Aigenzey Privacy Policy
Effective date: August 20, 2026
This Privacy Policy explains how Aigenzey (“Aigenzey,” “we,” “us,” or “our”) collects, uses, discloses, and protects information when you use Aigenzey Cowork (the “Service”), our AI-powered workspace application.
Aigenzey is a brand operated by Aigentic Technologies Private Limited (“the Company”). References to “Aigenzey” throughout this policy mean the Company acting under that brand. See Contact Us for how to reach us regarding this policy.
By using the Service, you agree to the collection and use of information in accordance with this policy. If you use the Service on behalf of an organization, this policy applies to your organization’s use as well, and your organization’s administrator may be able to view or manage certain settings and data as described below.
Table of contents
- Information we collect
- How we use your information
- How we share your information
- Human access to your data
- Data protection and security
- AI and machine-learning processing
- Data retention
- Deleting and exporting your data
- Your rights and choices
- Children’s privacy
- International data transfers
- Contact us
- Changes to this policy
1. Information we collect
1.1 Account and profile data
When you or your organization create an Aigenzey account, we collect:
- Your name, work email address, and (for password-based accounts) a password, which we store only as a one-way cryptographic hash — we never store your password in plain text and cannot recover it for you.
- If your organization signs up directly, we also collect the organization name, a business phone/mobile number, and, if provided, the department(s) and role you belong to within your organization.
- If you sign in using a third-party identity provider (for example, a “single sign-on” button, or your organization’s own identity provider), we receive your name, email address, and a stable account identifier from that provider so we can create and recognize your account. We do not receive your password from that provider, and we do not request ongoing access to that account beyond confirming your identity for sign-in.
- Your browser-detected timezone, which we store so that scheduled actions and displayed times are shown correctly to you.
We do not collect your home address, date of birth, or any government- issued identification number as part of account creation.
1.2 Content you provide or generate
We collect and store the content you create or provide while using the Service, including:
- Messages you send to the Service and the responses it generates.
- Files you upload (such as images, PDFs, and office documents) and files the Service generates for you (such as documents, presentations, spreadsheets, and images).
- Reusable “skills,” saved memory items, and organizational knowledge entries you or your organization choose to save within the Service.
1.3 Data from connected third-party accounts
The Service lets you optionally connect third-party accounts — such as an email account, a calendar, a cloud file-storage/document/spreadsheet/ presentation account, a professional networking account, a social media account, a team messaging account, or various business and productivity tools — so that the Service can act on your behalf inside those tools.
Connecting an account is always your choice, made one account at a time, through that provider’s own consent screen, which tells you exactly what access you are granting. We only request the specific, narrow permissions needed to power the features you use, and where a provider offers a narrower, read-only alternative to a broader permission for the same feature, we request the narrower one. For example, for an email account we request the ability to read, compose, and send messages on your behalf, but we deliberately do not request permission to permanently and irrecoverably delete your entire mailbox. For document, spreadsheet, and presentation storage accounts, we typically request read-only access.
Depending on which accounts you connect, the data we may access includes:
- Email: message content, so the Service can read, search, draft, and send email at your direction.
- Calendar: event details (times, attendees, descriptions), so the Service can view, create, update, or manage your calendar at your direction.
- Files, documents, spreadsheets, and presentations: the content of files you direct the Service to read, so it can summarize, analyze, or work with them.
- Professional networking / social media accounts: your profile information and, where you authorize it, the ability to post or manage content on your behalf.
- Team messaging / chat accounts: messages and channel information you direct the Service to read or send.
- Other connected business tools (for example, project-management, support, CRM, HR, or developer tools): the specific data those integrations are built to read or act on, always scoped to your own granted permissions.
Each connected account is private to the individual user who connected it. Even within the same organization, one user’s connected-account access and data are never visible to or usable by another user. You can disconnect any connected account at any time from within the Service; doing so immediately revokes and deletes the credentials we stored for that connection (see Section 8).
1.4 Usage and technical data
- Cookies: the Service uses a small number of strictly necessary, first-party cookies to keep you securely signed in — essentially, a session cookie that identifies your logged-in session and, for administrators of our operator console, a separate session cookie for that console. These cookies are marked so they cannot be read by scripts on other sites and are only sent over a secure connection in production. We do not use advertising cookies, analytics cookies, cross-site tracking cookies, or any third-party tracking pixels or scripts. We do not use any third-party analytics, advertising, or telemetry service.
