1. Information We Collect
We collect information necessary to provide and improve AXION AI services, including:
- Account information (email, password hash, workspace name)
- Agent configuration data (prompts, knowledge bases, automation rules)
- Uploaded documents and knowledge bases (processed for RAG indexing)
- Usage analytics (API calls, message volumes, active sessions)
- Payment and billing information (via Stripe; we do not store credit cards)
- Communication logs (WhatsApp, Instagram conversations; encrypted at rest)
2. How We Use Your Data
Your data is used exclusively to:
- Provide AI agent services and knowledge retrieval
- Process and respond to messages via integrated channels
- Generate usage reports and analytics for your workspace
- Improve model performance through aggregated, anonymized telemetry
- Detect and prevent abuse, fraud, and security threats
- Send transactional and account notifications
3. Third-Party Integrations
We integrate with trusted third-party services:
- OpenAI / Groq / Google: LLM API calls pass your prompts and document snippets (never full knowledge bases)
- Supabase: Database and authentication infrastructure (SOC 2 compliant)
- Stripe: Payment processing (PCI-DSS compliant; we never see full card numbers)
- Twilio: WhatsApp integration (your WhatsApp account is linked, not stored by us)
- Meta / Instagram Graph API: Direct integration with your Instagram Business Account
Each third party operates under their own privacy policy. We recommend reviewing them before integration.
4. Data Retention
We retain your data as follows:
- Active account data: Retained for the duration of your subscription
- Deleted accounts: All personal data is purged within 30 days (except legal holds)
- Communication logs: Retained for 90 days for audit and debugging; older logs are anonymized
- Backups: We maintain encrypted backups; restoration available within 7 days of deletion
5. Security
We employ industry-standard protections:
- TLS 1.3 encryption in transit
- AES-256 encryption at rest
- Regular penetration testing and vulnerability assessments
- Strict access controls (role-based permissions)
- SOC 2 Type II compliance (audited annually)
6. Your Rights
You have the right to:
- Access your data in portable format (JSON export)
- Request deletion of your account and associated data
- Correct inaccurate personal information
- Withdraw consent for marketing communications
- Lodge complaints with your local data protection authority
Submit requests to axionaiautomation@gmail.com.
7. Changes to This Policy
We may update this privacy policy periodically. Material changes will be communicated via email or prominent notice on the site. Continued use of AXION AI constitutes acceptance of updated terms.
8. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to track activity on our platform and hold certain information. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our service (like authentication).
9. International Data Transfers
Your information, including Personal Data, may be transferred to — and maintained on — servers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction. By using AXION AI, you consent to this transfer.
10. Children's Privacy
Our Service does not address anyone under the age of 18. We do not knowingly collect personally identifiable information from anyone under the age of 18. If we become aware that we have collected Personal Data from children without verification of parental consent, we take steps to remove that information from our servers immediately.
11. Business Transfers
If AXION AI is involved in a merger, acquisition, or asset sale, your Personal Data may be transferred. We will provide notice before your Personal Data is transferred and becomes subject to a different Privacy Policy.