Last updated: September 6, 2026

Privacy Policy

Introduction

Aivius ("Aivius," "we," "us," or "our") operates the website and AI search research tools available at https://aivius.ai (the "Service"). The seller's verified legal identity is disclosed in the applicable checkout and order confirmation. We do not publish a physical mailing address that has not been verified for business use.

This Privacy Policy explains what personal information we collect, how we use it, who we share it with, how long we keep it, and the rights you have over that data. It applies to website visitors, users of our free tools, purchasers of digital products, and customers of separately scoped research services.

If you have entered into a separate Data Processing Agreement (DPA) with us — typically as an Enterprise or Agency customer — the terms of that DPA govern our processing of personal data on your behalf. Our DPA is available at /legal/dpa. In the event of a conflict between this Privacy Policy and a signed DPA, the DPA controls for data we process as a processor on your behalf.

For any privacy question or to exercise a right described below, contact us at hello@aivius.ai. We respond to all verified requests within 30 days, as required by GDPR Article 12, and within 45 days for CCPA requests, as described in Section "Your Rights."

Information We Collect

Information you provide directly

When you create an account, contact us, or use our Service, you may provide:

  • Account information: your name, email address, company name, job title, and password (stored as a one-way salted hash). We use this to create and administer your account.
  • Brand and domain data: the brand names, website domains, and competitor names you add to your Aivius dashboard. We use these to query AI engines on your behalf and report citation results.
  • Billing information: for purchases processed through Creem, Creem acts as Merchant of Record and collects billing and payment details directly. Aivius receives order information needed to identify the product, confirm payment status, deliver the purchase, and provide support. Aivius does not receive or store your full card number.
  • Support and contact information: information you voluntarily provide in support emails or contact form submissions, including the contents of your message and any attachments.
  • Marketing preferences: if you subscribe to our changelog or product updates email, we store your email address and subscription status. You can unsubscribe at any time using the link in every email.

Information we collect automatically

When you visit our website or use the Service, we automatically collect certain technical and usage data:

  • Usage data: pages visited, features used, time spent in the dashboard, clicks, and in-app events. We use this to improve the product and to understand aggregate behavior.
  • Aggregate usage data: page path, referring host, campaign parameters, event type, and a salted one-way visitor hash derived from IP address and user agent. Raw IP addresses, full referring URLs, and user-agent strings are not stored in the analytics table.
  • Cookies and tracking technologies: see the "Cookies and Tracking Technologies" section below for a full breakdown of which cookies we set, why, and how to disable them.
  • Communication metadata: when you email us, we retain the email content and metadata (sender, recipient, timestamp) to provide support and to maintain a record of the conversation.

Information from AI engine queries

The core function of Aivius is to query AI models (ChatGPT, Perplexity, Google AI Overviews, Gemini, Claude, Microsoft Copilot, Meta AI, Amazon Rufus, and Apple Intelligence) using prompts you configure or that we generate from your niche. As part of this, we process:

  • Prompt data: the search-style prompts and questions you track, and the auto-generated prompts our research engine suggests for your brand.
  • Citation and mention data: the text snippets, source URLs, and sentiment tags returned by AI engines when they mention or cite your brand or your competitors' brands.
  • Competitor brand names: the names of competitors you add to your account, which we use solely to benchmark their AI visibility against yours.

We treat competitor brand names as configuration data you provide, not as personal data, because brand names do not identify individuals. If a competitor brand name happens to be a personal name (for example, a creator brand), we process it only to perform the citation query you requested and delete it on account termination.

How We Use Your Information

We use your personal information for the following purposes, each tied to a lawful basis under GDPR and a business purpose under CCPA:

  • To provide the Service: creating and administering your account, querying AI engines for your tracked brands, generating visibility reports, and displaying competitor benchmarks. (GDPR lawful basis: performance of a contract. CCPA purpose: providing the services you requested.)
  • To process purchases: confirming orders, delivery, refunds, and applicable tax handling through Creem as Merchant of Record. (GDPR: performance of a contract. CCPA: processing payment information.)
  • To provide customer support: responding to your emails, diagnosing bugs, and maintaining a support history. (GDPR: legitimate interest in providing effective support. CCPA: providing the services.)
  • To improve and develop the Service: analyzing aggregate usage patterns, identifying bugs, and prioritizing features. (GDPR: legitimate interest. CCPA: maintaining or improving the Service.)
  • To communicate with you: sending product updates, security notices, billing receipts, and (only if you opted in) marketing emails. (GDPR: consent for marketing, contract for transactional. CCPA: directly related to the original purpose.)
  • To ensure security and prevent abuse: detecting fraud, rate-limiting abusive accounts, and investigating violations of our Terms of Service. (GDPR: legitimate interest. CCPA: security and integrity.)
  • To comply with legal obligations: responding to lawful requests from authorities, enforcing our rights, and keeping records required by tax and corporate law. (GDPR: legal obligation. CCPA: compliance with legal obligations.)

We do not use your personal data to train our own AI models. The citation data we retrieve from AI engines is processed on your behalf and is not repurposed for model training.

