Last updated: July 15, 2026

Privacy Policy

Introduction

Aivius, Inc. ("Aivius," "we," "us," or "our") operates the AI visibility platform available at https://aivius.ai (the "Service"). We are incorporated in Delaware, United States, with a mailing address at 123 Delaware Ave, Wilmington, DE 19801.

This Privacy Policy explains what personal information we collect, how we use it, who we share it with, how long we keep it, and the rights you have over that data. It applies to visitors of our website, users of our free tools, and customers on any paid plan (Free, Starter, Pro, or Agency). It is written to satisfy both the General Data Protection Regulation (GDPR) for users in the European Economic Area (EEA), the United Kingdom, and Switzerland, and the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), for residents of California.

If you have entered into a separate Data Processing Agreement (DPA) with us — typically as an Enterprise or Agency customer — the terms of that DPA govern our processing of personal data on your behalf. Our DPA is available at /legal/dpa. In the event of a conflict between this Privacy Policy and a signed DPA, the DPA controls for data we process as a processor on your behalf.

For any privacy question or to exercise a right described below, contact us at privacy@aivius.ai. We respond to all verified requests within 30 days, as required by GDPR Article 12, and within 45 days for CCPA requests, as described in Section "Your Rights."

Information We Collect

Information you provide directly

When you create an account, contact us, or use our Service, you may provide:

  • Account information: your name, email address, company name, job title, and password (stored as a one-way salted hash). We use this to create and administer your account.
  • Brand and domain data: the brand names, website domains, and competitor names you add to your Aivius dashboard. We use these to query AI engines on your behalf and report citation results.
  • Billing information: when you upgrade to a paid plan, billing name, address, and payment metadata are collected by our payment processor, Paddle (our Merchant of Record). We never receive or store your full card number; we only store the last four digits, card brand, and expiration date for display in your billing page.
  • Support and contact information: any information you voluntarily provide in support emails, contact form submissions, or Discord community messages, including the contents of your message and any attachments.
  • Marketing preferences: if you subscribe to our changelog or product updates email, we store your email address and subscription status. You can unsubscribe at any time using the link in every email.

Information we collect automatically

When you visit our website or use the Service, we automatically collect certain technical and usage data:

  • Usage data: pages visited, features used, time spent in the dashboard, clicks, and in-app events. We use this to improve the product and to understand aggregate behavior.
  • Device and browser data: IP address (truncated for analytics), browser type and version, operating system, screen resolution, preferred language, and referring URL.
  • Cookies and tracking technologies: see the "Cookies and Tracking Technologies" section below for a full breakdown of which cookies we set, why, and how to disable them.
  • Communication metadata: when you email us, we retain the email content and metadata (sender, recipient, timestamp) to provide support and to maintain a record of the conversation.

Information from AI engine queries

The core function of Aivius is to query AI models (ChatGPT, Perplexity, Google AI Overviews, Gemini, Claude, Microsoft Copilot, Meta AI, Amazon Rufus, and Apple Intelligence) using prompts you configure or that we generate from your niche. As part of this, we process:

  • Prompt data: the search-style prompts and questions you track, and the auto-generated prompts our research engine suggests for your brand.
  • Citation and mention data: the text snippets, source URLs, and sentiment tags returned by AI engines when they mention or cite your brand or your competitors' brands.
  • Competitor brand names: the names of competitors you add to your account, which we use solely to benchmark their AI visibility against yours.

We treat competitor brand names as configuration data you provide, not as personal data, because brand names do not identify individuals. If a competitor brand name happens to be a personal name (for example, a creator brand), we process it only to perform the citation query you requested and delete it on account termination.

