Legal

Privacy Policy.

Last updated August 7, 2026. This describes what iPolytex Limited actually collects and does with personal data across ipolytex.com and the IntelliFusion platform.

Who we are

iPolytex Limited ("iPolytex", "we", "us") is based in Hong Kong at Flat B1, 21/F, Chiap King Industrial Building, 114 King Fuk Street, San Po Kong, Kowloon. This policy covers ipolytex.com and the IntelliFusion platform it links to.

What we collect

Contact form. If you use the contact form, we store your name, phone number (if given), email address, and message, to respond to your enquiry.

IntelliFusion accounts. If you register or sign in, we store your username, email, display name, and (for password-based accounts) a securely hashed password - we never store your password in a readable form. If you sign in with Google, Microsoft, or LinkedIn instead, we receive your email, name, and a provider account identifier from that provider; we do not receive or store your password on those services.

Sessions. Signing in sets an essential, secure cookie to keep you signed in. This cookie is required for the account features to work and is not used for advertising or cross-site tracking.

Blog readers. Reading the blog does not require an account and we do not collect personal data from readers. Posts are written by iPolytex staff through an internal admin tool.

How we use it

  • To respond to enquiries submitted through the contact form
  • To create and secure your IntelliFusion account, and let you sign back in
  • To send account-related email - password resets and similar notifications
  • To operate and improve the platform

We do not sell personal data, and we do not use it for advertising.

What we hold, and what we do not

We are deliberately precise here, because "we never hold your data" is a claim we could not stand behind.

We do not hold your business content as the master copy. Documents, knowledge files and generated outputs are written to your own workspace. What the platform keeps is the operational record of running your service — who ran what, when, with which model, how long it took, whether it failed — plus a working copy of the payload for the retention window above. You can export that record.

Some data must sit with the platform and cannot live in your workspace: your identity, your roles and permissions, your sessions, and the API keys we issue you. These are what we need in order to reach your workspace in the first place, so they cannot be stored inside it.

Each account's knowledge, files and vector collections are isolated from every other account.

AI processing and model providers

When you use a feature that calls a language model, the content of that request — your prompt, and whatever evidence the feature retrieved to ground it — is sent to the model provider you have selected.

Which provider that is depends on your own configuration. If you supply your own API key for OpenAI, Anthropic or Google, your requests go to that provider under your own agreement with them, and their terms and privacy policy govern what they do with it. If you select a locally hosted model, the content stays within the deployment and is not sent to a third party.

We do not use your content to train models, and we do not sell it. Requests are made to fulfil the action you asked for.

Model output can be wrong. Actions with an external effect — sending mail, writing to a connected system — are held for human review before they happen; see the Terms of Use.

Voice and dictation

Where dictation is offered, pressing the microphone records audio in your browser and uploads it to the iPolytex server that is serving you. It is transcribed there, by a speech model running on that same deployment.

Your voice is not sent to an external speech service. It does not go to Google, Apple, Amazon or any other transcription provider, and it is not used to train anything.

The recording is deleted as soon as transcription finishes, including when transcription fails. We keep no audio. What remains is the text, which is placed in the message box for you to read and edit — nothing is sent on your behalf until you send it.

If this ever changes — for example if a future version transcribes in your browser using the browser maker’s own speech service, or uses a paid transcription provider — this section will say so before that version ships, and the microphone will say so at the point you use it.

Who we share it with

We use a small number of service providers to operate iPolytex, each only for the specific purpose below:

  • Resend - delivers transactional emails we send (password resets, enquiry confirmations)
  • Google, Microsoft, LinkedIn - only if you choose "Sign in with" one of these; they authenticate you and share your basic profile with us as described above

We don't share your data with anyone else except where required by law.

Cookies

We use one essential session cookie for signed-in accounts. We do not currently use analytics, advertising, or third-party tracking cookies on this site.

Data retention

Account data is kept while the account exists and is deleted, on request, with the account. Contact form enquiries are kept for as long as needed to answer them and to keep a record of the correspondence.

Operational data is deleted automatically on a schedule. Current default windows:

  • Execution payloads (the content an automated run read or produced) — 90 days, after which the payload is cleared and only the operational record of the run remains.
  • Channel messages (for example Telegram conversations) — 90 days, cleared the same way.
  • Operational logs and execution traces — 180 days, then deleted outright.

These windows are configurable per deployment; the figures above are the defaults we run. Deleting a payload does not delete the record that the run happened — that record is what lets us show you, and prove to an auditor, what the platform did.

Your rights

You can ask us what personal data we hold about you, ask us to correct it, or ask us to delete your account and associated data, by emailing info@ipolytex.com.

Security

Passwords are hashed with Argon2id, a modern, deliberately slow hashing algorithm designed to resist brute-force attacks. Sessions use secure, httpOnly cookies. We take reasonable technical measures to protect the data described in this policy, though no system is completely immune to risk.

Contact

Questions about this policy or your data: info@ipolytex.com, or by post to Flat B1, 21/F, Chiap King Industrial Building, 114 King Fuk Street, San Po Kong, Kowloon.

Changes to this policy

We'll update the date at the top of this page when this policy changes. Significant changes will be reflected here before they take effect.