Privacy Notice

How aieinstein handles your data

Home

1. Controller

The data controller for aieinstein is the operator of the volvence stack. Sign-in identity is delegated to Volvence Accounts, which acts as the identity provider.

2. What we collect

Account profile data forwarded by Volvence Accounts (user id, email, display name); your conversation prompts; the assistant responses produced by the DLaaS substrate; technical operation logs (timestamps, status codes, IP) needed to operate the Service.

3. Purposes

Operating the chat product, building per-user durable memory, providing account export and deletion, protecting the Service from abuse, and complying with applicable law.

4. Sharing

Prompts and assistant text are processed by the DLaaS platform under the same operator. We do not sell personal data. Volvence Accounts receives only the identity attributes you authorize at sign-in.

5. Retention

Per-user conversation memory is retained until you delete your account or specific threads. Account audit rows default to a rolling 365-day retention; DLaaS lifecycle job records default to 90 days after they reach a terminal state. Both windows are operator-tunable via the EINSTEIN_AUDIT_RETENTION_DAYS and EINSTEIN_LIFECYCLE_RETENTION_DAYS environment variables documented in the SLO runbook.

6. Your rights

You can access, export, and delete your data from the Account page. You may also contact us using the channel below to raise objections, corrections, or restrictions consistent with your local law (GDPR, PIPL, CCPA, etc.).

7. International transfers

Depending on the deployment region, processing may occur on infrastructure outside your country. When applicable we rely on standard contractual safeguards.

8. Security

Secrets are kept server-side; the chat surface communicates with DLaaS over TLS-backed channels in production; per-user memory is namespaced by your account id.

9. Children

aieinstein is not directed at children under 13 (or the equivalent age of digital consent in your jurisdiction).

10. Contact

For privacy requests that are not covered by the export / delete controls in the product, contact the operator listed in the deployment-specific README.

Effective 2026-05-25