Privacy Policy

Last updated: 20 July 2026

This policy explains how Alayans handles personal data across its products and services. It should be read together with any customer agreement, in-product notice, or connected-provider permission screen that applies to a feature you use.

1. Controller and scope

Alayans BV, company number BE 1031.160.676, at Hundelgemsesteenweg 296A, 9820 Merelbeke-Melle, Belgium ("Alayans", "we", "us") is the controller for the processing described in this policy unless a customer agreement identifies another controller and Alayans as its processor.

This policy covers alayans.ai and its forms, our Projectmanagers and other Alayans applications on Android, iOS, Windows, and macOS, our backend and cloud services, and integrations you connect to those services (together, the "Services").

2. Data we collect and process

The categories depend on the product, device, permissions, and integrations you choose:

  • Account and organization data: name, email address, phone number, company or workspace, authentication identifiers, language, time zone, preferences, and account status.
  • Recordings and audio: meeting recordings, voice commands, uploaded audio, temporary audio chunks, audio metadata, and speaker or timing information.
  • Content and project context: transcripts, prompts, user messages, assistant responses, notes, reports, summaries, action items, project context, tasks, and other information you add to a workspace or conversation.
  • Files and media: photos, images, documents, attachments, filenames, file types, and extracted or generated content.
  • Connected email data: message bodies, subject lines, senders, recipients, attachments, message identifiers, labels or folders, timestamps, and related metadata when you enable an email feature.
  • Calendar, contact, and task-provider data: events, titles, descriptions, attendees, availability, contacts, tasks, projects, assignees, due dates, comments, and related provider metadata when you connect an integration.
  • Credentials and integration data: OAuth access and refresh tokens, granted scopes, provider account identifiers, connection status, and API credentials you choose to configure.
  • Subscription and transaction data: plan, entitlement or subscription status, store or transaction identifiers, and billing records. Payment card details are handled by the applicable store or payment provider unless we tell you otherwise at collection.
  • Device, notification, and diagnostic data: device and browser type, operating system, app version, IP address, user agent, push notification token, timestamps, feature events, crash details, security events, and service logs.
  • Website and request data: information submitted in contact, download, newsletter, beta, privacy-rights, and account deletion forms, together with page, referrer, IP address, user agent, and request time.

We receive this data from you, your device, your organization, the connected services you authorize, and service providers involved in delivering the feature you request.

3. Purposes and legal bases

  • Providing the Services and requested integrations:to create and secure accounts, record and transcribe audio, respond to prompts, maintain project context, sync connected tools, and deliver requested actions. We rely on performance of our contract with you or the customer that provides your account.
  • Optional AI, speech, integration, and marketing features:where applicable, we rely on the permission or consent requested at first use or in the relevant provider authorization screen. You may withdraw consent at any time.
  • Support and business communications: to respond to requests and administer beta, demo, download, or newsletter submissions. We rely on your request, consent where required, and our legitimate interest in communicating with customers and users.
  • Security, diagnostics, and improvement: to prevent abuse, troubleshoot failures, measure service reliability, and improve usability. We rely on our legitimate interests, balanced against your rights.
  • Billing and legal compliance: to administer subscriptions, keep required records, respond to lawful requests, and establish or defend legal claims. We rely on contract, legal obligations, and legitimate interests as applicable.

Alayans does not make decisions producing legal or similarly significant effects about you solely through automated processing.

4. AI and speech service providers

When a feature requires third-party AI or speech processing, we send only the information needed for that request. The data can contain personal data if it appears in the selected recording, conversation, file, email, calendar item, task, or project context.

ProviderData it may receivePurpose
OpenRouterPrompts, conversation messages, assistant responses, transcript excerpts, relevant email, calendar, task and project context, and supported images, documents, or extracted content.Route inference requests to the configured model provider and return generated responses or structured results.
Google, OpenAI, and xAIThe subset of prompt, conversation, file, transcript, and connected-account context selected for the requested feature and forwarded through the production model route.Generate responses, summaries, extractions, proposed actions, and configured model fallbacks.
SonioxRecordings or audio, language information, timestamps, speaker information, and technical audio metadata.Speech recognition, live or batch transcription, and related transcription features.
ElevenLabsAudio or response text and the technical metadata needed for the configured speech feature.Speech processing, generated voice output, and configured speech fallbacks.

The active provider and model can vary by feature, configuration, availability, and fallback behavior. We do not describe these requests as "zero retention" unless the applicable production setting and contract support that statement. Provider retention, training use, processing region, subprocessor chain, and transfer safeguards are governed by the applicable production account and contract; contact us if you need the current details for your deployment.

5. First-use permission and withdrawal

Before first use of a feature that sends personal data to a third-party AI or speech service, the product presents the relevant notice and asks for permission where required. If permission is not given, the features that require that processing remain unavailable.

You can withdraw permission through the available in-app privacy or account controls, by disconnecting the relevant integration, or by contacting us. Withdrawal stops new transmissions for the affected feature and that feature may stop working. It does not automatically erase transcripts, messages, responses, reports, or other results created before withdrawal; those can be deleted separately or through account deletion.

6. Connected accounts and Google API data

We access a connected account only after its authorization flow and only within the scopes shown by that provider. Depending on enabled features, Google access can include Gmail message content and metadata, attachments, Calendar data, Contacts data, and Tasks data. Microsoft access can include Outlook mail and calendar content and metadata. Task and project integrations can include the project, issue, task, assignee, comment, status, and due-date data needed for the action you request.