- IP address: we use your IP address for security purposes — to apply rate limits that prevent abuse (such as automated password-guessing) and to enforce access rules an organization or Aigenzey may configure. We do not log your IP address as part of your ongoing activity history.
- Timezone: as noted in Section 1.1, your browser-reported timezone is stored to correctly display and schedule times for you.
1.5 What we do not collect
We do not collect payment card numbers or other payment credentials — the Service does not currently process payments directly. We do not collect biometric data or precise real-time geolocation.
2. How we use your information
We use the information described above only to provide, maintain, and improve the user-facing features of the Service that are visible and prominent within it — for example, using your connected email account’s data to draft or send an email you asked for, or using calendar data to answer a question you asked about your schedule. We also use it to:
- Create and maintain your account and your organization’s workspace.
- Operate core product functionality, including the AI assistant, generated documents, saved skills, and organizational knowledge features.
- Communicate with you about your account — for example, verifying your email address, confirming a password reset, or notifying you of a workspace invitation. We do not send marketing or promotional email; every email we send is transactional, tied to an action you or your organization took.
- Maintain the security, integrity, and reliability of the Service, including detecting and preventing abuse, fraud, and unauthorized access.
- Comply with applicable law.
We do not, and will not:
- Use your data, or data derived from it, to serve advertising of any kind, including retargeting, personalized, or interest-based advertising.
- Sell or transfer your data to advertising platforms, data brokers, or information resellers.
- Use your data to determine your creditworthiness or for lending purposes.
- Use data obtained through a connected third-party account for any purpose beyond providing or improving the specific, visible feature you authorized it for.
These restrictions apply to your raw data and to any data aggregated, anonymized, or derived from it.
3. How we share your information
We do not sell your data, and we share it only in the following limited circumstances:
- To provide the feature you requested, with your consent. For example, your organization administrator may be able to see workspace-level activity needed to administer your organization’s account.
- With service providers who process data on our behalf, under contractual obligations that restrict them to the purposes we direct — for example, infrastructure hosting and transactional email delivery. See Section 6 for how AI processing providers specifically are handled, which we treat as its own category given the sensitivity of that processing.
- For security purposes — for example, to investigate suspected abuse, a security incident, or a bug.
- To comply with applicable law, a valid legal process, or to protect the rights, property, or safety of Aigenzey, our users, or others.
- As part of a merger, acquisition, or sale of assets involving Aigenzey — but only after we obtain your explicit, prior consent, in the case of data obtained through a connected third-party account.
We do not otherwise transfer, disclose, or sell your data — including data obtained from connected third-party accounts — to any other party. In particular, we never transfer or sell such data to advertising platforms, data brokers, or information resellers, and we never use or transfer it to train third-party general-purpose AI/ML models (see Section 6).
We require every employee, contractor, and service provider who may encounter your data to comply with the obligations described in this policy.
4. Human access to your data
Your content is processed automatically by our systems and AI models to generate the responses and outputs you request. We do not allow any person — including our own staff — to read your messages, files, or data obtained from a connected account, except in the following narrow circumstances:
- You have first given your affirmative agreement to have a specific message, file, or other item reviewed by a person (for example, if you ask us for help troubleshooting a specific result).
- It is necessary for security purposes, such as investigating a bug or suspected abuse.
- It is necessary to comply with applicable law.
- The data has been aggregated and/or de-identified, and is used only for internal operations, consistent with applicable privacy laws.
5. Data protection and security
We apply technical and organizational measures designed to protect your data, including:
- Encryption of connected-account credentials. Access tokens and secrets for any third-party account you connect are encrypted before being stored, using industry-standard symmetric encryption, and are decrypted only at the moment they are needed to make an authorized request on your behalf.
- Password hashing. Passwords are never stored in plain text; they are hashed using a modern, computationally hardened hashing algorithm designed to resist offline attacks.
- Encrypted transport. Connections to the Service are encrypted in transit, and in production, session cookies are transmitted only over encrypted connections.
- Secure session handling. Session cookies are marked so they cannot be read by page scripts and are not sent across sites.
