AJERIS
TermsHome

Legal

Privacy
Policy

Last updated May 1, 2026

01

How Ajeris is offered

This policy covers two related products. Ajeris Personal Agent is a one-to-one assistant for an individual, reachable by SMS, voice, and other channels. Ajeris Business is a customer-service platform for small businesses; it answers a business’s inbound calls and messages, qualifies leads, and acts on the business owner’s behalf. References below to "you" mean the user of the relevant product. When you are a business owner using Ajeris Business, separate sections below cover data Ajeris stores on your behalf about your customers and leads.

02

What we collect

Ajeris collects only what is necessary to act on your behalf. Every piece of data you give us, or grant access to, serves an operational purpose.

  • ◆Your phone number, so we can reach your agent and you can reach us
  • ◆Conversation history (SMS, voice, iMessage) so the agent has context
  • ◆Core memories the agent has been told to remember about you
  • ◆OAuth tokens for services you explicitly connect (Gmail, Calendar, Spotify, Uber, Hue, Slack, and others)
  • ◆Financial account data via Plaid (balances, transactions), when you connect a bank
  • ◆Credit report data (score, utilization, accounts) from Equifax and TransUnion, when you opt in
  • ◆Usage data (latency, errors, feature counts) for operational reliability
03

How we use your data

Your data powers your agent and nothing else.

  • ◆Executing the actions you ask for, across the tools you have connected
  • ◆Maintaining memory and context between conversations
  • ◆Diagnosing errors and improving reliability
  • ◆Billing and account administration

We do not use your conversations or account data to train third-party models. We do not sell your data. Ever.

04

Who we share data with

We share data only with service providers strictly required to run the product.

  • ◆Anthropic and OpenAI, for language-model inference on your requests
  • ◆Twilio, for SMS, MMS, voice, and WhatsApp delivery
  • ◆ElevenLabs, for voice cloning and text-to-speech (Ajeris Business voice agent and voice memos)
  • ◆Amazon, for Alexa skill integration and hosting
  • ◆Plaid, for financial account access, when you connect a bank
  • ◆Stripe, for billing and (for Ajeris Business owners) Stripe Connect payment links to their customers
  • ◆Railway, for application and database hosting (per-user isolated agent containers run on Railway)
  • ◆Vercel, for website hosting (the Ajeris marketing site and hosted guide pages)
  • ◆Meta (Instagram and Messenger), only when an Ajeris Business owner explicitly connects those accounts so the platform can answer inbound messages and run comment-trigger automations on the owner’s behalf

Each provider is bound by its own privacy policy and only receives the minimum data needed to perform its function.

05

SMS and mobile information

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. This includes your phone number and any data collected via SMS.

  • ◆Phone numbers are used only to deliver messages between you and your agent, and to verify your account
  • ◆Messages from your agent are transactional and informational only (agent replies, action confirmations, account notifications), never marketing or promotional
  • ◆When you opt in via the web form at ajeris.com/opt-in, we record the submitted phone number, the consent timestamp, your IP address, and your browser user-agent so we can demonstrate a valid opt-in if a carrier or auditor requests proof
  • ◆Conversation history (the SMS messages you send your agent and the agent's replies) is retained per the Data retention section below
  • ◆Mobile opt-in consent is never a condition of purchasing any other Ajeris service or accessing any other part of ajeris.com

Text STOP at any time to unsubscribe; you will receive one confirmation message and nothing after that unless you reply START. Text HELP for support information, or email hi@ajeris.com. Message and data rates may apply, per your mobile carrier's plan.

06

Data retention

We keep your data only as long as it is useful to your agent, then we delete it.

  • ◆Conversation history: kept as long as your account is active
  • ◆Core memories: kept until you ask the agent to forget them, or your account is deleted
  • ◆Payment proposals that were never sent: auto-deleted after 30 days
  • ◆Daily activity logs: auto-deleted after 90 days
  • ◆Expired OAuth tokens: auto-deleted at expiry
  • ◆On account deletion: all personal data removed within 30 days, backups purged within 90 days

Where retention is legally required (for example, transactional records for tax purposes), we keep only the minimum required and isolate it from any agent access.

07

What we will never do

  • ◆Sell your personal data to advertisers or brokers
  • ◆Use your conversations to train models outside your account
  • ◆Share data with other Ajeris users or their agents
  • ◆Access your connected services without an explicit request from you
08

Data security

Ajeris is built to be robust. Your agent runs in a per-user isolated container, so one user cannot read another user’s data or influence another user’s agent.

  • ◆All data encrypted at rest using AES-256
  • ◆All traffic encrypted in transit using TLS 1.3
  • ◆Per-user isolated runtime containers
  • ◆OAuth tokens stored in a dedicated secrets vault, decrypted only at action time
09

Your rights

You can, at any time:

  • ◆Download every piece of data Ajeris holds about you
  • ◆Ask the agent to forget a memory
  • ◆Revoke access to any connected service
  • ◆Delete your account and all associated data

To exercise any of these rights, email hi@ajeris.com.

