Table of Contents

Privacy Policy

Version: 1.2 Effective date: July 20, 2026 Previous update: October 5, 2025


Welcome to AIVAX. This Privacy Policy describes how AIVAX collects, uses, stores, shares, and protects information in its AI inference services. It is written for transparency and technical clarity, and it does not constitute legal advice. Account Managers should review it with their own legal counsel when needed.

By using AIVAX services, the Account Manager acknowledges and agrees to the terms of this policy.

1. Definitions

  • AIVAX: Company providing the platform and AI model orchestration services.
  • AIVAX Account Manager ("Account Manager"): Natural or legal person who creates and administers the account and integrates the API.
  • End User: Individual who interacts with the Account Manager's application that consumes the AIVAX API.
  • Account Data: Registration and administrative data, such as name, email, company, role, internal identifiers, preferences, and API key settings.
  • Billing Data: Data required for invoices, receipts, account balance, credits, payment events, and payment processing through third-party processors.
  • Inference Data: Inputs sent to models and resulting outputs. In the Terms of Use, this maps to Input Content and Generated Content.
  • Semantic Training Data: Account-deidentified eligible RAG and Reflex search content collected after the Account Manager enables semantic data collection, as described in Data Collecting. Document indexing and storage are excluded.
  • Conversations: Stored sequences of inference interactions, including messages, metadata, model name, usage object, tools, resources, and error information when conversation logging is enabled.
  • Technical Metadata: Request logs, IP or forwarding information, timestamps, latency, session identifiers, token usage, response codes, request identifiers, and security or abuse signals.
  • Processor: AIVAX when it processes data according to the Account Manager's instructions.
  • Controller: AIVAX when it defines purposes for account, billing, security, and compliance data.
  • Subprocessor: Third party contracted or configured by AIVAX to support processing, such as infrastructure, email, billing, model providers, search providers, or object storage.

2. Processing Roles

Data Type AIVAX Role Account Manager Role
Account Data Controller Data subject or controller of its own internal relationship
Billing Data Controller for legal, contractual, and operational billing purposes Provides and verifies
Inference Data / Conversations Processor for customer-directed processing; Controller for security, abuse prevention, and operational logs where applicable Controller of content and purpose
Semantic Training Data Controller for model and semantic-system development based on the Account Manager's consent Controller of the originating content and responsible for the legal basis and required notices to end users
Technical Metadata Controller for security, reliability, abuse prevention, and platform operations; Processor when generated as part of service execution Controller of the originating application context

When acting as Processor, AIVAX follows the Account Manager's instructions as expressed through API calls, dashboard settings, model selection, and configured integrations.

For contractual consistency, Inference Data in this policy corresponds to Input Content and Generated Content in the Terms of Use.


3. Categories of Collected Data

  1. Provided directly by the Account Manager: Account Data, preferences, account settings, organization information, generated API keys, and credentials stored as hashes or tokens where applicable.
  2. Generated by use: Technical metadata, usage records, token counts, latency, model usage, request resources, error information, and billing events.
  3. Inference Data and Conversations: Text and other content sent to models, model outputs, message history, conversation metadata, and related usage data.
  4. Semantic Training Data: RAG query terms, contents and relevance scores of documents returned by a search, selected reranker, Reflex queries, documents submitted to Reflex, and ranking results collected while semantic data collection is enabled. Document indexing and storage are not collected. These records exclude account, API key, request, collection, and document identifiers, document names, billing data, and collection timestamps.
  5. Support and Communication: Ticket messages, emails sent to support or contact channels, and operational communications.
  6. Billing: Fiscal, payment, invoice, credit, account balance, payment intent, and payment webhook data.
  7. Aggregated or Anonymized Data: Derived metrics that do not identify the Account Manager or end users.

AIVAX does not require special categories of sensitive personal data. If the Account Manager sends sensitive personal data in Inference Data, the Account Manager is responsible for having the appropriate legal basis and notices.