- Tenant data isolation. Data belonging to your organization — and within it, the credentials and connections tied to your individual account — is logically separated from other organizations’ and other users’ data.
- Upload safeguards. Uploaded file names and content are validated and sanitized before storage and use, to prevent them from being used to manipulate the Service or access data they shouldn’t.
- Layered defenses against malicious content. Because the Service reads content from external sources (such as connected accounts and the web) on your behalf, we apply multiple layers of automated screening and confirmation steps designed to detect and stop attempts to manipulate the AI assistant through that content before it can take a sensitive action.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a security incident affecting your data, we will notify you and take appropriate steps as required by applicable law.
6. AI and machine-learning processing
The Service uses artificial intelligence and machine-learning models — including models operated by third-party AI providers — to generate the responses, drafts, summaries, and other outputs you request. This means content you provide, and content obtained from any third-party account you connect, may be transmitted to a third-party AI model provider solely to produce the specific output you asked for in that moment.
6.1 Limited Use and platform integration standards
Aigenzey’s use and transfer of information received from third-party APIs and platform integrations to any other application or service strictly adheres to industry-standard platform user data policies and Limited Use requirements:
- Prominent user-facing features only. Data received via connected third-party APIs is used solely to provide, operate, or improve user-facing features that are visible and prominent within the Service interface at your direct instruction (for example, reading a document to summarize it, inspecting schedule availability, or drafting an email you requested).
- Strict transfer limitations. We do not transfer data received from third-party APIs to any third party, except: (a) as necessary to provide or improve the user-facing features you explicitly authorized; (b) to comply with applicable law; (c) for security and abuse investigations; or (d) in connection with a merger, acquisition, or sale of assets, and only with your prior explicit consent.
- No advertising, marketing, or data resale. Under no circumstances do we transfer, sell, or disclose connected account data to third parties such as advertising platforms, data brokers, or information resellers, nor do we use it for serving advertisements (including personalized, targeted, or retargeted ads) or determining creditworthiness.
- Strict human access limitations. No humans (including Aigenzey staff) are permitted to read raw or derived user data obtained through third-party APIs, unless: (a) you have provided affirmative agreement to review specific items for troubleshooting or support; (b) required for security, bug, or abuse investigations; (c) required by applicable law; or (d) the data is aggregated and anonymized for internal operational metrics.
- Prohibition of unauthorized AI model training. Data obtained through connected third-party APIs is never used, transferred, or sold to train, fine-tune, or otherwise improve any generalized, foundational, or third-party AI/ML models without your explicit, affirmative consent. We select AI model providers under enterprise terms that prohibit them from retaining or using submitted data to train their own models.
6.2 Connected platform and workspace data disclosures
The following disclosures apply to data accessed from connected third-party platforms, identity providers, and workspace productivity tools:
- Connected Platform Data Accessed: Depending on the specific features or
connectors you choose to authorize:
- Single Sign-on / Identity: Name, email address, profile picture, and stable account identifier to authenticate and identify your account.
- Email Integrations: Email message body, subject lines, sender/recipient headers, message labels, and draft content to read, summarize, draft, send, and organize emails at your direct instruction.
- Calendar Integrations: Calendar events, meeting titles, descriptions, times, and attendee lists to view your availability, summarize schedules, and create or update meetings you request.
- Cloud Storage & Document Integrations: File metadata and content of documents, spreadsheets, and presentations in read-only mode to summarize or reference specific documents you select.
- How We Use Connected Platform Data: Connected platform user data is used exclusively to power visible, user-initiated productivity workflows within the Service interface. It is never used for advertising, marketing, profiling, or credit scoring.
- Sharing, Transfer, and Disclosure of Connected Platform Data: We do not sell, rent, or transfer connected platform user data to any third party, data brokers, or advertising platforms. Data is transmitted to third-party AI providers strictly in real-time to execute the specific task you request, subject to enterprise zero-data-retention agreements where the AI provider is contractually prohibited from using your data to train their models.
- Data Protection Mechanisms for Sensitive Data: All connected platform data is encrypted in transit using TLS 1.3 and encrypted at rest using AES-256 encryption for authentication tokens and credentials. Each connected account is logically isolated to the individual authorizing user and is never accessible to other workspace members or administrators. Personnel are strictly prohibited from reading connected platform user data.