How We Use Your Information

We use your personal information for the following purposes, each tied to a lawful basis under GDPR and a business purpose under CCPA:

  • To provide the Service: creating and administering your account, querying AI engines for your tracked brands, generating visibility reports, and displaying competitor benchmarks. (GDPR lawful basis: performance of a contract. CCPA purpose: providing the services you requested.)
  • To process payments: handling subscription billing, upgrades, downgrades, refunds, and tax collection via Paddle. (GDPR: performance of a contract. CCPA: processing payment information.)
  • To provide customer support: responding to your emails, diagnosing bugs, and maintaining a support history. (GDPR: legitimate interest in providing effective support. CCPA: providing the services.)
  • To improve and develop the Service: analyzing aggregate usage patterns, identifying bugs, and prioritizing features. (GDPR: legitimate interest. CCPA: maintaining or improving the Service.)
  • To communicate with you: sending product updates, security notices, billing receipts, and (only if you opted in) marketing emails. (GDPR: consent for marketing, contract for transactional. CCPA: directly related to the original purpose.)
  • To ensure security and prevent abuse: detecting fraud, rate-limiting abusive accounts, and investigating violations of our Terms of Service. (GDPR: legitimate interest. CCPA: security and integrity.)
  • To comply with legal obligations: responding to lawful requests from authorities, enforcing our rights, and keeping records required by tax and corporate law. (GDPR: legal obligation. CCPA: compliance with legal obligations.)

We do not use your personal data to train our own AI models. The citation data we retrieve from AI engines is processed on your behalf and is not repurposed for model training.

Legal Basis for Processing (GDPR)

For users in the EEA, UK, and Switzerland, we rely on the following lawful bases under GDPR Article 6:

  • Performance of a contract (Art. 6(1)(b)): processing your account, billing, and brand-tracking data to deliver the Service you signed up for.
  • Legal obligation (Art. 6(1)(c)): retaining billing and tax records, and responding to lawful requests from authorities.
  • Legitimate interests (Art. 6(1)(f)): providing customer support, securing the Service against abuse, and improving the product based on aggregate usage. We conduct legitimate-interest assessments for these activities and balance them against your rights.
  • Consent (Art. 6(1)(a)): setting non-essential cookies, sending marketing emails, and any optional data collection you explicitly agree to. You can withdraw consent at any time without losing access to the Service.

Where we rely on consent, consent is freely given, specific, informed, and unambiguous — obtained through a clear affirmative action such as checking an unchecked box or clicking "Accept" on our cookie banner. Withdrawing consent does not affect the lawfulness of processing before the withdrawal.

Cookies and Tracking Technologies

We use cookies and similar technologies (local storage, pixel tags) for the following categories of purposes:

  • Strictly necessary cookies: required for login, session management, and the cookie consent banner itself. These cannot be disabled, as the Service would not function without them.
  • Preference cookies: remember your dashboard settings (e.g., selected AI engines, language toggle) between visits.
  • Analytics cookies: we use a privacy-friendly analytics tool to understand aggregate traffic and usage. We do not use cross-site tracking pixels for advertising.
  • Functional cookies: support chat widget state (when active) and form persistence.

We do not set advertising cookies, and we do not sell cookie-based data to ad networks. Our cookie banner, shown on first visit, lets you accept all cookies, decline non-essential cookies, or manage preferences by category. For EEA, UK, and Swiss users, non-essential cookies are only set after you opt in. For California users, the "Do Not Sell My Personal Information" link in our footer addresses CCPA opt-out — see the "Your Rights" section below.

You can also control cookies through your browser settings. Most browsers let you block third-party cookies, delete existing cookies, and warn you before a cookie is set. Disabling strictly necessary cookies will prevent you from logging in.

Data Sharing and Disclosure

We do not sell your personal data, as "sell" is defined under CCPA. We share personal data only with the categories of recipients described below, each bound by written contracts that require them to protect your data to a standard no less protective than our own:

