Legal

Legal Hub

Last updated July 8, 2026

Central index of Illana legal, privacy, security, and compliance documents. Questions: legal@illana.ai.

1

Legal Overview

1.1 Purpose of this hub. This Legal Hub is the central index for Illana's contractual terms, privacy practices, security commitments, AI policies, and compliance resources. It helps customers, users, developers, and partners locate the documents that govern their relationship with Illana (Illana, we, us, or our).

1.2 What Illana provides. Illana operates a memory and retrieval platform: you connect authorized third-party sources (email, calendar, documents, financial and accounting systems), sync selected content into a searchable vault, and query that content through natural-language search, AI-assisted responses, APIs, MCP, Slack, Microsoft Teams, and related channels (collectively, the Services).

1.3 Document hierarchy. If documents conflict, the following order of precedence generally applies (specific Enterprise Agreements may vary):

  1. a signed Enterprise Agreement, order form, or data processing addendum (DPA) executed with your Organization;
  2. the Illana Terms & Conditions;
  3. this Legal Hub and linked policies (Privacy Policy, Acceptable Use, API Terms, and others); and
  4. product documentation, rate limits, and in-app notices.

1.4 Audience. Different sections apply to different audiences: all users should review Terms and Privacy; developers should review API and Developer Terms; enterprise procurement and legal teams should review DPA, SLA, subprocessors, and Enterprise Agreement Terms; security teams should review the Security and Trust Center and vulnerability disclosure materials.

1.5 Updates. We may update documents in this hub. Material changes will be communicated as described in the relevant document and, where required by law, by email or in-app notice. The “Last updated” date at the top of this page reflects the most recent revision to this hub index.

1.6 Not legal advice. These materials are provided for transparency and contractual clarity. They do not constitute legal advice. Consult qualified counsel for your specific compliance obligations.

2

Terms of Service

Full document: terms

2.1 Binding agreement. The Illana Terms & Conditions (the Terms) are the primary contract governing access to and use of the Services. By registering, connecting integrations, using APIs or MCP, linking Slack or Teams, or otherwise accessing the Services, you agree to the Terms.

2.2 Key topics covered. The Terms include, among other subjects:

  • eligibility, account security, and organization administrator responsibilities;
  • Connected Services (Google, Microsoft, Plaid, QuickBooks) and read-oriented sync;
  • customer data ownership, processing scope, retention, and deletion;
  • AI processing disclosures, accuracy limitations, and prohibited misuse;
  • acceptable use, security practices, confidentiality, and data isolation;
  • API and MCP usage, rate limits, billing, suspension, and termination;
  • compliance, international transfers, export control, liability, and dispute resolution.

2.3 Full text. The Terms comprise sixty-six (66) numbered sections with table of contents and anchor navigation. Read the complete document before using the Services: illana.ai/terms.

2.4 Questions. Contractual questions about the Terms: legal@illana.ai.

3

Privacy Policy

Full document: privacy

3.1 Scope. Our Privacy Policy explains how Illana collects, uses, discloses, retains, and protects personal information relating to account holders, website visitors, and individuals whose data appears in customer-synced vault content.

3.2 Controller and processor. Illana is typically the controller for account, billing, and website data. For personal information in vault content synced at a customer's direction, the customer is typically the controller and Illana acts as processor.

3.3 Key commitments. The Privacy Policy describes:

  • categories of data collected from direct input, Connected Services, and technical logs;
  • purposes including service delivery, AI processing, security, and legal compliance;
  • no sale of personal information and no training of foundation models on vault content;
  • encryption (TLS in transit, AES-256-GCM at rest), access controls, and customer isolation;
  • retention, deletion, export, international transfers, and regional privacy rights (GDPR, CCPA/CPRA); and
  • contacts for privacy requests at privacy@illana.ai.

3.4 Full text. Fifty-seven (57) sections with full detail: illana.ai/privacy.

4

Cookie Policy

4.1 What this policy covers. This Cookie Policy explains how Illana uses cookies, local storage, session tokens, pixels, and similar technologies (collectively, cookies) on our websites and web application. It supplements our Privacy Policy.

4.2 Why we use cookies. Cookies enable core functionality, remember preferences, maintain secure sessions, measure product usage, and—where permitted—evaluate marketing effectiveness on public pages.

4.3 Categories.

  1. Strictly necessary: authentication sessions, CSRF protection, load balancing, and security controls required to operate the Services. These cannot be disabled without breaking login and core features.
  2. Functional: language, timezone, theme, and UI preferences that improve your experience.
  3. Analytics: aggregated measurement of page views, feature adoption, and performance. We use analytics to improve the product, not to sell data or build third-party advertising profiles from vault content.
  4. Marketing (public sites only): where enabled and where consent is required by law, cookies that measure campaign effectiveness on marketing pages. The authenticated product app is not used for cross-context behavioral advertising.

