Privacy Policy

Last updated 3 August 2026

This is a notice, not an agreement.

It states what is done with data. You are not asked to agree to it and no record says you did — it is written as a page rather than stored as a hashed document, so an acceptance of it could not prove what it said. The documents that are agreements work the other way round: each is stored as text, hashed, never edited once published, and readable forever at the revision you agreed to. They are all here, and your own record says which revision of each you agreed to, and when.

iPE is a marketplace, escrow agent, and recordkeeping service operated as part of IGES AI. Companies use it to engage independent, state-licensed Professional Engineers. iPE is not a party to the engineering contract, does not offer or perform engineering services, and does not review, approve, or warrant any engineer’s work product.

1.Who is responsible

IGES AI is the controller of the data described here. Questions, requests, and complaints go to leo@iges-ai.com.

2.What we hold

Five categories, because they are treated very differently.

Account data
Your name, email address, profile image, and sign-in records. Sign-in is through Google or GitHub; we never receive your password.
Licensure records
For engineers: licence numbers and jurisdictions, expiry dates, the disciplines a licence authorises, professional liability certificates, and the record of each verification — including the board register page a reviewer consulted and what they concluded. This is the most sensitive category we hold.
Engagement content
Drawing packages, the design inputs and assumptions behind them, findings raised, responses, and revisions. This is your commercial material and your counterparty's.
Payment data
Held by Stripe, not by us. We store identifiers that let us reconcile a payment, never card numbers or bank details.
The Responsible Charge Record
A tamper-evident, hash-chained log of what an engineer examined, what they required to be changed, how it was answered, what they attested to, and when a seal was applied or refused. Section 4 explains why this one is different.

3.Why we hold it

Account data, to operate your account. Licensure records, to verify that an engineer holds the licence they say they hold — a check clients rely on and boards expect. Engagement content, to run the engagement you asked us to run. Payment data, to move money and to reconcile it. The Responsible Charge Record, because a sealed engineering document carries professional and legal consequences for years, and the engineer who sealed it needs to be able to show what they did.

4.How long we keep it — and what we will not delete

Account data and engagement content are deleted on request, subject to any legal hold and to what we must keep for tax and accounting.

The Responsible Charge Record and sealed documents are different. They are retained for not less than ten years from the date of the seal, and are exempt from deletion requests. We think you are owed the reason rather than an exception buried in a list.

A sealed drawing goes into the world. It gets built. If a question is raised about it years later — by a client, an insurer, or a state licensing board — the engineer who sealed it has to be able to show what they were given, what they demanded be changed, and what they concluded. That record is their defence. Allowing anyone to delete it would mean a client could erase the evidence underpinning a document now standing in a building, or an engineer could quietly remove the record of a review they later regretted. Neither is something we are willing to make possible, and a record that can be deleted on request is not evidence in the first place.

Ten years is our floor, chosen against the periods during which construction claims are typically still actionable. Where a jurisdiction requires longer, we will extend it. A legal hold suspends destruction entirely for as long as it is in force.

Engagements that end without a seal — including where an engineer completed a review and declined to seal — retain the same record, on the same basis and for the same period, measured from the date the engagement ended. A refusal to seal is a professional judgment with the same consequences as a seal, and is not treated as a failed transaction to be swept up.

An engineer can export their own copy of this record at any time. It contains the scope, the findings, the attestation, their licence details as they stood, and the cryptographic hashes of everything examined — but not the client’s drawings, because an engineer holding a copy of a client’s commercial material indefinitely is a problem we should not create.

5.Who can see what

Access is decided per record, not per role. Companies see their own jobs and engagements; engineers see the engagements they were assigned to or engaged on. Competing companies cannot see each other’s work.

Staff access is narrow and separated by function. Reviewers who verify credentials can see licensure records, because that is the job; they cannot see escrow balances. Support staff can read support tickets and cannot read licensure documents — answering a billing question has never required someone’s licence file.

An engineer’s seal impression is not readable through any interface — not by the client, not by staff, and not by the engineer who owns it. There is no screen and no endpoint that returns it. It is composited onto a document server-side, during a sealing the engineer personally authorised, and at no other time.

6.What is public

A verified engineer’s profile is public when they choose to publish it: their name, the jurisdictions and disciplines they are licensed in, their experience, and reviews of completed work. Licence numbers appear because they are already public record on the issuing board’s register.

Two things are readable without an account by design, because requiring one would defeat them. Anyone can check a sealed drawing against the record, and anyone can read every legal document at every revision it has ever had. Neither discloses who agreed to anything, or who engaged whom: what a document said is the public record of this platform, and who signed it is the parties’ business.

7.Your rights

You can ask for a copy of your data, ask us to correct it, and ask us to delete it. We will respond within 30 days. Deletion covers everything except the records described in Section 4 and anything under a legal hold; where we cannot delete something, we will tell you which record and why rather than declining in general terms.

Depending on where you live you may have additional rights, including to object to processing or to complain to a supervisory authority. Write to leo@iges-ai.com and we will not make it difficult.

8.Who processes data on our behalf

Hosting and infrastructure
Our application host and managed database provider.
Payments
Stripe, which holds payment details directly. We never see them.
Authentication
Google and GitHub, for sign-in.
Email
Google, which also carries our transactional email — verification outcomes, engagement notifications, and support replies.
File storage
Our object storage provider, for drawing packages and sealed documents.

We do not sell personal data, and we do not use engagement content or licensure records for advertising.

9.Changes, and where this page sits

This notice is not one of iPE’s versioned agreements. It is not stored as a document, it carries no digest, and no acceptance of it is recorded — a page that can be changed in a commit must never be something a record says you accepted. Changes to it are dated at the top, and where a change materially affects you we will say so rather than quietly updating that date.

The agreements are handled the other way round, and all of them are published: every revision is kept, an acceptance records the digest of the exact text that was shown, and that text stays readable at its own address for good. If a privacy policy is ever published into that record, this address will serve that document instead of this page, and it will be governed by the same rules as every other agreement.