Privacy Policy

GDPR Compliant

Last updated: January 2025

Your Privacy Rights

Download your data

Export all your data anytime

Delete your account

Permanently remove all data

Cookie control

Choose what tracking you allow

30-day email retention

Email bodies auto-purge

Our Commitment to Privacy

This Privacy Policy describes how Ayari ("we," "us," or "our"), operated by Aiether Ltd ("Aiether"), collects, uses, and protects your information. We understand that your email and calendar data is highly sensitive. We cache your email and calendar data locally to provide fast, responsive panel access while implementingautomatic data retention limits - email bodies are automatically purged after 30 days, and you can delete all your data at any time.

Controller & Contact

  • Controller: Aiether Ltd (Company No: 16811773)
  • Registered office: 71-75 Shelton Street, Covent Garden, London
  • Email: [email protected]

1. Information We Collect

1.1 Account Information

  • Email address (used for authentication)
  • Name (from your Microsoft/Google profile)
  • Profile picture (optional, from Microsoft/Google)
  • Time zone preferences
  • Subscription status and billing information (via Stripe)

1.2 Microsoft 365 & Google Workspace Data Access

When you connect your email and calendar accounts, we access and cache your data to provide fast, AI-powered assistance:

  • Email data we cache:
    • Email metadata (sender, recipient, subject, date, labels)
    • Email body content (HTML and plain text) - cached for 30 days, then automatically purged
    • Attachment metadata (filename, size, type) - NOT the actual file contents
    • AI-assigned tags and categories for organization
  • Calendar data we cache:
    • Event details (title, description, location, times)
    • Attendee information including email addresses
    • Video conference links (Meet, Teams, Zoom)
    • Recurrence rules for recurring events
  • Authentication data:
    • OAuth tokens (encrypted with AES-256) for API access
    • Sync timestamps for efficient delta synchronization
  • What we do NOT store:
    • Attachment file contents (downloaded directly from your provider when needed)
    • Email bodies older than 30 days (automatically purged)

1.3 AI Processing & Conversation Data

When you use our AI assistant, here's what happens with your data:

  • AI Processing: When you ask for summaries, drafts, or analysis, we send relevant email/calendar content to third-party AI providers (OpenAI, Anthropic, and Google) to generate responses
  • AI Provider Guarantee: Our AI providers use enterprise API terms that prohibit using your data to train their models
  • Data Retention by AI Providers: AI providers process your data in real-time and do not retain it (OpenAI/Anthropic: 30 days max per their enterprise terms)

What we store in our database:

  • Your conversations with the AI assistant (your questions and AI responses)
  • AI-generated summaries and insights (which may contain information from your emails/calendar)
  • Task lists and reminders you create
  • Draft emails you compose through Ayari
  • Your preferences and automation rules

Important: You can delete individual conversations or all conversation history at any time from your settings. Deleting conversations permanently removes them from our database.

1.4 Technical Data

  • IP address (for security and rate limiting)
  • Browser type and version
  • Device information
  • Diagnostic and performance logs strictly necessary for operation
  • Error logs (sanitized of personal data)

2. How We Use Your Information

2.1 Primary Uses

  • Real-time data access: Fetching your emails/calendar from Microsoft/Google when you interact with them through our AI assistant
  • AI processing: Sending email/calendar content to AI providers (OpenAI, Anthropic, Google) to generate summaries, drafts, and insights based on your requests
  • Email management: Sending emails on your behalf when you approve AI-generated or manually composed messages
  • Calendar management: Creating and updating calendar events as you request through the AI assistant
  • Usage analytics: Analyzing anonymized usage patterns (not email/calendar content) to maintain service reliability and fix bugs

What we do NOT do with your email/calendar data:

  • We do not sell your data to third parties
  • We do not use your email/calendar content for advertising
  • We do not use your email/calendar data to develop, train, or improve AI models (ours or third-party)
  • We do not access your emails/calendar unless you explicitly use features that require it

