01
Who this policy covers and Ajani's role
Ajani Automation (“Ajani,” “we,” “us,” or “our”) operates the Ajani website, account and authentication features, voice-note and written-request flow, client workspace, and related service communications. For those activities, Ajani decides why and how the personal information described in this Policy is processed.
When Ajani processes personal information solely on a client's instructions inside a client automation, that client generally determines the purpose and means of processing and Ajani acts as its processor or service provider. The client's privacy notice governs that processing. Direct requests about client-system data to the relevant client first; Ajani will assist as required by the applicable agreement and law.
02
Information Ajani collects and its sources
Ajani collects information directly from you; from your browser, device, and interactions with the service; from Clerk and an OAuth provider you select; from an authorized organization administrator; and, for client-directed workflows, from the client that operates the workflow.
- Account and contact information: name, business name, email, phone, avatar, organization, role, and authentication identifiers.
- Request and project content: written notes, audio recordings, transcripts, clarification answers, proposed routes, development and email briefs, documents, approvals, project messages, support records, and client-provided business rules.
- Generated and derived information: suggested questions, summaries, classifications, workflows, provider and model identifiers, prompt versions, confidence, usage, and status metadata.
- Device, security, and operational information: IP-derived security fingerprints, user agent and device information, timestamps, origin, cookies, session events, request limits, errors, and operational logs.
- Billing information, when enabled: customer, subscription, invoice, amount, currency, and payment-status metadata. Ajani does not receive full payment-card numbers through the public request flow.
Notice when you submit a request. Ajani uses request content, contact details, device and security data, and generated workflow information to transcribe and structure the note, provide the requested intake and project services, prevent abuse, and maintain records. The providers in Section 06 receive only the information needed for their listed functions. Ajani does not sell this information or share it for cross-context behavioral advertising. The retention criteria in Section 09 apply.
03
Why Ajani uses information
Ajani uses information to provide requested pre-contract and contract services; create and administer accounts; transcribe and structure requests; suggest an editable route; deliver and support client systems; authenticate users; prevent fraud and abuse; troubleshoot and secure the service; send project and transactional communications; process approved billing; maintain records; comply with law; and improve service operations through limited internal reporting.
Where European Economic Area or United Kingdom data-protection law applies, Ajani relies on performance of a contract or steps you request before a contract for intake and project services; legitimate interests in security, reliability, support, and limited business administration; legal obligations for required records; and consent where law requires it. You may withdraw consent for future processing at any time, but withdrawal does not make earlier lawful processing unlawful.
04
Voice recording and transcription
When you choose Start voice note, your browser asks for microphone access. During recording, audio remains in memory in the active tab. If built-in speech recognition is available, your browser or operating-system provider may process speech under its own terms to draft live text.
When you choose Finish note or Use this note, Ajani may send the audio through its server to Deepgram to create or confirm the editable transcript shown in the request flow, unless you already supplied enough written text. The supported request path requires the current processing acknowledgment before this provider call. Ajani configures Deepgram transcription requests to opt out of Deepgram's Model Improvement Program. The immediate transcription response is not cached by Ajani's endpoint.
If you approve and send a request containing a recording, the original audio is uploaded to private Ajani storage and may be processed again to create or verify a durable transcript. You can edit the transcript before handoff or use the written option instead. Record only yourself unless you have provided all required notice and obtained all required permission from every other speaker.
05
AI-assisted processing
Before a request is saved, Ajani may send the written note through Vercel AI Gateway or directly to Anthropic to suggest clarification questions. The supported request path requires the current processing acknowledgment before this provider call. After you confirm answers, Ajani may process the note and answers again to propose an editable workflow, outcome, protection statement, and internal email brief. When a request is saved, Ajani may process request context to classify business type and automation outcome for internal demand reporting. A local rules-based fallback keeps the flow usable if an AI provider is unavailable.
Ajani configures AI Gateway requests to prohibit prompt training. Ajani does not train its own general-purpose model on your request. Direct Anthropic API processing and other provider processing are governed by Ajani's account settings and provider contracts. Do not submit sensitive or regulated personal information through the public intake.
AI output can be incomplete or wrong. You can review and edit the proposed route, and a person remains responsible for deciding whether it should be built. Ajani does not use AI output as the sole basis for legal, medical, financial, employment, insurance, housing, credit, or similarly significant decisions.
06
Service providers and other disclosures
Ajani discloses information only as needed to providers that support the service or a client-approved workflow. Current provider categories include Vercel for hosting, infrastructure, and AI routing; Clerk for authentication; Supabase for databases and private file storage; Deepgram for transcription; Anthropic for AI generation; and Resend for internal request-routing email. Stripe is inactive in the public flow and receives billing information only if billing is activated.
Google or GitHub receives information when you choose its sign-in method. YouTube receives standard network and device information when its privacy-enhanced embedded player loads or when you interact with it. A browser or operating-system provider may receive speech data when its built-in recognition feature is used. Those services may act independently for their own account, platform, or security purposes.
