Skip to content
ALETHEIONAGIGROUNDING
ProductResultsPricingDocsDashboardCompanyTry 1,000 queries

Privacy policy · Updated August 14, 2026

Data stays inside its authority boundary.

This Policy explains how AletheionAGI processes personal data under Brazil's LGPD when operating the website, portal and Grounding & Memory service.

1. Scope and roles

“AletheionAGI,” “we” or “us” means AletheionAGI, registered under Brazilian CNPJ 55.641.006/0001-30, with its address at Rua Duarte Schutel, 61, apt. 1001, Centro, Florianópolis, Santa Catarina, Brazil. For account, website, commercial, billing, support and security data, we generally act as controller. For memories, questions and other content submitted by a customer for its application, the customer generally acts as controller and AletheionAGI acts as operator under the customer's documented instructions.

The customer decides what end-user data is submitted, why it is processed and who may access it. End users should first direct LGPD requests about customer content to that customer.

2. Data we collect

  • Identity and account data, such as name, email, authentication identifiers, organization membership and role.
  • Commercial and billing data, such as plan, amount, currency, invoice details, Stripe customer and transaction identifiers and payment status.
  • Customer content, including memories, metadata, authorization labels, namespace identifiers, grounding inputs, evidence and outputs.
  • Reader connection metadata and encrypted provider credentials configured by an authorized organization administrator.
  • Usage, audit, device, network, security, diagnostic, support and communication data.
  • Cookie, analytics and preference data described below.

3. Sources

We receive data from you, your organization and its applications; from identity, payment and reader providers; from browsers and devices; and from service logs generated when the platform is used. We do not intentionally buy data-broker profiles for Grounding & Memory operations.

4. Purposes and LGPD legal bases

  • Perform the contract, provision workspaces, authenticate users, retrieve authorized evidence and meter purchased capacity.
  • Comply with legal, tax, accounting, sanctions, fraud-prevention and regulatory obligations.
  • Pursue legitimate interests in securing, maintaining, diagnosing and improving the service, balanced against data-subject rights.
  • Exercise rights in judicial, administrative or arbitration proceedings.
  • Use consent where the LGPD requires it, including for optional communications or technologies when applicable.

When we act as operator, the customer determines the applicable legal basis and gives the processing instructions.

5. Stripe payments

Stripe provides Checkout and processes payment information. Card or payment credentials are submitted directly to Stripe; AletheionAGI does not receive the complete card number or security code. We receive limited customer, transaction, risk and status data needed to fulfill purchases, prevent fraud, provide support and maintain accounting records.

Stripe may act as an independent controller for its own compliance, fraud and payment-network purposes and as a processor or service provider for other activities, as explained in the Stripe Privacy Policy and Stripe Privacy Center. Optional Link use is also governed by Stripe's terms and privacy notices.

6. Sharing and subprocessors

We disclose data only as needed to providers supporting cloud hosting, databases, identity, security, observability, communications, support, professional services and payment processing; to a reader provider selected by the customer; to authorities when legally required; or in a corporate transaction subject to appropriate safeguards. We do not sell personal data.

Providers receive only the data necessary for their role and are subject to contractual, confidentiality and security obligations where required.

7. International transfers

Some providers may process data outside Brazil. We use lawful LGPD transfer mechanisms and appropriate safeguards, considering the recipient, purpose, security controls and applicable regulations. Stripe describes its transfer safeguards in its Privacy Policy and Privacy Center.

8. Retention and deletion

We retain account and contract data while the relationship is active and afterwards for legal, accounting, security and claims periods. Customer content follows the active plan, deletion instructions, backup lifecycle and applicable order. Deleting a memory removes it from active retrieval and records an auditable lifecycle event; encrypted backups and derived state expire or are rebuilt under their applicable retention process.

We do not promise instantaneous erasure from every backup or a stronger model-state erasure property unless expressly contracted and technically verified. Data may be retained when legally required or necessary to establish, exercise or defend rights.

9. Security and reader credentials

We use access controls, tenant and namespace boundaries, encryption, credential hashing, auditing and operational safeguards appropriate to the service. Reader BYOK credentials are submitted through the authenticated portal, encrypted at rest and not returned to browser code. No internet service is risk-free; organization owners must protect their credentials and promptly report suspected exposure.

10. Security incidents

When acting as operator, we notify the affected customer without undue delay after confirming a relevant incident and provide available information needed for the customer's assessment. When acting as controller, we communicate incidents that may cause relevant risk or damage to data subjects and the ANPD within the period and form required by applicable regulation, currently three business days unless a specific rule provides otherwise.

11. Your LGPD rights

Subject to legal conditions, data subjects may request confirmation of processing; access; correction; anonymization, blocking or deletion of unnecessary, excessive or unlawfully processed data; portability; information about sharing; withdrawal of consent; review of relevant automated decisions; and information about the consequences of refusing consent.

Contact privacy@aletheionagi.com. We verify identity and authority before acting. If AletheionAGI holds the data only as an operator, we will direct or forward the request to the responsible customer controller.

12. Automated processing

The service performs retrieval, authorization, grounding and metering automatically. It is infrastructure for customer applications and does not itself make final legal, employment, credit, health or similarly consequential decisions about individuals. Customers must provide appropriate notices, controls and human review for their use case.

13. Cookies and analytics

Strictly necessary cookies support authentication, organization selection, security and session continuity. Limited analytics may measure page and product performance. Browser or consent controls can restrict optional technologies, but blocking necessary storage may prevent sign-in or portal operation.

14. Children

The service is offered to businesses and is not directed to children. Customers must not submit children's personal data without a valid legal basis, required safeguards and an appropriate contracted use case.

15. Changes and contact

We may update this Policy to reflect service, legal or provider changes. Material changes will be communicated through the website, portal or registered contact. Privacy questions and LGPD requests may be sent to privacy@aletheionagi.com or to Rua Duarte Schutel, 61, apt. 1001, Centro, Florianópolis/SC, Brazil. Security reports may be sent to security@aletheionagi.com.

ALETHEIONAGI

Grounding & Memory infrastructure
for AI systems.

ProductGrounding BridgeMeasured resultsPricing
DevelopersDocumentationDashboardSign in
CompanyAboutPartnershipsContactPrivacyTermsRefundsCancellation