  • Cloud infrastructure provider: Amazon Web Services (AWS), US-East region. We use AWS to host our application servers, databases, and object storage. AWS is a subprocessor that stores and processes data on our behalf under their GDPR-compliant DPA.
  • Payment processor (Merchant of Record): Paddle. Paddle handles subscription billing, tax collection, and invoicing. We share your billing name, email, and plan details with Paddle; Paddle collects and stores your card data directly — we never receive it.
  • Email delivery: Resend (transactional emails such as receipts and support replies) and our marketing email provider for opt-in product updates. These providers receive your email address and the content of messages sent to you.
  • Analytics: our privacy-friendly analytics provider receives aggregated, pseudonymized usage data. No cross-site tracking, no advertising profiles.
  • Customer support tools: we use a helpdesk tool to manage support tickets. The content of your support emails may be stored there to maintain a support history.
  • AI engine APIs: to perform citation queries, we send your configured prompts and brand names to the AI models you track (ChatGPT, Perplexity, Google, Anthropic, Microsoft, Meta, Amazon, and Apple). These providers are independent controllers of the data they receive; their processing is governed by their own privacy policies.
  • Legal and compliance: we may disclose personal data to law enforcement, regulators, or courts when required by law, or to protect our rights, property, or safety, or that of our users or the public.

A current list of our subprocessors, including their location and purpose, is maintained in our Data Processing Agreement. We notify customers of any new subprocessor at least 30 days before it begins processing data, giving you the right to object.

International Data Transfers

Aivius is a remote-first company with team members and infrastructure across multiple countries. Your data may be processed in the United States (our primary AWS region is US-East), in the European Union (where some team members and future infrastructure may reside), and in the United Kingdom.

For transfers of personal data from the EEA, UK, or Switzerland to countries that have not received an adequacy decision from the European Commission, we rely on the European Commission's Standard Contractual Clauses (SCCs) as adopted under Implementing Decision (EU) 2021/914. These clauses are incorporated into our DPAs with subprocessors and are available on request.

For transfers to the United States, we participate in the EU-U.S. Data Privacy Framework (DPF) as established by the European Commission's adequacy decision of July 10, 2023. Aivius self-certifies under the DPF and is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission. Our DPF certification can be verified at dataprivacyframework.gov.

If you are a UK resident, transfers to the US are made under the UK Extension to the DPF, and for Switzerland, under the Swiss-U.S. DPF, each as supplemented by the UK International Data Transfer Addendum or the Swiss equivalent.

Data Retention

We retain your personal data only as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required by law. Specific retention periods:

  • Account data: kept for as long as your account is active. When you delete your account, we remove your account data, brand configuration, and citation results within 30 days, except where we must retain billing records for tax and accounting purposes (typically 7 years under US law).
  • Billing and payment records: retained for 7 years after the end of the tax year in which the transaction occurred, as required by US federal tax law and Delaware corporate law.
  • Support communications: retained for 2 years after your last interaction, then deleted.
  • Usage and analytics data: aggregated and anonymized within 13 months of collection; raw event-level data is deleted within 13 months.
  • Marketing email subscriptions: kept until you unsubscribe. We retain a suppression record of your email address to honor the unsubscribe request indefinitely.
  • Server logs: retained for 90 days for security and troubleshooting, then automatically purged.

When you close your account, you can also request a full export of your data in JSON or CSV format under your data portability right, before deletion occurs.

Your Rights

Rights under GDPR (EEA, UK, Switzerland)

If you are located in the EEA, UK, or Switzerland, you have the following rights:

  • Right of access (Art. 15): request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16): correct inaccurate or incomplete personal data.
  • Right to erasure (Art. 17): request deletion of your personal data ("right to be forgotten"), subject to lawful retention obligations.
  • Right to restriction of processing (Art. 18): request that we limit processing of your data while a dispute is resolved.
  • Right to data portability (Art. 20): receive your personal data in a structured, machine-readable format (JSON or CSV) and transmit it to another controller.
  • Right to object (Art. 21): object to processing based on legitimate interests or for direct marketing.
  • Right to withdraw consent (Art. 7(3)): withdraw consent for any processing that relied on it, without affecting prior processing.
  • Right to lodge a complaint: complain to your local data protection authority. Contact details for EU authorities are at edpb.europa.eu; for the UK, the ICO at ico.org.uk.

