Privacy Policy
How we handle your information.
This Privacy Policy explains how Qytherion AI collects, uses, stores, and shares information across Qytherion AI workspace services and related communications workflows. For a product and pricing summary (plans and features), see Qytherion AI product facts—this policy covers legal and vendor disclosures.
Effective date: February 27, 2026 · Last updated: May 21, 2026
Quick summary
- No resale. We do not sell personal data or workspace content.
- Data sovereignty. Cancelling a paid plan or missing a payment does not delete your workspace by default—accounts move to a rate-limited free tier unless you request verified deletion.
- Consent first. SMS and calling workflows require lawful consent and clear opt out controls.
- Clear controls. You can request access, correction, export, or deletion by emailing [email protected].
- Twilio aware. Communication metadata, delivery status, and consent evidence are retained for compliance, fraud prevention, and support.
- Workspace controls. Optional Protected mode and chat encryption at rest in Qytherion AI when you enable them.
- Strict security. We monitor for abuse, may block malicious traffic, and may report network abuse to operators when warranted.
Scope
Who this policy covers
This policy applies when you visit our site, use a Qytherion AI account, or run communication automations through Qytherion AI.
Controller and operator. Qytherion AI acts as the primary service operator for account, billing, support, and product workflows.
Customer instructions. For contact uploads and campaign data, we process information according to customer configuration and campaign settings.
Channels in scope. Website forms, workspace onboarding, Qytherion AI panels, email support, and Twilio powered voice/SMS delivery paths.
Collection
What we collect
We collect what is needed to provide service, support operations, secure systems, and meet legal obligations.
Account and onboarding data. Name, email, organization, role, plan details, project goals, onboarding notes, and billing setup details.
Workspace and automation data. Agent configurations, workflow prompts, uploaded files, imported contacts, queue states, and campaign settings.
Communication data. Phone numbers, email addresses, message body templates, call routing details, timestamps, delivery outcomes, and support transcripts.
Twilio event data. Message/call identifiers, sender/recipient metadata, status callbacks, error codes, carrier responses, and anti abuse telemetry.
Technical and security data. Device/browser signals, IP logs, authentication events, API request diagnostics, and fraud/risk indicators.
Agent leasing and Stripe Connect. If you monetize Registry agents, we process lease pricing you configure, Stripe Connect account identifiers, payout status, subscription metadata, and billing events needed to route monthly subscriber payments to creators. Stripe processes payment card and payout details under its own privacy policy.
Twilio compliance
Voice and messaging privacy controls
When workflows use Twilio, we apply telecom specific safeguards for consent, opt out, and auditability.
Consent requirements. Customers must collect and maintain lawful consent before initiating SMS or automated calling campaigns.
Consent evidence. We may store capture method, source page/form, timestamp, campaign context, and proof references used to demonstrate consent.
Opt out and assistance. Standard controls include STOP/UNSUBSCRIBE style opt out handling and HELP style support responses where applicable.
Do not contact handling. Opted out numbers are suppressed from future sends unless a valid new opt in is recorded.
Call recording and transcription. If recording/transcription is enabled, customers are responsible for lawful notice and jurisdiction specific compliance.
Carrier and pricing notice. Message and data rates may apply. Carrier delivery is not guaranteed and depends on recipient network and handset conditions.
Restricted content. Customers must not use Qytherion AI or Twilio paths for illegal, deceptive, or prohibited communication traffic.
Usage
How we use information
Data usage is limited to operating, securing, improving, and supporting the services you request.
Service delivery. Account creation, workspace provisioning, campaign execution, call routing, queue management, and issue resolution.
Product reliability. Performance monitoring, incident response, debugging, and quality improvements for dashboards, automations, and integrations.
Safety and fraud prevention. Abuse detection, unusual traffic investigation, automated and manual security monitoring, blocking of malicious or excessive traffic, account integrity checks, and policy enforcement under our Acceptable Use Policy.
Legal compliance. Recordkeeping, tax and invoicing obligations, lawful requests, and dispute handling.
No sale of personal information. We do not sell personal data. We do not share personal data for unrelated third party advertising.