2.2 Data Caching

To provide fast panel loading (under 100ms), we cache your email and calendar data:

  • Email metadata: Synced every 2 minutes, kept while your account is active
  • Email body content: Cached when you view an email, automatically purged after 30 days
  • Calendar events: Synced every 2 minutes, kept while your account is active
  • Draft emails: Kept until you send or delete them
  • All cached data is encrypted at rest and isolated per user
  • You can delete all cached data by deleting your account

3. Data Sharing & Third Parties

We never sell your data. We share data only in these limited circumstances:

3.1 AI Service Providers

When you use AI features, we share relevant email/calendar content (up to ~2000 characters) with these providers:

  • Anthropic (Claude models): Primary AI for conversation, email analysis, and complex reasoning
  • OpenRouter: AI routing service used to access multiple model providers
    • Privacy Policy: openrouter.ai/privacy
    • Routes requests to OpenAI (GPT models) and Google (Gemini models)
    • Enterprise API terms: Data is not used for model training
  • OpenAI (via OpenRouter): For email drafting and summarization
  • Google (via OpenRouter): For fast responses and lightweight AI tasks

3.2 Infrastructure & Platform Providers

  • Microsoft: OAuth authentication and Graph API access (for Outlook/Microsoft 365 integration)
  • Google: OAuth authentication and Gmail/Calendar API access (for Google Workspace integration)
  • Supabase: Database hosting (stores metadata, conversation history, and settings - not full email content)
  • Vercel: Application hosting and deployment
  • Stripe: Payment processing (does not receive email/calendar data)
  • Clerk: User authentication and subscription management

3.3 Legal Requirements

We may disclose data if required by law, court order, or to protect rights and safety. We will notify you unless legally prohibited.

4. Data Security

We implement industry-standard security measures:

  • Encryption at rest: All stored data is encrypted using AES-256
  • Encryption in transit: All connections use TLS 1.3+
  • Token security: OAuth tokens are encrypted and regularly refreshed
  • Access controls: Strict authentication and authorization
  • Periodic reviews: Regular security assessments and improvements
  • Breach notification: We will notify without undue delay and in accordance with applicable law

5. Your Rights & Controls

5.1 Data Access & Portability (GDPR Article 20)

  • Download your data: Use the "Download My Data" button in Settings → Privacy to export all your data in machine-readable JSON format
  • What's included: Profile, conversations, AI messages, email metadata, calendar events, drafts, proposals, and service connections
  • What's not included: Email bodies (since these are cached from your provider - export directly from Gmail/Outlook)
  • Export your conversation history anytime

5.2 Data Modification & Deletion

  • Update your profile information anytime
  • Delete specific conversations or data
  • Request complete account deletion
  • Revoke Microsoft permissions instantly

5.3 Privacy Controls

  • Adjust data retention settings
  • Choose which AI providers process your requests
  • Manage notification preferences
  • Clear cache on demand

6. Data Retention

We follow these retention policies:

  • Email body content: Cached for 30 days, then automatically purged
  • Email metadata: Kept while account is active, deleted immediately on account deletion
  • Calendar events: Kept while account is active, deleted immediately on account deletion
  • Draft emails: Kept until sent or deleted by you
  • AI proposals: Kept until confirmed/cancelled, or 90 days
  • Conversation history: Kept for your reference, deletable anytime
  • Account data: Deleted immediately upon account deletion request
  • Audit logs: Anonymized and kept as required by law (typically 7 years for financial records)

7. Cookies & Tracking

We use cookies to provide and improve our Service:

  • Essential cookies: Required for authentication, security, and basic site functionality. These cannot be disabled.
  • Analytics cookies: Help us understand how you use the site (Google Analytics, PostHog). These are only enabled with your consent.

When you first visit our site, you'll see a cookie consent banner where you can accept or reject analytics cookies. You can change your preferences at any time in Settings → Cookie Preferences.

We do not use advertising cookies or sell your data to advertisers.

