aikuaa

Privacy policy

Last updated:

This policy explains which personal data aikuaa processes, why, for how long, and how to exercise your rights over it. It is written to be read, not endured: if anything here is unclear, write to us and we will fix it.

Data controller

aikuaa is a platform that answers questions about a company’s documents and databases. The controller of the data described in this policy is AIKUAA.AI - INTELIGENCIA CORPORATIVA E.A.S., the company that operates aikuaa, operating from Paraguay.

This policy applies to the website www.aikuaa.ai, the aikuaa web app, and the aikuaa app for iPhone and Android.

For any privacy matter, the contact is contacto@aikuaa.ai.

Your account data

To create an account or sign in to aikuaa, on the web or in the app, we process the data below. If you create the account with your email, we send you a code to confirm the address is yours. If you sign in with Google or Microsoft, you do not give us a password: we receive your name, your email and your account identifier from that provider.

  • your name and your email address;
  • your password, if you create the account with your email or sign in with a password. We do not store it in readable form: it is stored transformed by a hashing algorithm;
  • your WhatsApp number, only if you choose to add it to your profile. It is optional and stays as contact data on your account: it is seen by you, your organisation’s administrators and the team that runs aikuaa. Exhibitors and other event participants do not see it, and it is erased when you delete your account;
  • if you fill them in on your profile, your “About me” text and your chat instructions. The instructions are sent to the AI models along with your messages, to tailor the answers; the “About me” text is not;
  • an internal account identifier, used to keep your session and recognise you on each sign-in;
  • technical data about each sign-in — IP address, browser or device, and date — for security and auditing.

Data we receive when you sign in with Google

aikuaa uses Google sign-in to identify who is logging in. At that moment we receive only the basic identity data Google returns with the profile and email scopes:

  • the name on the Google account;
  • the email address and whether Google has verified it;
  • the unique identifier Google assigns to that account, which we use to recognise you on later sign-ins.

What we never access

aikuaa does not access Gmail, Google Drive, Google Calendar, Contacts, Photos or any other Google service. The permissions we request are limited to the basic identity described above, and no product feature asks for more.

aikuaa’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Google tokens

aikuaa does not store the Google access token or refresh token. They are used only during the authentication exchange, within the same operation, and discarded when it ends.

As a direct consequence, aikuaa cannot act on your Google account outside the moment of sign-in — not even if it wanted to.

What we use your identity for

Identity data is used to link your sign-in to a user account inside aikuaa and to the organisation that account belongs to. That link is what determines which documents, databases and agents you can query.

We also use it to keep the minimum security and audit record needed — who signed in and when — and to contact you about the service. We do not use your identity data for advertising, and we neither sell it nor share it with third parties for commercial purposes.

The one exception is described under “Your activity with exhibitors at an event”: if you accepted an event’s terms of use, exhibitors on the premium plan can see your name and email alongside your activity on their profile.

People without an account: access requests

In aikuaa, each organisation decides who can reach its data. If you sign in with a Google account that is not yet linked to any organisation, you get access to no data at all. Instead, you can create an access request.

From that request we keep the name, email, Google identifier, date and the organisation named, so an administrator can review it. The request grants nothing on its own: until it is approved, the account sees no content.

The request and the administrator’s decision are kept on record and are not erased automatically. If you want us to erase yours, write to contacto@aikuaa.ai.

What you write, dictate and attach in the chat

When you use the assistant, we process the content you send in order to answer you:

  • the messages you write and the assistant’s answers, which stay in your conversation history;
  • the audio you record when dictating a message, which is sent to our servers to be turned into text;
  • in the web app, the files and images you attach to a conversation (the mobile app does not attach files);
  • the ratings (like or dislike) and comments you leave on answers.

Third-party artificial intelligence

To generate answers, aikuaa uses third-party artificial intelligence models. We send them your messages, the audio you record to dictate, the files you attach in the web app, your name — so the assistant can address you — and your chat instructions. That content may include personal data.

Some of those services are configured for each organisation: the chat models, audio transcription, message moderation, embeddings (numerical representations of text used to search documents) and the automated analysis of questions and of answer quality. Others are used by aikuaa across the whole platform: web search and relevance ranking of what is found. They are named under “Providers”.

aikuaa does not train artificial intelligence models on your conversations or on your organisation’s content. An administrator of your organisation or of the aikuaa team may manually save a real question that someone asked the assistant about the organisation’s databases, together with its answer, as an example or to reuse that answer with other people in the organisation. Each provider handles the data it receives under its own terms of service.

In the app, before you use the chat for the first time we ask for your explicit permission for that transfer. If you do not give it, you will not be able to use the chat and your session is closed.

