Privacy Policy

Last Updated: July 14, 2026

1. Scope and Our Role

This Privacy Policy explains how the AIO platform operator ("AIO," "we," "us," or "our") collects, uses, discloses, and retains personal information through AIO Services, our websites, applications, APIs, desktop and mobile software, support, and related services (collectively, the "Services").

AIO is the business or controller for information used to manage our direct relationship with customers, website visitors, and account holders. When customers submit information about their members, employees, clients, passengers, contacts, children, or other people ("Customer Data"), AIO generally processes it on the customer's instructions.

This Policy does not govern a customer's independent activities or third-party services you connect. Their own notices and terms apply.

2. Personal Information We Collect

The categories below describe information we may collect. We collect only the categories relevant to the Services, features, devices, and integrations you use.

Identifiers and account information

Name, email, phone number, postal address, username, organization, role, account and device identifiers, login records, authentication data, preferences, and support details.

Commercial and billing information

Plan, subscription status, invoices, transaction and donation records, usage, tax and billing details, and limited payment-method information. Payment processors generally receive full card or bank details directly; AIO may receive tokens and masked details.

Customer content and communications

Contacts, leads, forms, messages, email, SMS, call and meeting records, recordings, voicemails, transcripts, notes, tasks, events, files, media, social content, financial records, and other information submitted to or generated through a customer account.

AI, workspace, and connected-service data

Prompts, responses, project context, code, files, tool calls and outputs, automation rules, repositories, browser activity performed through the Services, deployment logs, configuration, API tokens, and data received from integrations you authorize.

Sensitive, child, and consumer health information

Where a customer enables relevant features, this may include dates of birth, child and guardian records, photographs, authorized pickups, allergies, medical or accessibility notes, prayer or pastoral-care information, precise location used for check-in, financial account data, credentials, and other information treated as sensitive by law.

Device, internet, and usage information

IP address, browser, device and operating-system details, cookie and session identifiers, pages and features used, clicks, referring URLs, approximate location derived from IP, crash reports, diagnostics, security events, performance, and audit logs.

Inferences and derived information

Summaries, classifications, risk or spam signals, recommended actions, usage patterns, preferences, and other information inferred from the categories above to provide, personalize, secure, or improve the Services.

3. Sources of Information

We may obtain personal information:

  • Directly from you, a parent or guardian, or another person acting for you.
  • From a customer, account administrator, authorized user, or other user of the Services.
  • Automatically from devices, applications, cookies, logs, and use of the Services.
  • From providers and integrations you or a customer connects, including communications, payment, accounting, social, AI, repository, cloud, calendar, and identity providers.
  • From public sources, referrals, service providers, and business partners where lawful.
  • By deriving or inferring information from other information described in this Policy.

4. How We Use Personal Information

Depending on our role and applicable law, we use personal information to:

  • Provide, operate, personalize, maintain, and troubleshoot the Services.
  • Authenticate users; manage organizations, plans, billing, usage, devices, and support.
  • Process messages, files, recordings, payments, check-ins, workflows, and other requested actions.
  • Route prompts and context to AI providers and tools selected or configured by a customer.
  • Detect fraud, abuse, spam, security incidents, policy violations, and service errors.
  • Analyze performance and improve reliability, accessibility, safety, and product quality.
  • Send transactional, security, billing, service, and legally permitted marketing communications.
  • Comply with law, enforce agreements, protect rights and safety, and resolve disputes.
  • Carry out another purpose disclosed when information is collected or with valid consent.

Where a law requires a legal basis, our bases may include performing a contract, legitimate interests such as operating and securing the Services, compliance with law, consent, and protection of vital interests. A customer determines the legal basis for Customer Data it controls.

5. AI Providers and Automated Processing

When you or a customer uses an AI or agent feature, AIO may send relevant prompts, files, messages, project context, tool results, and instructions to the selected AI provider or connected service. Which provider receives data may depend on account settings, model choice, availability, and the requested action. Provider retention and model-improvement practices depend on that provider's product, account type, contract, and settings.

AIO may use Customer Data and related interactions to provide, evaluate, secure, support, and improve the Services as allowed by the applicable customer agreement, configuration, and law. We may use feedback and aggregated or de-identified information for product improvement. Do not submit information to an AI feature unless you are authorized to do so.

The Services may produce inferences or recommendations, but customers and users are responsible for human review and for notices, consent, assessments, and appeal rights required before using automated processing for consequential decisions.

6. How We Disclose Personal Information

We may disclose the categories described above to:

  • Customers and authorized users: account administrators, team members, guardians, or other people authorized through account permissions and workflows.
  • Service providers and processors: hosting, storage, security, analytics, communications, payments, support, identity, email delivery, and professional advisers.
  • AI and integration providers: providers selected, connected, or directed by a customer or user to perform requested features or actions.
  • Authorities and affected parties: when we reasonably believe disclosure is required by law or needed to protect rights, safety, systems, users, or the public.
  • Transaction participants: advisers, lenders, investors, buyers, and successors involved in a financing, reorganization, merger, acquisition, bankruptcy, or transfer of all or part of a business, subject to appropriate safeguards.
  • Others: at your direction, with valid consent, or as otherwise disclosed.

Service providers may process information only for contracted purposes and subject to their agreements with AIO. Third-party services you independently authorize may use information under their own terms and privacy policies.

7. Sale, Sharing, and Targeted Advertising

AIO does not sell personal information for money. As of the date of this Policy, AIO does not share personal information for cross-context behavioral advertising as those terms are defined by California law. We also do not knowingly sell or share personal information of people under 16.

