Effective Date: March 5, 2026 | Last Updated: March 5, 2026
Aiva.io ("Aiva", "we", "us", or "our") is an AI-powered communication assistant operated by Aiva.io. Our registered business is located in Australia.
This Privacy Policy explains how we collect, use, disclose, store, and protect your personal information when you access or use our website at www.tryaiva.io (the "Website"), our application, and any related services (collectively, the "Service").
By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with the practices described herein, please do not use the Service.
This Privacy Policy is designed to comply with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), the General Data Protection Regulation (GDPR) (EU/EEA), the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), the Google API Services User Data Policy, and other applicable data protection laws.
For the purposes of this Privacy Policy:
Aiva integrates with Google services to provide AI-powered email management and calendar scheduling. This section specifically addresses how we access, use, store, and protect data obtained through Google APIs, in compliance with the Google API Services User Data Policy and the Google APIs Terms of Service.
When you connect your Google account, Aiva requests the following OAuth scopes and accesses the corresponding data:
| OAuth Scope | Data Accessed |
|---|---|
| gmail.readonly | Email messages (subject, body, sender, recipients, timestamps, labels, attachments metadata) |
| gmail.send | Ability to send emails on your behalf (only AI-drafted replies you approve, or auto-send with your configured thresholds) |
| userinfo.email | Your Google account email address |
| userinfo.profile | Your Google account name and profile picture |
| calendar.readonly | Calendar events (title, time, location, attendees, description) |
| calendar.events | Ability to create and modify calendar events (for AI-assisted scheduling) |
Google User Data is used exclusively to provide and improve the Aiva Service. Specifically:
Google User Data is shared only with:
We do NOT:
Aiva's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
When you create an account, we collect your name, email address, and authentication credentials. If you sign in via a third-party OAuth provider (Google, Microsoft, GitHub), we receive your name, email, and profile picture from that provider. For Shopify merchants, we also receive your store name, domain, owner information, and store email through Shopify's OAuth system.
To provide our AI inbox assistant services, we access and store messages from your connected communication channels (Gmail, Microsoft Outlook) with your explicit permission. This includes email subject lines, body content, sender and recipient information, timestamps, labels, and attachment metadata. This data is used solely to power AI features such as classification, reply drafting, summarisation, task extraction, and scheduling.
When you connect your Google Calendar or Microsoft Outlook Calendar, we access event details including titles, descriptions, times, locations, attendees, and organiser information. This is used for scheduling conflict detection and AI-assisted event creation.
If you use Aiva through our Shopify App, we access and store customer data (name, email, phone, address, order history), order data (financial details, line items, shipping addresses), and product data (titles, descriptions, pricing) from your Shopify store. This data is used to provide AI-powered customer support and contextual replies to customer inquiries.
We automatically collect information about how you interact with our Service, including features used, pages visited, messages processed, AI actions taken (classifications, drafts generated, auto-sends), preferences set, timestamps of interactions, and error logs. This is collected through privacy-respecting analytics tools.
We collect your IP address, browser type and version, operating system, device type, referring URLs, and timezone. This information is used for security, fraud prevention, and service optimisation.
If you use the Voice Aiva feature, your voice audio is transmitted to OpenAI's Whisper API for speech-to-text transcription. The transcribed text and AI responses are stored as part of your voice conversation history. Voice audio is not permanently stored by Aiva.
Payment processing is handled by Stripe (for web customers) and Shopify Billing (for Shopify App users). We do not directly store your credit card numbers. Stripe and Shopify store your payment details securely under their respective privacy policies and PCI DSS compliance.
We use the information we collect for the following purposes:
We process your personal information on the following legal bases:
We do not sell your personal information or Google User Data to any third party. We never have and never will.
We share data with the following categories of third-party service providers, solely to operate and improve the Service:
| Provider | Purpose | Data Shared |
|---|---|---|
| OpenAI | AI classification, summarisation, reply drafting, voice transcription | Email content (subject, body, sender), voice audio |
| Supabase | Database hosting, authentication, real-time updates | All application data (stored with row-level security) |
| Vercel | Application hosting and CDN | Server-side request data, IP addresses |
| Stripe | Payment processing | Name, email, billing address, payment method tokens |
| ElevenLabs | Text-to-speech (Voice Aiva, Pro plan) | AI-generated response text |
| PostHog | Product analytics | Anonymised usage events, feature interactions |
| Sentry | Error tracking and monitoring | Error reports, stack traces, device info |
| Resend | Transactional email delivery | Recipient email addresses, notification content |
We may also disclose your information:
We implement industry-standard technical and organisational measures to protect your data:
While we strive to protect your personal information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to maintaining industry best practices.
We retain your data for only as long as necessary to provide the Service and fulfil the purposes described in this Privacy Policy:
| Data Type | Retention Period |
|---|---|
| Account information | Duration of account existence + 30 days after deletion |
| Email and calendar data (Gmail, Outlook) | Duration of active channel connection + 30 days after disconnection |
| AI classifications and drafts | Duration of active subscription + 30 days after account deletion |
| AI audit logs | 12 months (for compliance and quality assurance) |
| Voice conversation data | Duration of active subscription + 30 days after account deletion |
| Billing records | 7 years (as required by tax and financial regulations) |
| Anonymised analytics data | Indefinite (cannot be linked back to individuals) |
Deleting Your Data:
Aiva is operated from Australia. Your data may be transferred to, stored in, and processed in countries other than your country of residence, including the United States and countries within the European Economic Area (EEA), where our service providers operate.
When transferring data internationally, we ensure appropriate safeguards are in place:
Depending on your location, you have certain rights regarding your personal information. We are committed to honouring these rights regardless of where you reside.
Under the Australian Privacy Act 1988, you have the right to:
If you are in the EU/EEA, you have the right to:
If you are a California resident, you have the right to:
Do Not Sell or Share My Personal Information: Aiva does not sell or share (as defined by the CCPA/CPRA) your personal information for cross-context behavioural advertising.
Regardless of your location, you can:
To exercise any of these rights, visit your account settings or contact us at privacy@tryaiva.io. We will respond to your request within 30 days (or sooner where required by applicable law).
We use the following types of cookies and similar technologies:
You can control cookie preferences through your browser settings. Disabling non-essential cookies will not affect the core functionality of the Service.
The Service is not intended for use by children under the age of 16 (or 13 in jurisdictions where a lower age of consent applies). We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@tryaiva.io and we will promptly delete the information.
We may update this Privacy Policy from time to time to reflect changes to our practices, technologies, legal requirements, or other factors. When we make material changes:
We encourage you to review this Privacy Policy periodically.
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
We aim to respond to all privacy-related inquiries within 30 days. For urgent matters involving data breaches, please include "URGENT" in your email subject line.
If you are not satisfied with our response to a privacy concern, you have the right to lodge a complaint with the relevant data protection authority:
Australia
Office of the Australian Information Commissioner (OAIC)
Website: www.oaic.gov.au
Phone: 1300 363 992
European Union
Contact your local Data Protection Authority (DPA). A list of EU DPAs is available at: European Data Protection Board