1. Controller
The data controller for aieinstein is the operator of the volvence stack. Sign-in identity is delegated to Volvence Accounts, which acts as the identity provider.
How aieinstein handles your data
The data controller for aieinstein is the operator of the volvence stack. Sign-in identity is delegated to Volvence Accounts, which acts as the identity provider.
Account profile data forwarded by Volvence Accounts (user id, email, display name); your conversation prompts; the assistant responses produced by the DLaaS substrate; technical operation logs (timestamps, status codes, IP) needed to operate the Service.
Operating the chat product, building per-user durable memory, providing account export and deletion, protecting the Service from abuse, and complying with applicable law.
Prompts and assistant text are processed by the DLaaS platform under the same operator. We do not sell personal data. Volvence Accounts receives only the identity attributes you authorize at sign-in.
Per-user conversation memory is retained until you delete your account or specific threads. Account audit rows default to a rolling 365-day retention; DLaaS lifecycle job records default to 90 days after they reach a terminal state. Both windows are operator-tunable via the EINSTEIN_AUDIT_RETENTION_DAYS and EINSTEIN_LIFECYCLE_RETENTION_DAYS environment variables documented in the SLO runbook.
You can access, export, and delete your data from the Account page. You may also contact us using the channel below to raise objections, corrections, or restrictions consistent with your local law (GDPR, PIPL, CCPA, etc.).
Depending on the deployment region, processing may occur on infrastructure outside your country. When applicable we rely on standard contractual safeguards.
Secrets are kept server-side; the chat surface communicates with DLaaS over TLS-backed channels in production; per-user memory is namespaced by your account id.
aieinstein is not directed at children under 13 (or the equivalent age of digital consent in your jurisdiction).
For privacy requests that are not covered by the export / delete controls in the product, contact the operator listed in the deployment-specific README.
Effective 2026-05-25