4.4 Third-party cookies. We may use third-party services (such as analytics or payment processors) that set their own cookies when you interact with their embedded components. Those providers' policies govern their cookies.

4.5 Your choices. Browser settings may block or delete cookies. Blocking strictly necessary cookies may prevent login. Where required by law, we present consent banners on marketing sites for non-essential cookies. You may withdraw consent through banner controls or browser settings.

4.6 Do Not Track. Illana does not uniformly respond to Do Not Track signals. See the Privacy Policy for regional opt-out rights where applicable.

4.7 Retention. Session cookies expire when you close the browser or log out. Persistent cookies have varying lifetimes depending on purpose—typically from days to twelve months for analytics and preferences.

4.8 Contact. Cookie questions: privacy@illana.ai.

5

Acceptable Use Policy

5.1 Scope. This Acceptable Use Policy (“AUP”) applies to all users of the Services, including individuals, Organization members, Administrators, API consumers, MCP clients, and Slack or Teams Access Connectors. It is incorporated into the Terms and violations may result in suspension or termination.

5.2 Permitted uses. You may use Illana to connect authorized data sources, sync content into your vault, search and retrieve Customer Data for legitimate business or personal productivity, generate AI-assisted outputs for internal decision support with appropriate human review, and integrate approved workflows via API, MCP, or Access Channels.

5.3 Prohibited uses. You may not:

  1. access the Services without authorization or share credentials except with permitted Authorized Users;
  2. sync or query data you do not have lawful rights and consents to process;
  3. use the Services to violate privacy, employment, financial, healthcare, or sector-specific laws;
  4. harass, defame, threaten, or infringe the rights of others;
  5. probe, scan, or test vulnerabilities except under our Vulnerability Disclosure Policy;
  6. circumvent rate limits, authentication, or access controls;
  7. scrape, replicate, or resell the Services except as expressly permitted in an Enterprise Agreement;
  8. introduce malware, spam, or abusive automated traffic;
  9. use AI Output as the sole basis for legally significant decisions about individuals without human review;
  10. use the Services for illegal surveillance, stalking, or unauthorized monitoring of individuals; or
  11. use the Services in violation of export control, sanctions, or anti-terrorism laws.

5.4 Connected Service compliance. You must comply with Google, Microsoft, Slack, Plaid, Intuit, and other provider terms when using integrations. Illana is not responsible for your violations of third-party platform policies.

5.5 Organization responsibility. Administrators must configure shared Connections and workspace access consistent with organizational policies. Offboard users and revoke keys when access should end.

5.6 Enforcement. We may investigate suspected violations, remove content, throttle API access, suspend Accounts, or terminate access. We may report illegal activity to authorities where required or appropriate.

5.7 Reporting abuse. Report misuse to legal@illana.ai or security@illana.ai.

6

Data Processing Agreement (DPA)

6.1 When a DPA applies. Organizations that sync personal data from Connected Services into Illana and are subject to GDPR, UK GDPR, Swiss FADP, or similar laws typically require a Data Processing Agreement. Illana acts as processor (or subprocessor, where applicable) for Customer Data processed on the customer's documented instructions.

6.2 Standard terms. Our DPA incorporates processor obligations including:

  1. processing only on documented instructions from the customer;
  2. confidentiality commitments for personnel with access to Customer Data;
  3. appropriate technical and organizational security measures (see Security and Trust Center);
  4. assistance with data subject requests, DPIAs, and breach notification where required;
  5. restrictions on subprocessing with notice and objection rights;
  6. deletion or return of Customer Data upon termination, subject to legal retention; and
  7. audit and information rights as specified in the DPA.

6.3 International transfers. The DPA includes Standard Contractual Clauses (SCCs) or equivalent mechanisms for transfers from the EEA, UK, and Switzerland to the United States and other jurisdictions, supplemented by transfer impact assessments where required.

6.4 Relationship to Terms and Privacy. If the DPA conflicts with the Terms or Privacy Policy regarding processing of personal data covered by the DPA, the DPA controls for that processing scope.

6.5 Execution. To request a DPA, contact legal@illana.ai with your organization name, billing contact, and applicable regulatory framework. Enterprise customers may receive pre-signed or click-through DPA options.

6.6 HIPAA and regulated data. Illana does not by default offer HIPAA business associate services. Customers with regulated data obligations must assess suitability and request supplemental agreements if available.

7

Security and Trust Center

Full document: security

7.1 Trust commitment. Illana is designed to protect customer data through encryption, access control, logical isolation, and operational security practices. Our Security and Trust Center provides an overview for customers and security reviewers.

