Privacy Policy
Last updated: May 12, 2026 (rev 6)
These documents were last reviewed by Aspired AI LLC on May 12, 2026. We recommend consulting a licensed attorney for advice specific to your situation.
Aspired AI LLC ("we," "us," or "our") operates Aspired AI at aspired-ai.com. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our Service.
1. Information We Collect
1.1 Information You Provide
- Account information: name, email address, username, password
- Business information: business name, industry, business description, goals, and team size provided during onboarding
- Brain entries: notes, documents, and context you save to your agents
- Payment information: processed and stored by Stripe — we do not store your full payment card details
- Communications: messages you send to our AI agents and support team
1.2 Information Collected Automatically
- Usage data: pages visited, features used, agents interacted with, message counts, and session duration
- Device information: browser type, operating system, IP address, and device identifiers
- Cookies and similar technologies: used to maintain your session, remember preferences, and analyze usage patterns
1.3 Information from Third Parties
- Google: if you sign in with Google, we receive your name, email address, and profile picture from Google. If you optionally connect Google Calendar and Gmail (see Section 4.3), we additionally process the data described there.
- Social media integrations: if you connect Facebook, Instagram, or LinkedIn, we receive access tokens and the data described in Section 4 below. We act solely on your behalf, only on the accounts and pages you administer, and only via official APIs.
2. How We Use Your Information
We use the information we collect to:
- Create and manage your account
- Provide, operate, and improve the Service
- Personalize your AI agents based on your industry and business context
- Process payments and manage subscriptions
- Send transactional emails including receipts, trial warnings, and account notifications
- Send optional product updates and weekly digests (you may opt out)
- Respond to your support requests
- Detect, prevent, and address fraud and abuse
- Comply with legal obligations
- Analyze usage patterns to improve the Service
3. Your Brain Data
Information you store in your Brain (business context, notes, and documents) is used exclusively to personalize your AI agent responses. We do not sell, share, or use your Brain data to train AI models. Your Brain data is private to your account.
4. Third-Party Platform Integrations
Aspired AI offers optional integrations with third-party platforms so that the authenticated customer (the "Authorized Client") can manage their own presence on those platforms from within Aspired AI. We are first-party tooling for our customers, not a middleware layer that resells or aggregates third-party data.
4.1 Meta (Facebook & Instagram)
The following commitments apply specifically to Meta-sourced data we process on your behalf as your Authorized Client tooling.
4.1.1 Scope of Access
- We access Meta data only via official Meta Graph API endpoints, never via scraping, crawling, or unofficial means.
- We request only the OAuth permissions required for features you explicitly enable.
- We act solely on behalf of the authenticated Authorized Client for the Facebook Pages and Instagram Business Accounts they administer.
4.1.2 Data We Receive From Meta
- Authenticated user's basic profile (name, profile photo, email) for account linking.
- The list of Facebook Pages the user administers, with per-Page access tokens scoped to that Page only.
- Instagram Business Accounts linked to those Facebook Pages.
- Post content and engagement metrics (reactions, comments, shares) for the user's own Pages and posts.
- Comments on the user's own posts, where the user requests we read them.
- Page Insights metrics (impressions, reach, page views, follower changes) for the user's own Pages.
- Instagram media metrics and comments for the user's own Instagram Business Accounts.
4.1.3 How We Use Meta Data
- Solely to provide the authenticated customer with first-party tooling to manage their own Facebook and Instagram presence.
- We do not use Meta data to train AI models.
- We do not commingle Meta data across customers.
- We do not build aggregated databases of member profiles, leads, or engagement data.
- We do not enrich, verify, or append to user profiles using Meta data.
- We do not resell, rent, lease, or sublicense Meta data to any third party.
- We do not use Meta data for advertising, sales prospecting, or lead generation outside the authorizing customer's own first-party use.
4.1.4 Data Retention (Meta-Specific)
The retention windows below apply to Meta-sourced data only and are stricter than the general retention policy in Section 6.
