この文書は英語で提供されており、英語版が優先されます。
Privacy Policy
Last updated: September 25, 2026
This Privacy Policy explains how AskAIs collects, uses, shares, and protects personal information. AskAIs is operated by MiniCode LLC, located at 30 N Gould St Ste R, Sheridan, WY 82801, USA (“AskAIs”, “we”, “us”), the data controller for personal information about our account holders and website visitors. It applies to our website at askais.com and cs.askais.com and to the AskAIs service.
Public website measurements
When enabled, our first-party website counter records daily totals for page views and clicks on sign-up, sign-in and App Store links. These totals are grouped by broad website section and language, not by visitor or account. The counter does not store full URLs, query strings, message content or raw IP addresses, and does not set tracking cookies. It respects browser Do Not Track and Global Privacy Control signals. A keyed, short-lived hash of a network address is used for rate limiting and expires within two minutes. Aggregates older than 90 days are pruned during collection; remaining aggregates may be retained while collection is disabled. Service authentication and operational security logs are separate from this counter.
1. Controller and processor roles
We act as a data controller for personal information about our customers (account holders) and our own website visitors. When our customers use AskAIs to communicate with their end users, we process those end users’ personal information as a data processor, on our customers’ behalf and under their instructions; in that case the customer is the controller. This policy describes our practices as a controller. Our processing on behalf of customers is governed by our agreement with them, including a Data Processing Addendum available on request. We keep each customer’s data logically separated from that of other customers (multi-tenant isolation). The Service may also be white-labeled, so an end user may see only the customer’s brand and may not be aware that AskAIs provides the underlying technology.
2. Information we collect
- Account information: your name, email address, password, workspace and company details, and role.
- Billing information: your plan, transaction history, and billing identifiers. Card details are collected and stored by Stripe, not by us.
- Usage and device data: log data, IP address, browser and device type, pages viewed, and actions taken in the Service.
- Connected AI client data: when you authorize ChatGPT, Codex, Claude, or another MCP-compatible client, we process the client name, your AskAIs user and workspace identifiers, granted permissions, connection and revocation timestamps, and limited MCP call metadata such as tool name, outcome, duration, and client platform. We do not store MCP tool arguments, prompts, tool results, passwords, full API keys, or plaintext OAuth tokens in the MCP usage log.
- Support communications: messages and information you send when you contact us.
- Customer Data: conversations, contacts, knowledge-base documents, and other content that our customers and their end users submit, which we process as a processor (see “Controller and processor roles”). Depending on how a customer configures the Service, this may also include an end user’s IP address and the approximate location derived from it (such as country and city), the platform and device they use to reach the customer, any custom attributes the customer records about them, membership or account fields the customer chooses to store, voice messages and their transcripts, and translations of messages that agents choose to translate.
- Cookies and similar technologies (see “Cookies and tracking”).
3. How we use information
- to provide, operate, and maintain the Service;
- to authenticate users and secure accounts;
- to establish, operate, audit, and let you revoke authorized MCP connections;
- to process payments and prevent fraud;
- to provide AI-assisted replies, translation, voice dictation, and related features (see “Third-party AI services”);
- to respond to support requests;
- to analyze and improve the Service;
- to send service-related and, where permitted, marketing communications;
- to comply with legal obligations and enforce our Terms.
4. Legal bases (EEA and UK)
Where the GDPR or UK GDPR applies, we rely on the following legal bases: performance of a contract (to provide the Service and process billing); our legitimate interests (to secure, analyze, and improve the Service); your consent (for example, certain cookies or marketing); and compliance with legal obligations. You may withdraw consent at any time where processing is based on consent.
5. Payments
We use Stripe for payments, analytics, and other business services. Stripe may collect personal data including via cookies and similar technologies. The personal data Stripe collects may include transactional data and identifying information about devices that connect to its services. Stripe uses this information to operate and improve the services it provides to us, including for fraud detection, loss prevention, authentication, and analytics related to the performance of its services. You can learn more about Stripe and read its privacy policy at https://stripe.com/privacy.
6. Connected AI clients and MCP
If you choose to connect an MCP-compatible AI client, that client can access only the AskAIs workspace and permission scopes shown on the authorization screen. Depending on the permissions you grant and the tool you ask the client to use, relevant Customer Data may be transmitted between the client and AskAIs to perform your request. Read and write tools are identified separately, and external or destructive actions may require confirmation in the client.
OAuth authorization codes are short-lived and single-use. Access and refresh tokens are random credentials returned only to the authorized client; AskAIs stores only cryptographic hashes of those tokens. You can review and revoke connections from your AskAIs MCP connection settings. Revocation immediately prevents further use of associated tokens.
7. Third-party AI services
Some features of AskAIs use a third-party AI service to process content. For these features we use OpenAI, which acts as our subprocessor. We send it only the content a feature needs, and only when that feature is used:
- AI replies. When a workspace turns on automated replies that use our platform-hosted AI, we send OpenAI the visitor’s messages and the recent conversation, relevant excerpts from the workspace’s knowledge base, and contact details the workspace already holds that help answer the question, such as the visitor’s name, device, and approximate location, so that it can draft a reply. The visitor’s IP address is not included.
