Axari Privacy Policy

Effective date: 4 September 2026

This document describes Axari’s current privacy practices and is provided for transparency purposes. It does not create contractual obligations unless expressly incorporated into a written agreement. Capitalized terms not defined here have the meanings set forth in Axari’s Terms of Service.

1. Who we are and what this covers

Axari Technologies, Inc. (“Axari”, “we”, “us”) provides Axari: a service that gives each person on a security team a personal AI colleague (a “Twin”) that works inside messaging platforms such as Slack and Microsoft Teams, connects to tools that person chooses, and performs work with that person's approval.

This policy explains what information we collect, how we use it, who we share it with, how long we keep it, and the rights you have. It covers the Axari product (including the Slack and Teams apps and app.axari.ai) and our marketing website (www.axari.ai). It applies to Customers (organizations), their Users (individuals with a Twin), and visitors to our website.

Where Axari processes Customer Data on behalf of a Customer organization, the Customer is the data controller and Axari acts as a processor under the applicable agreement and Data Processing Agreement. This policy describes our practices in plain language; contractual terms live in the Terms of Service and any DPA.

2. Information we collect

2.1 Account and profile information

  • Name, work email address, and organization, provided at signup or by the admin or colleague who invited you.
  • Basic profile details from your messaging platform when you sign in (for example your Slack user ID, display name, title, and workspace), used to create your account and personalize your Twin.
  • The role or roles you select (for example GRC lead, SOC lead), used to tailor what your Twin suggests and how it communicates.

2.2 Content you bring to your Twin

  • Messages you send to your Twin, and conversation content you explicitly invoke it on (for example via a slash command or message shortcut in a thread).
  • Data from integrations you personally connect (for example calendar, email, ticketing, or security tools). Each integration is a separate, scoped authorization that you grant and can revoke at any time. Axari accesses connected tools only to provide the service.
  • Tasks, commitments, and preferences you ask your Twin to track or remember.

2.3 Proactive assistance

Your Twin can work proactively: it evaluates content from the sources you have connected or invoked it on, in order to track commitments, watch deadlines, and surface things that need your attention. It applies exclusions designed to leave sensitive personal content alone, and everything it does is recorded in an activity log you can review. It does not read channels or conversations you have not connected it to or invoked it in.

2.4 Memory

Your Twin learns how you work: formats, tone, priorities, and corrections you give it. This memory is private to you, visible to you, and deletable by you (ask your Twin to forget something, or manage memory in the app).

2.5 Service telemetry and session records

We record what the service does: sessions, actions taken, tools called, errors, latency, and credits consumed. Session content is summarized and redacted at ingestion for operational use; we use these records to run the service reliably, investigate problems, meter usage, and improve the product. We do not use Customer Data to train foundation models by default (see Section 3).

2.6 Organizational information from public sources

To give Twins useful context, we compile profiles of organizations from publicly available sources (for example a company's website, public filings, and security pages). This can include your Customer organization and, where a User runs vendor-risk work, third-party vendor organizations. These profiles describe organizations, not private individuals; they may include the names and roles of publicly listed leadership. Profiles can be incomplete or out of date, are marked with their sources, and should be verified before being relied on.

2.7 Billing information

For self-serve plans, payment is processed by our payment processor (Stripe). Axari receives billing status, plan, and card metadata (such as last four digits), never full card numbers. Enterprise billing is handled per the applicable Order Form.

2.8 Website visitors and cookies

Our marketing website uses necessary cookies for basic operation and, only with your consent, analytics cookies (Google Tag Manager and Google Analytics). The invite request form is provided by HubSpot, which may set cookies related to form delivery and spam prevention. You can accept or reject analytics on first visit and change your choice anytime via Cookie preferences in the footer. The product application uses cookies required to authenticate users and operate the service.

3. How we use information

  • To provide the service: run your Twin, execute the work you approve, deliver briefs and notifications, and maintain your activity log.
  • To keep the human in control: consequential actions (external sends, posts, and writes) wait for your explicit approval before executing.
  • To personalize: apply your role, preferences, and memory so your Twin works the way you do.
  • To operate and improve the product: monitor reliability, investigate errors, understand which capabilities are used, and identify failures. This uses summarized, redacted session records.
  • To meter and bill: count credits consumed and administer plans, top-ups, and contracts.
  • To secure the service: detect abuse, enforce isolation, and respond to incidents.
  • To communicate: service notifications (approvals, billing receipts, account changes) and a limited set of lifecycle emails, governed by suppression rules. Account and security notices cannot be muted; other notifications can.

