Privacy Policy
This Privacy Policy explains how Aqen Inc ("Aqen", "we", "us") collects, uses, shares, retains, and protects personal information. It applies to our website, product, and related services (the "Service"). For a plain-English summary of how data flows through the product, see the Data Handling page.
The Service is currently offered in closed beta. Where this Policy describes specific data-handling commitments, those commitments apply during the beta period as well as at general availability.
1. Information We Collect
1.1 Information you provide
- Account & profile: name, email, password (hashed by our auth provider), organization name.
- Business context: the information you share with the Service about your business — stage, industry, model, team, financials — that the Business Understanding Engine uses to tailor recommendations.
- Content: documents, prompts, conversations, files, and other content you submit ("Customer Content").
- Connected-system credentials: OAuth tokens for integrations you connect, stored encrypted.
- Billing: billing contact, plan tier, and payment-method metadata. Card numbers are handled by our payments processor (Stripe) and never reach Aqen's servers.
1.2 Information collected automatically
- Device: IP address, user agent, OS, browser, viewport, locale.
- Metering telemetry: each metered operation generates a record with tenant id, seat id, business id (where the operation is scoped to a business), model identifier, model mix, token counts, USD cost estimate, and credits consumed. This record is used to bill, to power the in-product cost ledger, and to defend the credit schedule. Marketing-website visitors are anonymous; metering applies only to authenticated product usage.
- Logs & telemetry: server logs, traces, and exception reports used to operate and debug the Service.
1.3 Information from third parties
- Identity and seat data from your organization's SSO/identity provider when SSO is configured.
- Data the Service retrieves from systems you connect (e.g., billing, CRM, banking metadata) only as needed to perform the function you requested.
2. How We Use Information
- To provide, operate, secure, and improve the Service.
- To execute actions you authorize on connected systems and to record their outcomes in the Brain.
- To bill, communicate about your account, send service notices, and respond to support requests.
- To detect abuse, fraud, and security incidents.
- To comply with legal obligations and enforce our agreements.
- With your separate consent, to send marketing communications. You can opt out at any time.
Foundation-model training. We do not use Customer Content to train foundation models, and we configure our model providers (Anthropic, OpenAI, Google Cloud Vertex AI) to disable training on inputs and outputs where that option is available.
Per-tenant fine-tuning. We may fine-tune per-tenant model adapters on PII-sanitized Customer Content from your own Brain to personalize the Service to your business. The fine-tuning pipeline scrubs personal identifiers using stable per-tenant tokens before training; the resulting adapter is scoped to your tenant and is never served to other customers. We do not fine-tune any cross-tenant model on Customer Content.
Third-party integrations you connect. Where you connect a third-party system (for example, HubSpot, Mercury, Carta), we exchange data with that system on your instructions and only to perform the function you requested. Those third parties operate under their own terms and privacy policies, which we do not control. Note that Stripe appears in our sub-processor list in Section 3 below because it is Aqen's own payments processor for your subscription; if you also connect a separate Stripe account of your own to Aqen as an integration (for example, to pull your business's revenue data), that connected Stripe account is governed by this paragraph, not by the sub-processor list.
3. Sub-processors
We use the following sub-processors. Each processes only the data needed for its function and is bound by contract to confidentiality and security obligations.
| Sub-processor | Purpose | Region |
|---|---|---|
| Anthropic | LLM inference (default) | US |
| OpenAI | LLM inference (alternate) | US |
| Google Cloud Vertex AI | LLM inference (alternate) | US |
| Clerk | Authentication & identity | US |
| Stripe | Payments & billing | US |
| Cloudflare | Website hosting & content delivery | Global |
| Resend | Transactional email delivery | US |
The current list is also reflected on the Data Handling page. We will give at least 30 days' notice of material additions to this list before new sub-processors begin handling Customer Content, except where a shorter period is required by law, security, or operational necessity. We will not include third-party systems you connect on your own initiative (for example, HubSpot, Mercury, Carta) in this list; those are integrations you authorize directly and are not Aqen sub-processors. As noted in §2, Stripe appears in the table above because it is Aqen's own payments processor for your subscription, which is distinct from any Stripe account you might separately connect as an integration.
4. Sharing & Disclosure
We share personal information only:
- With sub-processors listed above, under contract, to deliver the Service.
- With third parties you connect to and explicitly direct the Service to interact with on your behalf.
- To comply with law, valid legal process, or to protect rights, safety, or the integrity of the Service.
- In connection with a corporate transaction (merger, acquisition, financing, or asset sale), subject to confidentiality and notice.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
5. International Data Transfers
The Service is hosted in the United States. If you access it from outside the US, your information will be transferred to and processed in the US. Where required, we rely on appropriate transfer mechanisms (e.g., Standard Contractual Clauses) to safeguard cross-border transfers.
6. Retention
We retain personal information for as long as your account is active and as needed to provide the Service. After account closure or upon your verified deletion request, we will delete or de-identify Customer Content within 30 days, subject to:
- Backup rotation (additional ~30 days for disaster-recovery snapshots, after which backups are overwritten).
- Session recordings retained for 30 days then automatically deleted; on a verified deletion request, removed within the same 30-day window as Customer Content.
- Logs and audit trails retained for security, fraud-prevention, and legal-compliance reasons (typically 12 months).
- Records we are legally required to retain (e.g., billing records, tax records).
Per-tenant model adapters. Any per-tenant model adapter fine-tuned on your Customer Content is deleted within the same 30-day window as your Customer Content, on the same triggers (account closure or verified deletion request). We do not retain derived artifacts after the underlying Customer Content is deleted.
7. Your Rights
Subject to local law, you may have rights to:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Delete your information ("right to be forgotten").
- Receive a copy of your information in a portable format.
- Object to or restrict certain processing.
- Withdraw consent where processing relies on consent.
- Lodge a complaint with your local supervisory authority.
To exercise any of these rights, email privacy@aqen.ai or use the in-product Delete my data action available in your account settings. We will respond within the timeframes required by applicable law (typically 30 days).
California residents (CCPA/CPRA): You have the right to know, delete, correct, and opt out of "sale" or "sharing" of personal information. Aqen does not sell personal information and does not share it for cross-context behavioral advertising. We do not knowingly process the personal information of consumers under 16.
EU/EEA/UK residents (GDPR/UK GDPR): Aqen is the controller of personal information processed for our own purposes (e.g., account, billing, service operation, and per-tenant fine-tuning to personalize the Service) and the processor of Customer Content processed on your instructions. The legal bases we rely on include:
- Contract performance (Art. 6(1)(b)) — providing and operating the Service you signed up for, executing actions you authorize, billing, and the metering telemetry (tenant, seat, business, model, tokens, credits, cost) that produces the invoice and supports cost defense for paid plans.
- Legitimate interests (Art. 6(1)(f)) — securing and improving the Service, fraud and abuse prevention, and per-tenant fine-tuning of model adapters on PII-sanitized Brain content to personalize the Service to your business. We have assessed that the privacy impact of these activities is proportionate given the tenant-scoped boundary, PII sanitization, and the operational necessity of running the Service.
- Legal obligation (Art. 6(1)(c)) — retaining records we are legally required to keep (e.g., billing, tax).
- Consent (Art. 6(1)(a)) — marketing communications (where applicable), and any optional features that ask for explicit consent.
You have the right to object (GDPR Art. 21) to processing based on legitimate interests, including the per-tenant fine-tuning activity. To object, email privacy@aqen.ai. On a valid Art. 21 objection, Aqen will stop fine-tuning on your Customer Content and delete any per-tenant adapter derived from it within the timeframes in Section 6, unless we can demonstrate compelling legitimate grounds that override your interests.
8. Data Processing Agreement (DPA)
A DPA template is available on request for B2B customers. Email privacy@aqen.ai with your organization name and the email of the signatory.
9. Security
We use industry-standard administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit (TLS) and at rest, encrypted token storage, access controls, audit logging, and least-privilege provisioning. No system is perfectly secure; if we ever experience a security incident affecting your information, we will notify you as required by law.
10. Children
The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact privacy@aqen.ai and we will delete it.
11. Changes to this Policy
We may update this Policy. Material changes will be communicated by email and/or in-product notice at least 30 days before they take effect, except where a shorter period is required by law or by a security or compliance issue.
12. Contact
Privacy questions or rights requests
Email privacy@aqen.ai. Mail: Aqen Inc, attn: Privacy. We aim to acknowledge requests within 5 business days and resolve within 30 days, or sooner where required by law.