Enterprise Privacy & Zero-Retention Architecture

Privacy Policy

Last updated: September 2026. Complete transparency on how your company documents, vector embeddings, customer conversations, and AI model integrations are handled and protected.

Security Guarantees

Zero Model Training

Your business data is NEVER used to train or fine-tune public foundation models.

Tenant-Isolated Storage

PostgreSQL pgvector partitions secured by Row Level Security (RLS).

Zero Data Retention (ZDR)

Context is processed in-memory during inference without provider persistence.

Permanent Purging

Deleting a file immediately purges all vector chunks and metadata permanently.

AES-256-GCM Encryption

All database connections and inbox credentials are encrypted at rest.

1. Information We Collect and Process

Aidni.io operates an AI customer support and lead capture platform. To deliver accurate, grounded responses on your website, we process the following categories of information:

  • Account & Billing Data: Name, work email address, organization name, and transaction identifiers. Payment card details are tokenized and processed exclusively by PCI-DSS Level 1 compliant payment gateways (Razorpay / Stripe); Aidni never stores raw credit card numbers.
  • Knowledge Base Data: PDF documents, DOCX files, web URLs, sitemaps, YouTube transcripts, and text notes that you explicitly upload or connect.
  • Connected Database Metadata: Schema descriptions, table column definitions, and read-only query results returned when an end-user asks about live transactional data (e.g., tracking an order status). Connection strings are stored encrypted using AES-256-GCM.
  • Customer Conversation Logs: Chat messages exchanged between your website visitors and your deployed AI agent, including capture details (name, email, phone) provided voluntarily by leads for follow-up.

2. AI Model Providers (OpenAI & OpenRouter) and Zero Data Retention

Aidni utilizes industry-standard, commercial foundation model APIs to synthesize responses from your retrieved documents. We use direct OpenAI commercial APIs (GPT-4o mini, text-embedding-3-small) as our primary inference engine, with OpenRouter serving as our enterprise multi-model fallback gateway.

Our Commitments with Model Providers:

  • Zero Model Training: Under commercial API agreements, neither OpenAI nor OpenRouter trains, fine-tunes, or evaluates public foundation models on data submitted via Aidni APIs.
  • Transient Processing: Prompt context and vector excerpts are processed strictly in-memory during real-time generation. Upstream providers do not retain your proprietary text for model improvement.
  • Provider Selection Standards: We route queries strictly to SOC 2 Type II compliant providers that maintain enterprise-grade confidentiality and data isolation guarantees.

3. PII Data Masking & Vector Storage Isolation

To protect privacy before information reaches external networks, Aidni employs multi-layered defenses:

  • Bidirectional PII Redaction: Sensitive identifiers (Social Security numbers, credit card numbers, personal telephone numbers, and email patterns) are automatically scrubbed or masked on the server prior to generating embeddings or logging conversation analytics.
  • PostgreSQL Row Level Security (RLS): All document chunks, raw files, and vector embeddings are stored in dedicated PostgreSQL tables with strict RLS policies. Each database query is cryptographically scoped to your authenticated organization ID, ensuring zero cross-tenant visibility.
  • Transport & Rest Encryption: Data in transit is secured using TLS 1.3 encryption. Data at rest (vector embeddings, database credentials, lead inbox tokens) is encrypted with AES-256.

4. Data Retention, Customer Deletion & Account Purging

You retain complete ownership and sovereignty over your company data at all times:

  • Immediate Document Purge: When you delete a PDF, URL, sitemap, note, or database connection from your Knowledge Source panel, the source record, all associated vector embeddings, and chunk records are permanently purged from the database immediately.
  • Chat Session Deletion: You can delete specific visitor sessions or individual customer conversation logs directly from the Inbox panel at any time.
  • Account Termination: If you delete your account or request termination, an automated cascade delete permanently purges all chatbots, vector databases, analytics history, and integration tokens within 24 hours.

5. Inbound Sales & Email Inbox Privacy

When connecting your email inbox for automated lead triage and sales intelligence:

  • Strict Scope: Aidni only reads inbound messages addressed to your designated sales or support addresses. We do not access internal personal email folders or unrelated threads.
  • Encrypted Credentials: SMTP/IMAP credentials and OAuth refresh tokens are encrypted at rest using AES-256-GCM and never exposed to client-side browsers or external LLMs.

6. Data Subject Rights (GDPR, CCPA & Global Compliance)

Under GDPR, CCPA, and applicable global privacy laws, you and your website visitors have the right to:

  • Request access to all personal data and interaction logs stored about you.
  • Request rectification or immediate erasure of personal data.
  • Export your data in portable, machine-readable JSON/CSV formats.
  • Withdraw consent for lead processing at any time.

7. Contact Our Data Protection Officer

If you have questions about our privacy architecture, request a signed Data Processing Addendum (DPA), or need to execute a formal deletion request, please reach out to our security team:

Email: support@aidni.io