10

Plaid-specific disclosures

If you connect a bank via Plaid, Plaid receives your banking credentials under its own policy. Ajeris never sees those credentials. Ajeris only sees the tokenized account handle Plaid returns, plus the balance and transaction data scoped to that handle.

11

QuickBooks Online and Xero

If you connect QuickBooks Online or Xero, Ajeris receives accounting data on your behalf (profit and loss reports, balance sheets, invoices, customer and contact lists, transaction history). Access is granted via OAuth 2.0 with read-only scopes by default; any write capability is behind an explicit feature flag that is off for all users at connection time.

  • ◆QuickBooks Online scope: com.intuit.quickbooks.accounting. Ajeris stores your Intuit realmId, company name, and environment marker in a metadata record alongside the encrypted OAuth token.
  • ◆Xero scopes: accounting.reports.read, accounting.transactions.read, accounting.contacts.read, openid, profile, email, offline_access. Ajeris stores your Xero tenantId, tenantName, tenantType, and connectionId alongside the encrypted OAuth token.
  • ◆Accounting data is requested on demand when your agent answers a question that needs it, and is not cached outside the context of the conversation that triggered the request.
  • ◆We do not use your accounting data to train any AI or machine-learning model, our own or anyone else's. This is codified in our vendor contracts with Anthropic and OpenAI and aligns with Xero's March 2026 AI/ML data policy.
  • ◆Subprocessors who may see your accounting data in transit: Anthropic and OpenAI (model inference only, zero-retention endpoints), Railway (hosting), Vercel (web hosting). None of these train on your data.
  • ◆To disconnect, text your agent "disconnect QuickBooks" or "disconnect Xero", or follow the instructions at https://ajeris.com/disconnect. Disconnection calls the provider's revocation endpoint (Intuit /v2/oauth2/tokens/revoke for QuickBooks, DELETE /connections/{id} for Xero) and deletes the encrypted token row from our database within 24 hours.
  • ◆Retention: encrypted tokens persist until you disconnect or your account is deleted. No copy of your P&L, balance sheet, invoice list, or contact list is persisted beyond the response to the specific agent query that fetched it, except for usage logs (query type, latency, error code) that are auto-deleted after 90 days per the Data retention section above.

If disconnection does not appear to complete, or you want a full export of everything Ajeris held about a QuickBooks or Xero connection before it was deleted, email hi@ajeris.com. We respond within one business day.

12

Google Workspace data (Gmail, Calendar, Drive, YouTube)

The use of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. Concretely: data Ajeris receives from Google APIs is used only to provide the user-facing features the user explicitly requested, never for advertising, never sold or transferred to third parties, never used to train any AI or machine-learning model, and never read by Ajeris staff except for security or legal reasons. We request the narrowest scope that makes each feature work, and only the scopes for features Ajeris actually ships today.

  • ◆gmail.send (sensitive). Used to send email on the user's behalf when the user explicitly asks the agent to send an email, for example "email Maya the deck" or the post-meeting recap email. Ajeris cannot read inbox content with this scope; only the narrowest write capability is requested.
  • ◆calendar.events (sensitive). Used to read upcoming events so the agent can answer "what's on my calendar tomorrow", to create events when the user asks ("block 2-3pm Thursday"), to move or cancel events the user identifies, and to dispatch our meeting-join feature at the right time. No access to calendars the user has not explicitly connected.
  • ◆drive.file (non-sensitive, per-file). Used to create Docs, Sheets, and other files the agent generates on the user's behalf. drive.file restricts visibility to files Ajeris itself creates; Ajeris cannot list, read, or modify any other files in the user's Drive.
  • ◆youtube.readonly (sensitive). Used to read the user's subscriptions and likes when the agent answers questions like "find a recipe video from one of my cooking channels" or "what was that video I liked last week". Read-only; no uploads, edits, or comments.
  • ◆openid, profile, email (standard OpenID Connect). Used to identify which Google account is being connected so multi-account users can connect more than one Google account and the agent can route requests to the right one.

Token storage: Google OAuth refresh and access tokens are encrypted at rest using AES-256 and stored in a per-user secrets vault, decrypted only at the moment a tool call is executed. Tokens are deleted on user-initiated disconnect, on account deletion, and at expiry. To disconnect, text your agent "disconnect Google", visit https://ajeris.com/disconnect, or revoke directly at https://myaccount.google.com/permissions. Disconnection deletes the stored token row within 24 hours.

13

Lead and customer data (Ajeris Business)

When a small business uses Ajeris Business, the platform records information about people who contact the business or fill out a lead form on a page hosted by the business. This data is generated about, and on behalf of, the business and its customers. Ajeris stores and processes it for the business; the business is the controller of its customer relationships.

