Privacy Policy.
Effective date: July 27, 2026
Your privacy is fundamental to how we built Consilios™. This policy explains exactly what we collect, why we collect it, and what we do — and do not do — with your information.
Data controller: Maven Associates LLC, a limited liability company registered in the State of California, United States. Registered address: 26480 Ynez Road, Temecula, California, USA.
Privacy contact: privacy@consilios.ai
EU representative (Art. 27 GDPR): Maven Associates LLC is in the process of appointing an EU representative. EU/EEA residents may direct data protection enquiries to privacy@consilios.ai in the interim.
1. Who This Policy Applies To
This Privacy Policy applies to all users of the Consilios™ platform, including:
- Account holders — individuals who register for a Consilios™ account at consilios.ai
- Enterprise Workspace Members — individuals invited by an Enterprise plan owner to collaborate within an Enterprise Workspace. Members sign in using their own Consilios™ account and access documents within the document groups assigned to them by the workspace owner or administrator.
- Workspace Administrators (planAdmin) — Enterprise Workspace members designated with administrative permissions by the workspace owner. A planAdmin can manage document group access for other members and view workspace activity logs, but cannot upload, delete, or manage documents beyond their assigned group scope. Their actions are recorded in the workspace audit trail.
- End Users — individuals who interact with a Consilios™ chat widget embedded on a third-party website by a Business plan account holder, without themselves holding a Consilios™ account
- Visitors — individuals who access a publicly shared answer link (consilios.ai/s/…) created by an account holder
References to "you" mean the individual accessing the Service in any of these capacities.
2. What We Collect
Account information — When you register, we collect your name, email address, and password (stored as a secure hash). If you pay, our payment processor (Stripe) handles your card details; we never see or store card numbers.
Documents you upload — Files you upload are stored securely and used solely to generate answers to your questions. We do not read, analyse, or process your documents for any purpose other than providing the Service to you.
Usage data — We collect aggregated data about how you use the platform: number of queries made, documents uploaded, and session timestamps. This is used to operate and improve the Service and to enforce plan limits.
Custom instructions — If you configure custom instructions for AI responses, those instructions are stored on our servers associated with your account so they can be applied consistently across sessions.
Log data — Like all web services, our servers automatically record IP addresses, browser type, pages visited, and access times. This data is used for security monitoring and troubleshooting only.
Enterprise Workspace membership — When an Enterprise plan owner invites someone to their workspace, we store that person's email address, role (contributor, viewer, or planAdmin), and document group assignments to facilitate access control. If the invited person accepts, their user ID is associated with the workspace and their activity within it (queries made, documents accessed, group access changes made) is recorded in the workspace audit log and attributed to the workspace owner's account.
Document group access control — Enterprise plan owners may organise documents into named groups and assign members access to specific groups. We store these group assignments as part of the workspace configuration. Documents not assigned to any group are visible only to the workspace owner.
Widget End User queries — When an End User submits a question through an embedded widget, we collect the text of that question and the AI-generated answer. This data is attributed to the account holder who owns the widget key, not to the End User personally. We do not collect the End User's name, email, or any other identifying information. See Section 6 below for details.
Cookies — We use session cookies to keep account holders logged in and remember preferences. We do not use advertising cookies or cross-site tracking cookies. The widget iframe may use browser sessionStorage to maintain conversation continuity within a single page visit; this is cleared when the browser tab is closed and is never transmitted to our servers independently.
3. What We Do Not Collect
- We do not read the contents of your documents beyond what is necessary to answer your questions
- We do not collect biometric data, location data, or sensitive personal categories
- We do not run advertising tracking or sell data to advertisers
- We do not build profiles of you for any purpose other than operating your account
- We do not collect personally identifying information from widget End Users (no name, email, or account is created for them)
4. How We Use Your Information
We use the information we collect to:
- Provide, operate, and improve the Consilios™ platform
- Authenticate your identity and secure your account
- Process payments and manage your subscription
- Send transactional emails (account confirmation, billing receipts, security alerts)
- Respond to your support requests
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations
We will never use your data to send unsolicited marketing without your explicit consent.
5. AI and Your Documents
Consilios™ uses Claude (an AI model developed by Anthropic, hosted within AWS) to generate answers from your uploaded documents. When you ask a question, relevant passages from your documents are sent to the AI model along with your question. The AI generates a response and that response is returned to you.
