Privacy
Privacy Policy
This policy explains how Elav8 AI LLC collects, uses, shares, and protects information when providing Aether Agent.
Last updated: June 27, 2026
1. Information we collect
We collect account information, contact information, billing information, authentication information, organization settings, call and message metadata, recordings where enabled, transcripts, prompts, scripts, uploaded files, lead records, campaign details, opt-in evidence, support messages, usage logs, device information, and integration data.
We may receive information from customers, authorized users, recipients, service providers, communications carriers, payment processors, identity providers, analytics tools, and connected third-party applications.
We may collect information about websites, privacy policies, terms pages, opt-in forms, screenshots, page content, brand details, sample messages, consent language, campaign registration materials, phone numbers, sender identities, DNS records, and carrier or registry responses.
We may collect technical information such as IP address, user agent, device identifiers, browser type, operating system, pages viewed, referring URLs, timestamps, API requests, webhook payload metadata, error logs, security events, cookie identifiers, and approximate location derived from IP address.
2. How we use information
We use information to provide, secure, maintain, support, personalize, troubleshoot, bill for, and improve the Service; process communications; operate AI features; register and monitor messaging programs; detect abuse; comply with legal obligations; and enforce our agreements.
We may create aggregated or de-identified information that does not reasonably identify a person or customer, and may use that information for analytics, forecasting, benchmarking, abuse prevention, and product improvement.
We use communications data to route calls and messages, generate transcripts and summaries, run AI agents, produce analytics, attribute outcomes, honor opt-outs, maintain consent records, support customer workflows, and investigate deliverability, fraud, spam, security, or compliance issues.
We use registration and compliance information to submit or support carrier registrations, toll-free verifications, 10DLC campaigns, email sending domains, brand vetting, compliance scans, appeals, and related evidence packages.
3. How we share information
We share information with service providers and subprocessors that help us provide the Service, including cloud hosting, communications carriers, AI model providers, payment processors, email providers, analytics, support, compliance tooling, and security vendors.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third party except aggregators and providers of the text message services as necessary to deliver the messaging program.
We may share information with telecommunications carriers, messaging aggregators, campaign registries, vetting providers, email providers, DNS providers, payment processors, fraud-prevention vendors, identity providers, legal advisors, auditors, and government or law-enforcement authorities when needed to provide the Service or comply with obligations.
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be disclosed or transferred as part of that transaction, subject to appropriate confidentiality protections where practical.
4. Customer responsibilities
Customers are responsible for their own privacy notices, lawful bases, consent records, call recording notices, AI disclosures, opt-out handling, data subject requests, and compliance with laws that apply to their leads, contacts, employees, and end users.
Customers must not submit sensitive or regulated information unless the Service Order expressly permits it and Elav8 AI LLC has agreed in writing to any required additional terms.
Customers are responsible for configuring agents, integrations, retention choices, consent workflows, lead sources, and disclosures in a way that matches their legal obligations. Customers must not use the Service to collect information from children or to process data they are not authorized to process.
When we process personal information on behalf of a customer, we act as the customer service provider or processor as applicable. Requests from individuals about customer-controlled data may need to be directed to the relevant customer.
5. Security and retention
We use commercially reasonable safeguards designed to protect information against unauthorized access, loss, misuse, and alteration. No system is perfectly secure, and customers are responsible for securing their own users, devices, credentials, and integrations.
We retain information for as long as needed to provide the Service, comply with law, resolve disputes, enforce agreements, preserve audit trails, maintain security, and meet carrier or billing obligations. Retention periods may vary by data type and customer configuration.
Telephony, messaging, consent, billing, audit, signed agreement, security, and carrier-registration records may be retained for longer periods because they are needed to document legal compliance, defend claims, support carrier obligations, investigate abuse, or satisfy accounting and tax requirements.
We may redact, quarantine, or delete payment card data, secrets, credentials, malware, or other high-risk information if discovered in unsupported areas of the Service.
6. Choices and requests
Account users may update certain account information in the Service. Privacy requests may be sent to legal@aetheragent.app. We may need to verify the request and may route requests involving Customer-controlled data to the relevant customer.
Recipients can opt out of SMS by replying STOP where supported, request HELP where supported, use unsubscribe links for email, or contact the customer that initiated the communication.
Depending on location, individuals may have rights to access, correct, delete, port, restrict, or object to certain processing. We will handle requests according to applicable law and our role in relation to the data.
Some browser or device controls may limit cookies, analytics, or local storage. Disabling those controls may affect login, security, preferences, or functionality.
7. International transfers
The Service is operated primarily from the United States. Information may be processed in the United States and other jurisdictions where we, our customers, or our service providers operate.
Where required, customers must ensure appropriate transfer mechanisms, notices, consents, and processing terms are in place before submitting personal information subject to non-U.S. data protection laws.
8. Changes to this policy
We may update this Privacy Policy from time to time. If changes are material, we will provide reasonable notice when feasible. Continued use of the Service after the effective date means the updated policy applies.