Privacy Policy

Last updated: 14 September 2026 · Versión en español

This policy explains what personal data Aire Digital Solutions SpA (“AireClaw”), a company incorporated in Chile, tax ID 78.173.032-7, registered at Los Militares 5620, Office 905, Las Condes, Santiago, Chile, processes in connection with the AireClaw platform.

It is written against what the platform actually does. If the processing changes, this page is updated.

1. What data we process

Account data. When you sign up (with Google or with email), we process your name, your email address and, if you provide it, your phone number. Authentication is handled with Firebase Authentication (Google).

Your business data. During onboarding and use, you give us information about your business, your role, your goals and the content you create or manage (contacts, leads, campaigns, posts, quotes, and so on). This data is yours and lives isolated in your workspace.

Integration credentials. If you connect third-party services (Gmail, social networks, your CRM, your own AI model, payment gateways), we store the necessary tokens and credentials encrypted, in order to act on your behalf according to your instructions. They are never exposed in the browser or in error messages.

Content processed by AI. To generate content or execute actions, your content may be processed by the AI model you use: the platform’s, or your own if you connect it (BYO-LLM).

Payment data. If you buy credits or a plan, payment is processed through MercadoPago. We do not store full card details; the payment provider handles them.

Technical and usage data. We record standard technical data (IP address, browser) and platform usage, for security, abuse prevention and operation. We use Google reCAPTCHA Enterprise to protect sign-up against bots.

Storage in your browser. We store a session cookie (to keep you signed in) and, in local storage, the language you chose, your cookie preference and, if you enable reminders, your push notification subscription. We do not use advertising or cross-site tracking cookies.

2. What we use it for, and legal basis

Sensitive actions proposed by agents go through your approval (Decision Inbox): you keep control. We do not make automated decisions with legal effects on you.

3. Who we share data with

We do not sell your data nor transfer it to third parties for their own purposes. We use providers (processors) that process it on our behalf and following our instructions:

ProviderWhat for
Google Cloud (Google LLC)Hosting and infrastructure (Cloud Run, database, storage)
Firebase (Google LLC)User authentication
Google reCAPTCHA EnterpriseAbuse prevention at sign-up
Platform AI providers (e.g. Anthropic, OpenAI, Google)Processing content to generate responses/actions (if you use the platform model)
MercadoPagoPayment processing
Services YOU connect (Gmail, social networks, your CRM, your own LLM)Executing actions you authorise, on your behalf

If you connect your own AI model (BYO-LLM), processing of that content is performed by the provider you choose, under your own account.

3 bis. Google API data you connect

What Google user data we access

If you connect your Google account, AireClaw accesses only the permissions (scopes) you authorise on the consent screen, and only for the features you request. For each one, the table states what Google data is accessed, how we use it, who it is shared with and how long we keep it:

ScopeWhat it accessesHow we use itWho it is shared withRetention / deletion
calendar.events The events in your Google Calendar Create, read and update the events and meetings you or your AI assistant schedule No one outside AireClaw; never sent to AI providers Read and written live; we keep no copy of your calendar; the token is deleted when you disconnect
youtube.upload Your YouTube channel, in order to publish to it Upload the video, title, description and thumbnail you choose to publish from Content Studio No one outside AireClaw We keep no copy of the video beyond your own workspace; the token is deleted when you disconnect
spreadsheets The Google Sheets you choose to connect Read and write those sheets for the automations you configure (e.g. export leads, sync data) No one outside AireClaw We keep no copy of the sheet; it is accessed live each time; the token is deleted when you disconnect
gmail.send Nothing from your mailbox — this permission only allows sending, not reading Send the emails you or your assistant draft and you explicitly approve before sending The recipient you chose; never any additional third party We keep the sent message as part of your CRM/agent history, subject to section 5; the token is deleted when you disconnect
drive.file Only the files you select with Google’s native picker Attach or use them in the flow you are running (e.g. Content Studio) No one outside AireClaw The file is not replicated; we access the one you selected; the token is deleted when you disconnect

We do not request gmail.readonly, gmail.modify, full drive, youtube.readonly or youtube.force-ssl. Features that would need them are disabled in the product and say so in the interface, rather than asking you for a broader permission.

How we use Google user data

Google data is used solely to provide the feature you activated: scheduling a meeting, sending an email you approved, reading or writing a sheet in an automation you configured, publishing a video you chose to publish. We do not use it for advertising, we do not sell it, we do not build profiles for purposes unrelated to the feature, and we do not use it to train, retrain or fine-tune any artificial-intelligence model.

Who we share Google user data with

We do not sell, rent or trade Google data, and we do not transfer it to third parties except in these cases and no others:

Google data is not shared with any other AireClaw customer: every workspace is isolated and none can reach another’s connection.

Google user data and AI providers

AireClaw lets each customer connect their own artificial-intelligence provider (OpenAI, Anthropic, xAI and others). Google data is never sent to those providers.

This is guaranteed in code, not only in this policy: when a workspace has a Google account connected and an agent is able to read Google Workspace data, AireClaw forces that run onto the platform model and does not use the customer-configured provider. The decision is made before the provider is selected, so there is no path by which Workspace content reaches a third-party model.

How we protect Google user data

How long we keep Google user data, and how it is deleted

Protection of this data. Access tokens are stored encrypted at rest and isolated per workspace (tenant) — they are never exposed in the browser, in logs or in error messages, and no other AireClaw customer can access your connection. See also section 7 (Security).

AireClaw’s use of information received from Google APIs is governed by the Google API Services User Data Policy, including its Limited Use requirements: we do not use this data for advertising, we do not sell it, we do not train AI models with it, and we do not transfer it to third parties except to provide the feature you activate, to comply with the law, or as a secure part of an operation (with your consent).

