1. Who we are
aiOS is operated by AI Genesis LLC, a Delaware limited liability company (“we,” “us,” “our”). Our office is located at 611 South DuPont Highway Suite 102, Dover, Delaware 19901.
2. What we collect
When you use aiOS, we may collect:
- Account information (email address, name, phone number)
- Website URL you provide during onboarding
- Publicly available content scraped from your website
- Chat messages and interactions with our AI agents (including iMessage conversations)
- Voice call recordings and transcripts (when voice features are used)
- AI-generated content created on your behalf (images, video, text, audio)
- Usage data (features used, actions taken, timestamps)
- Payment information (processed by our payment provider — we never store card numbers)
- OAuth tokens for connected services (encrypted at rest with AES-256-GCM)
- Device and browser information for security and fraud prevention
3. How we use your data
- To provide and improve aiOS services
- To analyze your website and generate content on your behalf
- To power AI agents that work for your business
- To process billing and manage your subscription
- To send service-related communications (onboarding, billing, support)
- To detect and prevent abuse or unauthorized access
- To maintain conversation context across messaging sessions
- To provide voice call transcripts and summaries
- To read, draft, and send email from a mailbox you connect (Gmail or Outlook) only when you explicitly ask the assistant to do so
4. Third-party services (subprocessors)
To deliver aiOS we partner with industry-leading providers across the following categories:
- AI and machine learning — Language models, image generation, and multimodal processing
- Cloud infrastructure — Hosting, compute, CDN, and DDoS protection
- Authentication and data storage — User identity, session management, and encrypted databases
- Payments — Billing and subscription processing (we never store card numbers)
- Messaging — iMessage, SMS, and email delivery
- Voice — Real-time voice processing, transcription, and AI calling
- Media generation — AI-powered video, image, and audio creation
- Integrations — Secure OAuth connections to CRM, social, and productivity tools
- Analytics — Anonymized product usage analytics
Our current sub-processors include:
- Supabase, Inc.— authentication and encrypted database (stores account data and encrypted connected-service tokens)
- DigitalOcean, LLC— cloud compute that runs the aiOS API and self-hosted services
- Vercel, Inc.— hosting for the aiOS web app and OAuth callback routes
- Anthropic, PBC(Claude), and where applicable OpenAI and Google — large language models that power the assistant
- Stripe, Inc.— payment and subscription processing (we never store card numbers)
- ElevenLabs, Inc.and our voice/telephony provider — voice synthesis, transcription, and AI calling
- Our SMS/iMessage and email delivery providers — message and email transport
- Media-generation providers (e.g. image and video model vendors) — AI-generated media you request
We only share the minimum data necessary for each provider to deliver their service, and we require each to protect it. We will notify you of material additions to this list; you can request the most current version anytime at privacy@ai-genesis.ai.
Sub-processors with access to Meta data. If you connect a Meta (Facebook/Instagram) account, the only providers that store or process your Meta data are Supabase (stores your encrypted access token and account identifiers), DigitalOcean (compute that calls the Meta APIs on your behalf, including our self-hosted OAuth broker), Vercel (completes the secure connection in the OAuth callback), and Anthropic(the language model that processes connected-account content — such as a post or comment you ask the assistant to act on — to deliver the feature you requested). Your Meta access token is never sent to a language model.
5. Facebook, Instagram & Meta data
If you connect a Facebook Page, an Instagram Professional account, or a Meta ad account to aiOS, we access data through the Meta APIs solely to provide the features you ask for — for example, publishing a post to your own Instagram account, replying to comments and messages on your own accounts, or reporting on your own ad campaigns. Specifically:
- We store an encrypted access token and basic metadata (account IDs, Instagram username, linked Facebook Page name, and ad-account name) needed to act on your behalf.
- We use this data only to deliver the connected features you requested through the aiOS assistant.
- We do not sell Meta data, use it for advertising to you, or share it with third parties beyond the subprocessors that operate aiOS.
- You can revoke access at any time by disconnecting the Meta card in Dashboard → Integrations, by deleting your account, or by removing aiOS in your Facebook Settings → Business Integrations. See our Data Deletion page for full instructions and our deletion callback.
Our use of information received from the Meta APIs adheres to the Meta Platform Terms and Developer Policies, including the Limited Use requirements.
6. Google data (Gmail & Google Calendar)
If you connect a Google account (Gmail and/or Google Calendar) to aiOS, we access your Google user data through the Google APIs solely to provide the features you ask the assistant for. Specifically:
- Gmail (read): with the
gmail.readonlyscope, when you ask the assistant to triage, search, summarize, or reply to your mail, we read only the messages needed to fulfil that request. - Gmail (send): with the
gmail.sendscope, when you explicitly instruct the assistant to send an email (you dictate the recipient, subject, and body), we send that one message from your connected Gmail account. The assistant shows you the draft and requires your confirmation before sending, and it sends only the messages you ask it to. We never send bulk, marketing, or automated mail through this scope, and we never send on our own behalf. - Google Calendar: with the Calendar scopes, we read and create events only when you ask the assistant to manage your schedule.
