Privacy Policy
Effective August 1, 2026
This Privacy Policy describes how Aindy collects, uses, discloses, and protects information when you use Aindy's websites, web application, AI assistant, and supported messaging and integration features (collectively, the "Service"). We have written it in plain English.
In summary: Aindy collects the information needed to identify you, provide and secure the Service, remember your conversations and approved workspace content, and operate integrations you choose to connect. Aindy uses third-party service providers, including a large-language-model provider, to process requests and provide the Service. We do not sell your personal information, use it for targeted advertising, or share it with advertisers. You can request deletion of your data by emailing [email protected] from the email address associated with your account.
1. Who we are
The Service is operated by Aindy ("Aindy," "we," "us," or "our"). For questions or requests about this policy or our handling of personal information, contact [email protected].
2. Information we collect
The information we collect depends on how you use Aindy and which optional channels and integrations you connect.
Account and identity information
- Google account information. When you sign in with Google, we receive your Google account identifier, email address, and, if available, display name. We do not receive or store your Google password.
- Messaging-channel identifiers. If you use Aindy through a supported messaging service, we receive and store the identifier needed to recognize and respond to you, such as a workplace-messaging user ID or an RCS/SMS-capable telephone number.
- Session information. After web sign-in, Aindy places a signed, essential session cookie in your browser. It contains an internal user ID and expiration time, is inaccessible to browser scripts, and normally expires after 30 days. Short-lived cookies and one-time tokens may also be used to link a messaging identity to your authenticated account.
Conversations and content you provide
- Conversation data. We collect the messages and instructions you send to Aindy and the responses Aindy returns. Depending on the channel, associated records may include a conversation or thread identifier, channel identifier, message role, external message/event identifier, and timestamp.
- Workspace content. We store content that you create, edit, save, or approve in Aindy, including documents, memories, projects, tasks, decisions, rules, summaries, tags, relationships between records, and other metadata. Content may be private to your account or, where you explicitly request it, made available as shared or global content within the Service.
- AI interaction data. To answer you, Aindy assembles relevant conversation history, saved memories and documents, account context, and results returned by connected services. This information is processed by a third-party large-language-model provider to generate a response, as described below. Aindy separately stores AI responses and tool-call content in the conversation transcript in our database.
Please do not submit sensitive personal information that is not needed for your use of the Service.
Information from optional connected services
If you choose to connect a third-party service, Aindy receives an authorization token and the permissions you grant. The current integrations are:
- Todoist data. If you connect Todoist, Aindy may access your account information, projects, and tasks and, at your direction, create, update, or complete tasks.
- Google Calendar data. If you connect Google Calendar, Aindy may access calendar names, settings, events, locations, dates, times, attendees, links, and free/busy information and, at your direction, create, update, or delete events.
Aindy accesses connected-service data as needed to carry out your instructions. Data used by the AI may appear in its context, response, and Aindy's stored conversation transcript. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Connection records stored in the database include the provider, connection status, granted scopes, token-secret reference, source channel or conversation, and relevant creation, update, and expiration times. Production OAuth access and refresh tokens are stored separately through a cloud secrets-management service rather than in the primary database.
Messaging-service data
When you communicate with Aindy through a supported workplace-messaging or RCS/SMS service, the relevant platform sends us the message text and delivery metadata needed to process and answer the message. This can include the sender and channel identifiers, thread or message identifiers, timestamps, and retry or delivery information. Our response is sent back through the same platform.
If an unauthorized account or number attempts to use a messaging channel, we may retain the channel, attempted identifier, message text (limited by the application to 8,000 characters), and time of the attempt for security and access-control auditing. This audit content is not supplied to the AI agent.
Technical and diagnostic information
When you access the Service, Aindy and its hosting providers may automatically process standard request and operational information, such as IP address, request date and time, requested URL, HTTP headers, browser or device information, response status, and server or application error details. We use this information to deliver, secure, troubleshoot, and maintain the Service.
Some Aindy pages load a font from a third-party web-font service. When that resource is requested, the provider may receive standard request information such as your IP address and browser headers.
The current codebase does not include an advertising network, advertising identifier, tracking pixel, or general-purpose product-analytics service. A preview-only development tool may receive route and error information when the marketing site is run inside that tool's editor; it is not part of the production Aindy application described here.
3. How we use information
We use information to:
- authenticate users and maintain signed-in sessions;
- receive, understand, and respond to messages through the web app and supported messaging channels;
- provide AI-generated assistance and maintain conversation history;
- create, retrieve, edit, organize, and search documents, memories, projects, tasks, and other workspace content;
- connect to and perform actions in services you authorize;
- maintain continuity across an account's supported channels;
- enforce access controls, prevent duplicate processing, investigate misuse, and protect the Service;
- diagnose errors, maintain infrastructure, and improve the reliability and functionality of Aindy;
- comply with law, enforce our agreements, and protect users, Aindy, and others; and
- respond to privacy, support, and other communications.
Research and development
It is in our legitimate business interests to develop, analyze, maintain, and improve the Service and our business. For these purposes, we may create and use aggregated, de-identified, or anonymized information derived from the information we collect. We take reasonable measures designed to remove or alter information that directly identifies an individual and do not attempt to re-identify information that we maintain in de-identified form. We may use this aggregated, de-identified, or anonymized information for lawful business purposes, including analyzing how the Service performs, improving its reliability and functionality, understanding general usage patterns, conducting research, and describing or promoting our business. We may disclose this information to service providers, professional advisers, prospective business partners, or other third parties for those purposes. We do not use your personal content to train general third-party AI models.
