AIOSAIOS← Back
LEGAL

Privacy Policy

Last updated: 19 August 2026

AIOS is operated by CleverFox AI (“we”, “us”), the data controller for the personal data described here. Questions, requests and complaints all reach a person at hello@cleverfox-ai.com.

What we collect

Account data — your name, email address, role and workspace membership, provided when your workspace administrator adds you.

Content you put into AIOS — tasks, documents you upload, team chat messages and attachments, voice notes, and anything you type to an AI agent.

Technical data — authentication session cookies (required to sign you in; we set no advertising or analytics cookies), and usage logs of AI calls (model, token counts, cost) for billing and capacity.

We do not run analytics trackers, advertising pixels or fingerprinting of any kind.

Why we process it

To provide the service you or your employer contracted for (performance of contract); to secure it — authentication, access control, abuse prevention (legitimate interest); to account for AI usage costs (legitimate interest); and to respond when you contact us (legitimate interest). If you fill in the onboarding form as a prospective customer, we use those details to follow up on your enquiry and for nothing else.

AI processing — what you should know

AIOS is an AI product. When you use an AI feature, your input — including uploaded documents and voice recordings — is sent to a third-party AI provider to generate the response: Anthropic (chat and document analysis), OpenRouter (alternative model routing), Deepgram and OpenAI Whisper (voice transcription).

Anthropic and OpenAI do not use API content to train their models by default. Models reached through OpenRouter are hosted by third parties whose retention terms vary by model; our sub-processor register records the position per provider. AI output can be wrong — treat it as a draft, not a fact.

Who else processes your data

We use the following processors. Integrations marked “when connected” receive nothing unless your workspace connects them.

  • Supabasedatabase, authentication and file storage — where your workspace data lives
  • Vercelhosting and scheduled jobs — serves the application
  • AnthropicAI model provider — processes chat input and uploaded documents when you use AI features
  • OpenRouterAI model routing — processes chat input when routed models are selected
  • Deepgramvoice-note transcription — processes audio you record
  • OpenAIfallback voice-note transcription (Whisper)
  • GoogleGmail, Calendar, Drive, Docs, Sheets, Slides — when a Google account is linked
  • Slack, HubSpot, Xero, Firefliesworkspace integrations — only when connected, only the data those tools already hold
  • Resendtransactional email (invites, password resets, notifications)
  • Meta (WhatsApp) and Telegramdelivery of briefs to messaging channels, when configured
  • GitHubthe development pipeline for the product itself

We never sell personal data, and no processor receives it for its own marketing.

How long we keep it

Account data lasts as long as your account; workspace content (tasks, documents, chat, uploads) lasts as long as the workspace, or until deleted inside the app; AI usage logs are kept for 24 months for cost accounting; onboarding enquiries that go nowhere are deleted within 12 months. The full schedule lives in our retention policy, available on request.

Your rights

Under UK GDPR you can ask for access to your data, a machine-readable export, correction, deletion, or restriction of processing, and you can object to processing based on legitimate interest. Email hello@cleverfox-ai.com — we answer within one month. Deletion removes your sign-in, your uploads from storage, and your personal details from team content.

If you are unhappy with how we handle a request, you can complain to the UK Information Commissioner’s Office (ico.org.uk).

Security

Data is encrypted in transit and at rest, access is scoped per workspace and enforced in the database as well as the application, and every administrative action is logged. Security issues can be reported via the route described in our security policy.

Changes

When this policy changes, the date at the top changes with it, and material changes are announced to workspace administrators. Continued use after a change means the new version applies. See also our Terms of Service.