7.2 Key controls.

  • Encryption: TLS in transit; AES-256-GCM at rest for sensitive vault content and connection credentials;
  • Isolation: per-account and per-workspace logical separation; no cross-customer retrieval in query paths;
  • Access control: authentication, role-based workspace permissions, OAuth-scoped Connections, API key management;
  • Data ownership: customers retain ownership of Customer Data; disconnect purges synced content from active storage;
  • Monitoring: security logging, abuse detection, and incident response procedures.

7.3 Shared responsibility. Customers are responsible for credential hygiene, MFA, workspace configuration, and choosing appropriate Connection scopes. Security is a partnership.

7.4 Full materials. Visit the Security and Trust Center and security white paper: illana.ai/security.

7.5 Enterprise security. Enterprise customers may request security questionnaires, penetration test summaries, or custom security exhibits under NDA through legal@illana.ai or security@illana.ai.

8

Subprocessors List

8.1 What subprocessors are. Subprocessors are third parties engaged by Illana to process personal information on our behalf in connection with the Services—for example, cloud infrastructure, monitoring, email delivery, payment processing, and AI model API providers.

8.2 Categories of subprocessors. Illana may use subprocessors in the following categories:

  1. Cloud infrastructure and hosting — compute, storage, networking, and database services;
  2. Security and observability — logging, monitoring, intrusion detection, and incident tooling;
  3. Communications — transactional email and notification delivery;
  4. Payments — subscription billing and payment tokenization;
  5. Support and CRM — customer support ticketing where personal data is processed;
  6. AI model providers — large language model APIs used to generate AI Output from retrieved snippets (configured with use limitations; vault content is not used to train Illana foundation models); and
  7. Identity and analytics — where used for authentication flows or aggregated product analytics on public surfaces.

8.3 Contractual protections. All subprocessors are bound by written agreements requiring confidentiality, security measures appropriate to the processing, and use limitations consistent with our DPA and Privacy Policy.

8.4 Changes. We may add or replace subprocessors as the Services evolve. Enterprise customers with DPAs may receive advance notice and objection rights for new subprocessors as specified in their agreement.

8.5 Detailed list. A current subprocessor list with entity names, processing purposes, and locations is available to enterprise customers upon request at legal@illana.ai. We do not publish a public exhaustive list in this hub to reduce operational security exposure; enterprise procurement may obtain the authoritative list under DPA.

9

AI Usage Policy

9.1 Purpose. This AI Usage Policy governs how you may use Illana's artificial intelligence features, including query interpretation, search planning, ranking, entity resolution, optional embeddings, and synthesis of AI Output from retrieved Customer Data.

9.2 Permitted use. Use AI features for internal research, summarization, drafting assistance, and decision support where human review is applied before material actions. AI Output should be verified against cited sources in Search Results.

9.3 Prohibited use. You may not:

  1. rely on AI Output as sole basis for legal, medical, financial, or employment decisions about individuals;
  2. present AI Output as human-authored professional advice without disclosure and review;
  3. use the Services to generate unlawful, deceptive, harassing, or discriminatory content;
  4. attempt to extract training data or probe model weights through the Services;
  5. automate high-risk actions based on AI Output without explicit authorization and safeguards; or
  6. misrepresent Illana AI Output as guaranteed accurate or complete.

9.4 Data use. Illana does not use Customer Data in your vault to train foundation models offered as general-purpose AI products. Queries and retrieved snippets may be sent to third-party model APIs to generate responses for your Account. See AI Transparency Statement and Privacy Policy Sections 27–29.

9.5 Visibility in channels. Queries and AI Output sent through Slack or Teams may be visible to channel members. Do not submit confidential information to channels with unauthorized audiences.

9.6 Enforcement. Violations may result in throttling, feature restriction, or Account suspension under the Terms and AUP.

10

AI Transparency Statement

10.1 Our approach. Illana uses AI to help you find and synthesize information already authorized in your vault. We believe users should understand when AI is involved, what data is used, and what limitations apply.

10.2 When AI is used. AI may be invoked when you submit natural-language Queries, enable synthesis features, or use Access Channels that return AI-assisted replies. Search-only retrieval may use AI for query planning even when final output is primarily structured Search Results.

10.3 Inputs. AI features may process your Query text, workspace context, and retrieved snippets from Customer Data scoped to your permissions. We do not send your entire vault to model providers for routine requests.

10.4 Outputs. AI Output is probabilistic. It may be incomplete, outdated, or incorrect—including hallucinations. Where feasible, responses include citations to underlying Memory Items. Always verify before acting.

10.5 Third-party models. We may use third-party large language model providers under contractual use restrictions. Provider identities and configuration options may be disclosed to enterprise customers under NDA or DPA.

10.6 No training on vault data. Customer Data synced into your vault is not used to train Illana foundation models for general-purpose AI products.

10.7 Human review. Illana personnel may review sampled interactions for quality and safety under restricted access policies (Section 11 and Privacy Policy Section 30).