AireClaw uses the YouTube API Services. By connecting YouTube you accept the YouTube Terms of Service and the Google Privacy Policy. You can revoke AireClaw’s access to your Google account at any time from your Google account security permissions or from Settings → Integrations inside AireClaw; on revocation, we delete the stored token immediately.

Artificial intelligence and Limited Use

AireClaw uses artificial-intelligence models to draft content and propose actions. When those models process data obtained from the Google Workspace APIs, these rules apply:

Limited Use disclosure. The use of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

That covers the Google permissions. Meta’s are described separately, in the next section.

3 ter. Meta platform data (WhatsApp and Instagram) you connect

This section covers only the permissions granted by Meta — WhatsApp Business, Instagram and Facebook Pages — through the AireClaw application registered with Meta for Developers. They bear no relation to the Google permissions described in the previous section: they are different platforms, with independent authorisations and consent screens.

If you connect a WhatsApp Business or Instagram account, AireClaw accesses only the permissions you authorise and only for the features you request:

Meta permissionWhat it accessesHow we use itWho it is shared withRetention / deletion
whatsapp_business_messaging The messages of the WhatsApp Business number you connect Receive in your inbox the messages your customers write to you, and send the replies you or your team approve The recipient customer you choose; no one else outside your workspace Kept as conversation history in your workspace, subject to section 5; the token is deleted when you disconnect
whatsapp_business_management Your WhatsApp Business account configuration: the number and the templates Meta already approved for you Check that the connection is valid and show you which templates you can use when the 24-hour window is closed No one outside AireClaw; never sent to AI providers Queried live; we keep no copy of your templates
instagram_basic The identity of the Instagram Business account you choose Identify which account manages this workspace and show it as connected No one outside AireClaw The token is deleted when you disconnect
instagram_content_publish Your Instagram account, in order to publish to it Publish the photo, carousel or reel you review and approve in Content Studio No one outside AireClaw; it is published to your own account We keep no copy of the content beyond your workspace
instagram_manage_comments The comments on your own posts Bring them into your inbox and publish the reply you approve, or the one dictated by a rule you configured The reply is published on your account, visible like any comment History in your workspace, subject to section 5
instagram_manage_messages The direct messages of your Instagram account Bring them into the same inbox and send the approved reply The recipient person; no one else outside your workspace History in your workspace, subject to section 5
pages_show_list The list of Facebook Pages you administer So you can choose which Page — and the Instagram account linked to it — manages this workspace No one outside AireClaw We do not keep the full list; only the one you choose is recorded
pages_read_engagement Basic data of the Page you chose Resolve which Instagram Business account is linked to that Page No one outside AireClaw Queried live; the token is deleted when you disconnect
pages_manage_metadata Your Page’s subscription to Meta’s notifications Subscribe your Page so Meta delivers new messages and comments as they arrive No one outside AireClaw The subscription is cancelled when you disconnect
pages_messaging Your Page’s messaging Receive and reply to messages addressed to your Page and to your Instagram account The recipient person; no one else outside your workspace History in your workspace, subject to section 5
business_management The relationship between your Page, your Instagram account and your Meta business portfolio Verify that the account you are connecting truly belongs to you, before treating it as connected No one outside AireClaw Queried at the moment of connecting; we keep no copy

Protection of this data. As with Google: tokens are stored encrypted at rest and isolated per workspace (tenant), are never exposed in the browser, in logs or in error messages, and no other AireClaw customer can access your connection or your conversations. See also section 7 (Security).

Limited use. Data obtained from Meta platforms is used exclusively to provide the feature you activate. We do not use it for advertising, we do not sell or transfer it to third parties, and we do not train artificial-intelligence models with it. We do not send bulk messages or unsolicited promotions, and we do not write to anyone who has not previously contacted your business or given their consent.

Who decides what is sent. By default, every reply an assistant prepares waits for your approval before going out. If you enable automatic mode for a specific case, there are still handover rules to a human for complaints, sensitive matters or an explicit request to speak with someone on the team.

How to revoke. You can disconnect WhatsApp or Instagram at any time from Settings → Integrations inside AireClaw: when you do, we immediately delete the stored credentials, withdraw the application’s permissions at Meta and cancel your Page’s subscription, so we stop receiving and stop being able to send anything through that account. You can also withdraw access yourself from Business Integrations in your Facebook account. AireClaw’s use of this information is additionally governed by the Meta Platform Terms.

4. International transfers

AireClaw runs on Google Cloud Platform in the europe-west1 region (Belgium). Some providers are outside Chile (mainly the United States and the European Union). By using the platform, your data may be transferred to those countries. For transfers subject to the GDPR, we rely on Standard Contractual Clauses or adequacy decisions, depending on the provider.

5. How long we keep data

We keep your account data for as long as the account is active. If you request deletion, we delete it within a maximum of 30 days, except what the law requires us to keep (e.g. billing records). Prospect data with no activity is deleted 24 months after the last contact.

6. Your rights

You may at any time request access, rectification, deletion, restriction of or objection to processing, and the portability of your data. You may also withdraw your consent whenever you wish, without affecting the lawfulness of prior processing.

Exercise them from Delete my data or by writing to support@aireclaw.ai. If you reside in Chile, you may turn to the competent supervisory authority; in the European Economic Area, to your country’s data protection authority.

7. Security

Traffic travels encrypted (TLS). Your integration credentials are stored encrypted and are never exposed in the browser or in errors. Your data is isolated per workspace. We perform automatic backups with point-in-time recovery. No system is infallible: should a breach affecting your data occur, we will notify you and report it to the authority where regulation requires it.

8. Minors

The platform is aimed at businesses and at people over 18. We do not knowingly collect data from minors.

9. Changes

If we change this policy, we will update the date in the header. Substantial changes will be communicated to registered users.