You can withdraw that permission at any time in the app, under Preferencias → «Retirar permiso de IA» (in Portuguese, Preferências → «Retirar permissão de IA»), and give it again whenever you like. This permission is requested and withdrawn in the app; while it is withdrawn you will not be able to use the app. In the web application the chat does not yet ask for this permission: if you do not want your messages sent to AI providers, do not use the chat on the web, or delete your account. Withdrawing it does not undo transfers already made and, if automated analysis of answer quality is enabled for your organisation, that analysis may keep processing your earlier conversations for as long as your account exists; to stop it, delete those conversations or delete your account. We keep a record that you gave the permission and that you withdrew it.

Camera, photos and microphone in the app

The app asks for device permission for these features:

  • camera, to scan the QR code of your organisation or of an event. The image is used at that moment to read the code and is not stored;
  • camera or photo library, if you choose to set a profile photo. It is optional: the photo you pick is sent to our servers and stays linked to your account;
  • microphone, to dictate messages. Dictated audio follows the path described in the chat section.

Data stored on your device

So you can browse an event offline, the app stores on your device a copy of its schedule, exhibitors and speakers. It also stores your signed-in session, in the system’s protected storage.

Your activity with exhibitors at an event

When you use aikuaa at an event, we record, linked to your account, which exhibitor profiles you open — and, in the web app, which photos, videos or links on those profiles you open — and which exhibitors appear in the assistant’s answers to your questions. Of the question we keep only a technical hash, never its text.

We use this to measure each exhibitor’s audience as part of the event service. Who sees what:

  • each exhibitor sees how many times it appeared in the assistant’s answers; exhibitors on the premium plan also see how many times their profile was opened and the list of people who interacted with it, with name, email, date of last contact and type of interaction;
  • you only appear on that list if you accepted the event’s terms of use, and never just because an exhibitor appeared in one of the assistant’s answers;
  • the event organiser sees the same data for every exhibitor, regardless of plan;
  • exhibitors do not see your WhatsApp number;
  • the detailed record is erased about 12 months after the event ends (erasure runs once a month), or earlier, the moment you delete your account. Only daily totals per exhibitor remain, and they identify no one.

Who sees your data

Besides you, your data can be seen by:

  • your organisation’s administrators: your name, your email, your WhatsApp number if you added one, your activity in the service, the ratings and comments you make on answers, quality signals from your conversations and your messages that moderation blocked or could not check;
  • premium-plan exhibitors and an event’s organiser, in the cases explained under “Your activity with exhibitors at an event”;
  • the aikuaa team that runs the platform, to operate the service, provide support and keep it secure;
  • the providers listed under “Providers”, to deliver their service to us.

Automated analysis of messages

Depending on what is enabled for your organisation, a moderation model reviews each message before the answer to stop abusive content. If it blocks the message, or cannot check it, we keep the message text, your name and the decision, so your organisation’s administrators can review it.

Depending on what is enabled for your organisation, we also use an automated text-analysis service to understand questions and measure answer quality. What is sent to it does not carry your account identifier, and emails, phone numbers and some ID document numbers appearing in the text are hidden; names are not.

No advertising or tracking

The aikuaa app includes no third-party advertising, tracking or analytics components. We show no ads and we do not follow you across other companies’ apps or websites.

Company data

The organisation’s documents and databases belong to it, not to aikuaa. We process them on that organisation’s behalf, under the service agreement, and only the users it authorises can reach them.

Your conversations with the assistant are stored linked to your account and to that organisation, and they are erased if you delete them or delete your account.

This website

This site measures visits with Cloudflare Web Analytics, which uses no cookies, no browser fingerprinting, and does not identify visitors. That is why there is no consent banner here.

We store one cookie of our own, holding the language you picked, so we do not ask again. The contact form uses Cloudflare Turnstile to stop automated submissions, and the data you send in it (company, contact, phone and email) is used only to reply to you.

The account deletion page also uses Turnstile. The email and the code you type there are used only to process that request.

Providers

To run the service we rely on these providers, which process data to deliver their service to us:

  • Railway: hosting of the API and of the service’s databases;
  • Cloudflare: hosting of this site, visit measurement, anti-abuse protection and file storage, such as profile photos;
  • Google and Microsoft: sign-in;
  • Resend: email delivery;
  • Sentry: logging of the service’s technical errors, without the content of conversations;
  • artificial intelligence model providers — for example OpenAI, Anthropic, Google, Groq or OpenRouter — for the chat, audio transcription and message moderation, as configured for your organisation;
  • DeepInfra, for embeddings of documents and queries, as configured for your organisation;
  • TypeSafe, for the automated analysis of questions and of answer quality, when it is enabled for your organisation;
  • Tavily, to search the web when the answer is not in the organisation’s sources: it receives a query built from your question;
  • Cohere, to rank the passages found by relevance: it receives the question and those passages.

