1. Scope and roles
This policy applies when you visit our websites, create or use an Aila account, communicate with us, or when information about you is processed through the Services.
Aila customers decide which call recordings, transcripts, CRM data, borrower or prospect information, files, and other content they send to Aila. For that information, the customer generally acts as the business or controller and Aila acts as its service provider or processor. If your information was submitted by an Aila customer, direct your request to that customer first. We will assist customers with valid requests as required by contract and law.
Aila acts as a business or controller for information used to manage accounts, billing, security, websites, sales, support, and our own business operations.
2. Information we collect
Account and business information
- Name, business email, phone number, job title, company, and team membership.
- Account identifiers, authentication information, roles, permissions, and security events.
- Subscription, seat, transaction, and billing status. Payment card details are processed by Stripe or our current payment processor; Aila does not store full payment card numbers.
- Communications with sales, onboarding, support, and customer-success teams.
Customer Content
Depending on the features a customer enables, Aila may process:
- Call, meeting, and audio recordings; transcripts; speaker labels; summaries; notes; comments; scores; coaching content; and AI-generated analyses.
- CRM, dialer, calendar, meeting, contact, opportunity, and workflow data supplied by the customer or an authorized integration.
- Prospect, customer, borrower, applicant, and employee information contained in recordings, transcripts, forms, files, or connected systems.
- Mortgage application information and generated FNMA MISMO files, which may contain financial information and government identifiers when a customer chooses to process them.
- Files, prompts, checklists, custom fields, configurations, and exports submitted or created through the Services.
Integration information
When a customer connects a CRM, dialer, calendar, meeting platform, storage provider, or other third-party service, we receive the account identifiers, authorization tokens, configuration, and data needed to provide the requested integration. The connected service controls what information it makes available and may separately govern that information under its own terms and privacy policy.
Website, device, and usage information
- IP address, browser, device and operating-system details, language, approximate location derived from IP, referring URL, and timestamps.
- Pages viewed, links and buttons selected, searches, feature use, errors, performance data, and diagnostic logs.
- Cookie, local-storage, session-storage, advertising, and campaign identifiers, including UTM parameters and Meta click identifiers.
- Interaction and session-replay data on our websites and web application, including clicks, scrolling, and form interactions. On our marketing website, session replay is configured to mask form inputs and page text.
Information from other sources
We may receive information from our customers, their authorized users and integrations, business partners, payment processors, marketing and analytics providers, public business sources, and people who refer or invite you to the Services.
3. How we use information
We use information to:
- Provide, configure, operate, maintain, and support the Services.
- Ingest, transcribe, analyze, score, summarize, search, export, and sync Customer Content as directed by customers.
- Create and administer accounts, authenticate users, manage permissions, process payments, and provide customer support.
- Monitor reliability, troubleshoot errors, prevent fraud and abuse, protect accounts, investigate incidents, and enforce our agreements.
- Measure website and product use, understand demand, attribute campaigns, and improve our websites, products, and customer experience.
- Send service notices and, where permitted, product updates and marketing communications. You can unsubscribe from marketing emails without affecting transactional messages.
- Comply with law, respond to lawful requests, establish or defend legal claims, and complete corporate transactions.
4. AI processing and model training
The Services use automated transcription, extraction, summarization, scoring, and artificial intelligence. To provide those features, Aila may send Customer Content to contracted transcription and AI service providers.
Aila does not use Customer Content to train general-purpose AI models and does not permit third-party AI providers to use Customer Content to train their general-purpose models, unless the customer gives written permission. We may use aggregated or de-identified data to evaluate, secure, and improve the Services when that data does not identify a customer, user, borrower, prospect, or other individual.
AI and transcription outputs may be incomplete or inaccurate. They are designed to assist authorized users and require human review, especially before use in lending, underwriting, pricing, employment, compliance, legal, or other consequential decisions.
5. How we disclose information
We may disclose information to:
- Service providers. Hosting, database, storage, AI, transcription, meeting capture, communications, observability, security, analytics, advertising, payment, and customer-support providers that perform services for Aila.
