Skip to content
← Back

Privacy Policy

This Privacy Policy explains what personal data airays.ai and the Howdi product (together, "airays", "we") collect, how we use it, who we share it with, and what rights you have over it. It applies to airays.ai, smartchat.airays.ai, studio.airays.ai, and any related services we operate.

airays is provided by [airays, Inc.] (to be updated once the Delaware entity name is confirmed), a company organized in Delaware, United States. We act as the data controller for the information described below. If you use airays as part of an organization on the Business tier, that organization is the controller for its team's data and airays acts as data processor.

1. What we collect

Account information (via Clerk, our authentication provider):

  • Email address, and optionally name, profile photo, and handle
  • Authentication tokens and session records
  • Sign-in metadata: device user-agent string, IP address (fingerprinted after 30 days), timestamps
  • If you sign in via a third-party identity provider (Google, Apple, GitHub, etc. via Clerk), we receive from them your email address, name, and profile photo. We do not receive your friends list, contacts, or activity on those services.

Content you create in the product:

  • Peer chat messages (text, images, videos, voice notes)
  • Assistant chat threads with our AI, including your prompts and AI responses
  • AI-generated images, videos, and voice recordings you produce
  • Voice recordings you provide for voice-cloning training (see Section 2 — sensitive data)
  • Saved prompts, custom personas, and templates you author
  • Call recordings, transcripts, and summaries (only if you enable them)
  • Content in accounts you connect (Slack, Gmail, SMS via Twilio, WhatsApp Business)
  • Group workspace documents you edit collaboratively

Product usage and analytics:

  • Feature adoption events (which surfaces you use, high-level counts) — fingerprinted, not linked to your name in logs
  • Emotional Shield verdicts and any overrides you make
  • AI generation cost, credit usage, and per-feature meter readings
  • Aggregate performance data (page load, error rates) via Sentry — no personal content
  • Cloudflare Web Analytics (if enabled) — cookieless page-view counts

Payment information:

  • We use Paddle.com Market Limited ("Paddle") as our merchant of record. Paddle collects and processes your payment details (card number, billing address, country, tax ID). airays receives from Paddle only: order status, subscription tier, credit top-up amounts, and billing email — never card numbers or full addresses.
  • See Paddle's privacy policy at paddle.com/legal/privacy.

What we deliberately do not collect:

  • Third-party analytics cookies or trackers (no Google Analytics, no Facebook Pixel, no LinkedIn Insight)
  • Advertising identifiers or interest-based advertising signals
  • Full IP addresses in application logs (we store SHA-256 fingerprint prefixes only)
  • Message body content in application logs — ever, per our internal privacy-lint policy
  • Address book uploads (we do not scan your device contacts)
  • Location data (we do not collect precise geolocation)
  • Biometric data other than voice (no facial recognition, no fingerprint scanning)

2. Sensitive personal information

Some of the content you provide may include sensitive categories of personal data. We process these categories only with your explicit consent, and only for the purpose you provided them:

  • Biometric data — voice recordings and voice profiles you upload for cloning. Retained until you delete the profile or close your account. Every generation from a cloned voice is watermarked and logged in your evidence chain.
  • Health-related data — conversations you have with health-related personas (doctor, therapist, nutritionist, etc.). Encrypted at rest. Not used for training. You may delete any thread or the entire memory record at any time.
  • Sexuality, religion, political views, ethnic origin — may appear in personal chat content you send to other users. Encrypted at rest. We do not analyze this content for any purpose other than delivering the message and running Emotional Shield safety classification.

You can withdraw consent for processing of sensitive data at any time from Settings. Withdrawal does not affect the lawfulness of processing before withdrawal.

3. Legal basis for processing (EU / UK)

If you are in the European Economic Area, United Kingdom, or Switzerland, we rely on the following legal bases under Article 6 of the GDPR / UK-GDPR to process your personal data:

  • Contract performance (Art 6(1)(b)) — authenticating you, delivering messages, generating AI outputs, processing payment, providing customer support.
  • Legitimate interests (Art 6(1)(f)) — fraud prevention, security monitoring, aggregate service improvement, rate-limit enforcement, product analytics in de-identified form. You may object to processing based on legitimate interest at privacy@airays.ai.
  • Consent (Art 6(1)(a)) — voice cloning, cross-thread memory, marketing communications, connector authorization, use of sensitive data categories. Withdrawable at any time.
  • Legal obligation (Art 6(1)(c)) — retention of billing records for tax purposes, response to lawful government requests, CSAM reporting under applicable law.