Ajani may also disclose information to professional advisers under confidentiality obligations; authorities when legally required; a successor in a merger, financing, reorganization, or sale subject to appropriate safeguards; or another recipient at your direction or with your consent. See the dated Service Providers & Subprocessors list.
07
Client-directed processing
A client automation may process categories of information that are not collected by the public website. Those categories, purposes, instructions, providers, security measures, retention, and deletion terms belong in the client's Order and, where needed, a data-processing addendum.
Ajani does not accept protected health information or other regulated data through the general public intake. A regulated workflow requires a written, approved process and the necessary contracts before information enters that workflow.
08
Cookies and local browser storage
Ajani and Clerk use cookies or similar technologies necessary for authentication, session security, fraud prevention, and account operation. The public intake stores the written note, answers, generated route, current stage, processing-notice acknowledgment version, and a private draft capability in session storage so a refresh in the same tab does not erase the work. Raw recording blobs are not placed in browser storage.
Session storage normally remains until the browser session closes or Ajani clears it after a completed handoff or deletion; browser behavior can vary. Ajani does not currently use advertising pixels or cross-site behavioral-advertising analytics on its public pages. Privacy-enhanced YouTube content may still receive network and device information when the embed loads.
09
Retention and deletion
Ajani retains information only for the period reasonably necessary for the purpose described here, subject to legal holds, disputes, security needs, backups, and contractual or legal requirements.
- Unfinished browser-session state: until submission, deletion, or the browser clears the session.
- Unclaimed saved drafts and voice uploads: 30 days, then queued for scheduled batch deletion. A processing backlog may delay final removal.
- Public abuse-prevention fingerprints: 7 days.
- Failed administrative sign-in fingerprints: 30 days.
- Processed authentication-webhook event metadata: 90 days.
- Claimed requests, original recordings, account, project, approval, billing, and support records: for the active relationship and then for the period reasonably needed to provide the service, preserve agreed records, resolve disputes, and meet tax, legal, or contractual duties.
Provider logs and backups may persist for a limited period after deletion. Deleting a Clerk identity does not automatically erase project records Ajani is legally or contractually required to retain. A verified privacy request initiates review across Ajani and applicable providers.
10
Security
Ajani uses administrative, technical, and organizational safeguards designed to protect personal information. Current measures include access controls, encrypted transport, private storage for voice uploads, scoped upload capabilities, randomized object paths, hashed draft capabilities, input and media validation, request limits, and abuse prevention.
No system can guarantee absolute security. Do not submit passwords, full payment-card numbers, health information, government identifiers, biometric templates, or other sensitive data through the public request tools. Report a suspected security issue to hello@ajaniautomation.com.
11
International processing and transfers
Ajani is operated in the United States and uses providers that may process information in the United States and other countries. Those countries may have different data-protection laws from where you live. Before processing that requires an international-transfer mechanism, Ajani must document the mechanism and any supplementary safeguards in its provider or client agreements. Contact Ajani to ask which arrangement applies to a specific processing path.
12
Your privacy choices and requests
Depending on where you live, you may have rights to know or access, correct, delete, or obtain a portable copy of personal information; object to or restrict processing; withdraw consent; opt out of sale, targeted advertising, or qualifying profiling; and appeal a denied request. Ajani does not discriminate against a person for exercising an applicable privacy right.
Email hello@ajaniautomation.com with “Privacy request” in the subject. You do not need an account. Ajani may verify your identity and authority and may retain or withhold information where law permits or requires it. An authorized agent should identify the person represented and provide evidence of authority. To appeal a decision, reply with “Privacy appeal” and explain the requested review.
People in the EEA or UK may also complain to their local supervisory authority. If your request concerns information processed for an Ajani client, Ajani may direct you to that client or assist the client in responding.
13
U.S. state privacy disclosures
The categories collected during the preceding 12 months are described in Section 02; the sources and purposes appear in Sections 02 and 03; and the recipient categories appear in Section 06. Ajani does not sell personal information or share it for cross-context behavioral advertising, and does not offer a financial incentive in exchange for personal information.
Ajani does not use the public voice feature for speaker identification or to create a voiceprint. The service transcribes the content of a note. Requests to access, correct, delete, or obtain a copy may be submitted through the method in Section 12, subject to verification, legal exceptions, and rights available in your state.
14
Children
Ajani is a business service and is not directed to children. You must be at least 18 to create an account or submit a request. If Ajani learns that personal information was collected from a child contrary to this restriction, contact Ajani and appropriate deletion steps will be taken.
15
Changes and contact
Ajani may update this Policy as practices or legal obligations change. The effective date identifies the current version. Any direct notice or renewed acknowledgment required by applicable law must be completed before Ajani relies on the change. Changes apply prospectively unless applicable law permits otherwise.
Questions, privacy requests, security reports, accessibility feedback, or requests for an accessible copy may be sent to hello@ajaniautomation.com. Do not include a diagnosis, medical record, password, or other sensitive information in the email. Ajani may request information needed to verify identity, authority, or the location of the relevant record.