- Customer-authorized systems. CRMs, dialers, meeting platforms, calendars, loan systems, APIs, webhooks, and other integrations a customer configures.
- Organizations and users. Customer administrators and other authorized users may access information within their organization based on their permissions.
- Professional advisors and authorities. Auditors, insurers, attorneys, accountants, law enforcement, regulators, courts, or other parties when reasonably necessary to comply with law or protect rights, safety, and security.
- Corporate transaction participants. Parties involved in a financing, merger, acquisition, reorganization, sale of assets, or similar transaction, subject to appropriate confidentiality protections.
We do not sell Customer Content. We do not sell personal information for money. Our use of advertising and analytics technologies may be considered a "sale," "sharing," or targeted advertising under some state privacy laws even when no money changes hands. See Section 6 for details and available choices.
6. Cookies, analytics, and advertising
Our websites and web application use cookies and similar technologies for security, functionality, analytics, session replay, campaign attribution, and advertising. Current providers may include Google Analytics, Mixpanel, and Meta. These providers may receive device identifiers, IP address, browser information, page activity, advertising identifiers, and information you submit through a marketing or demo form. On our marketing website, Mixpanel session replay is configured to mask form inputs and page text.
You can limit cookies through browser settings, use provider opt-out tools, unsubscribe from marketing emails, or contact us to exercise a privacy right available in your jurisdiction. Blocking cookies may affect site functionality. Do not submit Customer Content or other sensitive information through our public marketing forms.
7. Retention and deletion
We retain information for as long as reasonably necessary to provide the Services, maintain the account or business relationship, meet contractual commitments, protect the Services, resolve disputes, and satisfy legal, tax, accounting, and audit requirements.
During a subscription, customers may delete supported records or request assistance. After expiration or termination, Aila will, upon a valid written customer request, delete Customer Content within 60 days, except for information retained in backups, logs, billing, security, legal, or compliance records, or as otherwise required by law or legitimate recordkeeping needs. Retained information remains subject to applicable confidentiality and security obligations and is removed under normal retention cycles when no longer needed.
8. Security
We maintain administrative, technical, and organizational safeguards designed to protect information, including encryption in transit and at rest, access controls, monitoring, vulnerability management, backups, and incident-response procedures. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur. Learn more on our Security page.
9. International data transfers
Aila is based in the United States and the Services are operated from the United States and other locations where our service providers operate. If information is transferred across borders, it may be subject to laws that differ from those in your location. Customers must contact Aila before submitting personal data governed by the EU GDPR, UK GDPR, or another law that requires a data processing agreement or transfer mechanism.
10. Privacy rights and choices
Depending on your location and subject to legal exceptions, you may have rights to access, know about, correct, delete, or receive a copy of personal information; limit or object to certain processing; opt out of sale, sharing, or targeted advertising; withdraw consent; and appeal a denied request. We will not discriminate against you for exercising a privacy right.
Submit a request to support@aila.fyi with the subject "Privacy Request." Describe the right you want to exercise and the email address or account involved. We may verify your identity or authority before completing a request. Authorized agents must provide proof of authority where required.
If an Aila customer submitted your information, contact that customer first. Aila cannot independently change a customer's records without the customer's authorization unless required by law.
11. Children
The Services are intended for businesses and users age 18 or older. We do not knowingly collect personal information directly from children. Customers may not intentionally submit children's personal information to the Services. Contact us if you believe a child has provided information to Aila without proper authorization.
12. Third-party services
The Services may link to or integrate with third-party products. Aila does not control those parties' independent privacy practices. Review their policies before authorizing an integration or providing information directly to them.
13. Changes to this policy
We may update this policy as our Services, vendors, or legal obligations change. We will post the revised policy here and update the date above. If a change materially affects how we use personal information, we will provide additional notice when required by law.
14. Contact us
aila.fyi LLC
2810 N Church St
Wilmington, DE 19802
United States
Email: support@aila.fyi
