Privacy Policy

Last updated: 12 September 2026

1. Who we are

IMO (“Intelligent Multichannel Operator”) is operated by EGO HERO LIMITED, a company incorporated in New Zealand (“IMO”, “we”, “us”, “our”). We provide AI-powered “virtual employees” that help businesses run channels such as email, social media, phone, support and websites.

This policy explains how we collect, use, disclose and protect personal information in connection with our websites (including imo.nz and related subdomains) and the IMO platform (together, the “Service”). We are committed to complying with the New Zealand Privacy Act 2020 and its Information Privacy Principles and, where they apply to us, the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs).

Privacy questions and requests: privacy@imo.nz. General support: support@imo.nz.

2. Two kinds of personal information — our different roles

This policy distinguishes two categories of personal information, because our role differs for each:

  • Information we collect for ourselves — about visitors to our websites, people who join our waitlist, and the people who create and administer customer accounts. For this information we decide how and why it is processed.
  • Customer Content processed on a customer’s behalfwhen a business uses IMO, its virtual employees handle that business’s communications and data: messages, contacts, documents, knowledge-base items and similar material, which may include personal information about the customer’s own customers, staff and other people. We process this information as the customer’s service provider (agent), on the customer’s instructions. Under the Privacy Act 2020, information we hold solely as an agent is treated as held by the customer, and the customer is responsible for it as the accountable agency.

If you are a customer of a business that uses IMO and you have questions about how that business handles your information, contact that business directly — its own privacy policy applies. We will refer any request we receive about Customer Content to the relevant customer, and will assist the customer to respond.

3. What we collect

  • Identity and contact details — name, email address, business name and role, when you join the waitlist, create an account, or contact us. If you sign in with Google, that is where your name and profile picture come from (section 8).
  • Account and security data — login credentials (passwords are stored only in hashed form by our authentication provider), authentication tokens, and settings.
  • Plan data — which plan a workspace is on, its billing contact, and how much employee time it has used. Taking payment is not available in IMO yet; when it is, card details will be handled by a payment provider and never stored by us, and we will say so here before that starts.
  • Usage and device data — IP address, browser and device type, pages viewed, actions taken in the Service, and diagnostic logs, collected automatically to operate and secure the Service.
  • Communications — messages you send us, including support requests and feedback.
  • Customer Content — content you or your connected tools provide to the Service so your virtual employees can work: emails, messages, social posts, call summaries, contacts, documents, web pages and knowledge items, which may include personal information about third parties.

The Service stores the account, usage and Customer Content data needed to provide, maintain and secure your workspace.

Reminders.While employee work is switched on, we remind a workspace’s owner and admins about dates found in their own documents. If you turn notifications on for a device, the reminder is encrypted for that device and delivered through its notification provider (Apple, Google, Mozilla or Microsoft), which sees delivery details and not what the reminder says; the text can appear on your lock screen. When no device can take it — including when you have never turned notifications on — we send the same reminder by email through Resend instead. Notification records stay in our own database, and Inngest receives only references and counts.

4. How we collect it

  • Directly from you — when you sign up, configure the Service, or contact us.
  • Through your use of the Service — automatically generated usage, log and security data.
  • From tools you connect — such as email, calendar, messaging, social and CRM tools, reached only with the permission you grant on that provider’s own consent screen, and only to provide the Service.

Where you give us personal information about another person (for example, your staff or your customers), you confirm that you are authorised to do so and that you have met your own obligations under applicable privacy law, including telling them how their information will be handled.

5. Why we use it

  • To provide, operate and secure the Service, including running your virtual employees according to your instructions and autonomy settings.
  • To create and manage accounts, authenticate users, and provide support.
  • To administer plans and to measure the employee time a workspace has used.
  • To communicate service matters — onboarding, changes, security and billing notices.
  • To send marketing communications where permitted, with a working unsubscribe in every message, consistent with the New Zealand Unsolicited Electronic Messages Act 2007 and the Australian Spam Act 2003. You can opt out at any time.
  • To monitor, improve and develop the Service, using aggregated or de-identified data wherever practicable.
  • To detect, investigate and prevent fraud, abuse and security incidents.
  • To comply with law, and to establish or defend legal claims.

6. AI processing

The Service uses artificial-intelligence models, including models operated by third-party providers, to read, draft and act on content as part of doing the work you ask of your virtual employees. We permit AI providers to process Customer Content only to provide the Service. We do not use your Customer Content to train our own or any third party’s general-purpose AI models, and we do not permit our AI providers to do so, without your express prior consent.