4. How we use your data

  • To operate the service: deliver messages, generate AI outputs, run voice/video calls, apply Emotional Shield safety checks, extract memory, classify inbox
  • To personalize your experience: cross-thread memory (Pro+ only), template recommendations, priority-inbox learning — you can turn these off
  • To bill for paid plans and enforce tier limits and fair-use caps
  • To improve the service through aggregated, anonymized product usage analysis
  • To protect the service against fraud, abuse, and legal risk
  • To communicate with you about your account, security events, and product updates you have opted into
  • To comply with law and respond to lawful government requests

We do NOT:

  • Sell your personal information (as that term is defined under CCPA / CPRA)
  • Share your personal information for cross-context behavioral advertising
  • Use your content, prompts, responses, or messages to train third-party AI models (see Section 5)
  • Serve third-party behavioral advertisements or tracking pixels on airays
  • Share your content with third parties for their marketing purposes
  • Analyze your chat content to target advertisements at you

Affiliate recommendations (planned). When you explicitly ask Howdi for a product or service recommendation (e.g., "recommend a car" or "which laptop should I buy"), Howdi may include affiliate-tagged links in its response. airays may earn a small commission if you click through and purchase, at no additional cost to you. Every affiliate link is disclosed at the point of use.

What this does not involve:

  • We do NOT share your chat content, prompts, or personal information with affiliate networks or merchants
  • We do NOT analyze your general chat conversations to select ads or offers
  • We do NOT profile you across conversations for advertising
  • We do NOT run banner ads, video ads, pop-ups, or sponsored system messages during your conversations

When you click an affiliate link, you leave airays and the third-party merchant / affiliate network sees the click and may set their own cookies on their site (which are governed by their own privacy policies). See the Affiliate Disclosure for the full explanation. You can turn off affiliate recommendations in Settings → Privacy → Affiliate Recommendations.

Affiliate recommendations are opt-out on Free and Pro tiers. Business tier is affiliate-free by default (see the Business Supplement). This feature is planned; specific affiliate networks used will be listed in the sub-processors section below once integrated.

5. AI processing and training

When you interact with the AI in airays (chat, image gen, voice, etc.), your input is sent to one of our AI sub-processors (Anthropic, OpenAI, Replicate, ElevenLabs, Deepgram — see Section 7). The provider processes the request, returns an output, and the exchange is stored in your account under the retention periods described in Section 8.

Training on your content. We do NOT use your prompts, responses, message content, voice recordings, or generated outputs to train any AI model. Our AI providers do NOT train on our API traffic — this is contractually enforced under the enterprise or business terms we use with each provider (Anthropic's Zero-Retention API terms, OpenAI's Enterprise privacy terms, ElevenLabs Business terms, Replicate Business terms).

Aggregate improvement. We may compute aggregated, de-identified metrics from your usage (e.g., "average credits spent per Pro user per month", "top-10 most popular personas") to improve the product. These metrics cannot be linked back to you.

Human review. We do not routinely have humans read your peer messages, assistant chats, voice recordings, or generated content. Human review is limited to the following circumstances, in each case handled by a small number of authorized personnel under strict access controls:

  • Abuse reports — when another user reports a message you sent or a template you submitted, our moderators review the reported content to decide the enforcement action
  • Community-submission moderation — templates you submit to the shared community catalogue are reviewed by an automated classifier; borderline submissions are escalated to a human editor
  • Shield-override audit — Emotional Shield overrides are logged; aggregate patterns may be reviewed to tune the classifier, individual overrides are only reviewed following a specific incident
  • Debugging — engineers may access aggregated logs (fingerprint hashes only, no message content) to diagnose bugs; if a bug requires reading actual content, we do so only with your explicit consent or under a documented incident-response process
  • Legal process — we may review specific content in response to a valid legal request or to protect our rights or the safety of users

Content shared with our AI sub-processors (Anthropic, OpenAI, etc.) may be subject to those providers' own safety-review processes as documented in their terms. Our enterprise/business agreements with these providers restrict their use to what is strictly necessary for safety.

6. Automated decision-making

The following airays features involve automated processing of your content. None of these produces legal or similarly significant decisions about you without human involvement:

  • Emotional Shield classifies message tone before sending. You can override any classification. Overrides are logged in your evidence chain.
  • Command Centre classifier categorizes inbound messages into priority buckets. You can move messages between buckets or disable the classifier in Settings.
  • Memory extractor identifies facts and preferences from your conversations to personalize future responses. You can view, edit, and delete any memory item at Memory → Facts.
  • Content generation via large-language and image models produces AI Outputs based on your prompts.

Under GDPR Article 22 and equivalent laws, you have the right to obtain human review of any significant automated decision about you. Contact privacy@airays.ai.

7. Sub-processors

We use the following sub-processors to operate airays. Each has access to only the data necessary to perform its function.