Sharing
When information is shared
Information is shared only with providers and partners needed to deliver the services or when required by law.
Infrastructure providers. Hosting, storage, observability, and security vendors acting under contractual restrictions.
Communications processors. Twilio and related telecom delivery partners for SMS/voice transport and event processing.
AI and automation providers. When you use ChatDock model routing, prompts may be processed by the model route you select (for example open-weight endpoints, major hosted model providers, or our HRM (Hierarchical Reasoning Model) runtime), subject to that provider’s terms and our configuration. We also use proprietary in-house models for routing, quality, and security operations; additional Stunner-trained models are in development and are not yet offered as selectable ChatDock providers. The experimental Qytherion AI Symbolic MVP research stack is not a public workspace model offering.
Payments and billing. Payment processors and accounting systems required to manage subscriptions and invoices.
Legal and corporate events. Disclosure if required by law, valid legal process, or a merger/acquisition where permitted and protected by contract.
Security and abuse handling. When investigating attacks against our infrastructure, we may share limited technical information (such as timestamps, network identifiers, and summarized event descriptions) with hosting providers, ISPs, or upstream operators to request remediation. We do not share internal security architecture or proprietary detection methods in these communications.
Security
How we protect information
We use layered administrative, technical, and operational safeguards to protect customer and contact data.
Access controls. Role based permissions, account authentication controls, and least privilege access for internal operations.
Transport and storage protections. Encryption in transit, secure storage controls, and environment separation for production and testing.
Qytherion AI workspace controls. In ChatDock, Protected mode (when you turn it on) redacts common sensitive patterns in your messages before they are sent to AI providers and filters model output before display; it supports text-only conversations while active. Chat encryption at rest is available in workspace settings when you choose to enable it for stored conversation history. These features add to—not replace—HTTPS and our broader access and monitoring safeguards.
Operational monitoring. We use automated and manual monitoring (including our Sentinel security layer) for suspicious activity, unauthorized scanning, credential abuse, and service disruptions. We may apply rate limits, blocks, and account restrictions without publishing internal detection methods.
Enforcement without disclosure. We may deny access to addresses, accounts, or sessions that pose a security risk. We do not publish the specific techniques, thresholds, or tooling used to detect or stop attacks.
Customer responsibility. Customers must safeguard credentials, limit workspace access, and upload only lawfully sourced campaign data.
Retention
Retention and deletion timelines
Retention depends on data category, legal requirements, and active service status.
Workspace records. Maintained while your account is active—including on the standard free tier after paid cancellation or payment failure—unless you submit a verified deletion request. Paid-only capabilities may be rate-limited after plan changes; your history and configurations are preserved by default.
Communication logs. Twilio / Qytherion AI communication metadata and status events are retained for compliance, troubleshooting, and fraud prevention.
Financial records. Invoices and tax documentation are retained per legal and regulatory requirements.
Deletion requests. Verified requests are processed within 5 business days when no overriding legal obligation applies.
Detailed schedule. See Data Retention for category level windows, deletion SLAs, and backup lifecycle details.
Your rights
Access, correction, export, and opt out
You can manage your information and communication preferences through support and standard messaging controls.
Access and correction. Request a copy of account linked personal data or request corrections to inaccurate records.
Deletion and restriction. Request deletion or limited processing where legally available.
Communication controls. For SMS, reply STOP to opt out and HELP for support where applicable. You may also email support to update preferences.
Appeals and complaints. If you disagree with our response, contact us for escalation. You may also contact your local regulator where permitted.
Contact point. Email [email protected] for privacy requests.
Additional disclosures
Children, international processing, and updates
These terms clarify age limits, cross border processing, and policy change handling.
Children's privacy. Services are not directed to children under 13, and we do not knowingly collect personal data from children under 13.
International processing. Data may be processed in locations where service providers operate, subject to contractual and security safeguards.
Policy updates. We may revise this policy to reflect legal, technical, or product changes. Material updates are posted on this page with a revised effective date.
Related legal pages. See Terms of Service, Proof of Consent, and Consent Requests for operational and compliance context.