- We store an encrypted OAuth token (AES-256-GCM at rest) so the assistant can act on your behalf, and we obtain a fresh access token on demand. We do not store copies of your mailbox.
Limited Use.aiOS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide and improve the user-facing features you request; we do not transfer or sell it, do not use it for advertising, do not allow humans to read it (except with your explicit consent, for security or to comply with applicable law, or in aggregated/anonymized form for internal operations), and do not use Gmail or Calendar content to train generalized AI / ML models.
You can revoke aiOS's access to your Google data at any time by disconnecting the Gmail/Calendar card in Dashboard → Integrations, by deleting your account, or from your Google Account → Third-party access page. Disconnecting immediately revokes our stored token. See our Data Deletion page for full instructions.
7. Microsoft data (Outlook & Calendar)
If you connect a Microsoft account (Outlook mail and/or calendar) to aiOS, we access your Microsoft data through the Microsoft Graph API solely to provide the features you ask the assistant for. Specifically:
- Outlook mail (read & organize): with the
Mail.ReadWritepermission, when you ask the assistant to triage, search, summarize, draft, file, or clean up your mail, we read only the messages needed to fulfil that request and make only the changes you asked for (for example saving a draft or moving a message). We do not index or retain copies of your mailbox. - Outlook mail (send): with the
Mail.Sendpermission, when you explicitly instruct the assistant to send an email (you dictate the recipient, subject, and body), we send that one message from your connected Outlook account. The assistant shows you the draft and requires your confirmation before sending, and it sends only the messages you ask it to. We never send bulk, marketing, or automated mail through this permission, and we never send on our own behalf. - Outlook calendar: with the
Calendars.ReadWritepermission, we read and create events only when you ask the assistant to manage your schedule. - We store an encrypted OAuth token (AES-256-GCM at rest) so the assistant can act on your behalf, and we refresh it on demand. We do not store copies of your mailbox.
We use Microsoft data only to provide the user-facing features you request; we do not transfer or sell it, do not use it for advertising, do not allow humans to read it (except with your explicit consent, for security, or to comply with applicable law), and do not use your mail or calendar content to train generalized AI / ML models.
You can revoke aiOS's access to your Microsoft data at any time by disconnecting the Outlook card in Dashboard → Integrations, by deleting your account, or from your Microsoft account → Apps and services page (work and school accounts: myapps.microsoft.com). Disconnecting immediately revokes our stored token. See our Data Deletion page for full instructions.
8. TikTok data
aiOS integrates with TikTok's Content Posting API. If you connect your own TikTok account to aiOS, we access TikTok data solely to publish video content to your own TikTok account, on your behalf and with your explicit approval — for example, when you ask the assistant to post a video you provided or a branded video aiOS generated at your request. Specifically:
- Scopes we request. We request
video.publish(to publish a video directly to your connected account when you instruct us to),video.upload(to send a video to your TikTok inbox as a draft for you to finish), anduser.info.basic(to identify the connected account so we post to the correct profile). We request no other TikTok scopes. - First-party only. We post only to the single TikTok account you personally connected, only on your explicit instruction, and never in bulk. We do not post on our own behalf, do not operate or post to accounts you have not connected, and do not scrape or collect data from other TikTok users or from the public TikTok platform.
- You control visibility.Before every post, aiOS retrieves your account's available privacy options from TikTok and asks you to choose who can see the post — nothing is pre-selected and nothing is posted until you choose. We surface the relevant music-usage and branded-content disclosures and honor your account's posting eligibility and limits.
- What we access and store. We store an encrypted OAuth access token (AES-256-GCM at rest) and the basic account identifier needed to post on your behalf, isolated per tenant. We do not store a copy of your TikTok content library, followers, or analytics, and we obtain a fresh access token on demand.
- How we use it. We use TikTok data only to deliver the posting features you request. We do not sell TikTok data, use it for advertising, or share it with third parties beyond the subprocessors that operate aiOS.
- Disconnect & deletion. You can revoke access at any time by disconnecting the TikTok card in Dashboard → Integrations, by deleting your account, or from your TikTok app settings under Security & permissions → Manage app permissions. Disconnecting immediately revokes our stored token. See our Data Deletion page for full instructions and to request deletion of any associated data.
Our access to and use of information received from the TikTok APIs adheres to the TikTok Developer Terms of Service and the TikTok Developer Usage Guidelines, including their data-handling and limited-use requirements.
