This policy explains what personal data Aire Digital Solutions SpA (“AireClaw”), a company incorporated in Chile, tax ID 78.173.032-7, registered at Los Militares 5620, Office 905, Las Condes, Santiago, Chile, processes in connection with the AireClaw platform.
It is written against what the platform actually does. If the processing changes, this page is updated.
Account data. When you sign up (with Google or with email), we process your name, your email address and, if you provide it, your phone number. Authentication is handled with Firebase Authentication (Google).
Your business data. During onboarding and use, you give us information about your business, your role, your goals and the content you create or manage (contacts, leads, campaigns, posts, quotes, and so on). This data is yours and lives isolated in your workspace.
Integration credentials. If you connect third-party services (Gmail, social networks, your CRM, your own AI model, payment gateways), we store the necessary tokens and credentials encrypted, in order to act on your behalf according to your instructions. They are never exposed in the browser or in error messages.
Content processed by AI. To generate content or execute actions, your content may be processed by the AI model you use: the platform’s, or your own if you connect it (BYO-LLM).
Payment data. If you buy credits or a plan, payment is processed through MercadoPago. We do not store full card details; the payment provider handles them.
Technical and usage data. We record standard technical data (IP address, browser) and platform usage, for security, abuse prevention and operation. We use Google reCAPTCHA Enterprise to protect sign-up against bots.
Storage in your browser. We store a session cookie (to keep you signed in) and, in local storage, the language you chose, your cookie preference and, if you enable reminders, your push notification subscription. We do not use advertising or cross-site tracking cookies.
Sensitive actions proposed by agents go through your approval (Decision Inbox): you keep control. We do not make automated decisions with legal effects on you.
We do not sell your data nor transfer it to third parties for their own purposes. We use providers (processors) that process it on our behalf and following our instructions:
| Provider | What for |
|---|---|
| Google Cloud (Google LLC) | Hosting and infrastructure (Cloud Run, database, storage) |
| Firebase (Google LLC) | User authentication |
| Google reCAPTCHA Enterprise | Abuse prevention at sign-up |
| Platform AI providers (e.g. Anthropic, OpenAI, Google) | Processing content to generate responses/actions (if you use the platform model) |
| MercadoPago | Payment processing |
| Services YOU connect (Gmail, social networks, your CRM, your own LLM) | Executing actions you authorise, on your behalf |
If you connect your own AI model (BYO-LLM), processing of that content is performed by the provider you choose, under your own account.
If you connect your Google account, AireClaw accesses only the permissions (scopes) you authorise on the consent screen, and only for the features you request. For each one, the table states what Google data is accessed, how we use it, who it is shared with and how long we keep it:
| Scope | What it accesses | How we use it | Who it is shared with | Retention / deletion |
|---|---|---|---|---|
calendar.events |
The events in your Google Calendar | Create, read and update the events and meetings you or your AI assistant schedule | No one outside AireClaw; never sent to AI providers | Read and written live; we keep no copy of your calendar; the token is deleted when you disconnect |
youtube.upload |
Your YouTube channel, in order to publish to it | Upload the video, title, description and thumbnail you choose to publish from Content Studio | No one outside AireClaw | We keep no copy of the video beyond your own workspace; the token is deleted when you disconnect |
spreadsheets |
The Google Sheets you choose to connect | Read and write those sheets for the automations you configure (e.g. export leads, sync data) | No one outside AireClaw | We keep no copy of the sheet; it is accessed live each time; the token is deleted when you disconnect |
gmail.send |
Nothing from your mailbox — this permission only allows sending, not reading | Send the emails you or your assistant draft and you explicitly approve before sending | The recipient you chose; never any additional third party | We keep the sent message as part of your CRM/agent history, subject to section 5; the token is deleted when you disconnect |
drive.file |
Only the files you select with Google’s native picker | Attach or use them in the flow you are running (e.g. Content Studio) | No one outside AireClaw | The file is not replicated; we access the one you selected; the token is deleted when you disconnect |
We do not request gmail.readonly, gmail.modify, full drive, youtube.readonly or youtube.force-ssl. Features that would need them are disabled in the product and say so in the interface, rather than asking you for a broader permission.
Google data is used solely to provide the feature you activated: scheduling a meeting, sending an email you approved, reading or writing a sheet in an automation you configured, publishing a video you chose to publish. We do not use it for advertising, we do not sell it, we do not build profiles for purposes unrelated to the feature, and we do not use it to train, retrain or fine-tune any artificial-intelligence model.
We do not sell, rent or trade Google data, and we do not transfer it to third parties except in these cases and no others:
Google data is not shared with any other AireClaw customer: every workspace is isolated and none can reach another’s connection.
AireClaw lets each customer connect their own artificial-intelligence provider (OpenAI, Anthropic, xAI and others). Google data is never sent to those providers.
This is guaranteed in code, not only in this policy: when a workspace has a Google account connected and an agent is able to read Google Workspace data, AireClaw forces that run onto the platform model and does not use the customer-configured provider. The decision is made before the provider is selected, so there is no path by which Workspace content reaches a third-party model.
Protection of this data. Access tokens are stored encrypted at rest and isolated per workspace (tenant) — they are never exposed in the browser, in logs or in error messages, and no other AireClaw customer can access your connection. See also section 7 (Security).
AireClaw’s use of information received from Google APIs is governed by the Google API Services User Data Policy, including its Limited Use requirements: we do not use this data for advertising, we do not sell it, we do not train AI models with it, and we do not transfer it to third parties except to provide the feature you activate, to comply with the law, or as a secure part of an operation (with your consent).
