking technology attach extra obligations when that technology makes a significant decision about a person, and performance evaluation can be one. Itera's report is formative: it directs practice, not employment decisions, and your employer agrees in our terms of service not to use it as the sole basis for one. You can ask us how a score was reached by writing to privacidad@itera.la.
What we never do with it
We do not sell your personal information. We do not share it for cross-context behavioral advertising. We do not use it for third-party marketing. We do not use it to train foundation models. Aggregated, de-identified data may be used to improve Itera's cases and rubrics, and once de-identified we do not try to re-identify it.
Your rights
You can know what we collect and why, get a copy of it, correct it, delete it, and opt out of sale or sharing. There is nothing to opt out of, because we do neither. Write to privacidad@itera.la. We confirm within 10 business days and answer within 45 days, and if we need another 45 we tell you why. We verify who you are before we act, and we will never charge you or reduce your access to Itera for using a right. You can name an authorized agent to act for you.
If you work in Illinois
Illinois law requires your employer to tell you when AI is used to influence an employment decision, and that includes selection for training. Itera writes that notice so your employer can give it to you. Ask your administrator for it, or write to privacidad@itera.la.
Who else touches your data
Supabase stores it. Stripe processes payments. Anthropic runs the model that scores your work. Sendgrid sends transactional email. All are US providers, all are under contract as service providers, and none of them may use your data for their own purposes.
Retention
Session data and reports: 12 months after your last activity, then anonymized or deleted. Account records: for as long as your organization's subscription runs, plus 12 months. Billing and tax records: 7 years, to meet US tax and accounting record-keeping requirements.
Security
Row-level multi-tenant isolation in the database, encryption at rest, encryption in transit over TLS 1.3, an audit log of privileged access, and least privilege for Itera staff.
Changes to this notice
We notify active accounts by email 30 days before a material change takes effect.
Contact and complaints
Write to privacidad@itera.la. California residents who believe we have not respected their rights can complain to the California Privacy Protection Agency or to the California Attorney General.
Itera does not promise automatic legal compliance and does not give legal advice. Itera reports are formative: they direct practice, not employment decisions. For use with real personal data or an enterprise DPA, talk to your own counsel.