- Access tokens (user and Page): retained while integration is active and immediately invalidated and deleted upon disconnect or data deletion request.
- Page metadata (Page IDs, names, linked Instagram accounts): retained while integration is active and deleted within 10 days of integration disconnect or account closure.
- Cached post engagement data: retained while integration is active and deleted within 10 days of integration disconnect.
- Cached comment data and read history: retained while integration is active and deleted within 10 days of integration disconnect.
- Posts published through Aspired AI: the post content remains in your Aspired AI account history (with snapshotted Page name) so you retain a record of what you published. Live API references to Meta Page IDs are removed on integration disconnect.
- On user deletion request: all Meta-sourced data tied to that user is deleted immediately.
- On notice from Meta that we have breached the Platform Terms or Developer Policies: all Meta-sourced data is permanently deleted within 10 days.
4.1.5 Data Sharing
- Meta data is never shared with other Aspired AI customers.
- Meta data is never shared with advertising networks, data brokers, or analytics providers beyond what is strictly necessary to provide the Service to the authorizing customer.
- Subprocessors (see Section 5.1) are bound by data processing agreements at least as protective as Meta's Platform Terms.
4.1.6 User Rights
- Customers can disconnect their Meta integration at any time from the Integrations page, which immediately invalidates all access tokens and triggers cleanup of Meta-sourced data within 10 days.
- Customers can request immediate deletion of all Meta-sourced data via the "Request Data Deletion" button on the Integrations page, or by emailing privacy@aspired-ai.com.
- Meta users whose data passes through our system (e.g., commenters on the customer's posts) can request deletion via privacy@aspired-ai.com.
4.1.7 Meta Data Deletion Callback
In compliance with Meta Platform Terms, we maintain a Data Deletion Callback endpoint at:
https://aspired-ai.com/api/integrations/facebook/data-deletion-callback/
When a user removes the Aspired AI app from their Facebook account, Meta sends a signed deletion request to this endpoint. We process these requests immediately, hard-delete all Meta-sourced data associated with the user, and return a confirmation code. Users can check the status of their deletion request at:
https://aspired-ai.com/data-deletion-status?id={confirmation_code}
4.1.8 No Automation Prohibited by Meta
- Aspired AI does not automate posting, messaging, follower/following actions, or any other Meta member action without explicit user approval of the specific content.
- All publishing actions require the customer to review and approve the specific draft before publication.
- Scheduled posts are user-scheduled (the customer chooses the exact time and content).
- Comment replies are user-approved drafts; the agent never auto-publishes.
4.1.9 Compliance and Audits
- Every API action is logged to an internal audit table (IntegrationAction).
- We will cooperate fully with any Meta audit request and accommodate any required modifications to the integration.
4.2 LinkedIn
The following commitments apply specifically to LinkedIn data we process on your behalf as your Authorized Client tooling.
4.2.1 Scope of Access
- We access LinkedIn data only via official LinkedIn APIs, never via scraping, crawling, or unofficial means.
- We request only the OAuth scopes required for features you explicitly enable.
- We act solely on behalf of the authenticated Authorized Client and only access LinkedIn resources that authenticated user already administers — we do not enumerate, target, or read data belonging to LinkedIn users or organizations outside the connected member's own access.
4.2.2 Data We Receive From LinkedIn
- Authenticated user's basic profile (name, profile photo, email) for account linking.
- LinkedIn Event metadata: when the customer creates or updates a LinkedIn Event hosted by a Company Page the user administers (event title, description, start/end times, format, registration URL, address for in-person events), we receive the event identifier and a snapshot of the metadata. Event metadata is stored locally on the customer's account so the customer can list and manage their events; it is not used for any other purpose, never shared across customers, and is removed within 10 days of integration disconnect or account closure.
- LinkedIn Ad Library results: when the customer initiates a search, we receive publicly-available metadata (advertiser name, ad format, first-served date, served-country information, estimated impression range) for ads other companies are running on LinkedIn. This data is sourced from LinkedIn's own public Ad Library transparency surface (also browsable at linkedin.com/ad-library) — it is not member-private data and is not tied to any specific LinkedIn member's identity. Ad Library results are returned on-demand to the searching customer's session and are not retained, aggregated, re-indexed, sold, or used to train AI models.