AireClaw uses the YouTube API Services. By connecting YouTube you accept the YouTube Terms of Service and the Google Privacy Policy. You can revoke AireClaw’s access to your Google account at any time from your Google account security permissions or from Settings → Integrations inside AireClaw; on revocation, we delete the stored token immediately.
AireClaw uses artificial-intelligence models to draft content and propose actions. When those models process data obtained from the Google Workspace APIs, these rules apply:
Limited Use disclosure. The use of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
That covers the Google permissions. Meta’s are described separately, in the next section.
This section covers only the permissions granted by Meta — WhatsApp Business, Instagram and Facebook Pages — through the AireClaw application registered with Meta for Developers. They bear no relation to the Google permissions described in the previous section: they are different platforms, with independent authorisations and consent screens.
If you connect a WhatsApp Business or Instagram account, AireClaw accesses only the permissions you authorise and only for the features you request:
| Meta permission | What it accesses | How we use it | Who it is shared with | Retention / deletion |
|---|---|---|---|---|
whatsapp_business_messaging |
The messages of the WhatsApp Business number you connect | Receive in your inbox the messages your customers write to you, and send the replies you or your team approve | The recipient customer you choose; no one else outside your workspace | Kept as conversation history in your workspace, subject to section 5; the token is deleted when you disconnect |
whatsapp_business_management |
Your WhatsApp Business account configuration: the number and the templates Meta already approved for you | Check that the connection is valid and show you which templates you can use when the 24-hour window is closed | No one outside AireClaw; never sent to AI providers | Queried live; we keep no copy of your templates |
instagram_basic |
The identity of the Instagram Business account you choose | Identify which account manages this workspace and show it as connected | No one outside AireClaw | The token is deleted when you disconnect |
instagram_content_publish |
Your Instagram account, in order to publish to it | Publish the photo, carousel or reel you review and approve in Content Studio | No one outside AireClaw; it is published to your own account | We keep no copy of the content beyond your workspace |
instagram_manage_comments |
The comments on your own posts | Bring them into your inbox and publish the reply you approve, or the one dictated by a rule you configured | The reply is published on your account, visible like any comment | History in your workspace, subject to section 5 |
instagram_manage_messages |
The direct messages of your Instagram account | Bring them into the same inbox and send the approved reply | The recipient person; no one else outside your workspace | History in your workspace, subject to section 5 |
pages_show_list |
The list of Facebook Pages you administer | So you can choose which Page — and the Instagram account linked to it — manages this workspace | No one outside AireClaw | We do not keep the full list; only the one you choose is recorded |
pages_read_engagement |
Basic data of the Page you chose | Resolve which Instagram Business account is linked to that Page | No one outside AireClaw | Queried live; the token is deleted when you disconnect |
pages_manage_metadata |
Your Page’s subscription to Meta’s notifications | Subscribe your Page so Meta delivers new messages and comments as they arrive | No one outside AireClaw | The subscription is cancelled when you disconnect |
pages_messaging |
Your Page’s messaging | Receive and reply to messages addressed to your Page and to your Instagram account | The recipient person; no one else outside your workspace | History in your workspace, subject to section 5 |
business_management |
The relationship between your Page, your Instagram account and your Meta business portfolio | Verify that the account you are connecting truly belongs to you, before treating it as connected | No one outside AireClaw | Queried at the moment of connecting; we keep no copy |
Protection of this data. As with Google: tokens are stored encrypted at rest and isolated per workspace (tenant), are never exposed in the browser, in logs or in error messages, and no other AireClaw customer can access your connection or your conversations. See also section 7 (Security).
Limited use. Data obtained from Meta platforms is used exclusively to provide the feature you activate. We do not use it for advertising, we do not sell or transfer it to third parties, and we do not train artificial-intelligence models with it. We do not send bulk messages or unsolicited promotions, and we do not write to anyone who has not previously contacted your business or given their consent.
Who decides what is sent. By default, every reply an assistant prepares waits for your approval before going out. If you enable automatic mode for a specific case, there are still handover rules to a human for complaints, sensitive matters or an explicit request to speak with someone on the team.
How to revoke. You can disconnect WhatsApp or Instagram at any time from Settings → Integrations inside AireClaw: when you do, we immediately delete the stored credentials, withdraw the application’s permissions at Meta and cancel your Page’s subscription, so we stop receiving and stop being able to send anything through that account. You can also withdraw access yourself from Business Integrations in your Facebook account. AireClaw’s use of this information is additionally governed by the Meta Platform Terms.
AireClaw runs on Google Cloud Platform in the europe-west1 region (Belgium). Some providers are outside Chile (mainly the United States and the European Union). By using the platform, your data may be transferred to those countries. For transfers subject to the GDPR, we rely on Standard Contractual Clauses or adequacy decisions, depending on the provider.
We keep your account data for as long as the account is active. If you request deletion, we delete it within a maximum of 30 days, except what the law requires us to keep (e.g. billing records). Prospect data with no activity is deleted 24 months after the last contact.
You may at any time request access, rectification, deletion, restriction of or objection to processing, and the portability of your data. You may also withdraw your consent whenever you wish, without affecting the lawfulness of prior processing.
Exercise them from Delete my data or by writing to support@aireclaw.ai. If you reside in Chile, you may turn to the competent supervisory authority; in the European Economic Area, to your country’s data protection authority.
Traffic travels encrypted (TLS). Your integration credentials are stored encrypted and are never exposed in the browser or in errors. Your data is isolated per workspace. We perform automatic backups with point-in-time recovery. No system is infallible: should a breach affecting your data occur, we will notify you and report it to the authority where regulation requires it.
The platform is aimed at businesses and at people over 18. We do not knowingly collect data from minors.
If we change this policy, we will update the date in the header. Substantial changes will be communicated to registered users.