Legal

Privacy Policy

Last updated: August 19, 2026

This Privacy Policy explains how AXOIX TECHNOLOGIES PRIVATE LIMITED (“we”, “us”, “our”) — a private limited company registered in New Delhi, India (CIN: U62099DC2026PTC471359, TAN: DELA89123G, D-U-N-S: 581637158, DPIIT: DIPP270090) — collects, uses, and protects information when you use our website axoix.in, our marketing site axoix.com, our tenant dashboards at *.axoix.io, and any related services (collectively, the “Services”).

1. Information we collect

  • Account data — name, email address, phone number, company name, and credentials you provide when signing up, requesting a quote, or applying as a contributor.
  • Usage data — pages visited, features used, timestamps, IP address, device and browser information collected via server logs and analytics tooling.
  • Tenant content — on AXOIX, any data you or your users upload (documents, emails, chats, voice recordings, images, etc.) is stored in your tenant’s isolated database and object storage.
  • Communications — messages you send us via forms, email ([email protected]), or chat.
  • GitHub identity — if you sign in with GitHub (e.g. as a contributor), we receive your GitHub handle, user id, avatar URL, name, and verified primary email via the GitHub App OAuth flow.

2. How we use your information

  • To provide, operate, and maintain the Services.
  • To process signups, payments, invoicing, and tenant provisioning.
  • To respond to enquiries, support requests, and contributor applications.
  • To improve our products through aggregated, anonymised analytics.
  • To send service-related emails (account notices, receipts, policy changes).
  • To comply with applicable laws, including Indian tax and GST requirements.

3. AI processing — default vs. BYOK

By default, AXOIX runs on self-hosted AI infrastructure (fine-tuned local LLM, Whisper STT, Coqui TTS, image/video generation) on our own GPU server. Your tenant content is processed inside our servers, is not shared with any external AI provider, and is not used to train any shared or public model.

Bring Your Own Key (BYOK) is an optional fallback. If you explicitly add an API key for a third-party AI provider (currently supported: OpenAI, Anthropic, Groq) via your account settings and route a request to that provider, then the prompt and any attached content you send will leave our servers and be processed by that third-party provider under their own terms and privacy policy. We encrypt your stored API key at rest but we do not control what happens to your content once it reaches the third-party provider. Enabling BYOK is your informed choice; you can deactivate or delete your BYOK key at any time from Account → API Keys.

Examples of features where BYOK, when enabled, sends content out: AI chat, AI costing, AI content generation, AI image generation. Features that never leave our servers regardless of BYOK: database queries, file storage, email IMAP/SMTP via our own mail server, voice transcription on our Whisper instance, and TTS on our Coqui instance.

4. Connecting AI assistants via MCP

AXOIX operates a Model Context Protocol (MCP) server at mcp.axoix.io that lets you connect an AI assistant client (such as Claude, ChatGPT, or Cursor) directly to your AXOIX tenant. This is a separate, opt-in mechanism from the BYOK AI features described in section 3.

  • You initiate the connection. Nothing is shared with an AI assistant client until you explicitly add https://mcp.axoix.io/mcp as a custom connector in that client and complete an OAuth 2.1 login with your AXOIX email and password.
  • Scoped access only. During connection you choose which scopes to grant (read, write, Chorus content, finance). The assistant can only call the tools covered by the scopes you approved.
  • Tenant-isolated. Tool calls run through the same tenant-scoped API your dashboard uses; a connected assistant can never see or act on another tenant’s data.
  • Confirmation before write actions. Destructive or financial operations (sending a message, generating content, invoking a write operation) require your explicit confirmation inside the assistant before they execute.
  • Fully audited. Every call an assistant makes is logged to your tenant’s own audit trail, identical to actions taken through the dashboard.
  • Revocable anytime. Disconnect the connector inside your AI assistant client to invalidate AXOIX’s access token immediately.
  • No tenant content is used to train any AI model as a result of an MCP connection — the assistant client (e.g. Claude, ChatGPT) processes data you send it under that provider’s own terms, exactly as if you had entered the same information into that assistant directly.

See axoix.in/docs/mcp for setup instructions and supported scopes.

