Privacy & Data¶
This page explains what personal, activity, and monitoring data Aimee.ai stores, why we store it, and the rights you have over it. It is written to be clear rather than legalistic.
Draft - pending legal review
The retention periods, legal bases, and contact address on this page are placeholders that must be confirmed by legal counsel before this page is treated as our formal privacy notice. Anything marked confirm with legal is a placeholder.
What data we store and why¶
Your data always belongs to a workspace - the organisation you signed up under or were invited to. You can only see data within the workspaces you belong to, and workspaces do not share data with one another.
The legal basis column below states why we are permitted to process each category under data-protection law. These bases are indicative and must be confirmed with legal before publishing.
| Data category | What we store | Why we store it | Legal basis (confirm with legal) | How long |
|---|---|---|---|---|
| Account & identity | Your name, email address, username, and a securely hashed version of your password. We never store your password in a readable form. | To create and secure your account, sign you in, and let other members of your workspace recognise you. | Performance of a contract | While your account is active (confirm with legal) |
| Account security | Whether your email is verified, and - if you enable it - your multi-factor authentication (MFA) settings and backup codes. | To protect your account against unauthorised access. | Legitimate interests (security); legal obligation | While your account is active |
| Profile & preferences | Your optional profile picture and time-zone preference. | To personalise how the platform looks and shows dates and times to you. | Consent (profile picture); performance of a contract | While your account is active |
| Course activity & progress | Which courses you are assigned, your progress through slides, acknowledgements, quiz answers, uploads you submit, completions, and any course feedback you give. | To deliver your learning, track your progress, and let trainers see how their courses are performing. | Performance of a contract | While your account is active, unless your workspace is deleted (retention window: confirm with legal) |
| Assessment & scoring | Scores, pass/fail results, and the qualitative feedback generated for practice sessions and assessments. | To grade your work, show your results, and help you improve. | Performance of a contract | While your account is active (confirm with legal) |
| AI roleplay & scenario conversations | The transcripts of voice or text roleplay and scenario sessions you take part in (who said what, and when). | To score the session, generate your feedback, and let a trainer review it. See AI interactions below. | Performance of a contract | While your account is active (confirm with legal) |
| Activity & monitoring data | A record of key actions - see Activity & monitoring data below. | To keep the platform working, show trainers and administrators how their workspace is being used, and improve the experience. | Legitimate interests | (confirm with legal) |
| Billing (workspace owners) | Your workspace's subscription plan and status, and identifiers linking it to our payment processor. We do not store your card or bank details - those are held securely by our payment processor, Stripe. | To manage your subscription and process payments. | Performance of a contract; legal obligation (financial records) | While the subscription is active, plus any period required for financial record-keeping (confirm with legal) |
Activity and monitoring data¶
The request that brought you here often relates to this section, so we describe it in more detail.
To keep the platform reliable and to give trainers and administrators a view of how their workspace is being used, we record certain actions as they happen. Each record notes:
- What happened - for example: signing in, launching a course, completing a session, submitting a quiz, self-enrolling, or receiving a score.
- What it related to - for example the course, assignment, or session involved.
- When it happened - the date and time.
- A small amount of context - for example a course title, a score, or how long something took.
This is the data behind the Activity view that trainers and administrators see, and the My Activity view you see for yourself. It is used to improve the platform experience and to give your workspace's administrators visibility of engagement. It is not sold or shared with third parties.
Separately, we keep an administrative audit log of significant management actions (for example changes made by workspace administrators) so that a workspace can account for who changed what.
AI interactions¶
Aimee.ai uses AI to generate courses and to run voice and text roleplay sessions.
- Roleplay and scenario sessions produce a transcript of the conversation. We keep it so the session can be scored, so you can receive feedback, and so a trainer can review your performance.
- AI usage records. For every AI request the platform makes, we record technical usage information - which feature and model was used, how many tokens or seconds it consumed, how long it took, whether it succeeded, and its cost. These records do not contain the content of your prompts or the AI's responses; they exist for billing, cost control, and reliability monitoring.
Usage and billing records are kept longer
Because usage and billing records are financial and operational records, they are retained even after a workspace or account is deleted (exact retention period: confirm with legal). They are not linked to your other data once the account is removed.
How long we keep your data¶
Most of your data lives for as long as your account and workspace are active. When a workspace is deleted, the data belonging to it - members, courses, activity records, sessions, transcripts, and scores - is removed as part of that deletion.
Two kinds of record are kept beyond that point on purpose:
- A minimal, non-reversible record that a workspace was deleted (who requested it, when, and what was cleaned up), kept for accountability.
- Usage and billing records, kept as financial records as described above.
Specific retention periods are being finalised - see the review note at the top of this page.
Your data rights¶
Depending on where you live, you have rights over the personal data we hold about you. These typically include the right to:
- Access - ask for a copy of the personal data we hold about you.
- Rectification - ask us to correct data that is wrong or incomplete. You can update much of your own profile directly in the app.
- Erasure - ask us to delete your personal data ("the right to be forgotten"), subject to records we are legally required to keep.
- Portability - ask to receive your data in a portable format.
- Restriction and objection - ask us to limit or stop certain processing.
How to make a request¶
If you belong to a workspace, the quickest route is usually to contact your workspace owner or administrator, who can action many requests directly or escalate them to us.
To make a request to us directly, contact privacy@aimee.ai (placeholder - confirm the correct contact with legal before publishing). We will respond within the timeframe required by the applicable law.
Changes to this page¶
We may update this page as the platform evolves. When we make a significant change, we will make the updated version available here.