9. iMessage and SMS data
When you use aiOS via iMessage or SMS:
- Messages are relayed through our secure messaging infrastructure and processed by our AI
- We store message history to maintain conversation context
- Your phone number is stored securely and used only for service delivery
- We do not sell your phone number or message content to third parties
- You may request deletion of your message history at any time
10. Financial account data (budgeting features)
If you choose to connect bank accounts for budgeting features, this section describes how we collect, use, share, and protect that financial account information. Connecting is optional — every other part of aiOS works without it.
What we collect. When you connect through SimpleFIN, we receive read-onlydata: account names, institution names, balances, and transaction history (dates, amounts, descriptions). We never receive or store your bank username or password — you log into your bank at SimpleFIN, and your credentials stay there. The connection cannot move money; there is no payment or transfer capability in the protocol we use.
How we use it. To show you the budgeting insights you ask for (balances, spending, recurring charges, fees, low-balance warnings) and to send you the periodic money check-in you signed up for. Nothing else. All figures are computed by our own code on our own infrastructure.
What we share.We do not sell your financial data, and we do not share it with advertisers or data brokers. The only third parties that process it are the service providers that make the feature work: SimpleFIN (your bank connection, which you control directly), our database and hosting providers, and — for narration only — our AI provider, which summarizes budgeting numbers our code computed. We do not hand your raw transaction export to third-party AI services. We disclose financial data to others only if validly required by law.
How we protect it. Your connection token and financial descriptions are encrypted at rest (AES-256-GCM), with encryption keys stored separately from the database. Access is restricted by row-level security. Transactions older than about 13 months are automatically deleted on an ongoing basis.
Your controls.Tell the assistant to disconnect your bank at any time: we immediately and permanently delete your connection token and every synced balance and transaction on our side. Your SimpleFIN account is yours — you can also revoke or cancel it at simplefin.org, which cuts off our access at the source. Deleting your aiOS account deletes all of the above automatically.
11. Voice data
When you use aiOS voice features:
- Call audio may be recorded for quality assurance and to generate transcripts
- Recordings are stored in encrypted form and retained for 90 days
- Transcripts are associated with your account for context continuity
- You may request deletion of recordings at any time via privacy@ai-genesis.ai
12. Data security
- All data transmitted over HTTPS/TLS
- OAuth tokens encrypted at rest (AES-256-GCM)
- Row-Level Security on database tables (tenant isolation)
- Server-side API keys never exposed to client code
- Regular security audits of our infrastructure
- Isolated compute environments per customer (Enterprise tier)
- HMAC-based webhook verification for all integrations
Full details and verifiable claims are on our Security page.
13. Data retention
We retain your data for as long as your account is active. Upon account deletion, we remove your personal data within 30 days. Specific retention periods:
Biometric data (optional aiOS Presence pulse features) is governed by our separate Biometric Data & Retention Policy — it is stored only on your device and never reaches our servers.
- Account data: until account deletion + 30 days
- Message history: until account deletion + 30 days
- Voice recordings: 90 days (or earlier upon request)
- AI-generated content: until account deletion + 30 days
- Payment records: as required by law (typically 7 years)
- Aggregated, anonymized analytics data may be retained indefinitely
14. Your rights
You have the right to:
- Access your personal data
- Request correction of inaccurate data
- Request deletion of your data
- Export your data in a portable format
- Disconnect any connected service and revoke access
- Opt out of non-essential communications
- Object to processing of your data for certain purposes
- Withdraw consent at any time where processing is based on consent
To exercise any of these rights, email privacy@ai-genesis.ai. We will respond within 30 days.
15. California privacy rights (CCPA)
California residents have additional rights under the CCPA, including the right to know what personal information we collect and share, and the right to request deletion. We do not sell personal information. To make a CCPA request, email privacy@ai-genesis.aiwith the subject line “CCPA Request.”
16. European users (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the following applies:
- Legal basis: We process your data based on contractual necessity (to provide the Service), legitimate interest (to improve and secure the Service), and consent (for optional features like voice recording)
- Data transfers: Your data may be transferred to the United States where our servers are located. We rely on Standard Contractual Clauses (SCCs) where required
- Data Protection Officer: For GDPR inquiries, contact privacy@ai-genesis.ai
- Supervisory authority: You have the right to lodge a complaint with your local data protection authority
17. Children's privacy
aiOS is not directed at children under 18. We do not knowingly collect personal data from children. If we learn that we have collected data from a child, we will delete it promptly.
18. Changes to this policy
We may update this policy from time to time. We will notify you of significant changes via email or in-app notification at least 30 days before the changes take effect.
19. Contact
For privacy questions, contact us at privacy@ai-genesis.ai.
AI Genesis LLC
611 South DuPont Highway Suite 102
Dover, Delaware 19901