Category Primary Purpose Legal Basis (LGPD) Technical Retention or Limit
Account Data Account creation, authentication, account management, operational communications Contract execution / legitimate interest While the account is active; disabled or inactive accounts may be deleted by scheduled cleanup according to platform rules
Billing Data Invoices, credits, payment confirmation, fraud prevention, tax and accounting records Legal obligations / contract execution According to legal, accounting, and contractual requirements
Technical Metadata Security, abuse prevention, debugging, reliability, rate limiting, cost accounting Legitimate interest / contract execution Retained as needed for operational, security, audit, and billing workflows
Inference Data Execution of requested inference and configured integrations Contract execution Processed for the request and may be stored inside Conversations when conversation logging is enabled
Semantic Training Data Develop, train, fine-tune, evaluate, test, and improve models and semantic retrieval or ranking systems Consent Retained while reasonably necessary for these purposes, legal obligations, security, and audits; then deleted or irreversibly anonymized
Conversations Monitoring, support, export, debugging, usage review, and user-facing history Legitimate interest / contract execution Visible/exportable according to plan retention: Free up to 2 hours, Pro up to 2 days, Max up to 30 days
Support Resolve questions, incidents, and compliance requests Contract execution / legitimate interest Retained as needed to resolve the request and maintain business records
Aggregated or Anonymized Data Capacity planning, reliability, abuse prevention, service improvement Outside LGPD scope when irreversibly anonymized Indeterminate while anonymized

Conversation export periods are 2 hours, 1 day, 7 days, and 30 days, capped by the account plan's retention period.


5. Conversation Logging and Deletion

Conversation logging is enabled by default. When an Account Manager disables it, AIVAX does not store new conversation records for that account.

The authenticated Account Manager can list, view, export, and delete stored conversations through the conversations API, subject to authorization and retention windows. Deleting a conversation removes the matching conversation record for that account from production storage.


6. RAG, Memories, and Storage

AIVAX can store RAG collections, documents, embeddings, document metadata, user memories, media descriptions, web chat session data, and shell workspace files when those features are used.

Current storage accounting includes:

  • RAG document text and embedding bytes.
  • User persistent information.
  • Media descriptions.
  • Web chat session messages, extra context, and metadata.
  • Account shell files.

Storage quotas are plan-based. Current included storage is 30 MB for Free, 2 GB for Pro, and 20 GB for Max.


7. Optional Semantic Data Collection and Model Training

By default, AIVAX does not use Account Manager Inference Data or Conversations to train proprietary AIVAX models. When an authorized Account Manager enables semantic data collection, AIVAX may use eligible RAG and Reflex search records generated while the setting is enabled for the purposes described in Data Collecting. RAG document indexing and storage are not included and receive no program discount.

Before storage, AIVAX removes the account relationship and excludes operational identifiers, document names, billing data, and collection timestamps from these records. The account is consulted only to verify consent and apply the eligible discount. AIVAX does not retain an account-to-record mapping. This account-level anonymization does not inspect or redact identifying information that the Account Manager includes inside query or document text.

The setting is disabled by default. Disabling it stops new collection but does not automatically delete records collected while consent was active or reverse training already completed. Because account-to-record mappings are not stored, AIVAX cannot locate a training record from an account ID alone. The Account Manager remains responsible for the legal basis, notices, and permissions required for personal data submitted by its end users. Requests concerning personal data present inside semantic content may be sent to **privacy@aivax.net** or **wm@aivax.net** with enough information to locate the content where applicable.

Third-party model providers and aggregators may have their own processing terms, retention terms, and model-improvement policies independently of this optional program. The Account Manager should review the selected provider's policy before sending personal or sensitive data.


8. Data Subject Rights (Art. 18, LGPD)

When AIVAX acts as Controller, data subjects may request confirmation of processing, access, correction, anonymization, blocking or deletion, portability, information about sharing, revocation of consent where applicable, opposition to processing based on legitimate interest, and review of automated decisions where applicable.

Channel: **privacy@aivax.net** or **wm@aivax.net** (Data Protection Officer). We may request identity verification. For data where AIVAX acts as Processor, AIVAX may direct the data subject to the Controller Account Manager.


9. Data Protection Officer (DPO)

Data Protection Officer (Art. 41): (Anonymized identity) Contact: **wm@aivax.net**

Functions include communication with data subjects and the ANPD, internal compliance guidance, and support for privacy impact assessments.


10. Subprocessors and Third-Party Providers

AIVAX uses third-party services for infrastructure, object storage, transactional email, billing, web search, image generation, reranking, and AI model inference. The current technical list is maintained in Data Processors.