Model training default: Axari does not use Customer Data to train foundation models unless the Customer explicitly opts in and the use is documented and communicated.

4. The privacy of your Twin

A Twin works for one person. Its conversations, memory, and activity log are available to its owner. They are not made available to workspace admins, to the Customer's leadership, or to other users through Axari. Axari personnel access customer environments only through audited support processes. Aggregated, de-identified usage measures (for example seat counts and credit consumption) are visible to Customer admins for administration and billing; the content of a Twin's work is not.

5. Sharing and sub-processors

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We share information only with:

  • Model providers. Prompts and context are sent to large language model providers (for example via OpenRouter to Anthropic, OpenAI, and others) to generate responses, under agreements that prohibit training on this data. If your organization uses BYOK (bring your own key), inference traffic for agent work is sent to your organization's own model provider account under your organization's agreement with that provider; Axari continues to make limited platform model calls (for example message classification) on Axari's own keys.
  • Platform providers. Slack and Microsoft, to operate the apps inside those platforms.
  • Infrastructure and operations. Cloud hosting, payment processing (Stripe), product analytics (Mixpanel), observability and tracing, and email delivery providers.
  • Legal and safety. Where required by law, to protect rights and safety, or in connection with a corporate transaction, with notice where required.

6. Retention and deletion

  • Active accounts: data is retained while the account is active, per the practices in our Security Practices page.
  • Memory: you can delete individual memories at any time; deletion is honored in your Twin's future work.
  • Uninstall or termination: if the Axari app is removed from your workspace or your organization's contract ends, the service is suspended and data is retained for 30 days so your organization can export it. After 30 days, Customer Data is deleted and stored third-party authorizations (OAuth grants) are revoked, except where law requires retention. Backups expire on their own schedule thereafter.
  • Removed users: if an admin removes a user, that user's Twin is deactivated and their personal data is handled per this retention schedule.

7. International transfers

Axari is a Delaware, USA company and processes data in the United States and other locations where our sub-processors operate. Where required, transfers are protected by appropriate safeguards such as Standard Contractual Clauses. Details are available in the DPA.

8. Your rights

Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal information, and to object to certain processing:

  • EU/UK (GDPR): the rights above, plus the right to lodge a complaint with a supervisory authority.
  • California (CCPA/CPRA): the rights to know, delete, correct, and to non-discrimination. We do not sell or share personal information as those terms are defined in the CPRA.
  • India (DPDP Act): the rights to access, correction, erasure, and grievance redressal.

To exercise rights, contact privacy@axari.ai. If you use Axari through your employer, we may direct your request to your organization, which controls Customer Data. We respond within the timelines required by applicable law.

9. Security

Our technical and organizational safeguards (encryption, access control, tenant isolation, incident response) are described on our Security Practices page. If we learn of a security incident involving your data, we will notify affected customers without undue delay, consistent with legal and contractual requirements.

10. Children

Axari is a workplace product and is not directed to children under 16. We do not knowingly collect personal information from children.

11. Changes to this policy

We will update this policy as the product evolves. Material changes will be announced on this page and, where appropriate, by email or in-product notice. The effective date above always reflects the current version.

12. Contact

Privacy questions and rights requests: privacy@axari.ai. Security: security@axari.ai. Axari Technologies, Inc.

13. Google User Data & Google Workspace Services

Axari provides integrations with Google Workspace services, including Gmail, Google Calendar, and Google Drive. These integrations allow users and organizations to connect their Google Workspace accounts to Axari and authorize Axari to access specific Google data for user-requested functionality.

This section describes how Axari accesses, uses, processes, and protects information received through Google APIs.

13.1 Google User Data We Access

Depending on the Google services and permissions authorized by the user or organization, Axari may access:

Gmail

  • Email messages and content
  • Email subjects
  • Sender and recipient information
  • Email timestamps
  • Labels and other email metadata
  • Attachments where required for an enabled Axari feature

Google Calendar

  • Calendar events
  • Event titles and descriptions
  • Start and end times
  • Event attendees
  • Locations
  • Meeting links
  • Calendar metadata

Google Drive

  • Files that the user has authorized Axari to access
  • File names and metadata
  • File contents where required for an enabled Axari feature
  • Relevant file and sharing metadata

Google Account Information

Axari may also access basic account information required to authenticate and identify the connected Google account, such as the user's name, email address, and other profile information made available through the authorized authentication flow.

