Privacy Policy

Last Updated: April 4, 2026

Introduction

At Airgen, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our enterprise-grade AI platform. This policy applies to all users of our Service, including individuals and organizations.

By using the Service, you consent to the data practices described in this policy. If you do not agree with our policies and practices, please do not use our Service.

1. Information We Collect

1.1 Information You Provide

We collect information that you provide directly to us:

  • Account Information: Name, email address, phone number, company name, job title, and password
  • Payment Information: Billing address and payment method details (processed by third-party payment processors)
  • Profile Information: Profile photo, preferences, and account settings
  • Content Data: Text, files, documents, and other content you input into the Service
  • Communications: Messages, feedback, and support requests you send to us
  • Integration Data: Credentials and data from third-party services you connect to our platform

1.2 Information We Collect Automatically

When you use our Service, we automatically collect:

  • Usage Information: Features used, pages viewed, time spent, API calls made, and interaction patterns
  • Device Information: Device type, operating system, browser type and version, unique device identifiers
  • Log Data: IP address, access times, error logs, and performance data
  • Cookies and Similar Technologies: We use cookies, web beacons, and similar tracking technologies (see Section 8)
  • Location Data: Approximate location based on IP address for geographical compliance
  • Analytics Data: Usage patterns, performance metrics, and feature adoption statistics

1.3 Information from Third Parties

We may receive information from:

  • Authentication Providers: When you sign in using third-party services (e.g., Google, GitHub)
  • Integration Partners: Data from services you connect to our platform
  • Payment Processors: Payment confirmation and transaction details
  • Business Partners: Information from partners who offer complementary services

2. How We Use Your Information

We use the information we collect to:

2.1 Provide and Maintain the Service

  • Create and manage your account
  • Process your requests and transactions
  • Deliver AI agent services and features
  • Store and process your content
  • Provide customer support
  • Monitor and improve Service performance

2.2 Improve and Develop the Service

  • Analyze usage patterns and trends
  • Develop new features and functionality
  • Conduct research and testing
  • Debug and fix technical issues
  • Optimize performance and user experience

2.3 Communicate with You

  • Send service updates and notifications
  • Respond to your inquiries and requests
  • Provide technical support
  • Send marketing communications (with your consent)
  • Conduct surveys and gather feedback

2.4 Ensure Security and Compliance

  • Detect and prevent fraud, abuse, and security threats
  • Enforce our Terms of Service and policies
  • Comply with legal obligations
  • Protect rights, property, and safety
  • Monitor compliance with usage limits and policies

2.5 Business Operations

  • Process payments and manage subscriptions
  • Generate invoices and financial reports
  • Manage business relationships
  • Facilitate corporate transactions (mergers, acquisitions)

Important: We do NOT use your content data (prompts, inputs, outputs) to train our AI models or for any purpose other than providing the Service, unless you explicitly opt-in to a data sharing program.

3. Data Processing and AI Models

3.1 Third-Party LLM Providers

When you use third-party large language models (LLMs) through our Service, your prompts and data may be processed by those providers (e.g., OpenAI, Anthropic, Google, etc.). We use enterprise agreements with these providers that include:

  • Prohibition on using customer data for model training
  • Data processing agreements compliant with GDPR and other regulations
  • Security and confidentiality commitments
  • Data residency options where available

3.2 Geographical Compliance

Our Service allows you to select data processing regions to comply with geographical data residency requirements. We support multiple regions including:

  • European Union (GDPR compliance)
  • United States (CCPA and other state privacy laws)
  • Asia-Pacific regions
  • Other regions as specified in your subscription

3.3 Data Isolation

Enterprise customers can opt for enhanced data isolation, including:

  • Dedicated infrastructure and database instances
  • Virtual Private Cloud (VPC) deployment
  • Custom encryption keys (BYOK - Bring Your Own Key)
  • Single-tenant architecture options

4. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

4.1 Service Providers

We share information with third-party service providers who perform services on our behalf:

  • Cloud infrastructure providers (hosting, storage, compute)
  • LLM and AI model providers
  • Payment processors
  • Analytics and monitoring services
  • Customer support tools
  • Email and communication services

These providers are bound by contractual obligations to keep your information confidential and use it only for the purposes we specify.

4.2 Business Transfers

If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and provide choices regarding your information.

4.3 Legal Requirements

We may disclose your information if required to do so by law or in response to:

  • Valid legal processes (subpoenas, court orders, warrants)
  • Government or regulatory requests
  • National security requirements
  • Enforcement of our rights and agreements
  • Protection of safety and security

4.4 With Your Consent

We may share your information with third parties when you explicitly consent or direct us to do so, such as when you authorize integrations with other services.

4.5 Aggregated and De-identified Data

We may share aggregated or de-identified information that cannot reasonably be used to identify you for research, marketing, analytics, or other purposes.

5. Data Security

We implement comprehensive security measures to protect your information:

5.1 Technical Safeguards

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Network security and firewalls
  • Intrusion detection and prevention systems
  • Regular security assessments and penetration testing
  • Secure development practices and code reviews
  • Multi-factor authentication (MFA)
  • Role-based access controls (RBAC)

5.2 Organizational Safeguards

  • Employee background checks and security training
  • Confidentiality agreements
  • Incident response procedures
  • Business continuity and disaster recovery plans
  • Regular security audits and compliance reviews

5.3 Compliance Certifications

We maintain industry-standard security certifications including:

  • SOC 2 Type II compliance
  • ISO 27001 certification (in progress)
  • GDPR compliance
  • CCPA compliance

While we implement robust security measures, no system is completely secure. We cannot guarantee absolute security of your information. You are responsible for maintaining the confidentiality of your account credentials.

6. Data Retention

We retain your information for as long as necessary to provide the Service and fulfill the purposes described in this policy:

  • Active Accounts: We retain your account information and content while your account is active
  • Deleted Accounts: After account deletion, we retain data for 30 days to allow recovery, then permanently delete it
  • Backups: Data may persist in backups for up to 90 days after deletion
  • Legal Obligations: We may retain certain information longer if required by law or for legitimate business purposes
  • Aggregated Data: De-identified and aggregated data may be retained indefinitely

Enterprise customers may have custom data retention policies as specified in their agreements.

7. Your Privacy Rights

Depending on your location, you may have certain rights regarding your personal information:

7.1 Access and Portability

You have the right to access your personal information and receive a copy in a portable format.

7.2 Correction and Update

You can update your account information at any time through your account settings. You can also request that we correct inaccurate information.

7.3 Deletion

You can request deletion of your account and personal information. Note that some information may be retained as required by law or for legitimate business purposes.

7.4 Opt-Out

You can opt out of marketing communications by following the unsubscribe instructions in those communications. You cannot opt out of service-related communications.

7.5 Additional Rights (GDPR)

If you are in the European Economic Area, you have additional rights including:

  • Right to restriction of processing
  • Right to object to processing
  • Right to withdraw consent
  • Right to lodge a complaint with a supervisory authority

7.6 Additional Rights (CCPA)

If you are a California resident, you have the right to:

  • Know what personal information is collected
  • Know whether personal information is sold or disclosed and to whom
  • Opt out of the sale of personal information (we do not sell personal information)
  • Non-discrimination for exercising your rights

To exercise any of these rights, please contact us at privacy@airgen.ai. We will respond to your request within the timeframe required by applicable law.

8. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to collect and track information and improve our Service:

8.1 Types of Cookies

  • Essential Cookies: Required for the Service to function (authentication, security)
  • Functional Cookies: Remember your preferences and settings
  • Analytics Cookies: Help us understand how you use the Service
  • Marketing Cookies: Used to deliver relevant advertisements (with your consent)

8.2 Managing Cookies

You can control cookies through your browser settings. Note that disabling certain cookies may affect the functionality of the Service.

8.3 Analytics and Advertising

We use third-party analytics services (e.g., Google Analytics) to understand usage patterns. These services may use cookies and similar technologies. You can opt out of these services through their respective opt-out mechanisms.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws.

For transfers from the European Economic Area to countries not deemed adequate by the European Commission, we use Standard Contractual Clauses or other approved transfer mechanisms.

We ensure that appropriate safeguards are in place to protect your information when it is transferred internationally.

10. Children's Privacy

Our Service is not directed to children under 13 (or 16 in the European Economic Area). We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information, please contact us. If we learn we have collected personal information from a child without parental consent, we will take steps to delete that information.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

  • Posting the updated policy on this page
  • Updating the "Last Updated" date
  • Sending email notification for significant changes
  • Displaying a prominent notice in the Service

Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.

12. Data Protection Officer

For organizations subject to GDPR, we have appointed a Data Protection Officer who can be contacted regarding data protection matters:

Email: dpo@airgen.ai

Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: privacy@airgen.ai

Legal Department: legal@airgen.ai

Data Protection Officer: dpo@airgen.ai

Website: https://airgen.ai

We will respond to your inquiries within a reasonable timeframe, typically within 30 days as required by applicable law.

13. Jurisdiction-Specific Information

13.1 European Economic Area (EEA)

The legal basis for processing your personal information under GDPR includes:

  • Contract: Processing necessary to provide the Service
  • Consent: Where you have given explicit consent
  • Legitimate Interests: For business operations, security, and improvement
  • Legal Obligation: To comply with applicable laws

13.2 California

California residents can request a list of personal information categories we disclose to third parties for direct marketing purposes. We do not share personal information with third parties for their direct marketing purposes.

13.3 Other Regions

We comply with applicable privacy laws in all regions where we operate. If you have questions about region-specific privacy practices, please contact us.