Privacy Policy

What we collect, what we do with it, and what we never do.

Version 2026-07-26.1

What we hold

Workspace content — messages, files, images and annotations. Your organisation owns this; we process it to run the service.

Account information — name, email address, and optionally a phone number, job title, and profile picture.

Technical information — sign-in times, IP address, browser, and device information, kept for security and troubleshooting.

What we never do

  • We do not train machine-learning models on your content.
  • We do not sell your content or your personal information.
  • We do not use your content for advertising.

Content checks

HQ automatically checks messages and images — including direct messages — to keep this workspace professional. Most checks only ever show a private note to the sender and are never stored. Serious matters such as harassment or explicit content are reported to the people your workspace has designated for that, along with the content itself, and you will not be notified at the time.

Checks happen as a message is sent. For a private nudge — the lightest outcome — nothing at all is stored. Only where a message is held or reported is a record kept, and content itself is retained only for reported items, so that the people responsible for reviewing them can do so.

Your workspace's administrators choose which categories are checked and who receives reports. If your workspace has designated no moderation contact, nothing is reported to anyone.

Who can see your content

  • Members of your workspace, according to project and thread permissions
  • Your workspace administrators, who can export workspace data and view the audit log — this is normal for any workplace tool, and it is your employer's data
  • Designated moderation contacts, for reported content only
  • Us, only where necessary to operate the service, investigate abuse or security issues, or comply with a legal obligation

We require valid legal process before disclosing content to law enforcement, and we will tell the Customer before doing so unless legally prohibited.

Security

Passkeys and multi-factor authentication. Passwords hashed with Argon2id. Encryption in transit and at rest. Files in private storage, reachable only via short-lived signed links. Workspace data isolated at the query layer. An append-only audit log of significant actions.

Retention

Content is kept while the workspace is active. On closure, the workspace may be exported for 30 days, after which we may delete it.

Your rights

Depending on where you live you may have rights to access, correct, export or delete your personal information. Because your employer is the controller of workspace content, ask them first — we will support them in responding. For account information held about you directly, contact support@aioble.com.

Contact

support@aioble.com