Kembali

Privacy Policy (draft)

Kemas kini terakhir: 2026-09-29 · Draf — menunggu semakan peguam sebelum pelancaran.

1. What we collect

Account details: your email, the name you go by, and your password stored as a hash.

Company details: what you tell us about your business during onboarding or in Settings.

Material you upload for your employees to learn from, including files you pick from Google Drive.

Conversations: your chats with your AI employees, and your customers' chats with the Community Manager on Telegram, including their Telegram display name and chat id.

Drafts and records your employees make for you: emails, calendar changes, posts, bookkeeping entries.

Connected accounts: see sections 3 and 4 for Google, Facebook and Instagram. The access tokens for every connection are stored encrypted.

Usage: token counts and estimated cost per call, used for billing and to prevent abuse.

Visits: when you open one of our public pages we count the visit — which page, the site you came from, your language, and a one-way code that changes every day. We use no cookies for this, we do not keep your IP address, and we cannot follow you from one day to the next. We do not count visitors whose browser sends "Do Not Track".

Waitlist: if you join the waitlist before trial is open, just your email and the language the page was in — nothing else, and no account is created from it.

2. What we use it for

Only to run and improve the service: generating replies, doing the work you ask your employees for, maintaining each employee's memory, billing, preventing abuse, and telling you when something needs your attention. We never use one company's material or conversations for another company's employees. We do not sell any of it or use it for advertising. A waitlist email is used only to tell you when trial opens.

3. Google user data

When you connect your Google account, we ask only for what the features you turn on need, one at a time:

Calendar — your events and the list of your calendars, read to answer questions about your schedule, plan and check for clashes; and the events you approve (with a Google Meet link when you ask for one).

Sending email — emails you have approved are sent from your Gmail. We cannot read your inbox or any email you did not ask your employee to write.

Contacts — names and email addresses, looked up when you ask your employee to write to someone by name.

Tasks — your open tasks, read when you ask, and the reminders you ask for, added to your list.

Sheets — only the spreadsheet you point your employee at: its rows read to answer questions, and the rows you approve added.

Drive — only the files you pick in Google's own file picker, and the files AAAAI creates in an "AAAAI" folder. A document you pick for the knowledge base is read into it. Photos you put in Products and services are sent by the Customer Service employee into a Telegram conversation when a customer asks to see them; for a photo sent on Telegram we keep only Telegram's id for it and your note, and for one picked from Drive only its Drive id — never a copy of the photo (Telegram keeps the photo it delivers, as part of that conversation). A picture or video you pick for a post is read when your Social Media employee drafts the post and again when it is published to Instagram or Facebook (for a video, our server briefly takes a few still frames for the employee to look at and repackages the file into the format both platforms accept, without changing its content, deleting both right after); we keep its Drive id, size and length, never a copy of the picture or video. Files you upload in the Social Media employee's picker are saved by Google straight into an "AAAAI Media" folder in your Drive, without passing through our servers. We cannot see anything else in your Drive.

Gmail add-on — the one email you have open, read only after you press one of the add-on's buttons, and the reply draft it places in your reply box.

How we use it: only to provide those features to you. A person at AAAAI reads it only with your permission (for example when you ask for support), when needed for security or to investigate abuse, or when the law requires it. It is not sold, not used for advertising, and not used to develop, improve or train generalised AI or machine-learning models.

Who else receives it: to do the task you asked for, the relevant part — for example the email you want answered — is sent to Anthropic's Claude models, which process it under Anthropic's commercial terms; Anthropic does not train its models on data sent through its commercial API. Nothing else is shared.

How long we keep it: what becomes part of your chats, drafts or knowledge base is kept until you delete it or close your account. You can disconnect Google at any time on your Assistant's page, which deletes the stored access token at once, or revoke AAAAI's access in your Google Account's security settings.

AAAAI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. Facebook and Instagram data

When you connect a Facebook Page or an Instagram professional account, we keep its id, its name or username, and a token that lets us publish for it. We publish only the posts you approve. For Facebook posts we have published, we read their like, comment and share counts so your Social Media employee can review how they did. We do not read your messages, and we do not read comments beyond counting them.

You can disconnect either account at any time on your Social Media employee's page, which deletes the stored token at once, or remove AAAAI in Facebook's Business Integrations or Instagram's Apps and Websites settings. See the Data Deletion page for everything else.

5. Other services we rely on

Replies are generated by Anthropic's Claude models: the relevant conversation, your company details, and the retrieved passages of your material are sent to Anthropic for processing. When an employee searches the web, the search is made through Anthropic's search tool. The Community Manager and owner notifications use the Telegram Bot API. The service is hosted on Railway and its database on Neon. Each processes data only to provide its part of the service.

6. Separation between companies

Each company's data is stored under its own tenant identifier, and an AI employee can only read the material and memory belonging to its own company. Improvements to the shared role templates are based on anonymous statistics — how often a failure mode triggers — and never on any company's actual conversations.

7. When a person reads a conversation

A platform operator may read conversation content in two situations: when you ask for support, and when the system has flagged a reply as possibly out of control and it needs human review. Outside those cases we do not read your conversations.

8. Keeping and deleting data

Data is kept while your account is active. After you close your account there is a 60-day window in which it can be restored, after which it is permanently deleted. Operational logs are kept for 90 days. You can ask us to export or delete your data — including your uploaded material, conversations and employee memory — at any time. The Data Deletion page explains every way to do it.

9. Your customers' data

Messages from people who talk to your Community Manager on Telegram, and the people your employees email on your behalf, are processed by us on your instruction, as the business. It is your responsibility to meet your own obligations to them under local law, such as Malaysia's PDPA 2010. The Community Manager states that it is an AI at the start of every conversation.

Perlukan manusia?

Soalan, eksport atau pemadaman data, atau aduan tentang sesuatu yang dikatakan oleh pekerja — hantar e-mel kepada kami di: support@aaaai.ai. Seorang manusia yang membacanya, bukan AI.