This Privacy Policy explains how Nikhil Kulkarni, a sole proprietor operating Iridium (the "Service"), collects, uses, shares, and retains information when you use the Service. By using the Service, you agree to this Policy.
Iridium is a hosted LinkedIn automation tool provided through a Model Context Protocol (MCP) interface. The Service is operated by Nikhil Kulkarni as a sole proprietor. For any privacy-related request, contact nikhilkulkarni1755@gmail.com.
Account and identity information. When you sign in, we receive identity and authentication information through Supabase (our authentication provider), such as your name and email address.
LinkedIn connection data. To operate the Service, we connect to your LinkedIn account through Unipile, a third-party provider. We do not store your LinkedIn password or login credentials. Unipile holds a session token that maintains the connection; if that session is invalidated, the fix is to reconnect and regenerate the session, not account loss.
Content and activity data. To generate and perform the actions you configure, the Service processes profile information of accounts you interact with, the text of comments and messages, drafts, scheduled actions, and conversation records.
Usage and analytics data. We use PostHog to understand product usage. This may include your email, name, subscription status, and usage events (such as which features you use).
Billing information. If you pay for the Service, Stripe processes your payment. We receive your name, email, and a payment token; we do not store full payment card numbers.
Audit and activity logs. We record actions taken through the Service — including timestamp, action type, target, status, and latency — for security, abuse detection, and to establish, exercise, or defend legal claims. These logs exclude credentials and secrets.
We use the information we collect to:
We share information with the following third-party service providers strictly to operate the Service. Each provider processes data under its own terms and privacy practices.
| Sub-processor | Purpose | Data processed |
|---|---|---|
| Unipile | LinkedIn session and all LinkedIn API access | Session token, message content, profile data |
| Anthropic | AI draft generation | Profile data, draft text |
| Stripe | Billing and payments | Name, email, payment token |
| Supabase | Authentication and login | Identity and authentication data |
| Hetzner | Compute and database hosting | All application data |
| Cloudflare | Frontend hosting, DNS, object storage | IP address, request metadata, uploaded media |
| PostHog | Product analytics | Email, name, subscription status, usage events |
| Resend | Transactional email | Email address |
| Google (Gmail SMTP) | Billing email delivery | Email address |
We may add or replace sub-processors. Changes will be posted here. We do not sell your personal information.
Draft content is generated using Anthropic's API. Profile information and draft text are transmitted to Anthropic for this purpose.
Profile and post data is retained for a maximum of seven (7) days by default, after which it is deleted during the next processing cycle. Accounts with no activity may retain expired records until their next processing cycle.
Account deletion. When you delete your account, access is revoked and your LinkedIn session is destroyed immediately. Your personal data — profiles, drafts, scheduled messages, conversations, replies, and identity records — is permanently erased within thirty (30) days.
Audit and activity logs are retained after account deletion and are not erased. These records document actions taken through the Service and are kept for security, abuse investigation, and the establishment, exercise, and defense of legal claims. They exclude credentials and secrets. Logs are append-only in normal operation.
You can disconnect your LinkedIn account at any time, which severs the Unipile session and stops all pipelines. You can request deletion of your account and associated personal data by contacting us at nikhilkulkarni1755@gmail.com, subject to the log-retention exception above. Depending on where you live, you may have additional rights under applicable privacy law; contact us to exercise them.
We take reasonable measures to protect your information. We do not store LinkedIn credentials, and payment card data is handled by Stripe. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
The Service is operated from the United States and uses sub-processors located in multiple regions. By using the Service, you understand that your information may be processed in jurisdictions with different data-protection laws than your own.
The Service is not directed to individuals under 18, and we do not knowingly collect their information.
We may update this Policy from time to time. Material changes will be posted here with an updated "Last updated" date.
For any privacy request or question, contact nikhilkulkarni1755@gmail.com.