Rights under CCPA/CPRA (California)

If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you the following rights:

  • Right to know: request the categories and specific pieces of personal information we collect, the sources, the business or commercial purpose, and the categories of third parties we share it with.
  • Right to delete: request deletion of your personal information, subject to legal exceptions.
  • Right to correct: request correction of inaccurate personal information.
  • Right to opt-out of sale or share: we do not sell personal information as defined by CCPA. However, certain data sharing for advertising-like purposes may be considered a "share" under CPRA; you have the right to opt out. Use the "Do Not Sell My Personal Information" link in our footer or email privacy@aivius.ai with "Opt-out" in the subject line.
  • Right to limit use of sensitive personal information: we do not collect sensitive personal information (as defined by CPRA) beyond what you voluntarily provide. If we ever do, you have the right to limit its use.
  • Right to non-discrimination: we will not discriminate against you for exercising any of these rights, and we will not deny, degrade, or charge differently for the Service because you exercised a right.

Do Not Sell My Personal Information: As noted, Aivius does not sell personal information. To opt out of any data sharing that could be characterized as a "sale" or "share" under CCPA, click the "Do Not Sell My Personal Information" link in the footer of any page or email privacy@aivius.ai. We will process your opt-out within 15 business days.

We respect the Global Privacy Control (GPC) browser signal. If your browser sends a GPC signal, we treat it as a valid opt-out request for that browser and device.

For CCPA requests, we verify your identity by matching the email address on your account or, for access requests, by requiring you to log in before we disclose data. We do not require a government ID for verification unless we cannot otherwise verify you.

How to exercise your rights

To exercise any right above, email privacy@aivius.ai or use the contact form and select "Other." Include "Privacy Request" in the subject line. We respond within 30 days for GDPR requests and 45 days for CCPA requests, as allowed by law. If we need more time, we will inform you of the reason and extension period in writing.

Authorized agents may submit requests on your behalf with written permission. For California residents, an authorized agent must provide proof of their identity and your signed authorization.

Children's Privacy

The Service is intended for businesses and professionals. We do not knowingly collect personal information from children under 16. Under COPPA (US) we do not collect data from children under 13, and under GDPR Article 8 we do not offer information society services to children under 16 without parental consent.

If you believe we have collected personal information from a child, contact privacy@aivius.ai immediately and we will delete it within 10 business days.

Security Measures

We take the security of your personal data seriously and implement industry-standard technical and organizational measures, including:

  • Encryption in transit: all data is transmitted over TLS 1.2+ (HTTPS).
  • Encryption at rest: databases and object storage are encrypted with AES-256.
  • Access control: role-based access with least-privilege principle. Production data access is restricted to authorized engineers with MFA and is logged.
  • Secrets management: API keys and credentials are stored in a managed secrets vault, never in code.
  • Regular audits: we conduct periodic security reviews and vulnerability scans.
  • Vendor due diligence: subprocessors are reviewed before onboarding and periodically reassessed.
  • Incident response: we maintain an incident response plan and notify affected customers and authorities without undue delay — and in any case within 72 hours of becoming aware of a personal data breach affecting EEA users, as required by GDPR Article 33.

While we work hard to protect your data, no system is 100% secure. We cannot guarantee absolute security, but we commit to notifying you promptly if a breach affects your personal data.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we do, we will revise the "Last updated" date at the top of this page.

  • Material changes: if we make a material change — for example, a new category of data we collect, a new purpose, or a new subprocessor — we will notify you by email at least 30 days before the change takes effect and, where required by law, seek your consent.
  • Non-material changes: clarifications, formatting, or minor edits may be made without direct notice; the "Last updated" date will reflect the change.
  • Annual review: as recommended by CCPA, we review this policy at least annually.

We encourage you to review this page periodically. Continued use of the Service after a change takes effect constitutes acceptance of the updated policy, except where consent is required by law.

Data Processing Addendum

Customers who need a signed Data Processing Agreement (for example, to comply with their own GDPR obligations as a controller) can review and sign our standard DPA at /legal/dpa. Enterprise customers may request a custom DPA by contacting dpa@aivius.ai.

Contact Us

If you have any question, concern, or request regarding this Privacy Policy or your personal data, contact us:

We are committed to working with you to obtain a fair resolution of any privacy concern. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority or the California Attorney General.