  • Cloudflare (worldwide) — hosting, edge network, storage (D1, R2, KV), analytics
  • Clerk (United States) — authentication and identity
  • Paddle (worldwide, EU headquarters) — payment processing and tax compliance
  • Anthropic (United States) — LLM inference under Zero-Retention API terms (chat, memory extraction, safety classifiers, translation, summaries)
  • OpenAI (United States) — voice transcription (Whisper), voice synthesis (TTS), real-time voice agent (Realtime API) under Enterprise privacy terms
  • Replicate (United States) — image and video generation via hosted model providers
  • ElevenLabs (United States) — premium voice synthesis and voice cloning
  • Deepgram (United States) — streaming speech-to-text for live call captioning
  • LiveKit (worldwide) — WebRTC signaling and SFU for voice/video calls
  • Resend (United States) — transactional email delivery
  • Sanity (Norway / United States) — marketing content management
  • Sentry (United States) — error and performance monitoring (application errors only; no user content)

When you enable a connector (Slack, Gmail, Twilio SMS, WhatsApp Business), those third parties become sub-processors for your connected traffic under their own terms and privacy policies.

A current list of sub-processors, updated within 30 days of any addition or removal, is maintained here. Material changes will be notified by email at least 30 days in advance for Business customers.

8. Data retention

We retain your personal data only for as long as necessary for the purposes described in this policy. Specific periods and their rationale:

  • Account and profile: for the duration of your account. Rationale: authenticating you.
  • Peer messages: 30 days on Free tier; for the duration of your account on Pro and Business tiers, subject to your own delete actions. Rationale: providing chat history you rely on.
  • Assistant threads: same as peer messages.
  • Call recordings: 7 days on Free; 30 days on Pro; 1 year on Business. Rationale: post-call review; longer for enterprise compliance needs.
  • AI-generated content: retained with your account until you delete it or close your account. Rationale: it is your content.
  • Voice profiles for cloning: retained until you delete the profile or close your account. Rationale: to generate voice from your profile on request.
  • Memory items (facts, patterns, episodes): retained until you delete them or close your account. Rationale: personalization you rely on.
  • Evidence chain entries: for the duration of your account. Rationale: audit and provenance verification.
  • Server logs: 30 days rolling. Contain fingerprint hashes only. Rationale: debugging and security incident response.
  • Anonymized first-message samples: 30 days, no user identifier stored. Rationale: prompt-library coverage analysis in aggregate.
  • Billing records: retained by Paddle for at least 7 years. Rationale: tax and audit compliance.
  • Backups: encrypted, rolling 30-day window. Rationale: disaster recovery.

Deletion cascades are described in Section 10 below.

9. Cookies and local storage

airays uses a small number of first-party cookies necessary for the service to function. We do not use third-party analytics cookies, marketing pixels, or cross-site tracking. See the full Cookie Policy for a per-cookie breakdown.

10. Your rights and how to exercise them

Regardless of where you live, you can:

  • Access your data by exporting it from Settings → Account → Export my data. Delivered as a signed download link within 24 hours.
  • Correct your data by editing profile fields in Settings.
  • Delete your account and all associated data from Settings → Account → Delete account. Deletion cascades through every airays system within one hour of confirmation; encrypted backups purge on the next 30-day backup cycle. See Section 11 below for exactly what gets purged.
  • Withdraw consent for voice cloning, memory features, marketing communications, or connectors at any time in Settings. Withdrawal does not affect the lawfulness of processing before withdrawal.
  • Opt out of non-essential communication in Settings → Notifications.
  • Object to automated processing or request human review at privacy@airays.ai.
  • Data portability: your export is provided in machine-readable JSON + open-format files (mp3 audio, jpeg/png images, mp4 video).

We respond to data-subject requests within 30 days (GDPR) or 45 days (CCPA), extendable once by a further 30/45 days for complex requests with notice to you. We may need to verify your identity before responding.

If we deny your request, we will explain why and how to appeal. You may also lodge a complaint with your local data protection authority (EU / UK) or with the California Privacy Protection Agency (California residents).

11. Account deletion — what happens

When you delete your account, within one hour airays purges:

  • Your user profile record (name, email link, avatar, handle)
  • Every message you sent (in DMs and groups; group message bodies remain visible to other participants but your identity is removed)
  • Every memory item extracted from your conversations, including facts other users held about you
  • Every voice recording, voice-cloning profile, and voice note you own
  • Every AI-generated image, video, story, or voice you created
  • Every saved prompt, custom persona, and template you authored
  • Every connector account you linked (Slack, Gmail, Twilio, WhatsApp Business)
  • Every policy, budget, evidence-chain entry, and call transcript tied to your account
  • All R2-stored files (voice, images, videos, attachments, profile samples)
  • All conversations where you were the sole remaining participant

Content you submitted to the shared community prompt catalogue may remain published as anonymous community content (your name is never attached to public templates). If you want a community template removed as well, email privacy@airays.ai.