8. International Data Transfers

Where personal data is transferred outside the UK/EU/EEA, we implement appropriate safeguards including the European Commission’s Standard Contractual Clauses (SCCs) and the UK Addendum (IDTA), as applicable. Where our vendors participate in the EU–U.S. Data Privacy Framework and/or the UK–U.S. Data Bridge, we may rely on those certifications. We also apply technical measures such as encryption in transit and at rest.

9. Children's Privacy

Ayari is not intended for users under 18. We do not knowingly collect data from children. If you believe a child has provided us data, please contact us immediately.

11. UK/EU GDPR Information

For users in the UK and European Economic Area:

  • Purposes & legal bases:Account setup and core features → performance of contract; security/fraud prevention → legitimate interests; product analytics/marketing (if enabled) → consent; legal compliance (tax/accounting) → legal obligation.
  • Data controller: Aiether Ltd
  • Your rights: access, rectification, erasure, restriction, objection, portability, and to withdraw consent where relied upon.
  • Complaints: You may lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk or with your local EU supervisory authority.

12. API Compliance (Microsoft & Google)

Google API Services User Data Policy

Ayari's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

  • Limited Use: We use Gmail and Google Calendar data exclusively to provide our app's functionality - specifically the user-facing features you request (e.g., email summaries, calendar management, AI-assisted drafting). We do not use this data to develop, improve, or train AI models
  • Data caching: We cache email and calendar data to provide fast panel access; email bodies are automatically purged after 30 days
  • No transfer to others: We do not transfer Google user data to third parties except as described above (AI providers for processing, infrastructure providers for hosting)
  • No advertising: We do not use Google user data for serving advertisements
  • No human access: We do not allow humans to read your Gmail/Calendar data except when you explicitly request support and grant permission, or as required for security purposes (e.g., investigating abuse)
  • Minimum scopes: We request only the scopes necessary for our features:
    • gmail.readonly - View your email messages and settings
    • gmail.send - Send email on your behalf
    • calendar - See, edit, share and permanently delete your calendars

Microsoft Application Developer Agreement

Ayari complies with Microsoft's API Terms of Use and Application Developer Agreement:

  • Microsoft Graph API: We use Microsoft Graph API only to provide the features described in this Privacy Policy
  • User control: You can revoke our access anytime via your Microsoft account settings
  • Minimum permissions: We only request Mail.Read, Mail.Send, Calendars.ReadWrite, Calendars.ReadWrite.Shared, offline_access, and User.Read
  • Secure tokens: OAuth tokens are encrypted using industry-standard AES-256 encryption

General API Commitments

  • Data caching for performance: We cache email and calendar data to provide fast panel access (under 100ms loading times)
  • Automatic data cleanup: Email body content is automatically purged after 30 days; you can delete all data anytime
  • Transparent usage: Every API call is made in response to your explicit actions (asking the AI assistant, composing emails, etc.)
  • Regular audits: We regularly review our API usage to ensure compliance with provider policies
  • User revocation: You can disconnect your accounts at any time from Settings, immediately revoking our API access

Disclaimer: Ayari is operated by Aiether Ltd, an independent company. Ayari is not affiliated with, endorsed by, or sponsored by Microsoft Corporation or Google LLC. Microsoft 365, Outlook, and Microsoft Graph are registered trademarks of Microsoft Corporation. Gmail, Google Calendar, and Google Workspace are trademarks of Google LLC.

13. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of significant changes via email or prominent notice within the Service. Your continued use after changes indicates acceptance.

14. Contact Us

For privacy concerns or questions:

For data access requests, please allow up to 30 days for processing.

Privacy by Design

We cache your email and calendar data to provide fast, responsive panel access (under 100ms loading times). Email body content is automatically purged after 30 days. Attachment files are never stored - they're downloaded directly from your provider when needed. We process email content with AI providers only when you explicitly request it, and AI providers don't train models on your data. You can delete all your data at any time by deleting your account.