Your documents and questions are never used to train, fine-tune, or improve any AI model. All AI processing runs within AWS infrastructure and is covered by AWS's data processing agreements, which explicitly prohibit use of customer content for model training. This applies equally to queries submitted by End Users through embedded widgets and by Enterprise Workspace Members.
No document content is retained by the AI service after a response is generated. Each query is stateless from the AI model's perspective.
6. Widget Embed and End Users
Business plan account holders may embed a Consilios™ chat widget on their own websites using a widget API key. When an End User interacts with such a widget:
- The End User's question is processed against the account holder's documents using the same AI pipeline described in Section 5
- The query and response are recorded in the account holder's audit log and count against their monthly query quota
- No Consilios™ account is created for the End User
- We do not collect or store any personally identifying information from End Users independently — their queries are attributed to the account holder's widget key
- Widget keys are read-only and scoped to querying only — End Users cannot upload, delete, or manage documents through a widget
Account holder responsibility. When you deploy a Consilios™ widget on your website, you become the data controller for your End Users' interactions. You are responsible for: (a) informing your End Users that their questions are processed by Consilios™ AI; (b) obtaining any consent required under applicable law; and (c) including appropriate disclosures in your own privacy policy. Consilios™ acts as a data processor on your behalf for these interactions.
End Users who wish to understand how their queries are handled should contact the website operator (the Consilios™ account holder) who deployed the widget, not Consilios™ directly. We cannot identify or retrieve individual End User queries without cooperation from the account holder.
7. Shared Answer Links
Account holders may create shareable public links to individual Q&A exchanges (consilios.ai/s/…). When an account holder creates a shared answer:
- The question text, AI-generated answer, and source document filenames are stored on our servers and accessible to anyone with the link — no login required
- Shared answers expire automatically after 30 days and are then permanently deleted
- We do not collect any information about who views a shared answer link
- No cookies or tracking scripts are set on viewers of shared answer pages
Account holders are solely responsible for the content of shared answers. Before sharing, ensure that the question, answer, and source document names do not contain confidential, personal, or sensitive information you do not intend to make public.
8. Who We Share Data With
We do not sell your personal data. We share limited information only with trusted service providers who help us operate the platform:
- Amazon Web Services (AWS) — All document data, query history, audit logs, and vector search indexes are stored and processed within AWS infrastructure. For US accounts: us-east-1 (Virginia). For Enterprise accounts with EU data residency: eu-central-1 (Frankfurt, Germany). AI inference (question answering) runs on AWS Bedrock within the same region as your data — United States or European Union depending on your plan
- Clerk — User authentication and identity management — United States
- Stripe — Payment processing (billing information only; we never see card numbers) — United States
- Resend — Transactional email delivery (welcome emails, billing receipts, security alerts) — United States
- VoyageAI — Text embedding and semantic reranking (converts document text to searchable vectors; no document text is retained after processing) — United States. VoyageAI has opted out of using API data for model training.
- Sentry — Application error monitoring and crash reporting — United States
All providers are bound by data processing agreements and are not permitted to use your data for their own purposes. For EU Enterprise accounts, only Clerk (authentication) processes data outside the EEA, covered by EU Standard Contractual Clauses — EU-based embedding models are used for those accounts so document text does not leave the EEA. For a complete list of sub-processors, contact privacy@consilios.ai.
We may also disclose your information if required by law, court order, or to protect the safety of users or the public.
10. GDPR and EU/EEA Users
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, additional rights and obligations apply under the General Data Protection Regulation (GDPR) and applicable national data protection laws.
Legal basis for processing (Article 6 GDPR). We process your personal data on the following legal bases:
- Contract performance (Art. 6(1)(b)) — to provide the Services you signed up for, including processing documents you upload and returning cited answers
- Legitimate interests (Art. 6(1)(f)) — to improve our services, ensure security, prevent fraud, and maintain our audit log
- Legal obligation (Art. 6(1)(c)) — where retention is required by applicable law (e.g. financial records)
- Consent (Art. 6(1)(a)) — for non-essential cookies where you have provided consent via our cookie banner
International data transfers. For standard (US) accounts, data is stored and processed in the United States (AWS us-east-1, Virginia). Transfers from the EEA to the USA are made under the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914, Module 2: Controller to Processor). Business customers may request a signed copy of the applicable SCCs by contacting privacy@consilios.ai.