AI-generated outputs can be inaccurate. Your review and autonomy settings determine what is sent or actioned on your behalf — see our Terms of Service for your responsibilities.

The AI providers we use, and what each one does with your content:

  • Google (Gemini)— reading documents, answering your questions, and running employee tools. Content is processed to provide the Service and is not used to train Google’s models.
  • Alibaba (Qwen), reached through the Vercel AI Gateway — drafting and routine text work. Alibaba states that data sent to its API is not used for training. It does not state how long it keeps that data, and we will update this policy if that changes.
  • Voyage AI (a MongoDB company)— turning the documents you give an employee into a searchable index, so it can find the passage that answers your question and tell you the page it came from. Voyage’s standard terms let it train on what customers send it. We have opted out, and Voyage states that once a customer has opted out their content is “immediately deleted by Voyage AI after it is processed for you”. We opted out before sending it anything.

Web research is not switched on, and why we are telling you now.No employee searches the web for you today. When we do switch it on, those requests will run through Google’s search-grounded model, and Google retains the request, the surrounding context and the answer for 30 days to run, debug and test that feature — a retention that cannot be switched off, even on an account configured for zero retention. Research of that kind would involve your own properties, clients and contacts, so we will update this policy and tell you before the first request is made.

7. Who we share it with

We do not sell personal information. We disclose it only:

  • To service providers who process it for us under contract and only for the purposes above — currently Supabase (database and authentication, hosted on Amazon Web Services in Japan), Vercel (website hosting and delivery, and the gateway through which some AI requests are routed), Inngest (the workflow engine that keeps long-running employee work on track), Resend (email delivery), Google and Alibaba (AI models), and Voyage AI (making your documents searchable).
  • To integrations at your direction — when you connect a third-party tool, information flows to and from that tool under its own terms and privacy policy.
  • Within a corporate transaction — if we sell, merge or reorganise our business, on the basis that the recipient protects it consistently with this policy. Information from your connected Google account is carved out of this: it is transferred only with your explicit prior consent (section 8).
  • Where required or permitted by law — including to courts, regulators and law enforcement, or to protect the rights, safety or property of any person or of IMO.

8. What IMO does with your Google account

Two Google connections are available today — Gmail and Google Calendar — and each asks for one narrow permission. We name them here exactly as Google names them, so you can hold this page up against the screen Google shows you when you connect.

  • Gmail — send email as you. https://www.googleapis.com/auth/gmail.send. An employee can send an email from your address once you have approved it. This permission cannot read, search, list or delete anything in your mailbox, and IMO does not import or sort your inbox — it writes from the material you give it inside IMO.
  • Google Calendar — see, add, change and delete events on calendars you own. https://www.googleapis.com/auth/calendar.events.owned. That is what Google grants; what IMO does with it is narrower — it adds dates you approved, and reads back an entry it created so that trying the same approved batch again cannot add those dates twice. It does not reach calendars that are only shared with you, and we chose this permission over the wider one that would.
  • Who is connected. Connecting also asks for openid and email, so we can show you which account a connection belongs to.
  • Signing in with Google is a separate thing from connecting, and asks for email and profile — your email address, your name and your profile picture — so we can create your account and show you as yourself. It gives us no access to your mail or your calendar.

Connecting proves itself, once. When you connect Gmail we send one short email from your address to your own address; when you connect Google Calendar we add one entry to your calendar. That is so you can see for yourself that it works, and it is the only thing either connection does on its own. Anything meant for someone else — an email, a date — waits in your Review inbox until you or another reviewer approves it.

You can disconnect at any time in IMO. That deletes the keys we hold for that connection, so IMO can no longer reach the account, and we also ask Google to cancel them at its end — if Google cannot be reached at that moment we still delete our copy, and you can remove IMO yourself in your Google account’s security settings, which is the way to be certain.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Those requirements cover anything we derive from that information, and they take precedence over the general sharing terms in section 7. In particular:

  • we do not use Google user data for advertising;
  • we do not sell it, and we do not transfer it to anyone else except as necessary to provide the features you asked for, to comply with the law, or — in a merger, acquisition or sale of assets — with your explicit prior consent;
  • we do not use it to develop, improve or train generalised AI or machine-learning models;
  • people read it only where you specifically agree to them reading that information, where it is necessary for a security investigation, or where the law requires it; information that has been aggregated may be used for lawful internal operations.