5. Connecting your Google account (Calendar, Drive, YouTube, Classroom)

AXOIX can connect to your Google account so that Google services appear inside your tenant dashboard. This is entirely opt-in: nothing is requested until you start the connection yourself and approve it on Google’s own consent screen. We request only the scopes needed for the feature you enable.

You grant each service separately. Signing in asks only for identity; every other permission below is requested at the moment you enable that feature and not before.

YouTube is a separate connection, on a separate application registration. Google will not place YouTube permissions and Drive permissions in the same authorisation, and it stores one set of permissions per application per Google account — so on a single registration, granting one would silently withdraw the other. Since 19 August 2026 AXOIX therefore registers YouTube as its own application with Google. The practical effect is that connecting YouTube and connecting Drive, Docs, Sheets, Calendar, Ads, Analytics or Classroom create two independent grants on your Google account, and neither can disturb the other. You can hold either, both, or neither.

  • Sign-in — openid, userinfo.email, userinfo.profile. To identify which Google account is connected and display its name, email address, and avatar.
  • Calendar — calendar. To read the events in your calendar and write the bookings and class sessions you create in AXOIX back into it, attaching a Google Meet link where the booking is a meeting. AXOIX creates, updates and deletes only the events it wrote; it does not create calendars.
  • Drive (limited) — drive.file. Only files AXOIX creates, plus files you hand over explicitly through the Google Picker. This cannot list the rest of your Drive.
  • Docs and Sheets — drive.file only. AXOIX creates and edits the documents and spreadsheets it generates for you, plus any file you hand over yourself through the Google Picker. documents and spreadsheets — each of which would mean every Google Doc or Sheet in your account — were withdrawn on 9 September 2026 and can no longer be granted.
  • Google Ads — adwords. Google publishes no read-only variant, so a spend dashboard grants the same scope as campaign editing; AXOIX limits read versus write by your role inside the dashboard.
  • Analytics (GA4) — analytics.readonly, analytics.edit, analytics.manage.users.
  • YouTube — youtube.readonly, youtube.upload, youtube.force-ssl, yt-analytics.readonly, yt-analytics-monetary.readonly, youtube.channel-memberships.creator. To publish video; read channel statistics; edit, delete and thumbnail your uploads and moderate comments; show watch time, audience retention and traffic sources; show earnings, CPM, ad impressions and monetised playbacks; and list your channel members, their tier and how long they have been a member. The last three come from APIs separate from the YouTube Data API. The revenue and members permissions are additive — a channel connected before they existed keeps what it has and shows no Revenue or Members screen until you reconnect.
  • Google Business Profile — business.manage. To manage the listing you connect from CHORUS.
  • Google Classroom — classroom.courses, classroom.rosters, classroom.coursework.students, classroom.announcements, classroom.topics, classroom.profile.emails, classroom.courseworkmaterials. Offered only to Education tenants; the restriction is enforced on our servers, not merely hidden in the interface.

What we do not request. No Gmail permission of any kind. AXOIX does not request gmail.modify, gmail.send, gmail.readonly, gmail.metadata, gmail.compose, gmail.labels or mail.google.com. No part of AXOIX can read, send, label or delete mail in your Gmail mailbox, and no Google connection you make with us can be granted that ability. The mail features inside AXOIX run on mailboxes we host ourselves; they are unrelated to your Google account. We also do not request drive, drive.readonly or drive.metadata.readonly, so nothing in AXOIX lists your files in the background, nor youtube (the broad variant), youtubepartner or youtubepartner-channel-audit.

We request no restricted permission. Google classifies permissions as non-sensitive, sensitive or restricted, and restricted is the highest tier — reserved for permissions that expose the whole of a mailbox or the whole of a Drive. Every permission above is non-sensitive or sensitive. Earlier versions of this policy described two restricted permissions, gmail.modify for a full Gmail mailbox and drive for browsing your whole Drive. Both have been withdrawn from our Google client and neither can be granted on any AXOIX connection today. If we ever reinstate either, this page changes first, they go through Google’s restricted-scope verification and an independent CASA assessment, and you would still approve the new permission on Google’s own consent screen before anything was granted.