- Retention and Deletion of Connected Platform Data: Stored authentication tokens and credentials are permanently deleted immediately upon disconnecting the connector or deleting your Aigenzey account. Transient processing caches and generated draft artifacts are automatically purged within 30 days. You can also revoke Aigenzey’s access at any time via your connected platform provider’s account security settings.
- Affirmative Limited Use Compliance Statement:
Aigenzey’s use and transfer to any other app of information received from connected third-party platform APIs adheres to strict Limited Use requirements and the data protection principles defined in this Privacy Policy.
Today, the Service routes AI processing exclusively to third-party, API-hosted AI models — the Service does not currently operate a self-hosted or offline model that would avoid third-party transmission entirely. If that changes for a given model, we will update this policy to describe that setup and confirm that data processed by it is handled locally and not shared with any model provider for training or other secondary purposes.
We apply the same restrictions described in Section 3 to data shared with AI processing providers: it is never sold, never used for advertising, and never used to assess creditworthiness.
7. Data retention
We retain different categories of data for different periods, based on how long they are needed to provide the Service:
- Generated files (documents, presentations, images, and similar artifacts the Service creates for you) are retained for approximately 30 days, after which older, unused versions are automatically removed.
- Internal processing logs used to power and improve specific features (such as records of the steps an AI-assisted task took) are retained for approximately 30 days.
- Conversation history is retained until you delete it, subject to a reasonable per-user cap on the number of stored conversations, beyond which the oldest conversations are automatically removed to make room for new ones.
- Saved memory and organizational knowledge items you or your organization choose to create are retained until you or an administrator deletes them, or until your account or organization is deleted.
- Connected-account credentials are retained only for as long as the connection remains active; disconnecting an account deletes its stored credentials immediately (see Section 8).
- Records we are required to keep for accountability, security, or legal compliance purposes (such as administrative activity logs) are retained for longer periods as reasonably necessary for those purposes, even after other account data has been deleted.
8. Deleting and exporting your data
You can request an export of your data, or the deletion of your account and associated data, at any time. Depending on your organization’s configuration, this may be available directly within the Service, or by contacting us or your organization administrator as described in Section 12; either way, we will act on your request within a reasonable time and confirm once it is complete.
When you delete your account or disconnect a connected third-party account:
- Stored credentials for that connection are deleted immediately, and we make no further requests to that account.
- Your personal content is removed from our active systems, other than data we are required or permitted to retain as described in Section 7 (for example, accountability logs, or data your organization has designated as shared organizational knowledge rather than your personal data).
- If you are the only member of your organization’s workspace, deleting your account also removes your organization’s workspace data.
- If you are one of several members of your organization’s workspace, content you designated as personal is removed, while content your organization has designated as shared (such as an organization-wide knowledge base entry) remains available to your organization, consistent with how shared workspace tools generally operate.
9. Your rights and choices
Depending on your location and applicable law, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. We honor these rights for all our users as a matter of policy, regardless of where you are located. To exercise them, use the in-app option where available, or contact us as described in Section 12.
You also control:
- Connected accounts: connect or disconnect any third-party account at any time from within the Service. You can also revoke Aigenzey’s access directly from that provider’s own account-security settings at any time.
- Optional features that learn from your activity (such as a feature that learns your writing style to help draft content in your voice): these are opt-in, and you can decline or later withdraw consent, which stops further use of that feature going forward.
10. Children’s privacy
The Service is intended for business and professional use and is not directed to, and should not be used by, children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will take appropriate steps to delete it.
11. International data transfers
Depending on where you and your organization are located, your data may be processed in a country other than the one in which you reside, including by the service providers described in Section 3. Where we transfer data internationally, we take steps intended to ensure it receives an appropriate level of protection consistent with this policy and applicable law.
12. Contact us
If you have questions about this Privacy Policy, or want to exercise any of the rights or choices described above, contact us at:
Email: support@aigenzey.com
Company: Aigentic Technologies Private Limited, operating as Aigenzey
For formal legal correspondence, please direct communications to the Company at the above email, and we will provide further routing information as needed.
13. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. If we make material changes, we will notify you through the Service or by other reasonable means before the change takes effect. The “Effective date” at the top of this policy indicates when it was last revised.