Legal · Plain English

Data Handling

Effective: 2026-05-14 · Version 1.0

This page is the human-readable companion to our Privacy Policy. It describes — in plain language — what Aqen collects, how the Company Brain uses it, which third parties touch it, how long we keep it, and how to delete it.

What we collect

How the Brain uses it

The Company Brain is Aqen's shared memory for your business. Everything you tell Aqen — and every action Aqen takes on your behalf — is written to the Brain so future recommendations stay coherent across functions (formation, finance, GTM, marketing, ops).

Sub-processors that touch your data

The following third parties process your data on Aqen's behalf, each only for its specific function:

ProviderWhat they doWhat they receive
Anthropic LLM inference (default model provider) Conversation content + relevant Brain context for each request
OpenAI LLM inference (alternate provider) Conversation content + relevant Brain context for each request
Google Cloud Vertex AI LLM inference (alternate provider) Conversation content + relevant Brain context for each request
Clerk Authentication & identity Email, name, password hash, session metadata
Stripe Payments & billing Billing contact, plan, payment method tokens (no card numbers)
Cloudflare Website hosting & content delivery Marketing-site request metadata (IP, user agent) in transit
Resend Transactional email delivery Recipient email + message content for service notifications

Model providers and training. We configure each model provider to disable training on your inputs and outputs where that option is available. Aqen does not use Customer Content to train any foundation model, and does not fine-tune any model that is served to other customers. Per-tenant fine-tuning on PII-sanitized Brain content stays inside your tenant boundary.

Third-party systems you connect

Connectors (for example, HubSpot, Mercury, Carta) are not Aqen sub-processors. When you connect one, Aqen exchanges data with it on your instructions and only to perform the function you requested. Those third parties operate under their own terms and privacy policies, which we do not control. You can disconnect any connector at any time from your account settings; doing so revokes the stored access token and stops further data exchange.

Stripe is listed in the sub-processor table above because it is Aqen's own payments processor for your subscription. If you separately connect your own Stripe account to Aqen as an integration (for example, to pull your business's revenue data), that connected account is governed by this section, not by the sub-processor list.

Metering

Every metered operation also produces a cost-attribution record (tenant, seat, business, model, tokens, USD cost, credits). The record is used to bill, to power the in-product cost ledger, and to defend the credit schedule. It does not include the conversational content of the operation.

Where data is stored

The Service is hosted in the United States. Conversations, Brain content, and connected-system tokens are stored in encrypted form at rest. Network traffic is encrypted in transit using TLS.

How long we keep it

Deleting your data

  1. Email privacy@aqen.ai from the address on file with the subject line "Delete my data".

We will acknowledge within 5 business days, verify your identity, and complete deletion within 30 days. Some records (e.g., legally required billing records, security logs) are retained as described above.

Your other rights

Beyond deletion, you may request a copy of your data (data portability), correction of inaccurate information, or restriction of certain processing. See the Privacy Policy for the full list and email privacy@aqen.ai to exercise any of them.

Questions

Need a DPA, sub-processor list, or security questionnaire?

Email privacy@aqen.ai with your organization name. We provide a DPA template, an up-to-date sub-processor list, and SIG-Lite responses on request.