Legal Basis for Processing (GDPR)

For users in the EEA, UK, and Switzerland, we rely on the following lawful bases under GDPR Article 6:

  • Performance of a contract (Art. 6(1)(b)): processing your account, billing, and brand-tracking data to deliver the Service you signed up for.
  • Legal obligation (Art. 6(1)(c)): retaining billing and tax records, and responding to lawful requests from authorities.
  • Legitimate interests (Art. 6(1)(f)): providing customer support, securing the Service against abuse, and improving the product based on aggregate usage. We conduct legitimate-interest assessments for these activities and balance them against your rights.
  • Consent (Art. 6(1)(a)): setting non-essential cookies, sending marketing emails, and any optional data collection you explicitly agree to. You can withdraw consent at any time without losing access to the Service.

Where we rely on consent, consent is freely given, specific, informed, and unambiguous — obtained through a clear affirmative action such as checking an unchecked box or clicking "Accept" on our cookie banner. Withdrawing consent does not affect the lawfulness of processing before the withdrawal.

Cookies and Tracking Technologies

We use cookies and similar technologies (local storage, pixel tags) for the following categories of purposes:

  • Strictly necessary cookies: required for login, session management, and the cookie consent banner itself. These cannot be disabled, as the Service would not function without them.
  • Preference cookies: remember your dashboard settings (e.g., selected AI engines, language toggle) between visits.
  • Cookie-free analytics: we use a first-party endpoint to understand aggregate traffic and usage. It sets no analytics cookie, stores no full URL query string, honors Do Not Track and Global Privacy Control, and is not used for advertising.
  • Functional cookies: support chat widget state (when active) and form persistence.

We do not set advertising cookies, and we do not sell cookie-based data to ad networks. Our cookie banner, shown on first visit, lets you accept all cookies, decline non-essential cookies, or manage preferences by category. For EEA, UK, and Swiss users, non-essential cookies are only set after you opt in. For California users, the "Do Not Sell My Personal Information" link in our footer addresses CCPA opt-out — see the "Your Rights" section below.

You can also control cookies through your browser settings. Most browsers let you block third-party cookies, delete existing cookies, and warn you before a cookie is set. Disabling strictly necessary cookies will prevent you from logging in.

Data Sharing and Disclosure

We do not sell your personal data, as "sell" is defined under CCPA. We share personal data only with the categories of recipients described below, each bound by written contracts that require them to protect your data to a standard no less protective than our own:

  • Hosting infrastructure: Cloudflare hosts and delivers the public website, and Render hosts configured application services and databases. These providers process limited technical data required to operate and secure the Service.
  • Payment processor (Merchant of Record): Creem. Creem handles checkout, payment processing, applicable tax collection, receipts, and payment-related refunds. We share the selected product and information required to fulfill the order; Creem collects card and billing data directly.
  • Email delivery: Resend (transactional emails such as receipts and support replies) and our marketing email provider for opt-in product updates. These providers receive your email address and the content of messages sent to you.
  • Analytics infrastructure: aggregate, pseudonymized usage events are stored in Aivius's application database hosted with the configured infrastructure provider. No advertising profile or cross-site identifier is created.
  • Customer support tools: we use a helpdesk tool to manage support tickets. The content of your support emails may be stored there to maintain a support history.
  • AI engine APIs: to perform citation queries, we send your configured prompts and brand names to the AI models you track (ChatGPT, Perplexity, Google, Anthropic, Microsoft, Meta, Amazon, and Apple). These providers are independent controllers of the data they receive; their processing is governed by their own privacy policies.
  • Legal and compliance: we may disclose personal data to law enforcement, regulators, or courts when required by law, or to protect our rights, property, or safety, or that of our users or the public.

A current list of our subprocessors, including their location and purpose, is maintained in our Data Processing Agreement. We notify customers of any new subprocessor at least 30 days before it begins processing data, giving you the right to object.

International Data Transfers

Aivius is an early-stage remote project. Processing locations depend on the providers actually configured for the Service and will be documented as those relationships are verified.

Any international transfer mechanism will be documented after the relevant providers, processing locations, and legal basis are verified.

Aivius does not currently claim certification under the EU?U.S. Data Privacy Framework.

Data Retention

We retain your personal data only as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required by law. Specific retention periods:

  • Account data: kept for as long as your account is active. When you delete your account, we remove account data, brand configuration, and citation results within 30 days, except where records must be retained for security, dispute, tax, accounting, or legal obligations.
  • Billing and payment records: retained by Aivius and Creem for the periods required by applicable tax, accounting, payment-network, and legal obligations.
  • Support communications: retained for 2 years after your last interaction, then deleted.
  • Usage and analytics data: event-level records are automatically deleted after 90 days; longer-term reporting should use aggregate totals.
  • Marketing email subscriptions: kept until you unsubscribe. We retain a suppression record of your email address to honor the unsubscribe request indefinitely.
  • Server logs: retained for 90 days for security and troubleshooting, then automatically purged.

When you close your account, you can also request a full export of your data in JSON or CSV format under your data portability right, before deletion occurs.