- Translation. When an agent chooses to translate a message or a reply draft, in the web dashboard or in the mobile app, we send OpenAI the text of that message or draft and the language to translate it into. The translation of a received message is saved with that message so that it does not have to be translated again; reply drafts and their translations are not stored on our servers.
- Voice dictation. When an agent dictates a reply, in the web dashboard or in the mobile app, our servers forward the recording to OpenAI to convert it into text. We do not store the recording; the text is placed in the reply box for the agent to review before sending.
- Voice message transcripts. Where speech-to-text is turned on for a workspace, audio messages sent in its conversations may be sent to OpenAI to produce a written transcript, which is stored with the message.
Nothing is sent for these features unless they are used: AI replies and voice message transcripts only when the workspace has turned them on, and translation and dictation only when an agent chooses to use them. In the AskAIs mobile app, before an agent uses dictation or translation for the first time, the app explains what will be sent and to whom and asks for the agent’s permission. Nothing is sent until the agent agrees, and the agent can withdraw that permission at any time in the app’s settings (see “Mobile apps” below). Translated messages and drafts can include information that a workspace’s customers have shared, such as their name or order details; the workspace decides whether its agents may use translation.
OpenAI processes this content only to return the reply, translation, or transcript to us. According to OpenAI’s API data usage policy, content sent through its API is not used to train OpenAI’s models by default, and OpenAI may retain it for up to 30 days to monitor for abuse.
We engage OpenAI under written terms that require it to provide the same or equal protection of personal data as described in this Privacy Policy.
A workspace can instead connect its own AI provider account (its own API key) for AI replies. In that case the content for those replies is sent to the provider the workspace chose, under the workspace’s own agreement with that provider.
8. How we share information
We do not sell your personal information. We share it only as follows:
- Service providers and subprocessors that help us operate the Service, such as hosting, object storage for files and attachments (such as Amazon S3 or Cloudflare R2), payments (Stripe), AI model providers (see “Third-party AI services”), messaging channel providers (such as Telegram) where a customer connects those channels, email delivery, and analytics, under contracts that require them to provide the same or equal protection of personal data as described in this Privacy Policy;
- Legal and safety: to comply with law, respond to lawful requests, or protect the rights, property, and safety of AskAIs, our users, and the public;
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets;
- With your consent or at your direction.
9. Cookies and tracking
We and our providers use cookies and similar technologies to keep you signed in, remember preferences, secure the Service, and measure usage. You can control cookies through your browser settings, though some features may not work without them.
10. Data retention
We retain personal information for as long as your account is active and as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. Customer Data is retained according to our customers’ instructions and our agreements with them, and is deleted within a reasonable period after account termination.
OAuth authorization codes expire within minutes. OAuth access tokens normally expire within one hour and refresh authorization normally expires within 30 days unless revoked sooner. We retain connection records and limited MCP usage metadata while needed to operate, secure, and audit the connection and account. Revoked credential hashes and security records may be retained for a limited period to detect replay, abuse, or security incidents; they cannot be used as plaintext credentials.
When a message is deleted, we make reasonable efforts to also remove any associated files and attachments from our object storage, although residual copies may persist for a limited time in backups.
11. Security
We use technical and organizational measures to protect personal information, including encryption in transit, access controls, and reliance on PCI-DSS-compliant providers for card processing. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. International transfers
We are based in the United States and may process personal information there and in other countries. Where required, we use appropriate safeguards, such as Standard Contractual Clauses, for transfers from the EEA, UK, or Switzerland.
13. Your rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. Residents of the EEA and UK may also lodge a complaint with their local supervisory authority.
California residents have rights under the CCPA/CPRA, including to know, delete, and correct personal information and to opt out of the sale or sharing of personal information, and, as noted above, we do not sell personal information. We will not discriminate against you for exercising your rights.
To exercise your rights, email support@askais.com; we may need to verify your identity. If the information is held on behalf of one of our customers, we will refer your request to that customer.
14. Children’s privacy
The Service, including our mobile app, is a business tool for companies and their support staff and is not directed to children. We do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact us and we will delete it.
15. Data Processing Addendum
Business customers who require a Data Processing Addendum (DPA) for GDPR or UK GDPR compliance can request one at support@askais.com.
16. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version here with a new date and, where appropriate, provide additional notice.
17. Mobile apps
We publish the AskAIs agent app, a mobile app that lets a customer’s support agents work from a phone. Everything above applies to the app. Because the app also handles a few things that the web service does not — push notifications, the camera, microphone, and photo picker, the permission it asks for before dictation or translation is first used, device records used for remote sign-out, and in-app account deletion — those, together with the customer details (including IP address) that the app shows to agents, are described separately in our AskAIs Mobile App Privacy Notice, which supplements this policy rather than replacing it.
To delete your account, either in the app or by email, and to see which data is deleted and which is kept, see Delete your AskAIs account.
18. Contact
For privacy questions or to exercise your rights, email support@askais.com or write to MiniCode LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA.