Privacy Policy
Last updated: 19 August 2026
AIOS is operated by CleverFox AI (“we”, “us”), the data controller for the personal data described here. Questions, requests and complaints all reach a person at hello@cleverfox-ai.com.
What we collect
Account data — your name, email address, role and workspace membership, provided when your workspace administrator adds you.
Content you put into AIOS — tasks, documents you upload, team chat messages and attachments, voice notes, and anything you type to an AI agent.
Technical data — authentication session cookies (required to sign you in; we set no advertising or analytics cookies), and usage logs of AI calls (model, token counts, cost) for billing and capacity.
We do not run analytics trackers, advertising pixels or fingerprinting of any kind.
Why we process it
To provide the service you or your employer contracted for (performance of contract); to secure it — authentication, access control, abuse prevention (legitimate interest); to account for AI usage costs (legitimate interest); and to respond when you contact us (legitimate interest). If you fill in the onboarding form as a prospective customer, we use those details to follow up on your enquiry and for nothing else.
AI processing — what you should know
AIOS is an AI product. When you use an AI feature, your input — including uploaded documents and voice recordings — is sent to a third-party AI provider to generate the response: Anthropic (chat and document analysis), OpenRouter (alternative model routing), Deepgram and OpenAI Whisper (voice transcription).
Anthropic and OpenAI do not use API content to train their models by default. Models reached through OpenRouter are hosted by third parties whose retention terms vary by model; our sub-processor register records the position per provider. AI output can be wrong — treat it as a draft, not a fact.
Who else processes your data
We use the following processors. Integrations marked “when connected” receive nothing unless your workspace connects them.
- Supabase — database, authentication and file storage — where your workspace data lives
- Vercel — hosting and scheduled jobs — serves the application
- Anthropic — AI model provider — processes chat input and uploaded documents when you use AI features
- OpenRouter — AI model routing — processes chat input when routed models are selected
- Deepgram — voice-note transcription — processes audio you record
- OpenAI — fallback voice-note transcription (Whisper)
- Google — Gmail, Calendar, Drive, Docs, Sheets, Slides — when a Google account is linked
- Slack, HubSpot, Xero, Fireflies — workspace integrations — only when connected, only the data those tools already hold
- Resend — transactional email (invites, password resets, notifications)
- Meta (WhatsApp) and Telegram — delivery of briefs to messaging channels, when configured
- GitHub — the development pipeline for the product itself
We never sell personal data, and no processor receives it for its own marketing.
How long we keep it
Account data lasts as long as your account; workspace content (tasks, documents, chat, uploads) lasts as long as the workspace, or until deleted inside the app; AI usage logs are kept for 24 months for cost accounting; onboarding enquiries that go nowhere are deleted within 12 months. The full schedule lives in our retention policy, available on request.
Your rights
Under UK GDPR you can ask for access to your data, a machine-readable export, correction, deletion, or restriction of processing, and you can object to processing based on legitimate interest. Email hello@cleverfox-ai.com — we answer within one month. Deletion removes your sign-in, your uploads from storage, and your personal details from team content.
If you are unhappy with how we handle a request, you can complain to the UK Information Commissioner’s Office (ico.org.uk).
Security
Data is encrypted in transit and at rest, access is scoped per workspace and enforced in the database as well as the application, and every administrative action is logged. Security issues can be reported via the route described in our security policy.
Changes
When this policy changes, the date at the top changes with it, and material changes are announced to workspace administrators. Continued use after a change means the new version applies. See also our Terms of Service.