Data Handling
This page is the human-readable companion to our Privacy Policy. It describes — in plain language — what Aqen collects, how the Company Brain uses it, which third parties touch it, how long we keep it, and how to delete it.
What we collect
- Account info — your name, email, organization, and authentication data.
- Business context — facts you tell Aqen about your business (stage, industry, business model, team, financials, constraints) so the Business Understanding Engine can tailor recommendations.
- Conversations & documents — chats with Aqen and any files, prompts, or notes you upload.
- Connected systems — when you connect a tool (e.g., Stripe, HubSpot), we store an encrypted access token and read only the data needed for the function you requested.
- Usage data — which features you used, when, and how the Service performed (latency, errors). Used to operate, debug, and improve the Service.
How the Brain uses it
The Company Brain is Aqen's shared memory for your business. Everything you tell Aqen — and every action Aqen takes on your behalf — is written to the Brain so future recommendations stay coherent across functions (formation, finance, GTM, marketing, ops).
- Scoped to your business. Brain content is partitioned per-business and per-tenant. Other organizations on Aqen never see it.
- Used for inference. Brain content is read at inference time to generate responses and execute actions for you.
- Used for per-tenant personalization. We may fine-tune a per-tenant model adapter on PII-sanitized Brain content so the Service gets better at your business over time. PII is scrubbed via stable per-tenant tokens before training; the resulting adapter is scoped to your tenant and is never served to other customers. We do not use Brain content to train foundation models or any cross-tenant model.
- Auditable. Every action Aqen takes is logged with inputs, outputs, model identifier, token counts, USD cost estimate, and the chain of reasoning that produced it. Reversible actions are recorded with rollback information so you can undo them via the in-product rollback flow.
Sub-processors that touch your data
The following third parties process your data on Aqen's behalf, each only for its specific function:
| Provider | What they do | What they receive |
|---|---|---|
| Anthropic | LLM inference (default model provider) | Conversation content + relevant Brain context for each request |
| OpenAI | LLM inference (alternate provider) | Conversation content + relevant Brain context for each request |
| Google Cloud Vertex AI | LLM inference (alternate provider) | Conversation content + relevant Brain context for each request |
| Clerk | Authentication & identity | Email, name, password hash, session metadata |
| Stripe | Payments & billing | Billing contact, plan, payment method tokens (no card numbers) |
| Cloudflare | Website hosting & content delivery | Marketing-site request metadata (IP, user agent) in transit |
| Resend | Transactional email delivery | Recipient email + message content for service notifications |
Model providers and training. We configure each model provider to disable training on your inputs and outputs where that option is available. Aqen does not use Customer Content to train any foundation model, and does not fine-tune any model that is served to other customers. Per-tenant fine-tuning on PII-sanitized Brain content stays inside your tenant boundary.
Third-party systems you connect
Connectors (for example, HubSpot, Mercury, Carta) are not Aqen sub-processors. When you connect one, Aqen exchanges data with it on your instructions and only to perform the function you requested. Those third parties operate under their own terms and privacy policies, which we do not control. You can disconnect any connector at any time from your account settings; doing so revokes the stored access token and stops further data exchange.
Stripe is listed in the sub-processor table above because it is Aqen's own payments processor for your subscription. If you separately connect your own Stripe account to Aqen as an integration (for example, to pull your business's revenue data), that connected account is governed by this section, not by the sub-processor list.
Metering
Every metered operation also produces a cost-attribution record (tenant, seat, business, model, tokens, USD cost, credits). The record is used to bill, to power the in-product cost ledger, and to defend the credit schedule. It does not include the conversational content of the operation.
Where data is stored
The Service is hosted in the United States. Conversations, Brain content, and connected-system tokens are stored in encrypted form at rest. Network traffic is encrypted in transit using TLS.
How long we keep it
- Active accounts: data is kept as long as the account is active and necessary to operate the Service.
- After deletion: within 30 days of a verified deletion request or account closure, Customer Content is deleted from production systems.
- Per-tenant model adapters: any fine-tuned adapter derived from your Brain content is deleted on the same 30-day timeline, on the same triggers. We do not keep derived artifacts after the underlying content is gone.
- Session recordings: retained for 30 days then automatically deleted. On a verified deletion request, your recordings are removed within the same 30-day window as Customer Content.
- Backups: encrypted disaster-recovery snapshots roll over within ~30 days after that, after which deleted data is no longer retrievable.
- Logs & audit trails: security and audit logs are retained for up to 12 months.
- Records required by law: billing and tax records are retained as long as legally required.
Deleting your data
- Email privacy@aqen.ai from the address on file with the subject line "Delete my data".
We will acknowledge within 5 business days, verify your identity, and complete deletion within 30 days. Some records (e.g., legally required billing records, security logs) are retained as described above.
Your other rights
Beyond deletion, you may request a copy of your data (data portability), correction of inaccurate information, or restriction of certain processing. See the Privacy Policy for the full list and email privacy@aqen.ai to exercise any of them.
Questions
Need a DPA, sub-processor list, or security questionnaire?
Email privacy@aqen.ai with your organization name. We provide a DPA template, an up-to-date sub-processor list, and SIG-Lite responses on request.