Other providers. No Microsoft account can be connected yet. When one can, its own permissions will be named here in the same way before the connection is offered.

Text-message opt-in data. Where a messaging channel involves opt-in consent data (such as a phone number opted in to receive messages), we do not share that opt-in data with third parties for their marketing or promotional purposes.

9. Where it is stored — overseas disclosure

Our primary data infrastructure is hosted by Supabase on Amazon Web Services in Japan (Tokyo region). Website delivery, AI processing and some service providers operate from the United States and other countries. This means personal information may be stored and processed outside New Zealand and Australia.

Where we disclose personal information to an overseas provider, we take steps required by IPP 12 of the Privacy Act 2020 and APP 8: we only use providers that are subject to comparable privacy safeguards, or we put contractual protections in place requiring them to handle the information consistently with New Zealand privacy law and this policy.

What we keep out of the United States on purpose. Our workflow engine, Inngest, runs in the United States and keeps a record of each step an employee takes so that work can resume safely if something fails. We deliberately keep that record to references and counts — identifiers, page numbers, how many terms were found — and never the content itself, which includes the name of a file you uploaded and the words of any error. Documents you upload, the text we read out of them, and the drafts an employee writes stay in the Japan region with the rest of your data, and are passed between steps by reference rather than by being copied into the United States. This is a rule about that record only: the AI providers in section 6, and our hosting and email providers, process the content itself in the countries described above.

10. Security

We protect personal information with technical and organisational measures appropriate to its sensitivity, including encryption in transit, access controls, row-level database security, credential hashing and least- privilege access for our systems and staff. No method of storage or transmission is completely secure, and we cannot guarantee absolute security — please use strong, unique passwords and keep your credentials confidential.

Data breaches. If a privacy breach occurs that has caused, or is likely to cause, serious harm, we will notify the New Zealand Office of the Privacy Commissioner and affected individuals as required by the Privacy Act 2020, and, where the Australian Notifiable Data Breaches scheme applies, the Office of the Australian Information Commissioner and affected individuals, as soon as practicable.

11. Retention

  • Account information — for as long as your account is active, then deleted or de-identified within a reasonable period after closure, subject to the export window in our Terms.
  • Customer Content — for as long as your account holds it; deleted following account closure after the export window, except copies we must keep by law or that persist in routine encrypted backups for a limited period.
  • Billing records — for the period required by tax and companies legislation.
  • Waitlist details — until launch communications conclude or you unsubscribe, whichever is earlier.
  • Logs and security data — for a limited operational period unless needed for an investigation.

We do not keep personal information longer than the purposes above require, unless the law requires it.

12. Your rights — access, correction, complaints

Under the Privacy Act 2020 (and, where applicable, the APPs) you may request access to the personal information we hold about you and ask us to correct it. Email privacy@imo.nz — we will respond as soon as practicable and within any legally required timeframe (generally 20 working days in New Zealand). We may need to verify your identity first. If we decline a request, we will tell you why and how to challenge that decision; you may also ask us to attach a statement of correction to the information.

Requests that relate to Customer Content held for one of our customers will be referred to that customer, as the accountable agency, and we will assist them to respond.

If you are unhappy with how we have handled your information or a request, please contact us first. You may also complain to the New Zealand Office of the Privacy Commissioner (privacy.org.nz) or, in Australia, the Office of the Australian Information Commissioner (oaic.gov.au).

13. Cookies and similar technologies

  • Essential cookies — used to sign you in, keep your session secure and remember the workspace you are working in. The Service does not work without them.
  • Preferencesyour interface choices, such as a light or dark theme, are kept in your own browser’s local storage, not on our servers.
  • Analytics and advertising — we do not currently use third-party advertising trackers. If we adopt analytics tools, we will update this policy before relying on them.

You can block or delete cookies in your browser settings; essential cookies are required for signed-in parts of the Service. Our websites may link to third-party sites; their privacy practices are their own, and this policy does not cover them.

14. Children

The Service is built for businesses and is not directed at children. You must be at least 18 to hold an account. We do not knowingly collect personal information from children for our own purposes; if you believe we have, contact privacy@imo.nz and we will delete it.

15. Changes to this policy

We may update this policy as the Service and the law evolve. We will post the updated version on this page with a new “last updated” date and, for material changes affecting account holders, give notice by email or in the Service. The current version always applies.

16. Contact

EGO HERO LIMITED (New Zealand) · Privacy: privacy@imo.nz · Support: support@imo.nz