How we handle Google user data. The access and refresh tokens Google issues are encrypted at rest with authenticated encryption. Tokens for every service except YouTube and Business Profile are stored only in your tenant’s isolated database (Fernet — AES-128-CBC with HMAC-SHA256, from a key derived with PBKDF2-HMAC-SHA256 at 100,000 iterations); YouTube and Business Profile tokens are held in our central platform database, tagged to your tenant and encrypted with AES-256-GCM, because CHORUS publishing runs centrally. Your tenant database is dumped nightly and encrypted with AES-256 before it goes anywhere, so those tokens and any records synchronised from a Google service are inside that encrypted dump — whether the dump leaves our servers follows the cloud-storage rule in section 9. Google user data is also excluded from the MCP connector in section 4: that connector works from a closed catalogue of AXOIX operations, and no Google-backed operation is in it. Google user data is used solely to provide the feature you enabled. It is never sold, never used for advertising or ad personalisation, and never used to develop, improve, or train generalised AI or machine-learning models — including our own self-hosted models described in section 3. No AXOIX personnel read your Google user data except with your explicit consent (for example, when you raise a support request), where necessary for security purposes, or where required by law.

Revoking access. You can disconnect the account from inside AXOIX at any time, or revoke our access directly at myaccount.google.com/permissions. If you have connected YouTube as well, AXOIX appears there twice, and revoking one entry does not revoke the other. That is a direct consequence of YouTube being a separate application registration, described above. One entry covers YouTube; the other covers Drive, Docs, Sheets, Calendar, Ads, Analytics, Business Profile and Classroom. To withdraw our access completely, remove both. Disconnecting from inside AXOIX has the same split: each disconnect revokes and deletes only its own side.

On disconnect we send a revocation request to Google and delete the stored tokens — from your tenant database for every service, and from our platform database for YouTube and Business Profile. To also have records AXOIX kept on your behalf removed — synchronised Classroom data, calendar sync records, Drive file links — email [email protected] and we will delete them within 30 days. Encrypted backups written before that request are not rewritten; they expire on the schedule in section 9 and are restored only to recover the platform after a failure.

AXOIX’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6. Sharing & third parties

We do not sell personal data. We share data only with the categories of service providers and integrations listed below, and only to the extent necessary to operate the Services. Each provider is subject to its own terms and privacy policy.

Always involved (infrastructure)

  • Backblaze B2 — private per-tenant object storage for files you upload (documents, images, audio). Region: eu-central-003 (Frankfurt, Germany). Tenant bucket credentials are encrypted at rest before being stored in your tenant database.
  • Cloudflare — DNS, TLS, WAF, and CDN edge caching. File URLs served via cdn.axoix.io are validated with HMAC signatures, proxied through a Cloudflare Worker to Backblaze B2, and cached at Cloudflare edge locations globally so that repeat viewers are served from the nearest edge.
  • Hostinger / VPS host — our dedicated virtual private server (31.97.207.114) located in India hosts our application, databases, and email server.

Used when you choose to use the feature

  • Razorpay — payment processing. Receives only the billing information and payment details needed to complete the transaction.
  • Brevo (Sendinblue) — transactional email delivery for platform notices sent by us to you (signup confirmation, password reset, receipts, service notices). Does not process email in your tenant mailboxes.
  • GitHub — for contributors only, to verify identity via the GitHub App OAuth flow and manage repository invitations.
  • Social media OAuth providers — Meta (Facebook, Instagram, Messenger, WhatsApp), LinkedIn, X (Twitter), Threads, and Telegram. Used only when you explicitly connect an account from your tenant dashboard (e.g. CHORUS social media posting). We receive the access tokens each provider issues you; we do not receive your social login password.
  • Google — Calendar, Drive, Docs, Sheets, Ads, Analytics, YouTube, Business Profile and Classroom, only when you connect a Google account yourself. See section 5 for the exact scopes requested and how Google user data is handled.
  • Telephony — self-hosted FusionPBX on our VPS handles SIP routing. Outbound calls and SMS leave our network via our upstream DID/SMS carriers (e.g. LINK DID). Call audio is never sent to any AI provider without your BYOK configuration.
  • Third-party AI (BYOK) — OpenAI, Anthropic, Groq. Only when you add a BYOK key and actively invoke a BYOK-routed feature. See section 3.

