Legal
Privacy Policy
Effective Date: September 17, 2026
1. Introduction
This Privacy Policy describes how AION Technologies Inc. ("AION," "we," "us," or "our") collects, uses, discloses, and protects information obtained from users of our cloud AI platform — comprising GPU compute and inference (model-serving), together with related account, billing, and support services. AI agents and custom/fine-tuned model deployments are provided to enterprise customers under separate written agreements; where those solutions run within a customer's own cloud environment, customer data remains in that environment and this Policy's processing provisions apply to the AION-operated platform described here.
1.1 Scope of This Policy
This Privacy Policy applies to:
- Marketing Website (aion.xyz): discovery and information
- Platform Console (console.aion.xyz): compute, projects, and account management
- Inference API (api.aion.xyz): model-serving
- Pre-signup Browsing: anonymous catalog access
- Support and Documentation: docs.aion.xyz, status.aion.xyz
1.2 Our Commitment
We are committed to protecting your privacy while delivering high-performance AI infrastructure and services. This Policy explains our data practices and your rights, including how we handle the prompts, files, outputs, and agent activity you process through the Services.
2. Information We Collect by User Journey
2.1 Marketing Website Visitors (aion.xyz)
With Consent Only: Google Analytics 4 data, marketing pixel data (Meta, LinkedIn), and UTM parameters for attribution. No personal data is collected without explicit consent.
2.2 Platform Browsers (Pre-Signup)
Anonymous Catalog Access: availability viewing patterns, pricing calculator usage, region/SKU/model preferences. No identity or personal data collection.
2.3 Waitlisted Users
Upon Signup: email address (required), company name (optional), workload intent and use case. Enrichment via Folk CRM: firmographic and technographic signals, not shared with marketing pixels or third parties.
2.4 Active Platform Users
Account Information: name, email, encrypted password, organization details, tax ID, billing address, and KYC verification documents.
Full Platform Telemetry: PostHog session recordings and analytics, resource usage metrics, API call logs, Stripe billing data, and Intercom support interactions.
2.5 Compute Usage Information
For GPU compute, we collect resource usage (GPU hours, compute cycles, storage), instance configuration and regions, project information, SSH public keys, firewall rules, and API usage patterns.
2.6 Inputs and Outputs (Inference)
When you use the Inference Services, the following are processed:
- Inputs: the prompts, files, documents, embeddings, and other content you submit for inference
- Outputs: the content the models generate in response to your Inputs
- Operational Metadata: request and token counts, latency, error rates, and model selected
Zero retention. Inference runs on a zero-retention basis. Your Inputs and Outputs are processed only to generate a response and are not stored or logged by AION — including for abuse detection, safety filtering, or debugging — and are not used to train any model (see Sections 3.5 and 6). Models are hosted on AION-operated infrastructure, so your Inputs and Outputs are not shared with any third-party model provider. We retain only the non-content operational metadata above. You remain responsible for ensuring you have the rights and consents needed for the content you submit, and for limiting the sensitive or special-category data you include.
Agents and custom/fine-tuned deployments are provided under separate written agreements. Where such a solution runs within your own cloud environment, any prompts, outputs, agent activity, tool calls, connected-system data, and logs remain in your environment under your control; whether that data is logged or used for training is governed by your configuration and that agreement, not by this Policy.
2.7 Payment and Billing Information
Payment method details (processed by Stripe), billing history, credit information, and tax information (VAT numbers, exemption certificates).
2.8 Technical and Performance Data
Infrastructure metrics, error logs, security events (login attempts, access patterns, anomaly detection), and platform performance data.
2.9 Support and Communication Data
Support tickets, feedback, documentation usage, and community participation.
3. How We Use Your Information
3.1 Service Delivery and Operations
To provision compute; serve inference requests; run and orchestrate agents; authenticate users and enforce permissions; process billing; provide support; and maintain infrastructure availability and performance.