Where applicable law requires a legal basis, we process information as necessary to provide the Service you request, based on our legitimate interests in operating and securing the Service, with your consent where requested (including when you authorize an integration), and as necessary to comply with legal obligations. You may withdraw consent by disconnecting an integration or contacting us, but withdrawal does not affect processing already completed.
4. How we disclose information
We disclose information only as needed for the purposes described in this policy.
Vendors and service providers
To assist us in meeting business operations needs and to perform services and functions, we may disclose personal information to vendors and service providers, including providers of application hosting, database hosting, cloud infrastructure, secrets management, identity and authentication, large-language-model processing, calendar and task-management integrations, workplace messaging, telecommunications, web-font delivery, security, diagnostics, professional services, and other information technology services. Pursuant to our instructions and applicable agreements, these parties may access, process, transmit, or store personal information while performing services for us.
Our application-hosting provider processes requests and operational logs in US East (Virginia, United States). Our primary database provider stores accounts, channel identifiers, conversations, workspace content, connection metadata, and access-denial audit records in US East 1 (N. Virginia, United States).
Our third-party large-language-model provider receives the prompts and context needed to generate a response, which may include your current message, relevant conversation history, saved content, connected-service results, and limited account or channel context used by the assistant. The provider processes this content only to provide the requested AI functionality and is not permitted to use it to train general AI models. Aindy separately retains conversation records in its database as described in this policy.
These providers process information under their own terms and privacy notices as well as any applicable agreements with us. Third-party services you connect may retain information about actions Aindy performs in those services according to their own policies.
Other disclosures
We may also disclose information:
- when you ask or authorize us to do so;
- to professional advisers and contractors who need it to support the Service and are subject to confidentiality obligations;
- if reasonably necessary to comply with law, legal process, or a valid governmental request; to protect rights, safety, and security; or to investigate fraud or misuse; and
- in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of the business, subject to appropriate protections and notice where required.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising or use it to serve targeted advertisements. We do not disclose your information to data brokers or advertisers.
5. Information visible to other users
Aindy is a personal assistant, not a public social network. Your private conversations and account-scoped workspace content are not intended to be visible to other users. Content that you explicitly request to save with a global or shared scope may be available to other authorized users of the Service. Information you send in a shared third-party messaging channel remains visible according to that service's workspace and channel settings.
6. Children
The Service is not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you have reason to believe that a child under 16 has provided personal information through the Service, please contact [email protected], and we will delete it from our database.
7. Your rights and choices
You may:
- choose not to connect Google Calendar or Todoist;
- revoke a connected service through Aindy where that control is available, through the third party's account settings, or by contacting us;
- sign out of the web application and clear Aindy cookies through your browser;
- manage messages and channel visibility through the relevant third-party messaging platform; and
- request access to, correction of, or deletion of your personal information by emailing [email protected] from the email address associated with your Aindy account.
We may need to verify your identity before completing a request. If your Aindy account has no linked email address, include enough information for us to locate and securely verify the relevant account, such as the channel you used and the associated channel identifier. We will respond within the period required by applicable law; we aim to respond to verified requests within 30 days.
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of personal information; restrict or object to certain processing; withdraw consent; or appeal our response to a request. You may also have the right to complain to your local data-protection authority. These rights can be subject to exceptions under applicable law.
California and other U.S. state residents
Residents of California and certain other U.S. states may have rights to know or access the categories and specific pieces of personal information we collect, correct inaccurate information, request deletion, obtain a portable copy, and be free from discrimination for exercising privacy rights. As stated above, we do not sell personal information or share it for cross-context behavioral advertising.
You may exercise applicable rights by contacting [email protected]. An authorized agent may submit a request where permitted by law, but we may require proof of authority and verification of the consumer's identity.
8. Security
We use administrative, technical, and organizational safeguards designed to protect personal information. Based on the current implementation, these include HTTPS for production network traffic; signed, HTTP-only, SameSite session cookies; verification of messaging-service webhook signatures; user and channel access checks; separation of production integration tokens from the primary database through a cloud secrets-management service; redaction of common token and secret fields from integration errors; and access controls intended to keep user-scoped workspace records associated with the correct account.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a security incident affects personal information, we will investigate and provide notice where required by law.
9. International users
The Service is operated and hosted in the United States. If you access it from another country, your information will be transferred to and processed in the United States and may also be processed in other locations where our service providers operate. Those locations may have privacy laws different from those where you live. Where required, we use an appropriate legal mechanism for cross-border transfers.
Users in the European Economic Area, United Kingdom, or Switzerland may contact us at [email protected] with questions about the legal basis for processing, international transfers, or applicable privacy rights.
10. Third-party services and links
The Service may contain links to, communicate with, or allow you to take actions in third-party services. This policy governs Aindy's handling of information, not the independent practices of identity, calendar, task-management, messaging, telecommunications, hosting, database, cloud-infrastructure, AI, or other third-party providers. Review their privacy notices and account controls before using or connecting those services.
11. Changes to this policy
We may update this policy as Aindy and its integrations evolve. When we do, we will revise the effective date above. If a change materially affects how we handle personal information, we will provide additional notice where appropriate or required, such as through the Service or by email.
12. Contact
For questions, privacy requests, or complaints about how Aindy handles personal information, contact:
Last updated August 1, 2026.