Last updated: March 18, 2026
1. Introduction
This Privacy Policy describes how Aihio AI ("we", "our" or "Service") collects, uses, and protects your personal data when you use our chatbot building platform. We are committed to protecting your privacy and complying with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.
2. Data Controller
Aihio AI acts as the data controller for your personal data. Contact information:
Helsinki, Finland
3. Data Collected
3.1 Account Creation Data
- Name and email address
- Company name (for teams)
- Password hash
- Profile picture (optional)
3.2 Service Usage Data
- Chatbot configurations and training data
- Conversation logs and analytics
- API usage statistics
- Billing and payment information
3.3 Technical Data
- IP address and browser information
- Device information and operating system
- Cookies and similar technologies
- Login information and timestamps
4. Purposes of Data Processing
We use your data for the following purposes:
4.1 Service Provision
- Creating and managing user accounts
- Providing chatbot functionality
- Technical support and customer service
- Billing and payment processing
4.2 Service Development
- Improving user experience
- Developing and optimizing AI models
- Planning new features
- Performance monitoring and analytics
4.3 Communication
- Service notifications and updates
- Security and maintenance notifications
- Marketing communications (with your consent)
5. Legal Basis for Data Processing
We process your personal data based on the following legal grounds:
- Contract: Service provision requires processing your data
- Legitimate Interest: Service development and ensuring data security
- Consent: Marketing communications and cookie usage
- Legal Obligation: Compliance with accounting and tax legislation
6. Data Sharing
6.1 Service Providers
We share data with trusted service providers who help us provide the Service:
- Supabase: Database and authentication (within EU)
- Stripe: Payment processing
- OpenAI / Anthropic / Google / xAI: AI models for chatbots
- Vercel: Infrastructure and hosting
- Sentry: Error tracking and performance monitoring
- Resend (EU, Ireland): Email communications
6.2 Team Collaboration
When you join a team, the team owner and other members can see your profile name and email address.
6.3 Legal Obligations
We may disclose your data to authorities if required by law.
7. Data Retention
We retain your personal data:
- Active Accounts: As long as your account is active
- Deleted Accounts: 30 days after deletion, after which data is anonymized or deleted
- Billing Data: 10 years in accordance with accounting law
- Log Data: 90 days for security purposes
8. Data Security
We protect your data with many technical and organizational measures:
- Encryption during transfer and storage (TLS/AES-256)
- Access control and role-based permissions (RLS)
- Regular security audits
- Backup and recovery plans
- Staff training on data security
9. Your Rights
In accordance with GDPR, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your data ("right to be forgotten")
- Restriction: Restrict processing of your data
- Portability: Receive your data in a machine-readable format
- Objection: Object to processing of your data
You can exercise your rights in account settings or by contacting privacy@aihio.ai.
10. International Data Transfers
We primarily store your data within the EU. When using AI services (e.g., OpenAI, Anthropic, Google, xAI), data may be transferred outside the EU. We ensure appropriate safeguards, such as EU-approved standard contractual clauses.
11. Cookies and Local Storage
We use cookies to improve Service functionality and user experience. See more details in our Cookie Policy.
The Aihio AI chatbot widget uses the browser's localStorage and sessionStorage to store conversation history, session identifiers, and configuration data. This data is stored locally on the end user's device and is not transmitted to our servers without an active chat session.
12. Children's Privacy
Our Service is not intended for users under 16. We do not knowingly collect children's personal data.
13. Changes to Privacy Policy
We may update this policy from time to time. We will notify you of significant changes via email or through the Service.
14. Contact
For privacy-related questions, contact:
If you are dissatisfied with how we process your data, you can file a complaint with the data protection authority (tietosuoja.fi).