← Back to imikan.ai
This Privacy Policy explains how Imikan Technologies Ltd ("Imikan AI", "we", "us", or "our") collects, uses, discloses, and protects information when you visit imikan.ai, create an account, or use our document retrieval-augmented generation ("RAG") platform (together, the "Service"). By using the Service, you agree to the collection and use of information as described in this policy.

1. Who we are

Imikan AI is operated by Imikan Technologies Ltd, a company registered with the Registrar of Companies for England and Wales (Company Registration Number 17364117), and also registered with the Corporate Affairs Commission of Nigeria (CAC), RC9774268. For the purposes of UK data protection law, Imikan Technologies Ltd is the data controller for personal information processed through the Service.

2. Information we collect

We collect information in the following categories:

Account information

When you register for an account with your email address, we collect your full name, email address, phone number, and a securely hashed password. If you sign in using a third-party identity provider instead (see "Sign-in information" below), we do not collect a phone number.

Content you upload

The documents and files you upload for ingestion into the Service — PDF, Epub, Word (.docx), PowerPoint (.pptx), Excel/CSV, plain text, or Markdown files — along with any titles, descriptions, or metadata you provide about them. This content is processed to extract text (including, for scanned or image-based PDFs, via optical character recognition), generate embeddings, and make it searchable and retrievable through the Service, including via requests to our AI processing provider (see "Who we share information with" below). Each document is private to the conversation it was uploaded in and access is governed by role-based access control.

Sign-in information

In addition to email and password sign-in, you may sign in using a third-party identity provider — currently Google or Microsoft. If you do, we receive the basic profile information those providers share as part of the sign-in process (such as your name and email address) in order to create and authenticate your account; we do not receive your password for those services.

Usage and query data

The questions and prompts you submit to the Service, along with technical usage metrics such as query counts and token consumption, which we use to operate the Service and enforce the usage limits associated with your subscription tier.

Payment information

If you subscribe to a paid tier, billing is handled by our payment processor, Stripe. We do not store your card number or other card payment details on our own systems. We receive limited billing information from Stripe, such as subscription status, plan, and transaction history, in order to manage your account.

Technical and log data

Like most web services, our infrastructure automatically logs technical information when you use the Service, including your IP address, browser type, device information, and request timestamps. This is meant for security (including bot and account abuse protection), troubleshooting, and maintaining the reliability of the Service.

Cookies

See the "Cookies and similar technologies" section below for details.

3. How we use your information

We use the information we collect to:

Your documents are stored primarily in your chat, in an Aurora database, and in an S3 bucket with intelligent tiering. All three locations are locked to your account and are only accessible by you.

5. Who we share information with

We do not sell personal information. We share information with the following categories of third-party service providers ("sub-processors"), each of which processes data only as needed to provide their service to us:

Provider Purpose What's shared
OpenAI AI-generated responses and embeddings for the RAG Service Document content and query text submitted for processing
Stripe Payment processing and subscription billing Billing details, payment card data (handled directly by Stripe)
Amazon Web Services (AWS) Hosting, file storage, and database infrastructure Account data, uploaded documents, and application data
Google / Microsoft Optional third-party sign-in Basic profile information (name, email) shared during sign-in, if you choose this option
Email delivery provider Sending transactional emails (account verification, receipts, service notices) Your email address and the content of the email sent to you
Cloudflare Bot and abuse protection (Turnstile) on forms Limited technical/device signals used to verify you're not a bot
Google Analytics Website usage analytics on our marketing site Browsing behaviour and device/technical data via cookies

We may also disclose information if required to do so by law, or in connection with a merger, acquisition, or sale of assets, subject to appropriate safeguards.

6. Cookies and similar technologies

We use a limited number of cookies:

You can control or disable cookies through your browser settings; note that disabling strictly necessary cookies may affect the availability of some features.

7. International data transfers

Our service providers, including AWS and OpenAI, may process and store information in countries outside the United Kingdom or European Economic Area, including the United States. Where this occurs, we rely on appropriate safeguards recognised under UK and EU data protection law, such as Standard Contractual Clauses or equivalent mechanisms offered by our providers, to protect your information.

8. Account Deletion

If you delete your account, your account is deleted forever and you cannot sign up again with that email address. Your documents and chat history are also lost forever. This is an irreparable operation, and users must be aware of the consequences. We cannot be held liable for any data or information you lose when you delete your account yourself, by error, or when someone else deletes your account. Make use of MFA to secure your account against malicious actors.

9. Data security

We apply technical and organisational safeguards designed to protect your information, including encryption of data in transit and at rest, access controls, and web application firewall protection. No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but we work to maintain safeguards appropriate to the risk.

10. Your rights

If UK or EU data protection law applies to you, you have the right to:

To exercise any of these rights, contact us using the details below. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk, or with your local data protection authority if you are located elsewhere.

11. Children's privacy

The Service is intended for business and professional use and is not directed at children. We do not knowingly collect personal information from anyone under the age of 16. If you believe a child has provided us with personal information, please contact us so we can delete it.

12. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will update the "Last updated" date at the top of this page when we do. We encourage you to review this page periodically.

13. Contact us

If you have questions about this Privacy Policy or how we handle your information, contact us at:

Imikan Technologies Ltd
Email: support@imikan-technologies.com
Company Registration Number: 17364117 (England and Wales)