EU data residency (Enterprise plan). Enterprise customers may elect to have document content, embeddings, query history, audit logs, and AI inference stored and processed exclusively within AWS eu-central-1 (Frankfurt, Germany). For EU-region Enterprise accounts, EU-based embedding and reranking models are used in place of US-based providers, so document text does not leave the EEA for AI processing. The only data processed outside the EEA is authentication (Clerk, United States), covered by Standard Contractual Clauses. Contact privacy@consilios.ai to enquire about EU data residency before signing up for an Enterprise plan.
Data Processing Agreement (DPA). Enterprise and Business customers who upload documents containing personal data of their own employees, customers, or third parties act as data controllers and Consilios™ acts as their data processor. A signed DPA (incorporating the SCCs) is available on request at privacy@consilios.ai. EU/EEA business customers processing third-party personal data should request and sign a DPA before doing so.
Supervisory authorities. You have the right to lodge a complaint with your local data protection authority:
- EEA member states: your national supervisory authority listed at edpb.europa.eu
- United Kingdom: Information Commissioner's Office — ico.org.uk
11. Data Storage and Security
Document storage, vector indexes, query history, audit logs, and AI inference (question answering via AWS Bedrock) are hosted within Amazon Web Services infrastructure. For US accounts: us-east-1 (Virginia, United States). For Enterprise accounts with EU data residency: eu-central-1 (Frankfurt, Germany, within the EU). For US accounts, text embeddings and semantic reranking are processed by VoyageAI (United States) as a sub-processor; document text is transmitted to VoyageAI solely to generate vectors and is not retained after processing. For EU Enterprise accounts, EU-based embedding models are used so document text does not leave the EEA. All document data stays within your designated AWS region.
Data is encrypted in transit using TLS 1.3 and encrypted at rest. Access to production systems is restricted to authorised personnel only, using multi-factor authentication.
Widget API keys are stored as one-way hashes — the raw key value is shown only once at the time of generation and cannot be retrieved thereafter. If a key is compromised, it can be revoked immediately. A compromised widget key allows read-only query access only; it does not grant access to document management, account settings, or other keys.
No security system is impenetrable. In the event of a data breach that affects your personal data, we will notify you by email within 72 hours of becoming aware of the incident.
12. Data Retention
We retain your account data and documents for as long as your account is active. If you delete a document, it is permanently removed from all our systems immediately — there is no archive or recovery path.
Shared answer links expire and are permanently deleted after 30 days. Widget End User query logs are retained as part of the account holder's audit log and deleted when the account holder's account is closed.
Enterprise Workspace membership records (email address, user ID, role, document group assignments) are deleted when the workspace owner closes the workspace or removes the member. If a member closes their own account, their personal data is deleted within 30 days; their workspace activity history is retained as part of the workspace owner's audit log until the workspace is closed. When a document group is deleted, member group-access records referencing that group are immediately removed; the documents themselves are retained but revert to owner-private status.
If you close your account, we will delete all your personal data, documents, and associated query logs within 30 days. Billing records are retained for 7 years as required by financial regulations.
13. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — Request a copy of the personal data we hold about you
- Correction — Request correction of inaccurate data
- Deletion — Request deletion of your account and all associated data
- Portability — Request your data in a portable format
- Restriction — Request that we restrict processing of your data in certain circumstances
- Objection — Object to processing of your personal data based on legitimate interests
- Withdraw consent — Withdraw consent at any time where processing is based on consent (e.g. non-essential cookies), without affecting the lawfulness of processing before withdrawal
To exercise any of these rights, contact us at privacy@consilios.ai. We will respond within 30 days. EEA/UK users may also raise a complaint with their supervisory authority as described in Section 10.
End Users of embedded widgets should direct rights requests to the website operator who deployed the widget, as they are the data controller for those interactions. Consilios™ will cooperate with account holders to fulfil verified End User rights requests.
Enterprise Workspace Members and planAdmins may direct data rights requests to either the workspace owner or directly to privacy@consilios.ai.
14. Children
Consilios™ is not directed at children under 13 years of age. We do not knowingly collect personal data from children. Account holders who deploy the widget are responsible for ensuring their websites are not directed at children and for complying with applicable child privacy laws (including COPPA). If you believe a child has provided us with personal information, contact us and we will delete it promptly.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you by email and by posting the updated policy with a new effective date at least 14 days before changes take effect. Continued use of the Service after that date constitutes your acceptance of the updated policy.
16. Contact Us
For privacy-related questions, requests, or concerns, contact our privacy team at privacy@consilios.ai.
Also see our Terms of Service.