3.2 Platform Enhancement
To optimize performance, develop features, enhance security, improve reliability, and customize your experience — using account, telemetry, and operational metadata. This does not include using your Inputs or Outputs to train foundation models (see Section 3.5).
3.3 Communications
Service updates, security alerts, billing notifications, product announcements, and opt-in educational content.
3.4 Legal and Compliance
To meet legal obligations, enforce our Terms, prevent abuse and fraud, respond to legal requests, and protect our rights.
3.5 AI Model Training — Our Position
We do not use your Inputs, Outputs, or other Customer Content to train, fine-tune, or improve any models — our own or third parties'. Inference is zero-retention: your Inputs and Outputs are not stored or logged, including for abuse detection, safety filtering, or debugging, and there is no human review of them. We use only aggregated, de-identified operational metadata that does not contain your Input or Output content to secure, monitor, and improve the Services. Where you separately engage AION for fine-tuning or a custom deployment, any use of your data for training occurs only at your direction under that agreement.
4. Cookie and Tracking Technologies
As detailed in our Cookie Policy: the marketing site uses optional analytics cookies with explicit consent via CookieYes; the platform uses essential cookies plus PostHog analytics required for service delivery. Legal basis is consent for marketing cookies and legitimate interest for platform operations.
5. Legal Basis for Processing
5.1 Contract Performance
Providing compute, inference, and agent services; processing payments; managing your account and projects; and delivering support.
5.2 Legitimate Interests
Platform analytics, infrastructure and model-serving monitoring, security and fraud prevention, and service improvement based on operational metadata. We rely on legitimate interest to process Inputs and Outputs only to the extent necessary to deliver the Services you request and to keep them secure. We do not rely on legitimate interest for marketing cookies (those require consent).
5.3 Legal Obligations
Compliance with data protection, tax, financial reporting, and export-control laws, and responding to legal process.
5.4 Consent
Marketing communications, optional analytics, beta feature participation, and any optional use of your data to fine-tune Custom Models.
6. Data Sharing and Third Parties
6.1 Principle
We do not sell, rent, or trade your personal information. We share data only as necessary for service delivery or legal compliance.
6.2 Service Providers
- Infrastructure Partners: GPU providers, data centers
- Payment Processor: Stripe
- Analytics: PostHog (platform analytics)
- Support: Intercom
- CRM: Folk (lead enrichment)
- Marketing Analytics: Google, Meta, LinkedIn, Twitter/X (consent-based)
- Security Services: DDoS protection, threat detection
- Consent Management: CookieYes
Models are hosted and served on AION-operated infrastructure; your Inputs and Outputs are not sent to or processed by any third-party model provider. For agent or custom deployments provided under a separate agreement and run in your own environment, any data flow to or from systems you connect is governed by your configuration and those systems' own terms, not by AION.
6.3 Legal and Regulatory Sharing
We may share information to comply with law, respond to subpoenas, warrants, or court orders, protect safety and prevent harm, and protect our rights. We report data breaches to the relevant authorities as required by applicable law.
6.4 Data Processing Agreements
We maintain GDPR-compliant DPAs with our sub-processors, including PostHog, Stripe, Intercom, Folk, CookieYes, and our GPU and data-centre infrastructure providers. No third-party model provider is used to deliver inference. Enterprise customers may request copies at [email protected].
6.5 Business Transfers
In a merger, acquisition, or sale, your information may transfer to the successor, which will be bound by this Policy. We will notify you before any transfer.
7. Data Security Measures
7.1 Technical Safeguards
AES-256 encryption at rest, TLS 1.3 in transit, role-based access controls, multi-factor authentication, network security (firewalls, intrusion detection, DDoS protection), isolated environments, secure key management, and 24/7 monitoring.
7.2 Organizational Measures
Data protection policies, employee security training, need-to-know access restrictions, vendor security assessments, and incident response procedures (notification within 72 hours to authorities per GDPR, without undue delay to users).
7.3 Your Responsibilities
Maintain strong passwords and MFA; protect API keys and any credentials you provide to agents or integrations; report suspicious activity; and follow security best practices.