Encrypted backups are eligible for deletion in the next backup cycle (typically 30 days). We do not undelete data from backups.

Billing records held by Paddle are retained separately per Section 8 and are subject to Paddle's own privacy policy.

12. International data transfers

airays operates on Cloudflare's global edge network. Your data may be processed in data centers around the world. Sub-processors based in the United States receive personal data under:

  • The Standard Contractual Clauses (SCCs) adopted by the European Commission on 4 June 2021 (implementing decision (EU) 2021/914), for transfers from the EEA
  • The UK International Data Transfer Addendum to the SCCs, for transfers from the UK
  • The Swiss Federal Data Protection Act, for transfers from Switzerland
  • The EU-US Data Privacy Framework where applicable

A copy of the safeguards applied to a specific transfer is available on request at privacy@airays.ai.

13. Marketing communications

We send you two categories of email:

  • Transactional — billing receipts, security alerts, service updates, legal notices. Required for the service; you cannot opt out while your account is active.
  • Marketing — product news, feature launches, tips. Opt-in during signup or in Settings → Notifications. Unsubscribe at any time via the email footer or Settings.

14. Security

We store user content (message bodies, voice recordings) encrypted at rest with per-conversation keys derived from a master secret held in Cloudflare's secure secret store. We use HTTPS for all network traffic. Server-side logs are fingerprint- only; message content never enters logs. Access to production systems is restricted, MFA-required, and audited.

Every AI generation is watermarked (visible + machine-readable) and logged in a cryptographic evidence chain scoped to your account. You can export the chain at any time and use it to verify the provenance of content attributed to you.

No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify:

  • Relevant supervisory authorities within 72 hours (as required by GDPR Article 33)
  • You without undue delay if there is a high risk to your rights and freedoms (GDPR Article 34)
  • Affected users in accordance with US state breach-notification laws

15. Children

airays is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe we may have collected information from a child under 13, please contact privacy@airays.ai and we will delete it.

Users aged 13-15 may only use airays with a parent or guardian's consent, per Section 2 of our Terms of Service.

16. Do Not Track and Global Privacy Control

airays does not sell or share personal information for cross- context behavioral advertising, so Do Not Track (DNT) signals and Global Privacy Control (GPC) signals do not change our processing behavior.

17. California privacy rights (CCPA / CPRA)

If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

  • Right to know what personal information we collect and how we use it (see Sections 1, 4, and 7)
  • Right to delete your personal information (Settings → Delete account, or contact us)
  • Right to correct inaccurate personal information
  • Right to opt out of sale or sharing — we do not sell or share personal information as those terms are defined by the CCPA. Nothing to opt out of.
  • Right to limit use of sensitive personal information — see Section 2
  • Right to non-discrimination for exercising your rights
  • Right to portability — export your data from Settings → Account → Export my data

Categories of personal information collected in the past 12 months, per CCPA §1798.140: identifiers, personal information categories listed in Cal. Civ. Code §1798.80(e), commercial information, internet/network activity, audio/electronic information, professional information, inferences.

Categories sold in the past 12 months: none.

Categories shared for cross-context behavioral advertising: none.

Categories disclosed for a business purpose: to sub-processors listed in Section 7, only as needed to operate the service.

Retention: as described in Section 8. Contact us at privacy@airays.ai to exercise these rights.

18. European Union and United Kingdom

If you are in the EEA, UK, or Switzerland, in addition to the rights described in Section 10, you have the rights of access, rectification, erasure, restriction, portability, and objection under the GDPR / UK-GDPR. You have the right to lodge a complaint with your local supervisory authority. A list is maintained by the European Data Protection Board at edpb.europa.eu and by the UK ICO at ico.org.uk.

airays does not have an appointed EU representative (Article 27) at this time, given the scale of the preview launch. We will appoint one as required by law once we exceed the thresholds. Until then, contact us at privacy@airays.ai.

19. Other jurisdictions

Users in other jurisdictions with data-protection laws (Brazil LGPD, Canada PIPEDA, Australia APPs, India DPDPA, and others) have equivalent rights of access, correction, deletion, and portability. Contact privacy@airays.ai to exercise them.

20. Changes to this policy

We may update this Privacy Policy from time to time. Material changes (new sub-processors, expanded data collection, or changes to how we share data) will be notified by email or in-product notice at least 30 days before they take effect.

21. Contact

For any privacy question, including data-subject requests: privacy@airays.ai. We respond within 30 days.

Data Protection contact for airays: [Name and postal address pending — will be added by counsel before payment launch].