  • ◆Phone number, name, and email when a person provides them on a hosted guide page or supplies them in an inbound message
  • ◆The full content of voice calls, SMS, web-chat sessions, and (for businesses that connect Instagram or Messenger) Instagram comments and direct messages exchanged with the business agent
  • ◆AI-generated transcripts and summaries of voice calls so the business owner can review past conversations
  • ◆Lead-form submission metadata: timestamp, IP address, browser user-agent, the page on which the form was submitted, and the value of the TCPA consent checkbox
  • ◆Booking and appointment records the business agent creates with the lead or customer

This data is shared only with the business that owns the customer relationship. It is never shared with other businesses on the platform, never used to train AI models outside the business’s account, and never sold. The business owner can export, delete, or transfer it at any time. If you are an end customer who messaged or called a business that uses Ajeris and you want a copy or deletion of your data, please contact the business directly. Ajeris will support the business in fulfilling verified requests within 30 days; you may also email hi@ajeris.com to be routed to the business.

14

Voice cloning (Ajeris Business)

Business owners using Ajeris Business may record their own voice to create an AI voice agent that answers calls and sends voice messages on the business’s behalf. Voice cloning is provided by ElevenLabs and used only within the owner’s own business.

  • ◆Voice samples are provided by the business owner and used to train a per-business voice model linked only to that owner’s account
  • ◆The owner verifies ownership of the voice (selfie video plus a recorded consent statement) before the model is activated
  • ◆Voice models are not used to train any general AI or speech model, are not shared with other Ajeris customers, and are not made available outside the owner’s account
  • ◆Voice models and samples are deleted within 30 days when the owner removes the voice clone from their account or deletes the account

The owner is responsible for using the cloned voice only in compliance with applicable laws (including the Tennessee ELVIS Act and other state right-of-publicity laws) and for never using the platform to clone a voice they do not own or have explicit consent to use.

15

Meta platform data (Instagram and Messenger)

Business owners using Ajeris Business may connect their Instagram or Facebook Messenger accounts so the platform can answer customer messages and run comment-trigger automations. Ajeris’s use of Meta APIs adheres to the Meta Platform Terms and Developer Policies.

  • ◆On connection, Ajeris receives the business’s Instagram or Facebook account profile (username or page name, account ID, profile picture) and a long-lived OAuth token authorizing the requested actions
  • ◆Ajeris listens to webhook events Meta delivers: new comments on the business’s posts, new direct messages, message reactions, and message read receipts
  • ◆Ajeris sends direct messages and private replies through the Meta Graph API on the business’s behalf, only when the business has configured an automation or the AI agent is responding to an inbound message that the customer initiated
  • ◆Permissions Ajeris requests via Meta App Review for Instagram: instagram_business_basic, instagram_business_manage_comments, instagram_business_manage_messages, and human_agent (for replies outside Meta’s standard 24-hour window). For Messenger: pages_messaging, pages_show_list, and pages_manage_metadata
  • ◆Meta platform data is used solely to operate the connected business’s Ajeris account, never used to train AI models outside the business’s account, never shared with other businesses on the platform, and never sold
  • ◆Retention: archived Instagram and Messenger conversation data is retained for as long as the business’s account is active or as required by the business’s industry rules, then deleted

A business owner can disconnect their Instagram or Messenger account at any time from the Ajeris manage interface, from https://www.instagram.com/accounts/manage_access/ for Instagram, or from Facebook Business Settings for Messenger. Disconnection revokes the OAuth token, ends webhook delivery, and triggers deletion of stored Meta-platform data within 30 days.

16

Data deletion requests

Ajeris supports user-initiated data deletion through multiple channels. Choose the one that fits your situation.

  • ◆Personal Agent users: email hi@ajeris.com or text your agent "delete my account". Personal data is removed within 30 days; backups purged within 90 days
  • ◆Ajeris Business owners: email hi@ajeris.com from the email tied to your account, or use the Delete account control in the manage interface
  • ◆End customers of an Ajeris Business: contact the business owner directly. The business is the controller of its customer relationships; Ajeris will support the business in fulfilling verified deletion requests within 30 days of the business’s instruction
  • ◆Meta platform deletion callback: per Meta’s Platform Terms, Ajeris implements a data-deletion callback at https://gateway.ajeris.com/webhooks/meta/data-deletion. Meta calls this endpoint when an Instagram or Messenger user requests their data be deleted from third-party apps connected to their account; Ajeris removes the user’s data within 30 days and confirms via the callback acknowledgment

Status updates on a deletion request are available by email to hi@ajeris.com.

17

Children's privacy

Ajeris is not intended for users under 13. We do not knowingly collect data from children. If we learn we have, we delete it immediately.

18

Changes to this policy

If we materially change how we handle data, we will notify you via SMS and email before the change takes effect, and give you a grace period to decline and delete your account.

19

Contact

Questions about this policy? Email us at hi@ajeris.com.

HomeTerms

© 2026 Ajeris