Privacy Policy

Last updated: September 3, 2026

This Privacy Policy explains how AskAIs collects, uses, shares, and protects personal information. AskAIs is operated by MiniCode LLC, located at 30 N Gould St Ste R, Sheridan, WY 82801, USA (“AskAIs”, “we”, “us”), the data controller for personal information about our account holders and website visitors. It applies to our website at cs.askais.com and to the AskAIs service.

1. Controller and processor roles

We act as a data controller for personal information about our customers (account holders) and our own website visitors. When our customers use AskAIs to communicate with their end users, we process those end users’ personal information as a data processor, on our customers’ behalf and under their instructions; in that case the customer is the controller. This policy describes our practices as a controller. Our processing on behalf of customers is governed by our agreement with them, including a Data Processing Addendum available on request. We keep each customer’s data logically separated from that of other customers (multi-tenant isolation). The Service may also be white-labeled, so an end user may see only the customer’s brand and may not be aware that AskAIs provides the underlying technology.

2. Information we collect

  • Account information: your name, email address, password, workspace and company details, and role.
  • Billing information: your plan, transaction history, and billing identifiers. Card details are collected and stored by Stripe, not by us.
  • Usage and device data: log data, IP address, browser and device type, pages viewed, and actions taken in the Service.
  • Connected AI client data: when you authorize ChatGPT, Codex, Claude, or another MCP-compatible client, we process the client name, your AskAIs user and workspace identifiers, granted permissions, connection and revocation timestamps, and limited MCP call metadata such as tool name, outcome, duration, and client platform. We do not store MCP tool arguments, prompts, tool results, passwords, full API keys, or plaintext OAuth tokens in the MCP usage log.
  • Support communications: messages and information you send when you contact us.
  • Customer Data: conversations, contacts, knowledge-base documents, and other content that our customers and their end users submit, which we process as a processor (see “Controller and processor roles”). Depending on how a customer configures the Service, this may also include an end user’s IP address and the approximate location derived from it (such as country and city), the platform and device they use to reach the customer, any custom attributes the customer records about them, and membership or account fields the customer chooses to store.
  • Cookies and similar technologies (see “Cookies and tracking”).

3. How we use information

  • to provide, operate, and maintain the Service;
  • to authenticate users and secure accounts;
  • to establish, operate, audit, and let you revoke authorized MCP connections;
  • to process payments and prevent fraud;
  • to provide AI-assisted replies and related features;
  • to respond to support requests;
  • to analyze and improve the Service;
  • to send service-related and, where permitted, marketing communications;
  • to comply with legal obligations and enforce our Terms.

4. Legal bases (EEA and UK)

Where the GDPR or UK GDPR applies, we rely on the following legal bases: performance of a contract (to provide the Service and process billing); our legitimate interests (to secure, analyze, and improve the Service); your consent (for example, certain cookies or marketing); and compliance with legal obligations. You may withdraw consent at any time where processing is based on consent.

5. Payments

We use Stripe for payments, analytics, and other business services. Stripe may collect personal data including via cookies and similar technologies. The personal data Stripe collects may include transactional data and identifying information about devices that connect to its services. Stripe uses this information to operate and improve the services it provides to us, including for fraud detection, loss prevention, authentication, and analytics related to the performance of its services. You can learn more about Stripe and read its privacy policy at https://stripe.com/privacy.

6. Connected AI clients and MCP

If you choose to connect an MCP-compatible AI client, that client can access only the AskAIs workspace and permission scopes shown on the authorization screen. Depending on the permissions you grant and the tool you ask the client to use, relevant Customer Data may be transmitted between the client and AskAIs to perform your request. Read and write tools are identified separately, and external or destructive actions may require confirmation in the client.

OAuth authorization codes are short-lived and single-use. Access and refresh tokens are random credentials returned only to the authorized client; AskAIs stores only cryptographic hashes of those tokens. You can review and revoke connections from your AskAIs MCP connection settings. Revocation immediately prevents further use of associated tokens.

7. AI providers

To generate automated replies and related features, we may send relevant message content to third-party AI model providers acting as our subprocessors. These providers process the content to return results and do not use it to train their models except as permitted under our agreements. Customers can configure AI features or use their own provider API keys.

8. How we share information

We do not sell your personal information. We share it only as follows:

  • Service providers and subprocessors that help us operate the Service, such as hosting, object storage for files and attachments (such as Amazon S3 or Cloudflare R2), payments (Stripe), AI model providers, messaging channel providers (such as WhatsApp and Telegram) where a customer connects those channels, email delivery, and analytics, under contracts that require them to protect the data;
  • Legal and safety: to comply with law, respond to lawful requests, or protect the rights, property, and safety of AskAIs, our users, and the public;
  • Business transfers: in connection with a merger, acquisition, financing, or sale of assets;
  • With your consent or at your direction.

9. Cookies and tracking

We and our providers use cookies and similar technologies to keep you signed in, remember preferences, secure the Service, and measure usage. You can control cookies through your browser settings, though some features may not work without them.

10. Data retention

We retain personal information for as long as your account is active and as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. Customer Data is retained according to our customers’ instructions and our agreements with them, and is deleted within a reasonable period after account termination.

OAuth authorization codes expire within minutes. OAuth access tokens normally expire within one hour and refresh authorization normally expires within 30 days unless revoked sooner. We retain connection records and limited MCP usage metadata while needed to operate, secure, and audit the connection and account. Revoked credential hashes and security records may be retained for a limited period to detect replay, abuse, or security incidents; they cannot be used as plaintext credentials.

When a message is deleted, we make reasonable efforts to also remove any associated files and attachments from our object storage, although residual copies may persist for a limited time in backups.

11. Security

We use technical and organizational measures to protect personal information, including encryption in transit, access controls, and reliance on PCI-DSS-compliant providers for card processing. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

12. International transfers

We are based in the United States and may process personal information there and in other countries. Where required, we use appropriate safeguards, such as Standard Contractual Clauses, for transfers from the EEA, UK, or Switzerland.

13. Your rights

Depending on where you live, you may have rights to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. Residents of the EEA and UK may also lodge a complaint with their local supervisory authority.

California residents have rights under the CCPA/CPRA, including to know, delete, and correct personal information and to opt out of the sale or sharing of personal information, and, as noted above, we do not sell personal information. We will not discriminate against you for exercising your rights.

To exercise your rights, email support@askais.com; we may need to verify your identity. If the information is held on behalf of one of our customers, we will refer your request to that customer.

14. Children’s privacy

The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will delete it.

15. Data Processing Addendum

Business customers who require a Data Processing Addendum (DPA) for GDPR or UK GDPR compliance can request one at support@askais.com.

16. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version here with a new date and, where appropriate, provide additional notice.

17. Mobile apps

We publish the AskAIs agent app, a mobile app that lets a customer’s support agents work from a phone. Everything above applies to the app. Because the app also handles a few things that the web service does not — push notifications, the photo picker, device records used for remote sign-out, and in-app account deletion — those are described separately in our AskAIs Mobile App Privacy Notice, which supplements this policy rather than replacing it.

18. Contact

For privacy questions or to exercise your rights, email support@askais.com or write to MiniCode LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA.