Legal · Privacy

Privacy Policy

This policy explains what information Ayooda handles, why we use it, who it may be shared with, and the choices available to account holders and end users.

Effective and last updated: September 6, 2026

No sale of personal data

We use and disclose information to provide, secure, support, and improve Ayooda—not to sell personal data.

Customers control support data

For customer conversations, tickets, and knowledge, the Ayooda customer normally decides the purpose and Ayooda processes the data for them.

Privacy rights supported

You can request access, correction, deletion, portability, or other rights available under the law that applies to you.

Scope and our role

This Privacy Policy applies to ayooda.live, the Ayooda dashboard, our support channels, and the hosted services we provide (together, the “Service”). It explains how Ayooda collects, uses, discloses, and protects personal data.

For account administration, billing, website analytics, and our own business operations, Ayooda acts as a data controller. When a customer uses Ayooda to handle messages, tickets, knowledge, or information about its own users, the customer is normally the controller and Ayooda acts as its processor or service provider. In that case, the customer decides why the data is processed and should provide its own privacy notice. End users should direct requests about a customer conversation to the organisation whose agent they contacted.

Personal data we collect

The data we process depends on how you use the Service:

  • Account and profile data: name, email address, profile image, authentication identifiers, workspace membership, role, and account status.
  • Customer content: agent instructions, uploaded files and webpages, conversation messages, internal notes, support tickets, feedback, and other information submitted to the Service.
  • End-user identity and channel data: names, email addresses, phone numbers, customer identifiers, message metadata, and channel identifiers when supplied by an end user, a customer, or an authorised integration.
  • Configuration and integration data: channel settings, webhook destinations, tool definitions, connector metadata, and encrypted credentials or tokens needed to operate customer-selected integrations.
  • Billing data: plan, usage, billing status, Stripe customer and subscription identifiers, and transaction metadata. Payment-card details are collected and handled by Stripe, not stored by Ayooda.
  • Device, network, and usage data: IP address, browser and device information, referring pages, pages viewed, interactions, diagnostics, timestamps, and security or reliability events.
  • Support and communications: messages you send us and information needed to respond.

Please do not submit special-category or highly sensitive data unless it is necessary, lawful, and appropriate for your use of the Service.

Where data comes from

We collect data directly from account holders and end users; from customers that configure the Service or identify their users; automatically from browsers, devices, and our systems; and from connected services such as Google sign-in, communication channels, billing providers, or customer-authorised integrations.

How and why we use data

We use personal data to:

  • provide, personalise, maintain, and secure the Service;
  • authenticate users, administer workspaces, and provide customer support;
  • process customer conversations, retrieve relevant knowledge, generate AI-assisted responses, execute authorised tools, create tickets, and deliver messages;
  • process subscriptions, measure usage, prevent fraud, and enforce service limits;
  • monitor reliability, debug problems, understand product usage, and improve usability;
  • communicate service, security, billing, and policy updates; and
  • comply with law, resolve disputes, and protect Ayooda, our customers, and others.

Where the GDPR or similar law applies, our legal bases are performance of a contract, compliance with legal obligations, and our legitimate interests in operating, securing, supporting, and improving the Service. We rely on consent where applicable law requires it. When Ayooda processes customer content as a processor, we do so on the customer’s documented instructions and the customer determines the applicable legal basis.

AI-assisted processing

Ayooda uses AI models to analyse messages, retrieve relevant knowledge, draft or stream responses, score interactions, summarise context, and perform customer-configured workflows. Inputs may include conversation content, selected knowledge, agent instructions, and tool results. Outputs are probabilistic and may be inaccurate.

Ayooda does not use the Service to make decisions that produce legal or similarly significant effects about individuals on our own behalf. Customers are responsible for human oversight and for deciding whether their use case requires additional notices, consent, or restrictions. Customers may configure a supported model provider or compatible endpoint, in which case data is also processed under that provider’s terms.

Cookies, local storage, and analytics

We use an essential, HTTP-only session cookie to keep dashboard users signed in. We also use browser storage for preferences such as theme and navigation state. The widget may store a visitor identifier and conversation identifier in session or local storage according to the customer’s selected conversation-memory settings.

We use Mixpanel for product analytics, including autocaptured interactions and session recordings on the public website and authenticated dashboard. This can include page views, clicks, navigation, device details, and an account identifier after sign-in. We use this information to understand adoption, diagnose usability issues, and improve the Service. Browser or device controls may limit cookies and storage, although disabling essential technologies can prevent parts of the Service from working.

How we disclose data

We do not sell personal data. We disclose data only as needed to operate the Service, follow customer instructions, or meet legal obligations, including to:

  • Infrastructure and security providers, including Google Firebase and Google Cloud;
  • AI and retrieval providers, including Pinecone, Vercel AI Gateway, model providers routed through the gateway, or a customer-configured model endpoint;
  • Payments and analytics providers, including Stripe and Mixpanel;
  • Communication and integration providers, such as Resend, Slack, Telegram, Twilio, webhooks, MCP servers, and other services a customer chooses to connect;
  • Professional advisers and authorities where reasonably necessary to comply with law or protect rights, safety, and security; and
  • A successor organisation in connection with a merger, financing, acquisition, reorganisation, or sale of assets, subject to appropriate safeguards.

Customer workspace administrators and authorised teammates can access data according to their permissions. A customer may also instruct Ayooda to send data to destinations it controls.

International data transfers

Ayooda and our service providers may process data in countries other than the country where it was collected. Where required, we use recognised safeguards for international transfers, such as adequacy decisions or contractual protections, and take supplementary measures where appropriate. You may contact us for information about the safeguards relevant to your data.

Data retention

We retain personal data only as long as reasonably necessary for the purposes described here, including providing the Service, meeting contractual and legal obligations, resolving disputes, and maintaining security. Retention depends on the type of data, customer configuration, account status, sensitivity, and legal requirements.

  • Customer content is generally retained while the relevant workspace or account remains active, unless deleted earlier by an authorised user or subject to a configured retention period.
  • Optional agent memory is retained for the customer-selected period, currently between 1 and 365 days.
  • Widget browser identifiers may persist for the customer-selected period, currently up to 30 days, or for the browser session.
  • Channel reliability events expire after 30 days.
  • Billing, audit, fraud-prevention, and legal records may be retained longer where required or reasonably necessary.

When data is deleted, it may remain temporarily in backups or restricted systems until normal deletion cycles complete.

Security

We use technical and organisational safeguards designed to protect personal data, including access controls, workspace isolation, encrypted storage of supported integration credentials, transport encryption, restricted administrative access, and security logging. No internet service is completely secure, so we cannot guarantee absolute security. Customers should use strong authentication, limit permissions, rotate credentials, and avoid placing unnecessary sensitive data in agents or conversations.

Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a portable copy of your personal data; object to certain processing; withdraw consent; and appeal or complain to a data-protection authority. You may also have the right not to receive discriminatory treatment for exercising a privacy right.

To make a request about an Ayooda account or our own website processing, email legal@ayooda.live. We may need to verify your identity and may retain limited information needed to document the request. If your request concerns a conversation with one of our customers, contact that customer first; we will assist the customer as required. You may lodge a complaint with your local supervisory authority.

Children

The Service is intended for organisations and is not directed to children. You must be at least 18 years old, or the age of legal majority where you live, to create an Ayooda account. Customers must not knowingly use the Service to collect children’s personal data without the notices, permissions, and safeguards required by law. If you believe a child has provided data unlawfully, contact us.

Changes and contact

We may update this Policy as the Service or law changes. We will post the revised version here, update the date above, and provide additional notice when a change is material and applicable law requires it.

Ayooda operates ayooda.live. Questions, requests, and privacy concerns can be sent to legal@ayooda.live. You can also review our Terms of Use.