Axari requests only the Google permissions necessary to provide the functionality enabled by the user or organization.

13.2 How We Use Google User Data

Axari uses Google user data only to provide functionality requested or enabled by the user or organization.

This may include:

  • Analyzing and organizing relevant emails and calendar information
  • Preparing summaries, briefs, and meeting context
  • Identifying relevant information across authorized Google services
  • Supporting workflow automation and follow-up activities
  • Providing search, analysis, and productivity functionality
  • Performing actions through Google services when explicitly authorized
  • Providing security and operational workflows requested by the user or organization

Axari does not use Google user data for advertising, targeted advertising, or selling data to data brokers or information resellers.

13.3 AI Models and Model Providers

Axari is model agnostic and may use different artificial intelligence models and model providers to process information depending on the functionality, configuration, security, performance, or other operational requirements.

When Google user data is required for an AI-powered Axari feature, the relevant data may be transmitted to an AI model or service provider solely for the purpose of processing the data and providing the requested functionality.

Axari does not retain the underlying raw Google data after the processing required to provide the applicable functionality is completed.

Axari does not use Google user data obtained through Google APIs to train or improve generalized, non-personalized AI or machine-learning models.

13.4 Raw Google Data Retention

Axari follows a data-minimization approach for information obtained from Google services.

Axari does not store or retain the underlying raw Google data, including raw Gmail message content, raw Google Calendar content, or raw Google Drive file contents, after such data has been processed for the applicable functionality, except where temporary processing or retention is technically necessary to complete that functionality.

Axari may retain derived information, metadata, workflow state, identifiers, or other information necessary to provide ongoing functionality. Such information is subject to Axari's applicable security, retention, and deletion practices.

13.5 Sharing and Disclosure of Google User Data

Axari does not sell Google user data.

Axari does not share Google user data with advertising platforms, data brokers, or information resellers.

Google user data may be processed by third-party infrastructure, technology, and AI service providers acting on behalf of Axari where such processing is necessary to provide the functionality requested or enabled by the user or organization.

Such providers are subject to appropriate contractual, confidentiality, security, and data-protection obligations.

Because Axari is model agnostic, the specific AI model or provider used to process data may vary. Axari does not permit such providers to use Google user data for their own advertising, data-broker, or unrelated commercial purposes.

Axari may also disclose information where required by applicable law, legal process, or governmental request, or where necessary to protect the security, rights, or integrity of Axari, its users, or its services.

13.6 Human Access to Google User Data

Axari limits human access to Google user data.

Axari personnel may access Google user data only where necessary to:

  • Provide or support a requested Axari service
  • Investigate security incidents or technical issues
  • Prevent abuse or unauthorized activity
  • Comply with applicable legal requirements
  • Perform other activities permitted under applicable Google policies

Such access is subject to appropriate access controls and security measures.

13.7 Security

Google user data is protected using Axari's technical and organizational security controls described throughout this policy.

These controls include access controls, authentication, encryption, tenant isolation, monitoring, and other safeguards appropriate to the nature of the information being processed.

Access to connected Google services is scoped according to the permissions authorized by the user or organization.

13.8 Disconnecting Google Services and Deletion

Users can disconnect their Google account or revoke Axari's access through the applicable Google or Axari account controls.

When Google authorization is revoked, Axari will stop accessing Google data through that authorization.

Because Axari does not retain the underlying raw Google data after processing, disconnecting the integration does not leave a retained copy of the underlying Gmail, Calendar, or Drive content in Axari's systems.

Any derived information or metadata retained for Axari functionality remains subject to Axari's applicable retention and deletion practices.

13.9 Google API Services Limited Use

Axari's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Axari's use and transfer of Google user data is limited to providing or improving user-facing functionality that is requested or enabled by the user or organization, as permitted by Google's applicable policies.

Axari does not sell Google user data or use Google user data for advertising, including personalized, interest-based, or retargeted advertising.

Axari does not use Google user data to determine creditworthiness or for lending purposes.

Axari does not use Google user data obtained through Google APIs to train or improve generalized, non-personalized AI or machine-learning models.

These restrictions apply to Google user data and data derived from Google user data.

Attackers aren't going to use less AI. Defenders shouldn't either.

Prasen Shelar, Founder and CEO