When selecting a model or enabling a tool, the Account Manager may cause content to be sent to the selected model provider, aggregator, or tool provider. AIVAX does not control third-party policies and recommends prior review.


11. International Data Transfers

Data may be processed or stored outside Brazil depending on the selected infrastructure, model provider, search provider, object storage provider, or payment provider. AIVAX applies technical and contractual safeguards appropriate to the service, including access controls, encryption in transit, minimization, and logical segregation where applicable.


12. Information Security

Key measures include:

  • Encryption in transit with HTTPS/TLS.
  • API key authentication and account-scoped authorization.
  • Role-based administrative access.
  • Rate limiting for inference, RAG search, document insertion, tools, and payment operations.
  • Balance, minimum-balance, and storage-quota checks before cost-incurring operations.
  • Operational logs and error reporting for troubleshooting and abuse prevention.
  • Separation between account-owned resources, such as collections, documents, conversations, memories, and shell files.
  • Secure credential configuration through application initialization parameters rather than hardcoded secrets.

No security measure is absolute; AIVAX maintains a continuous improvement process.


13. Incident Management

Relevant security incidents are assessed based on impact, data nature, and risk to data subjects. When required, AIVAX will notify affected Account Managers and competent authorities with available information about the event, affected data categories, mitigation steps, and recommended actions.


14. Automated Decisions

AIVAX uses automation for rate limiting, balance checks, storage quota checks, abuse prevention, fraud prevention, indexing, routing, and operational monitoring. These automations may temporarily restrict requests or keys. The Account Manager may request review through support channels.


15. Cookies and Tracking Technologies

Dashboard interfaces may use strictly necessary cookies or equivalent browser storage for sessions, authentication, and preferences. AIVAX does not use behavioral advertising cookies in the documented platform flow.


16. Children, Adolescents, and Emancipated Minors

The services are not intended for persons under 18, except legally emancipated minors aged 16 or older under Brazilian law. The Account Manager is responsible for implementing appropriate checks when their use case may involve minors.


17. Sensitive Data

AIVAX does not require sensitive data to use the platform. The Account Manager should avoid sending health, biometric, genetic, religious belief, political opinion, or other sensitive data unless they have an appropriate legal basis and clear notices for data subjects.


18. Use Limitations and Prohibited Content

It is prohibited to use the platform to store or process illegal content, rights-infringing material, malware, defamatory material, or content that infringes third-party rights. AIVAX may suspend, restrict, or block keys upon reasonable suspicion of violation, preserving logs necessary for investigation.


19. Aggregated Data

AIVAX may generate aggregate statistics such as token volume, error rate, model distribution, storage usage, and latency. Aggregated statistics are used for capacity planning, reliability, billing, and abuse prevention.


20. Export and Portability

AIVAX provides APIs to export conversation history in JSON or JSONL within the configured retention window. Collection documents can be exported in JSONL format. Export availability is subject to authentication, authorization, retention, and account state.


21. Backups and Disaster Recovery

AIVAX may maintain backups and disaster recovery processes for operational continuity. Deleted production data may remain in backup media until backup rotation or disaster recovery procedures complete.


22. Changes to This Policy

Material changes may be notified by email, dashboard notice, or publication of an updated policy. Continued use after the effective date constitutes acceptance where permitted by law and contract.


23. Contact Channel and Complaints

Questions, rights requests, or complaints: **privacy@aivax.net** / **wm@aivax.net**. If unsatisfied, the data subject may appeal to the ANPD (National Data Protection Authority).


24. Revision History

Version Effective Date Major Changes
1.0 07/30/2025 Initial version published
1.1 10/05/2025 Added legal bases, rights, detailed retention, subprocessors, transfers, expanded security, incidents, automated decisions, cookies, sensitive data, versioning

25. General Contact

Legal / Privacy: **legal@aivax.net** Data Protection Officer: **wm@aivax.net**

Always use official channels to avoid social engineering.


26. Final Provisions

If any clause of this policy is deemed invalid, the remaining provisions remain in full force. In case of conflict between this policy and specific product terms, the more protective provision for data subjects will prevail unless a different legal obligation applies.

Note: This policy may be complemented by a specific Data Processing Agreement (DPA) between AIVAX and the Account Manager, when applicable.