A customer may independently configure advertising pixels, conversion APIs, campaigns, or other marketing tools in its tenant. The customer controls those activities and must provide any required notice and choice. If AIO's own practices change in a way that creates a right to opt out, we will update this Policy and provide the legally required choice mechanism.

8. Cookies and Privacy Signals

We use cookies, local storage, and similar technologies for authentication, security, preferences, functionality, diagnostics, and, where enabled, analytics. Necessary technologies are used to provide the Services. Where required, optional analytics or marketing technologies are controlled through the cookie preference tool.

You can manage browser storage through your browser and reopen cookie preferences through Your Privacy Choices. Where legally required, we treat a recognized Global Privacy Control signal as a request to opt out of sale or sharing. Because no common standard governs older Do Not Track signals, we do not separately respond to them unless required by law.

9. Retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, a customer's documented instructions, and legitimate operational, security, legal, accounting, and dispute-resolution needs. Retention depends on the type and sensitivity of information, the feature used, account and subscription status, customer configuration, legal limitation periods, provider requirements, and the risk of harm.

After deletion or account termination, information may remain temporarily in backups, security logs, legal holds, fraud-prevention records, and records that law requires us to retain. When deletion from a backup is not immediately feasible, we isolate the information from ordinary use until it is overwritten or safely deleted. Disconnecting an integration stops new access but does not necessarily delete copies already lawfully retained.

10. Security and Incident Response

We use administrative, technical, and physical safeguards designed to protect personal information, taking into account its nature and the risks of processing. No system, storage method, or transmission is completely secure, and we cannot guarantee absolute security. Users and customers are responsible for appropriate credentials, device security, permissions, backups, and integration settings.

If an incident triggers a legal notification duty, AIO will provide notices to affected customers, individuals, regulators, or others as required by applicable law and our role in the processing relationship.

11. Customer-Controlled Data

AIO generally cannot independently determine whether Customer Data is accurate, whether the customer had authority to collect it, or which customer retention rule applies. Customers control user access, purposes, permissions, and instructions for their Customer Data. If your request concerns information held in a customer account, contact that customer first. We will assist the customer as required by contract and law.

Account administrators may access, export, correct, restrict, or delete information in their organization. Their actions are governed by their relationship with you and are not controlled by AIO.

12. Consumer Health Data

Some organization-managed features may process allergies, medical or accessibility notes, pastoral-care information, or location used for check-in. Our separate Consumer Health Data Privacy Notice describes those categories, sources, purposes, disclosures, and rights. Customers must not collect or disclose consumer health data through the Services beyond what their notices, consents, contracts, and applicable law allow.

13. Children's Privacy

AIO account services are not intended for independent use by children under 13, and children may not create AIO accounts. Customers such as churches, schools, and other organizations may use adult-managed features to maintain information about children. In that context, the customer is responsible for providing direct notices, obtaining verifiable parental or guardian consent where required, limiting collection, managing access, and honoring parent rights. AIO processes the information on the customer's documented instructions.

If you believe a child submitted personal information directly to AIO without required authorization, contact us. We will investigate and delete or restrict it where required. Parents and guardians may use the privacy request process below or contact the relevant customer to request access, correction, or deletion.

14. Your Privacy Rights

Depending on where you live and subject to legal exceptions, you may have rights to confirm processing; access, correct, delete, or obtain a portable copy of personal information; opt out of sale, sharing, targeted advertising, or certain profiling; limit certain sensitive-data uses; withdraw consent; and appeal a denied request. You may also opt out of marketing email using the unsubscribe link and revoke communications consent by legally recognized methods.

Submit a request through Your Privacy Choices or email legal@aio.church. We may verify your identity, authority, and relationship to the information. Authorized agents must provide proof of authority where law permits. We will not unlawfully discriminate against you for exercising a privacy right.

We respond within the period required by applicable law. Many U.S. state laws allow 45 days and a permitted extension. We may deny or limit a request where an exception applies or we cannot reasonably verify it, and will explain available appeal or regulator-contact options when required.

15. California Notice

During the preceding 12 months, AIO collected the categories described in Section 2 as relevant to a person's use of the Services. We obtained them from the sources in Section 3, used them for the purposes in Sections 4 and 5, and disclosed relevant categories for business purposes to the recipient categories in Section 6. AIO has not sold personal information for money or shared it for cross-context behavioral advertising during that period.

California residents may request to know, access, correct, or delete personal information; obtain information about categories, sources, purposes, and disclosures; opt out of sale or sharing if those practices begin; limit sensitive personal information used beyond permitted purposes; and receive equal service. AIO uses sensitive personal information only for purposes reasonably necessary to provide requested Services, maintain security and integrity, and other purposes permitted by California law, unless we provide a separate notice and choice.

California's "Shine the Light" law may permit residents to request information about certain disclosures for direct marketing. Submit any such request using Section 14 and state that it is a California request.

16. International Processing

AIO and its providers may process information in the United States and other countries where privacy laws may differ from those where you live. Where a cross-border transfer mechanism is legally required, the relevant customer and AIO will use an applicable contractual or other recognized safeguard. Customers are responsible for determining whether their use of the Services requires a data processing addendum or additional regional terms.

17. Changes to This Policy

We may update this Policy to reflect changes in law, technology, providers, or our practices. We will post the revised Policy and update the date above. We will provide additional notice or obtain consent before applying a materially different practice where required by law.

18. Contact Us

AIO

Privacy email: legal@aio.church