- Sponsored Content campaign metadata and aggregate performance metrics: when the customer explicitly requests an ad performance report, we read aggregate metrics (impressions, clicks, spend, CTR, CPC, CPM, conversions, leads) along with campaign IDs, names, and statuses for ad accounts the customer administers. We receive aggregate metrics only — we do not receive individual user-level conversion data, member identities, creative text, or targeting selections. We do not retrieve campaign configurations or modify any campaign on the customer's behalf.
4.2.3 How We Use LinkedIn Data
- Solely to provide the authenticated customer with first-party tooling to manage their own LinkedIn presence.
- We do not use LinkedIn data to train AI models.
- We do not commingle LinkedIn data across customers.
- We do not build aggregated databases of member profiles, leads, or engagement data.
- We do not enrich, verify, or append to user profiles using LinkedIn data.
- We do not resell, rent, lease, or sublicense LinkedIn data to any third party.
- We do not use LinkedIn data for advertising, sales prospecting, recruiting, or lead generation outside the authorizing customer's own first-party use.
4.2.4 Data Retention (LinkedIn-Specific)
The retention windows below apply to LinkedIn-sourced data only and are stricter than the general retention policy in Section 6.
- LinkedIn profile data: retained no longer than 24 hours.
- LinkedIn social activity data (posts, comments, reactions): retained no longer than 48 hours.
- Ad performance report data: cached in memory for the request and persisted on the chat message it was generated from for as long as the user's account is active and that chat session exists. Deleted when the user deletes the chat session, disconnects the integration, or closes their account. We do not retain a separate cross-customer ad performance database.
- On user deletion request: all LinkedIn-sourced data tied to that user is deleted immediately.
- On integration disconnect or account closure: all LinkedIn-sourced data is permanently deleted within 10 days.
- On notice from LinkedIn that we have breached the API Terms: all LinkedIn-sourced data is permanently deleted within 10 days.
4.2.5 Data Sharing
- LinkedIn data is never shared with other Aspired AI customers.
- LinkedIn data is never shared with advertising networks, data brokers, or analytics providers beyond what is strictly necessary to provide the Service to the authorizing customer.
- Subprocessors (see Section 5.1) are bound by data processing agreements at least as protective as LinkedIn's requirements.
4.2.6 User Rights
- Customers can disconnect their LinkedIn integration at any time from the Integrations page, which immediately invalidates the access token and triggers a 10-day cleanup of LinkedIn-sourced data.
- Customers can request immediate deletion of all LinkedIn-sourced data via the "Request Data Deletion" button on the Integrations page, or by emailing hello@aspired-ai.com.
- LinkedIn members whose data passes through our system can request deletion via privacy@aspired-ai.com.
4.2.7 No Automation Prohibited by LinkedIn
- Aspired AI does not automate posting, messaging, connection requests, or any other LinkedIn member action.
- All publishing and scheduling actions require explicit customer approval of the specific content before execution.
- Scheduled posts are user-scheduled (the customer chooses the exact time and content); they are not automated content generation or automated outreach.
4.2.8 Compliance and Audits
- Every API action is logged to an internal audit table (IntegrationAction).
- We will cooperate fully with any LinkedIn audit request and accommodate any required modifications to the integration.
4.3 Google Workspace (Calendar and Gmail)
The following commitments apply specifically to Google-sourced data we process on your behalf as your Authorized Client tooling. Aspired AI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4.3.1 Scope of Access
We access Google data only via official Google Workspace APIs (Calendar API v3 and Gmail API v1), never via scraping, crawling, or unofficial means. We request only the OAuth scopes required for features you explicitly enable:
https://www.googleapis.com/auth/calendar.events — to create, read, update, and delete events you authorize our agents to manage on your primary Google Calendar.https://www.googleapis.com/auth/gmail.compose — to create draft emails in your Gmail Drafts folder for your review and approval. We cannot read your inbox, send email programmatically, or modify any other Gmail data with this scope.https://www.googleapis.com/auth/gmail.modify — to apply user-configured labels to emails in your Gmail account for the optional Inbox AI feature. We use this scope only to create and apply labels. We do not delete, archive, move messages between folders, modify message content, or read message body text outside of the classification process described in Section 4.3.3.openid, email, profile — to identify the connected Google account.