8. Data Retention
8.1 Retention Periods
- Active Accounts: throughout your subscription period
- Billing Records: 7 years for tax and accounting
- Consent Records: 2 years from consent date
- Usage Logs: 90 days for operational data
- Inference Inputs and Outputs: not retained — processed transiently to serve your request and never stored or logged (zero retention)
- Security Logs: 1 year for incident investigation
- Support Records: 3 years after ticket closure
- Deleted Projects: 30 days recovery period
8.2 Data Deletion
Upon account termination, instance data is terminated, account data is retained for 90 days for recovery, billing records are retained per legal requirements, and you may request immediate deletion subject to legal obligations.
9. Your Privacy Rights
9.1 Rights You May Exercise
Depending on your location: access, correction, deletion, portability, restriction, objection, and withdrawal of consent.
9.2 How to Exercise Rights
Via the dashboard, by emailing [email protected], via programmatic export, or by filing a privacy request ticket. We respond within 30 days, or 45 days for complex requests with notice.
9.3 California (CCPA)
Rights to know the categories, sources, and business purposes of data collected; to non-discrimination; and to opt out of data sales (we do not sell data).
9.4 European (GDPR)
Explicit consent requirements, the right to lodge complaints with supervisory authorities, the right to object to automated decision-making, and enhanced data portability.
9.5 Indian (DPDPA)
Rights to access, correction, and erasure; grievance redressal; nomination of a digital nominee; and consent withdrawal at any time (which may affect service availability).
10. International Data Transfers
Your data may be processed in the United States (primary processing), the European Union (regional deployments), your selected deployment regions, and support centers globally. We ensure protection through EU Standard Contractual Clauses, DPAs with sub-processors, consistent global security standards, and regional data isolation where required. Inference Inputs and Outputs are processed transiently on AION-operated infrastructure and are not stored, and are not sent to any third-party model provider.
11. Children's Privacy
The Services are not intended for users under 18 (or under 16 in the EU without parental consent). We do not knowingly collect data from minors below these ages and will delete such data if discovered.
12. AI and Automated Processing
12.1 Our Internal Automated Systems
We use automated systems to optimize resource allocation, detect fraud, distribute workloads, and identify security anomalies.
12.2 The AI Services Themselves
The Inference Services are AI systems that generate Outputs in response to your Inputs. Outputs are produced by probabilistic models and may be inaccurate; you are responsible for reviewing Outputs and for maintaining appropriate human oversight, particularly where a decision could significantly affect an individual, and the same applies to any agent solution you operate under a separate agreement. You control whether and how you deploy these Services in any consequential context, and you are the deployer for the purposes of applicable AI regulation.
12.3 Human Oversight of Our Decisions
You may request human review of automated decisions we make that significantly affect you, such as account suspension or credit-limit determinations.
13. Policy Updates
We notify you of material changes via email, dashboard notifications, and 30 days' advance notice for significant changes. Continued use after changes constitutes acceptance of the updated Policy.
14. Contact Information
Privacy Team — AION Technologies Inc., [email protected] (response within 48 hours) Data Protection Officer — [email protected]
Headquarters — AION Technologies Inc., 1450 Broadway, New York, NY 10018, United States
EU Representative — To be appointed. For EU data protection matters, contact [email protected].
Data Protection Officer for India — To be appointed when required under DPDPA. Contact [email protected].
15. Complaint Resolution
To file a privacy complaint, contact [email protected]. You will receive acknowledgment within 48 hours, investigation within 30 days, and escalation to the DPO if unsatisfied. You may also lodge complaints with your local data protection authority, the California Privacy Protection Agency, or the European Data Protection Supervisor.
16. Additional Resources
Cookie Policy — detailed cookie information
Terms of Service — platform usage terms
Document Version: 2.0
Last Review: September 17, 2026
© 2026 AION Technologies Inc. All rights reserved.
This Privacy Policy supersedes all previous versions.
