Privacy policy · Updated August 24, 2026

Data stays inside its authority boundary.

This Policy explains how AletheionAGI processes personal data under Brazil's LGPD when operating GQueries, IntentParse and Widport.

1. Scope and roles

AletheionAGI, Brazilian CNPJ 55.641.006/0001-30, is controller for account, website, security, commercial, billing and support data. For messages, intents, memories, sources, evidence and visitor data submitted by a customer, the customer generally acts as controller and AletheionAGI as processor under documented instructions. Data subjects should first direct requests about customer content to that customer.

2. Data processed

  • Identity, email, Clerk authentication, membership, role and preferences.
  • Plan, invoice, currency, Stripe identifiers and payment status.
  • GQueries: memories, metadata, labels, namespaces, questions, evidence, outputs and feedback.
  • IntentParse: messages, schema, intent, dimensions, confidence, validation and optionally retained intents.
  • Widport: domain, deployment, session, message, answer, experience, journey, correlation ID, handoff and support agents.
  • Knowledge: URL, extracted content, hash, classification, candidate, review decision and published memory.
  • BYOK provider/model, key hint and protected credential; technical, IP, device, security and support logs.

3. Sources and purposes

We receive data from you, your organization, applications and visitors; identity, payment and model providers; authorized scan URLs; and logs. We use it to perform contracts, authenticate, provision, parse intent, retrieve evidence, apply policy, deliver experiences and handoff, meter, bill, prevent fraud, secure, diagnose, support and comply with law.

Legal bases include contract performance, legal obligation, exercise of rights, assessed legitimate interests and consent where required. As processor, we follow the basis and instructions determined by the customer.

4. BYOK models and sharing

For inference, we send the selected provider only the necessary input, schema, context or evidence. We share data with identity, cloud, database, payment, email, security, observability and support providers; authorities when required; and protected corporate-transaction parties. We do not sell personal data. See Subprocessors.

5. International transfers

Providers may process data outside Brazil. We use a mechanism permitted by LGPD Articles 33–36 and ANPD Resolution 19/2024, including ANPD standard contractual clauses where applicable, with specific purpose, minimization, and contractual and technical safeguards.

6. Retention and deletion

  • Account and contract: during the relationship and legal, tax, security and claims periods.
  • GQueries: content until deletion, expiry, termination or instruction; deletion removes active retrieval and preserves a lifecycle event where necessary.
  • IntentParse: raw input is not retained by default; retained intent is opt-in and follows its configured TTL, generally capped at 30 days.
  • Widport: sessions, messages, answers, journeys and handoff may be kept for operation and support; configured policies and the order define periods. Resolved transcripts and technical events have separate retention.
  • Scans: content and candidates remain until review, revocation, replacement or source/account deletion.
  • Encrypted backups expire under their lifecycle; we do not promise instantaneous erasure from every backup or model-state erasure without specific contracting and verification.

7. Security and incidents

We use access controls, tenant/namespace separation, encryption, hashing, audit and operational safeguards. BYOK credentials are protected server-side and not returned to the browser. As processor, we notify the customer without undue delay after confirming a relevant incident. As controller, we notify the ANPD and data subjects when required within the applicable regulatory period.

8. LGPD rights

Subject to legal conditions, data subjects may request confirmation, access, correction, anonymization, blocking, deletion, portability, sharing information, objection, consent withdrawal and review of relevant automated decisions. Contact: privacy@aletheionagi.com.

9. Automation, cookies and children

The Services automate parsing, retrieval, authorization, grounding, policy and metering but do not themselves make legal, medical, credit, employment or health decisions. Necessary cookies support authentication and security; limited analytics may measure performance. The Services are B2B and not directed to children; customers must not submit children's data without a proper basis, safeguards and contracted use case.

10. Contact and changes

Material changes will be communicated through the website, portal or registered contact. Privacy/LGPD: privacy@aletheionagi.com. Security: security@aletheionagi.com.

ALETHEIONAGIRESEARCH & PRODUCTS

Independent AI research
and product organization.

Florianópolis · Brazil
OrganizationAboutResearchModelsOpen sourcePartnershipsBlogPrivacyTermsDPASubprocessorsAcceptable useGitHub ↗
ProductsGQueriesGrounding & Memory ↗IntentParseStructured Intent ↗WidportEmbedded Experiences ↗
AccountSign inWorkspaceContact
© 2026 AletheionAGI Independent research · Verifiable systems · Explicit limitations