We act solely on behalf of the authenticated user for the Google account they connect.
4.3.2 Data We Receive From Google
- Authenticated user's basic profile (name, email address, profile photo) for account linking.
- OAuth access tokens and refresh tokens, used to call Google APIs on your behalf.
- Calendar event data we create, update, or delete on your behalf (event title, description, start/end times, location, attendees, conferencing links). We do not enumerate, read, or store events that Aspired AI did not create.
- Gmail draft metadata for drafts our agents create on your behalf (recipient list, subject, body content, draft ID, message ID, thread ID). We do not read your inbox, sent mail, or any other Gmail content.
- Email metadata and content from messages in your inbox, processed in-memory only for AI classification when the Inbox AI feature is enabled. We do not persistently store email content from your inbox — only the resulting label assignment (e.g., "Hot Lead", "Newsletter") is recorded for audit purposes. See Section 4.3.4 for retention windows.
4.3.3 How We Use Google Data — Limited Use
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google data solely to provide and improve the user-facing features of Aspired AI that the user has explicitly requested (drafting calendar events, drafting emails for review).
- We do not use Google data to develop, improve, or train generalized or non-personalized AI or machine learning models. Calendar and Gmail content is never sent to model training pipelines.
- We do not transfer Google data to third parties except as necessary to provide or improve user-facing features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets (with user notice).
- We do not allow humans to read Google data unless: (a) we have your affirmative agreement for specific messages, (b) it is necessary for security purposes such as investigating abuse, (c) it is necessary to comply with applicable law, or (d) the data has been aggregated and anonymized and is used for internal operations.
- We do not use Google data for serving advertisements, including retargeting, personalized, or interest-based advertising.
- We do not sell Google data.
When Inbox AI is enabled, email content from your inbox is sent to Anthropic's Claude API solely for classification into your chosen labels. Anthropic is bound by a no-training agreement covering all API inputs and outputs. Classification results (label assignment only — not message content) are stored briefly for audit and display in the Aspired AI activity log. The original email text is not retained.
4.3.4 Data Retention (Google-Specific)
The retention windows below apply to Google-sourced data only and are stricter than the general retention policy in Section 6.
- Access tokens and refresh tokens: retained while the integration is active and immediately invalidated and deleted upon disconnect or data deletion request.
- Calendar event records (the event metadata for events Aspired AI created on your behalf): retained while integration is active so you retain a record of what was scheduled. Deleted within 10 days of integration disconnect or account closure.
- Gmail draft records (recipient, subject, body content of drafts our agents created): retained while integration is active so you retain a record of what was drafted. Deleted within 10 days of integration disconnect or account closure. Deleting the integration does not delete the drafts themselves from your Gmail Drafts folder — you manage those directly in Gmail.
- Inbox AI label assignments (which label was applied to which message, recorded for audit): retained while integration is active, deleted within 10 days of integration disconnect or account closure.
- Email content processed for Inbox AI classification: held in memory only during classification (typically under 2 seconds per email), never written to disk or persisted in any database.
- Inbox AI configuration (your chosen labels, custom labels, opt-in toggles): retained while integration is active so you can reconfigure the feature, deleted within 10 days of integration disconnect or account closure.
- On user deletion request: all Google-sourced data tied to that user is deleted immediately.