Legal

  • Legal obligations — when required by law, court order, or to protect our rights.

7. Where your data lives

  • Compute, databases, email server — our VPS in India.
  • Object storage (uploaded files) — Backblaze B2 eu-central-003 region (Frankfurt, Germany). Each tenant has a dedicated private bucket.
  • CDN edge cache — Cloudflare globally distributed edge servers cache publicly-accessed file responses (signed URLs) transiently to reduce latency and bandwidth cost. Cached copies are purged on a rolling TTL; you can request a purge at any time.
  • BYOK AI responses — if enabled, processed by the chosen provider in their region (see their documentation).

If your jurisdiction (e.g. EU GDPR, UK GDPR, DPDP Act India) imposes specific data residency or cross-border transfer obligations on you as a data controller, you are responsible for assessing whether this architecture meets those obligations before using AXOIX.

8. Data security

Credentials and secrets are stored in HashiCorp Vault. Tenant B2 storage credentials and mailbox passwords stored in your tenant database are encrypted at rest with authenticated encryption, using keys derived via PBKDF2-HMAC-SHA256 with 100,000 iterations. All public traffic uses HTTPS with TLS certificates from Let’s Encrypt. We restrict administrative access on a least-privilege basis. No system is impenetrable, but we take reasonable steps to protect your data against unauthorised access.

9. Data retention, backups & recovery

We retain account and tenant data for as long as your account is active. After account closure we retain minimum records required by law (e.g. invoices, tax records) and otherwise delete tenant content on request. Contact [email protected] to request deletion. Note that deletion of tenant content includes the contents of your Backblaze B2 storage; Cloudflare edge caches for your files are purged on request within 24 hours.

Backups

We keep encrypted backups so that we can restore the service after a failure. Backups are encrypted at rest and retained on a rolling basis — database backups for up to 30 days, platform and configuration backups for up to 7 days. Backups exist for disaster recovery only. We do not mine, analyse or otherwise use their contents, and they are never used to train any model.

Whether a copy leaves our servers depends on your plan, and on paid plans it is your choice:

  • Paid plans — you decide. We hold an off-site copy in Backblaze B2 (EU) only if you have given us cloud-storage consent. Without that consent your data is backed up on our own servers only and never reaches a third-party storage provider. You can withdraw the consent at any time from your dashboard, and we stop sending anything further immediately. Copies already stored are not deleted automatically — withdrawing consent is not a deletion request, and destroying files because you changed your mind about where they live could lose you data. Ask us and we will erase them, or migrate them back to our servers first; either way we action it without delay.
  • Free plan — included, and not optional. Free accounts are closed automatically after 40 days of inactivity, so the off-site copy is the only thing that makes an unintended closure reversible. For a free account the realistic alternative is not “stays on our servers” but “permanently destroyed”, so it is a condition of the free plan rather than a choice. Upgrading to any paid plan gives you the control described above.

If your account is closed for inactivity

Free accounts that go unused are closed after 40 days of inactivity, and we email you three times before that happens. Rather than destroying your data at closure, we move it to an encrypted recovery archive and hold it for 90 days, so that a closure you did not intend can be undone. After 90 days it is permanently and irreversibly deleted.

If you ask us to delete your account

A deletion you request is not placed in the recovery archive. We purge your data immediately, including any recovery copy and any backup we are able to reach, and the deletion cannot be undone by us or by you. You may also ask us at any time to erase a recovery archive created by an inactivity closure — a single request to [email protected] is enough, and we action it without delay rather than waiting for the 90 days to elapse.

10. Your rights

Subject to applicable law, you may: request a copy of the data we hold about you; correct inaccurate data; request erasure; object to processing; or withdraw consent where processing is based on consent. Email [email protected] to exercise any right.

11. Cookies

We use a minimal set of cookies for authentication sessions and basic analytics. You can control cookies via your browser settings; disabling cookies may impair parts of the Services that require sign-in.

12. Children

The Services are not directed to individuals under 18. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.

13. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified by email or a notice on the Services. Continued use after changes means you accept the revised policy.

14. Contact

Questions, complaints, or requests? Email [email protected] or call +91 888 214 0460. Postal: AXOIX Technologies, New Delhi, India.

See also our Terms of Service.