AINexLayer

Privacy Policy

Last updated: August 21, 2026

1. Introduction

Welcome to AINexLayer ("AINexLayer", "we", "us", or "our"). We operate the website at www.ainexlayer.comand the AINexLayer application and related products (collectively, the "Service"). We respect your privacy and are committed to protecting personal data. This Privacy Policy explains what data we collect, how we use it, who we share it with, and the choices you have.

By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our policies and practices, do not use the Service. We may update this policy from time to time; material changes will be reflected by updating the "Last updated" date above.

2. Data We Collect

We may collect the following categories of personal data:

  • Identity Data — name, username, or similar identifier you provide when registering for an account.
  • Contact Data — email address and other contact details you provide when contacting support or using our contact forms.
  • Account and Authentication Data — hashed passwords (for local sign-in) and tokens issued by identity providers (such as Google) when you sign in with a third-party account.
  • Chat and Knowledge Base Data — messages, prompts, documents, notes, and related content you submit while signed in. Anonymous sessions on our free public pages are not stored in a user-linked account database.
  • Document and Integration Data — content from files you upload and data retrieved from third-party services you connect (such as Slack, Google Drive, Notion, Confluence, GitHub, and similar tools) under the permissions you authorize.
  • Billing Data — information needed to process payments (such as transaction identifiers and credit balances). Payment card details are handled by our payment processors and are not stored on AINexLayer servers.
  • Technical Data — IP address, browser type and version, time zone, operating system, device identifiers, and similar technical information from devices used to access the Service.
  • Usage Data — how you interact with the Service, such as pages visited, features used, referring URLs, and timestamps.
  • Marketing and Communications Data — your preferences for product updates and marketing communications from us.
  • Aggregated Data — statistics derived from the above after identifiers are removed. Aggregated data that cannot reasonably identify you is not treated as personal data.

3. How We Use Your Data

We use personal data to:

  • Create and manage your account, authenticate you, and provide the Service you request.
  • Process payments, manage credit balances, and help prevent fraud and abuse.
  • Answer your queries by sending prompts and content you submit to large language model providers (see Section 8) and returning responses to you.
  • Synchronize data from third-party services you explicitly connect so the Service can search and reference that content on your behalf.
  • Monitor, analyze, and improve the Service, diagnose issues, and detect security incidents.
  • Communicate with you about product updates, security notices, support requests, and — where you have agreed — marketing.
  • Comply with applicable law and enforce our Terms of Service.

4. Cookies and Tracking Technologies

We and our partners use cookies, local storage, and similar technologies to operate the Service, remember preferences, measure usage, and (where applicable) serve advertising. Categories include:

  • Strictly necessary — required for authentication, session management, security (including CAPTCHA), and core functionality.
  • Preference — remember choices such as theme, language, and onboarding state.
  • Analytics — help us understand how the Service is used so we can improve it (for example, PostHog product analytics).

You can control cookies through your browser settings. Blocking strictly necessary cookies may prevent the Service from working correctly. Where required by applicable law, we ask for your consent before setting non-essential cookies.

5. Data Security

We implement technical and organizational measures designed to protect personal data against accidental loss, unauthorized access, alteration, and disclosure. Access to personal data is limited to people who need it to operate the Service.

No system can be guaranteed fully secure. We cannot guarantee that personal data transmitted to or stored by the Service will be free from unauthorized access. You are responsible for keeping your account credentials confidential.

6. Data Retention

We retain personal data only for as long as necessary to provide the Service and to comply with our legal, accounting, and reporting obligations. Aggregated data that no longer identifies you may be retained indefinitely for analytics and product improvement purposes. Anonymous chat sessions on our free pages are not retained in any user-linked database.

Account data is retained for the life of your account. You can delete your account yourself at any time from Settings. Deletion is immediate and cannot be undone: your profile, chats, documents, connectors, and API keys are erased, along with every workspace you own — including workspaces shared with other members, who will lose access to their work in them. Any unused credit is forfeited.

Two things outlive your account. We keep a one-way keyed hash (HMAC-SHA256) of your account identifier so that a new account created with the same identifier does not receive the free welcome credit a second time. This value cannot be reversed to recover your email or provider ID, and we use it for no other purpose. We rely on our legitimate interest in preventing abuse of promotional credit (GDPR Article 6(1)(f), Recital 47). Separately, our payment processor retains invoices and charge records where tax and accounting law requires it (GDPR Article 17(3)(b)).

7. Third-Party Services

We use third-party processors and providers to operate the Service. Each has its own privacy policy, which we encourage you to review:

  • Authentication — Google (OAuth sign-in) and other identity providers you choose.
  • Hosting and infrastructure — cloud hosting, CDN, DNS, and security providers (for example CAPTCHA via Cloudflare Turnstile).
  • Analytics — PostHog (product analytics).
  • Large language model providers — OpenAI, Anthropic, Google, and other LLM providers process prompts and content you submit so the Service can generate responses.
  • Payment processors — providers that process credit purchases and related payments.
  • Integration providers — when you connect a third-party service (such as Slack, Google Drive, Notion, Confluence, GitHub, Jira, Linear, or similar), data is exchanged with that service under the scopes you authorize.

We do not sell personal data. We share data with the providers above only as needed to operate the Service.

8. Your Rights and Choices

Subject to applicable law, you may have rights regarding your personal data, including the ability to:

  • The right to access the personal data we hold about you.
  • The right to request correction of inaccurate or incomplete data.
  • The right to request erasure of your personal data ("right to be forgotten"). You can exercise this yourself at any time by deleting your account in Settings, subject to the limited retention described in Section 6.
  • The right to object to or restrict certain processing of your data.
  • The right to data portability (to receive your data in a portable format).
  • Withdraw consent where we rely on consent (including for non-essential cookies or marketing).
  • Opt out of personalized advertising using the controls described in Section 5, or by using a browser privacy / global privacy control signal where we support it.
  • Contact a competent privacy authority if you believe our processing does not comply with applicable law.

To exercise these rights, contact us using the details in Section 12. We may need to verify your identity before responding.

9. Children's Privacy

The Service is not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will take steps to delete it. We do not knowingly serve personalized advertising to children.

10. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or operations. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, provide additional notice (such as an in-product notification or email). Continued use of the Service after an updated policy becomes effective means you accept the revised policy.

11. Contact Us

If you have questions about this Privacy Policy or our privacy practices, or want to exercise your rights, contact us at:

Email: support@ainexlayer.com