4.3.5 Data Sharing
Google data is never shared with other Aspired AI customers. Google data is never shared with advertising networks, data brokers, or analytics providers. Subprocessors (see Section 5.1) that touch Google data — specifically Anthropic (which receives the prompt content used to draft events and emails) and DigitalOcean (which hosts the database where draft metadata is stored) — are bound by data processing agreements at least as protective as Google's API Services User Data Policy, and Anthropic is bound by a no-training agreement covering all API inputs and outputs.
4.3.6 User Rights
You can disconnect your Google integration at any time from the Integrations page, which immediately revokes our access tokens with Google and triggers cleanup of Google-sourced data within 10 days. You can also revoke our access directly at https://myaccount.google.com/permissions. Email privacy@aspired-ai.com to request immediate deletion of all Google-sourced data.
4.3.7 No Automation Without User Approval
- Calendar events are drafted by our agents and require explicit user approval (clicking "Create event") before any event is created on your Google Calendar.
- Email drafts are created in your Gmail Drafts folder and require you to open Gmail and click Send. Aspired AI cannot send email on your behalf with the gmail.compose scope.
- Inbox AI label application: After you opt in and configure your labels via the Inbox AI onboarding modal, label application happens automatically as new emails arrive. You can disable Inbox AI at any time, which immediately stops classification and label application. We never delete, archive, or move messages — only labels are applied. You can manually remove any label from any message at any time directly in Gmail.
- Every API action is logged to an internal audit table (IntegrationAction).
4.3.8 Compliance
Aspired AI complies with the Google API Services User Data Policy, including the Limited Use requirements. We will cooperate fully with any Google audit request and accommodate any required modifications to the integration.
5. How We Share Your Information
We do not sell your personal information. We may share your information with:
5.1 Service Providers / Subprocessors
We use the following third-party companies to operate the Service. Each is bound by a data processing agreement and may only process your data as instructed by us.
| Subprocessor | Purpose | Data Shared | Region |
|---|
| DigitalOcean | Cloud infrastructure and database hosting | All Service data at rest | United States |
| Stripe | Payment processing and subscription billing | Billing details, payment card tokens (we never see card numbers) | United States |
| Anthropic | AI model provider for Claude (chat, drafts) | User-authored prompt content; bound by no-training agreement | United States |
| OpenAI | AI image generation | Image prompt text only | United States |
| SendGrid | Transactional email delivery | Email address, message body for Service emails | United States |
| Google | OAuth sign-in and Google Workspace integrations (Calendar, Gmail) | OIDC profile claims, OAuth tokens, calendar event metadata for events we create, Gmail draft metadata for drafts we create | United States |
5.2 Legal Requirements
We may disclose your information if required by law, court order, or government request, or if we believe disclosure is necessary to protect our rights or the safety of others.
5.3 Business Transfers
If Aspired AI LLC is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.
6. Data Retention
We retain your account information for as long as your account is active. If you delete your account, we will delete your personal information within 30 days, except where we are required to retain it for legal or regulatory purposes.
Conversation history (chat messages sent to AI agents) is retained for as long as your account is active. Individual conversations can be deleted at any time from your dashboard. Upon account deletion, all conversation history is permanently deleted within 30 days.
Note: Meta-sourced data follows the stricter retention windows in Section 4.1.4. LinkedIn-sourced data follows the stricter retention windows in Section 4.2.4. These platform-specific windows take precedence over this general policy.
7. International Data Transfers
Aspired AI is operated from and hosted in the United States. If you access the Service from outside the United States, your information will be transferred to, stored in, and processed in the United States. By using the Service, you consent to this transfer.
For users in the European Economic Area (EEA), the United Kingdom, or Switzerland, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to safeguard cross-border transfers of personal data, where applicable. Our subprocessors (see Section 5.1) provide equivalent contractual protections.
8. Your Rights and Choices
8.1 Access and Correction
You may access and update your account information at any time through your Settings page.
8.2 Deletion
You may request deletion of your account and associated data by contacting us at hello@aspired-ai.com. We will process deletion requests within 30 days. Deletion of LinkedIn-sourced data follows the immediate / 10-day windows in Section 4.2.4 and can also be triggered with the "Request Data Deletion" button on the Integrations page.
