Skip to main content

Privacy Policy

These documents are counsel-ready product disclosures, not jurisdiction-specific legal advice. A qualified lawyer must complete final legal review before AINA relies on them for a particular market, customer, or contract.

Effective 2026-08-14

Controller and contact

The data controller and operator of the AINA service is AINA Technologies LLC, a Colorado limited liability company. Questions concerning privacy or personal data may be sent to support@useaina.com.

AINA is operated by AINA Technologies LLC, a limited liability company organised under the laws of the State of Colorado, United States, with Colorado Entity ID 20261877839 and principal office at 1500 N Grant St, Ste 45878, Denver, CO 80203, United States.

Information processed

AINA processes account and authentication data, conversations, model selections, project instructions, memory, files and uploaded images, research queries and citations, generated artifacts, usage records, subscription facts, support messages, security events, and privacy requests.

Payment providers collect payment details. AINA stores the provider identifiers and normalized subscription, invoice, refund, and cancellation facts needed to operate and reconcile billing.

AI, research, and provider disclosures

AINA processes the prompt, relevant conversation context, requested research, and any files or uploaded images needed for the task. OpenRouter is the default model gateway and sends the required input to the upstream provider for the selected model. Smart Select may choose that model using task type, capabilities, tools, context, health, cost, speed, quality, plan, remaining usage, privacy, and policy requirements.

Search queries may be sent to a configured research provider. Provider responses, source titles, URLs, citations, and limited routing metadata may be stored with the conversation. AINA requests that OpenRouter deny provider data collection, but does not promise zero retention or no provider processing.

Files, images, projects, and memory

Uploads are validated and stored in private Supabase storage. Short-lived signed access is provided only to the eligible request or workspace surface that needs the file. Relevant recent turns, summaries, pinned facts, project instructions, attachments, and citations may be sent as model context.

Memory can be disabled. Conversation history stored in AINA is distinct from the subset of context sent to a model.

AINA Code and execution

For invited beta users, AINA Code may process repository metadata, selected files, prompts, diffs, tests, terminal output, and preview state. Execution remains disabled unless a separately approved executor is configured and the user approves the permission-sensitive step.

Execution may occur locally or in a configured cloud environment. Repository credentials and permissions must be limited to content the user is authorized to access.

Authentication, communications, and essential processing

Supabase provides authentication and data services. Configured email providers deliver account, security, billing, and support messages. Essential authentication, billing, fraud-prevention, security, and audit processing is not controlled by optional analytics choices. Product Analytics and Session Replay are not classified as Essential.

Product analytics and Session Replay

With your permission, AINA uses PostHog to understand how AINA is used, measure product performance, identify usability problems, evaluate features, and improve the service. Product Analytics and Session Replay are optional and controlled separately. They are disabled unless you make the applicable choice, and you can change or withdraw either choice at any time through AINA's privacy settings. Declining optional analytics does not prevent you from using AINA's core service.

For Product Analytics, AINA may provide PostHog with pseudonymous account or session identifiers and limited technical and product-usage information, such as features used, request or task identifiers, environment and release information, routing mode, selected model and provider, latency, token usage, AINA-recorded cost information, tool usage, attempt and fallback information, and safe completion or outcome categories.

AINA does not intentionally provide PostHog with the contents of your AI prompts or responses; uploaded file names or file contents; source-code contents; your email address or name; passwords, authentication tokens, API keys or other credentials; raw request bodies; raw error messages or stack traces; or AI input and output content.

If you separately enable Session Replay, AINA may use privacy-masked recordings of product navigation and layout to understand usability and technical problems. AINA configures Session Replay to mask displayed text and user inputs, block images and designated sensitive areas, and prevent collection of conversation content, console logs, network bodies, and other configured sensitive information.

AINA may use PostHog to measure technical metadata about AI execution, such as model and provider selection, routing mode, latency, token counts, cost, retries, fallbacks, tools, and outcome status. AINA's PostHog configuration is designed not to send the contents of prompts, model responses, source code, or uploaded files as AI-observability data.

PostHog processes this information on AINA's behalf as a service provider or processor. AINA uses PostHog's US Cloud. PostHog-hosted analytics and Session Replay data for AINA is processed and stored in the United States, using PostHog's US cloud region in Virginia. PostHog may use approved subprocessors as described in its current subprocessor documentation.

Because AINA uses PostHog's US Cloud, information sent to PostHog is processed in the United States. Where applicable data-protection law restricts international transfers of personal data, AINA relies on the safeguards provided for in its data-processing arrangements with PostHog and other legally recognised transfer mechanisms applicable to the transfer. Details of PostHog's current data-processing terms and subprocessors are available through PostHog's Trust Center.

AINA limits PostHog collection to information reasonably necessary for these purposes and applies additional technical controls intended to prevent sensitive AI content from being sent to PostHog.

Retention, export, and deletion

Workspace content is generally retained while the account remains active unless deleted earlier. Billing, security, immutable usage-accounting, legal-acceptance, and audit records may be retained where legally or operationally required; AINA does not claim universal zero retention.

PostHog Session Replay recordings are configured for 30-day retention. Product Analytics events and restricted AI-execution metadata follow the retention available under AINA's PostHog account and project settings; AINA does not state a shorter fixed Product Analytics deletion period that the current project cannot enforce.

Withdrawing Product Analytics or Session Replay consent immediately stops future optional collection for that purpose but does not by itself delete information collected before withdrawal. Users can request data export, correction, account deletion, or other privacy assistance from Settings or support@useaina.com. AINA maintains pseudonymous identity mappings sufficient to queue eligible PostHog person and event deletion when an account or applicable privacy deletion request is processed. Account deletion cannot erase records that must be retained for legal, security, billing, dispute, or integrity purposes.

Teams, transfers, and security

Controlled Team or Enterprise pilots may process membership, seat, permission, organization policy, pooled-usage, and audit data. Contracted customers may receive additional data terms.

Providers may process data in other jurisdictions. AINA uses access control, row-level security, signed file access, encrypted provider credentials where configured, and server-side authorization, but no internet service can guarantee absolute security.