Retention

These are the periods and criteria we keep data for. Where there is no automatic erasure period, we say so:

  • your account and profile data, your sessions and the record of your permission for the use of AI: while the account exists; they are erased when you delete it;
  • your conversations with the assistant: until you delete them or delete your account;
  • sign-in, security and audit records, ratings of answers and messages kept by moderation: while the account exists; when you delete it, they are erased or left without your identity, as explained under “What we keep after the account is deleted”;
  • service activity records — which assistant features were used in each conversation, without the text of the messages: 13 months;
  • telemetry of the tools the assistant uses and the technical trace of document searches: 90 days;
  • records of queries to the organisation’s databases, which may include the text of a question and its answer: not erased automatically; when you delete your account, they are left without your identity;
  • record of your activity with exhibitors: about 12 months after the event ends (erasure runs once a month);
  • access requests and messages sent through this site’s contact form: not erased automatically; if you want us to erase yours, write to us;
  • company data: for the term of the service agreement and the return-or-deletion period agreed in it;
  • data of a deleted account: as set out under “What we keep after the account is deleted”.

How to delete your account

You can delete your account yourself, in two ways: from the app, under Preferencias → «Eliminar mi cuenta» (the app is available in Spanish and Portuguese), or on the web, on the account deletion page, without needing the app installed.

In both cases we send a 6-digit code to the account’s email address, and the deletion runs when you confirm it. It is final: there is no grace period and no way to recover the account.

Some accounts cannot be deleted automatically: those holding content or activity that belongs to an organisation — for example, projects created or files uploaded to a shared workspace — and platform administration accounts.

In those cases, write to support.

What is erased when the account is deleted

The deletion runs the moment you confirm it, and your account stops being accessible immediately. If some part of the erasure is not completed at that moment, the account stays inaccessible and the system retries the erasure automatically for up to 7 days; if it is still not completed by then, the aikuaa team is alerted to resolve it.

If, before erasing starts, content that belongs to an organisation turns up, the deletion is cancelled, the account becomes active again without anything having been erased, and we tell you: on screen, if you are making the request, or by email, if the automatic retry finds it.

We erase:

  • your name, your email, your WhatsApp number if you added one, your password and the sign-ins linked with Google or Microsoft;
  • your “About me” text and your chat instructions;
  • your active sessions, with the technical data of each sign-in;
  • your conversations with the assistant and the files you uploaded in them;
  • the ratings and comments you left on answers;
  • your messages that moderation blocked or could not check;
  • your profile photo;
  • your link to the organisations and events you took part in;
  • the record of your activity with exhibitors at events;
  • the record of your permission for the use of artificial intelligence.

What we keep after the account is deleted

After the deletion we keep the following:

  • the record that you accepted an event’s terms: it is detached from your identity at once and erased after 60 days;
  • a technical record of the deletion — an internal identifier, its status and dates, without your name or email: it is erased after 31 days and exists so that an old session cannot be used again;
  • security, audit and service-usage records: they are left without your name, your email or your account identifier, though they may include technical data about a sign-in, such as the IP address and the browser;
  • the organisation’s operational query records, which may keep the text of a question and its answer, without your name, your email or your account identifier;
  • the daily totals of each exhibitor’s audience, which are only numbers and do not identify you;
  • your name as author on content you published on behalf of an organisation — for example, an exhibitor’s profile or an event notice — because it is part of that content;
  • the organisation’s documents, databases and other content, which belong to it;
  • records we must keep by legal obligation or to resolve an ongoing dispute.

Your rights

You can request access to, correction of, or deletion of your personal data at any time, and you can revoke the Google sign-in consent from your own Google account settings.

You can withdraw at any time your permission for sending data to AI providers: in the app, under Preferencias → «Retirar permiso de IA», or by deleting your account. This permission is requested and withdrawn in the app; while it is withdrawn you will not be able to use the app. In the web application the chat does not yet ask for this permission: if you do not want your messages sent to AI providers, do not use the chat on the web, or delete your account. Withdrawing it does not undo transfers already made, and automated analysis of answer quality may keep processing your earlier conversations for as long as your account exists, unless you delete them.

To exercise those rights, or to request deletion when you cannot do it yourself, write to contacto@aikuaa.ai from the account’s email address. If you request deletion that way, we answer within 30 days at most.

If the request concerns company data, we forward it to the contracting organisation, which is the party that decides on it.

Security

Access to aikuaa requires authentication and is scoped to each user’s organisation. Traffic is encrypted in transit and platform secrets are kept out of the code.

No system is infallible. If we detect a security breach affecting your personal data, we will tell you and report what happened without undue delay.

Changes to this policy

If we change this policy, we update the date in the header. When a change materially affects how we handle your data, we email active accounts before it takes effect.

Contact

Questions, deletion requests or privacy complaints: contacto@aikuaa.ai.