Your Rights

Rights under GDPR (EEA, UK, Switzerland)

If you are located in the EEA, UK, or Switzerland, you have the following rights:

  • Right of access (Art. 15): request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16): correct inaccurate or incomplete personal data.
  • Right to erasure (Art. 17): request deletion of your personal data ("right to be forgotten"), subject to lawful retention obligations.
  • Right to restriction of processing (Art. 18): request that we limit processing of your data while a dispute is resolved.
  • Right to data portability (Art. 20): receive your personal data in a structured, machine-readable format (JSON or CSV) and transmit it to another controller.
  • Right to object (Art. 21): object to processing based on legitimate interests or for direct marketing.
  • Right to withdraw consent (Art. 7(3)): withdraw consent for any processing that relied on it, without affecting prior processing.
  • Right to lodge a complaint: complain to your local data protection authority. Contact details for EU authorities are at edpb.europa.eu; for the UK, the ICO at ico.org.uk.

Rights under CCPA/CPRA (California)

If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you the following rights:

  • Right to know: request the categories and specific pieces of personal information we collect, the sources, the business or commercial purpose, and the categories of third parties we share it with.
  • Right to delete: request deletion of your personal information, subject to legal exceptions.
  • Right to correct: request correction of inaccurate personal information.
  • Right to opt-out of sale or share: we do not sell personal information as defined by CCPA. However, certain data sharing for advertising-like purposes may be considered a "share" under CPRA; you have the right to opt out. Use the "Do Not Sell My Personal Information" link in our footer or email hello@aivius.ai with "Opt-out" in the subject line.
  • Right to limit use of sensitive personal information: we do not collect sensitive personal information (as defined by CPRA) beyond what you voluntarily provide. If we ever do, you have the right to limit its use.
  • Right to non-discrimination: we will not discriminate against you for exercising any of these rights, and we will not deny, degrade, or charge differently for the Service because you exercised a right.

Do Not Sell My Personal Information: As noted, Aivius does not sell personal information. To opt out of any data sharing that could be characterized as a "sale" or "share" under CCPA, click the "Do Not Sell My Personal Information" link in the footer of any page or email hello@aivius.ai. We will process your opt-out within 15 business days.

We respect the Global Privacy Control (GPC) browser signal. If your browser sends a GPC signal, we treat it as a valid opt-out request for that browser and device.

For CCPA requests, we verify your identity by matching the email address on your account or, for access requests, by requiring you to log in before we disclose data. We do not require a government ID for verification unless we cannot otherwise verify you.

How to exercise your rights

To exercise any right above, email hello@aivius.ai or use the contact form and select "Other." Include "Privacy Request" in the subject line. We respond within 30 days for GDPR requests and 45 days for CCPA requests, as allowed by law. If we need more time, we will inform you of the reason and extension period in writing.

Authorized agents may submit requests on your behalf with written permission. For California residents, an authorized agent must provide proof of their identity and your signed authorization.

Children's Privacy

The Service is intended for businesses and professionals. We do not knowingly collect personal information from children under 16. Under COPPA (US) we do not collect data from children under 13, and under GDPR Article 8 we do not offer information society services to children under 16 without parental consent.

If you believe we have collected personal information from a child, contact hello@aivius.ai immediately and we will delete it within 10 business days.

Security Measures

We take the security of your personal data seriously and implement industry-standard technical and organizational measures, including:

  • Encryption in transit: all data is transmitted over TLS 1.2+ (HTTPS).
  • Encryption at rest: databases and object storage are encrypted with AES-256.
  • Access control: role-based access with least-privilege principle. Production data access is restricted to authorized engineers with MFA and is logged.
  • Secrets management: API keys and credentials are stored in a managed secrets vault, never in code.
  • Regular audits: we conduct periodic security reviews and vulnerability scans.
  • Vendor due diligence: subprocessors are reviewed before onboarding and periodically reassessed.
  • Incident response: we maintain an incident response plan and notify affected customers and authorities without undue delay — and in any case within 72 hours of becoming aware of a personal data breach affecting EEA users, as required by GDPR Article 33.

While we work hard to protect your data, no system is 100% secure. We cannot guarantee absolute security, but we commit to notifying you promptly if a breach affects your personal data.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we do, we will revise the "Last updated" date at the top of this page.

  • Material changes: if we make a material change — for example, a new category of data we collect, a new purpose, or a new subprocessor — we will notify you by email at least 30 days before the change takes effect and, where required by law, seek your consent.
  • Non-material changes: clarifications, formatting, or minor edits may be made without direct notice; the "Last updated" date will reflect the change.
  • Annual review: as recommended by CCPA, we review this policy at least annually.

We encourage you to review this page periodically. Continued use of the Service after a change takes effect constitutes acceptance of the updated policy, except where consent is required by law.

Data Processing Addendum

Customers who need a signed Data Processing Agreement (for example, to comply with their own GDPR obligations as a controller) can review and sign our standard DPA at /legal/dpa. Enterprise customers may request a custom DPA by contacting hello@aivius.ai.

Contact Us

If you have any question, concern, or request regarding this Privacy Policy or your personal data, contact us:

We are committed to working with you to obtain a fair resolution of any privacy concern. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority or the California Attorney General.