Privacy Policy
Last updated: April 13, 2026
1. Information We Collect
Information you provide
- Account information: Name, email address, company name, role
- Content you submit: Text inputs, uploaded documents, workflow parameters
- Business information: Company details, brand guidelines, client information you enter
- Communications: Support requests, feedback, approval reviews
Information collected automatically
- Usage data: Workflows executed, features used, timestamps
- Device information: Browser type, IP address (for rate limiting and security only)
- Performance data: Response times, error rates (anonymized)
Information from integrations
If you connect third-party services (Outlook, Gmail, HubSpot, Google Calendar), we access email metadata and content, calendar events, and CRM data only as needed for the features you use. All integration data is encrypted at rest.
2. How We Use Information
We use your information to provide and operate our services, execute workflows, personalize your experience, send transactional communications, monitor system health, and generate anonymized analytics.
We do NOT: sell your data, use your content to train AI models, share data between tenants, or display advertising.
3. Data Sharing
We share data only with: your channel partner (aggregated usage metrics and deliverables), our service providers (Anthropic, Supabase, Railway, Resend), and as required by law.
4. Data Retention
Account data and workflow outputs are retained while your account is active. AI inputs are processed by Anthropic with 30-day default retention (zero-retention available). All data is permanently removed within 30 days of account deletion.
5. Security
We protect your data with AES-256 encryption at rest, TLS 1.2+ in transit, role-based access controls, tenant-level data isolation (Row-Level Security), multi-factor authentication, and automated session management.
6. Your Rights
You can access, correct, delete, or export your data. You can opt out of non-essential communications and revoke integration connections at any time. Contact us to exercise these rights.
7. Cookies
We use authentication cookies only (essential for login). No third-party tracking, advertising, or analytics cookies.
8. Children
Our service is not intended for individuals under 18.
9. Changes
Material changes to this policy will be communicated via email. Continued use constitutes acceptance.
10. Contact
For privacy inquiries: privacy@ai-os.com