Our use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. We use Google user data to provide or improve the user-facing feature you requested, do not sell it, and do not use it for advertising or to train generalized AI or ML models. Human access is limited to cases permitted by that policy, such as security, support with your affirmative agreement, legal compliance, or aggregated and anonymized internal operations.

Disconnecting Google or Microsoft removes the corresponding OAuth access and refresh tokens from the active Alayans account record and stops future access through that connection. It does not automatically delete content already imported or results derived from it, such as a transcript, message, note, task, or report. Delete that content in the Service or submit an account deletion request. You can also revoke Alayans in your provider account settings. Organization-managed connections may require action by your administrator.

7. Other recipients and subprocessors

We disclose data only as needed to provide the Services, follow your instructions, protect the Services, or comply with law. Recipient categories include:

  • cloud hosting, database, object-storage, content-delivery, and backup providers that can process account data, content, files, recordings, and technical logs;
  • email, identity-verification, and push-notification providers that can process contact details, verification data, message delivery data, and push tokens;
  • Apple, Google, and applicable billing providers for store identity, transaction, entitlement, and subscription status;
  • analytics and diagnostic providers for device, page, feature, performance, and error data;
  • connected email, calendar, task, CRM, and project providers when you ask us to read from or write to those services; and
  • professional advisers, public authorities, or counterparties where reasonably necessary for legal compliance, security, or legal claims.

The AI and speech subprocessors used in current production routing are described in section 4. Contract-specific or deployment-specific subprocessor details are available from privacy@alayans.ai. We do not sell personal data.

8. Retention and deletion

We use the following periods or criteria. A customer contract may set a shorter period. Legal duties, security investigations, disputes, or technical backup rotation can require limited data to remain longer.

DataRetention period or criterion
Account, organization, and subscription statusWhile the account is active and then until verified account deletion is completed. Required invoices and transaction records remain for the period imposed by tax, accounting, or other applicable law.
Recordings and audioUntil you delete them, the workspace retention rule deletes them, or the account is deleted. Temporary chunks are kept only until processing, recovery, and the applicable storage lifecycle no longer require them.
Transcripts, messages, prompts, responses, notes, files, project context, tasks, and reportsWhile retained in the active workspace, until you delete the item, a customer retention instruction applies, or the account is deleted. Disconnecting a source integration alone does not delete these stored results.
OAuth tokensUntil the integration is disconnected, the token expires or is replaced, or the account is deleted. Google and Microsoft OAuth tokens are removed from the active account record on disconnect.
Push tokens and device registrationWhile the device is registered to an active account, until the token is replaced or no longer usable, or until account deletion.
Website forms, support, and deletion requestsUntil the request is resolved and then only as long as needed to document the response, comply with law, or handle a dispute. A minimal deletion audit record can remain after account data is removed.
Diagnostics, security events, and logsUntil no longer needed to investigate the event, secure the Services, troubleshoot the issue, or meet an applicable legal obligation, after which they are deleted or anonymized.
BackupsUntil overwritten under the applicable backup rotation. Deleted data in a recovery copy is isolated from normal use and is not intentionally restored to an active account.

For Projectmanagers, submit a no-login request at /projectmanagers/account-deletion. We verify ownership using the email address stored on the account. After verification, we complete deletion of the account and associated data within 15 days and send confirmation when complete. Data that must remain for a legal reason is restricted to that purpose.

9. Security

We use technical and organizational measures designed for the nature of the data and processing, including encrypted transport, authenticated APIs, access controls, restricted administrative access, logging, secret and token controls, service isolation, and security updates. No system is completely secure, and these measures cannot eliminate every risk.

10. International transfers

Alayans is established in Belgium. Some providers or their subprocessors may process data outside Belgium or the European Economic Area. Where EU law requires a transfer mechanism, we use the mechanism applicable to the recipient and transfer, such as an adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful safeguard. Processing regions and safeguards can vary by provider, feature, production configuration, and customer contract; contact us for the details applicable to your deployment.

11. Your rights and choices

Depending on applicable law, you may ask to access, correct, delete, restrict, or export your personal data, object to processing, or withdraw consent. Withdrawal does not affect processing that was lawful before withdrawal. You may also complain to a supervisory authority.

Send a request to privacy@alayans.ai. We may ask for proportionate information to verify your identity. We respond without undue delay and within the period required by applicable law. You may complain to the Belgian Data Protection Authority, Rue de la Presse 35, 1000 Brussels, or to the authority where you live or work.

12. Website analytics and device controls

Our website uses an Alayans analytics endpoint to understand page and feature use. Analytics and request logs can include page URL, referrer, browser or device information, timestamp, and IP-derived information. Your browser and operating system provide controls for cookies, local storage, permissions, notifications, microphone, camera, and photos. Disabling a required permission can stop the related feature.

13. Children

The Services are not intended for children under 16 and we do not knowingly collect their personal data. Contact us if you believe a child has provided personal data so we can investigate and take appropriate action.

14. Changes and contact

We may update this policy when our Services, providers, or legal obligations change. We will publish the updated policy and change the date above. If a change materially affects your rights, we will provide additional notice where required.

Privacy questions and rights requests: privacy@alayans.ai
Account deletion support: data@alayans.ai
Alayans BV, Hundelgemsesteenweg 296A, 9820 Merelbeke-Melle, Belgium · BE 1031.160.676