8.3 Email Preferences
You may opt out of marketing and digest emails through your Settings page or by clicking the unsubscribe link in any email. You cannot opt out of transactional emails such as billing receipts and security notifications.
8.4 Data Portability
You may request an export of your data by contacting us at hello@aspired-ai.com.
8.5 GDPR Rights (EEA / UK / Switzerland)
If you are located in the EEA, the United Kingdom, or Switzerland, you have the following rights under the GDPR or UK GDPR: the right of access, the right to rectification, the right to erasure, the right to restriction of processing, the right to data portability, the right to object, and the right not to be subject to automated decision-making. You also have the right to lodge a complaint with your local supervisory authority. Our lawful bases for processing are: performance of a contract (account creation and Service delivery), legitimate interests (Service improvement, fraud prevention), and consent (optional marketing emails). For data protection law purposes, Aspired AI LLC is the data controller.
8.6 California Residents (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), including the right to know what personal information we collect and how it is used, the right to correct inaccurate personal information, the right to delete your personal information, the right to limit use and disclosure of sensitive personal information, the right to opt out of the sale or sharing of personal information, and the right not to be discriminated against for exercising these rights. We do not sell or share personal information for cross-context behavioral advertising. To exercise your rights, contact us at privacy@aspired-ai.com.
8.7 Do Not Track
We do not respond to Do Not Track (DNT) browser signals. You may manage tracking preferences through your browser settings.
8.8 Data Breach Notification
In the event of a data breach that affects your personal information, we will notify you by email within 72 hours of becoming aware of the breach, where required by applicable law. The notification will describe the nature of the breach, the data affected, and the steps we are taking to address it.
9. Cookies
We use cookies and similar tracking technologies to:
- Maintain your login session
- Remember your preferences
- Analyze how the Service is used
You can control cookie preferences through your browser settings. Note that disabling cookies may affect certain features of the Service. We do not use cookies for advertising purposes.
10. Security
We implement industry-standard security measures to protect your information, including:
- HTTPS / TLS 1.3 encryption for all data in transit
- AES-256 encryption for sensitive data at rest
- Access controls limiting who can access your data
- Regular security monitoring and audit logging of integration activity
No method of transmission over the internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
11. Children's Privacy
The Service is not directed to children under 18 years of age. We do not knowingly collect personal information from children under 18. If we learn that we have collected information from a child under 18, we will delete it promptly.
Where data about LinkedIn members aged 16 or 17 passes through our system, we handle it in accordance with LinkedIn's youth-protection requirements and the retention windows in Section 4.2.4.
12. Third-Party Links
The Service may contain links to third-party websites. We are not responsible for the privacy practices of those websites and encourage you to review their privacy policies.
13. AI and Data Processing
Your messages to AI agents are processed by Anthropic's Claude API to generate responses. As of the date of this policy, Anthropic does not use API inputs and outputs to train their models. Image generation requests are processed by OpenAI; only the prompt text is sent. Message and prompt content are subject to the respective providers' usage policies.
We do not use your conversation data to train AI models. Conversation history is stored on our servers solely to provide chat history functionality within the Service.
When you use Aspired AI agents to draft Google Calendar events or Gmail emails, the natural-language instructions you provide to the agent are sent to Anthropic's Claude API to generate the draft content. The generated draft is then stored in our database and, upon your approval, written to Google via the Calendar or Gmail API. We do not send your existing Calendar events or Gmail messages to any AI provider — only the draft content the agent generates from your instructions.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on the Service. Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.
15. Contact for Privacy Matters
The individual responsible for privacy matters at Aspired AI LLC is:
Zachery Long, Founder
Aspired AI LLC
Privacy: privacy@aspired-ai.com
Security: security@aspired-ai.com
Legal / DMCA: legal@aspired-ai.com
General: hello@aspired-ai.com
Web: aspired-ai.com
For data deletion requests or to exercise any privacy right described in this Policy, email privacy@aspired-ai.com with the subject line "Privacy Request."
See also our Terms of Service.