Privacy Policy

Last updated: June 2, 2026

1. Information We Collect

We collect information you provide directly to us when you create an account, including your name, email address, and Google account information via OAuth 2.0. We also collect information about your use of our platform, including log data, device information, and usage patterns. We do not collect or store the content of documents you upload beyond what is necessary to provide our service.

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Authenticate your identity and manage your account
  • Send transactional communications about your account
  • Respond to your comments, questions, and requests
  • Monitor and analyze trends, usage, and activities
  • Detect, investigate, and prevent fraudulent or unauthorized activity

3. Google OAuth & Third-Party Authentication

We use Google OAuth 2.0 for authentication. When you sign in with Google, we receive your name, email address, and profile picture from Google. We do not receive your Google password. Your use of Google's services is governed by Google's Privacy Policy. We only request the minimum permissions necessary to authenticate your identity.

4. AI and Data Usage

As an AI-powered platform, we use Large Language Models (LLMs) to process and analyze the documents you upload. We do not use your private documents or data to train public foundation models. Any data processed by our AI agents is strictly isolated and used solely for the purpose of generating your specific due diligence reports. We have zero-data retention agreements with our third-party LLM providers.

5. Data Storage & Security

Your data is stored on secure servers hosted on AWS infrastructure. We implement industry-standard security measures including encryption in transit (TLS 1.3) and at rest (AES-256). Our platform is built with SOC 2 and ISO 27001 principles. While we strive to protect your information, no security system is impenetrable. We will notify you of any breach affecting your personal data as required by applicable law.

6. GDPR Rights (European Users)

If you are located in the European Economic Area, you have the following rights:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Request correction of inaccurate data
  • Erasure: Request deletion of your personal data
  • Portability: Receive your data in a structured, machine-readable format
  • Objection: Object to processing of your personal data

7. India PDPB Compliance

We are committed to complying with India's Personal Data Protection Bill (PDPB). We collect only the data necessary for the purpose stated, obtain appropriate consent before processing sensitive personal data, and provide mechanisms for data principals to exercise their rights including access, correction, and erasure of their personal data.

8. Data Retention

We retain your personal information for as long as your account is active or as needed to provide services. You may request deletion of your account and associated data at any time. Upon deletion, we will remove your personal information within 30 days, except where we are required to retain it by law.

9. Cookies & Tracking

We use essential cookies for authentication and session management. We use analytics cookies to understand how our platform is used and improve user experience. You can control cookie settings through your browser preferences. Disabling certain cookies may affect the functionality of our platform.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through a prominent notice on our platform. Your continued use of Aegis Impact AI after changes become effective constitutes your acceptance of the revised policy.

Contact Us

For privacy-related questions, contact us at hello@aegisimpact.ai