11

Responsible AI Principles

11.1 Commitment. Illana adopts the following principles for AI features in the Services:

  1. Customer control: you choose Connections, scopes, and who may query Shared Vault Data;
  2. Retrieval grounding: AI Output is designed to reflect retrieved Customer Data, with citations where feasible;
  3. Privacy by design: no sale of personal information; no vault training for foundation models; logical customer isolation;
  4. Transparency: disclose AI involvement and limitations in product documentation and legal materials;
  5. Human accountability: users must review AI Output before high-impact decisions; Illana does not make binding automated legal decisions about individuals;
  6. Safety and abuse prevention: monitor for misuse, enforce rate limits, and respond to harmful outputs reported through support or security channels; and
  7. Continuous improvement: iterate on retrieval quality, safety filters, and documentation based on feedback and incident learnings.

11.2 Limitations. Principles guide design but do not guarantee error-free AI. You remain responsible for how you use outputs in your environment.

11.3 Feedback. Report harmful or biased outputs to security@illana.ai or support. We investigate good-faith reports but cannot customize models for every use case.

12

Intellectual Property Policy

12.1 Illana IP. Illana owns all right, title, and interest in the Services, software, documentation, trademarks, logos, search and indexing technology, algorithms, UI, and aggregated de-identified analytics, excluding Customer Data and third-party materials.

12.2 Customer Data. You retain ownership of Customer Data. Illana receives only the limited license necessary to operate the Services as described in the Terms.

12.3 AI Output. Subject to Illana IP, third-party model terms, and applicable law, you may use AI Output generated for you for internal business purposes. AI Output may not be unique.

12.4 Feedback. If you provide suggestions or feedback about the Services, Illana may use them without restriction or compensation, separate from Customer Data.

12.5 Restrictions. You may not copy, modify, reverse engineer, decompile, or create derivative works of the Services except as permitted by law or express written authorization. You may not remove proprietary notices.

12.6 Third-party content. Customer Data may include third-party copyrighted material. You are responsible for ensuring your sync and use complies with applicable IP laws and provider terms.

12.7 Infringement claims. See Copyright and Trademark Information (Section 13) for notice procedures.

13

Copyright and Trademark Information

13.1 Illana trademarks. “Illana,” the Illana logo, and related marks are trademarks of Illana. You may not use our marks without prior written permission except as necessary to describe your lawful use of the Services (nominative fair use).

13.2 Copyright. The Services, website content, documentation, and marketing materials are protected by copyright. Unauthorized reproduction or distribution is prohibited.

13.3 DMCA and copyright complaints. If you believe content stored in Illana infringes your copyright, send a notice to legal@illana.ai including:

  1. identification of the copyrighted work claimed to be infringed;
  2. identification of the material claimed to be infringing and information reasonably sufficient to locate it;
  3. your contact information;
  4. a statement of good-faith belief that use is not authorized;
  5. a statement, under penalty of perjury, that the information is accurate and you are authorized to act; and
  6. your physical or electronic signature.

13.4 Counter-notice. If your content was removed in error, you may submit a counter-notice as permitted under applicable law. We may restore content unless the complainant seeks court action.

13.5 Repeat infringers. We may terminate Accounts of repeat infringers where appropriate.

13.6 Customer responsibility. Illana processes Customer Data at customer direction. Organizations are responsible for responding to infringement claims relating to content they synced.

14

Open Source Software Notices

14.1 Open source components. The Services may include third-party open source software components governed by their respective licenses (for example, MIT, Apache 2.0, BSD, and others).

14.2 Notices. Required license notices and attributions for open source components are maintained in our product repositories and may be provided upon request to legal@illana.ai or bundled in enterprise security documentation packages.

14.3 Source availability. Where a license requires offer of source code for copyleft components, Illana will comply with those requirements for the applicable component.

14.4 No warranty. Open source components are provided by their authors under their licenses. Illana disclaims warranties to the extent permitted by law for third-party components except as stated in the Terms.

14.5 Contributions. If you contribute code or feedback under an open source or contribution agreement, separate terms may apply. General product feedback is handled under the Terms IP provisions.

15

API Terms of Use

15.1 Scope. These API Terms of Use supplement the Terms for programmatic access to Illana search and related endpoints via API keys and MCP. By creating or using an API key, you agree to these terms.

15.2 Authentication. API access requires a valid API key associated with your Account. Keys must be kept confidential, rotated when compromised, and labeled for operational clarity. Illana may revoke keys for security or policy violations.

15.3 Default rate limits. Unless your order form or Enterprise Agreement specifies otherwise:

  • Per API key: sixty (60) requests per minute and one thousand (1,000) requests per day;
  • IP backstop: one hundred twenty (120) requests per minute per IP address across API traffic.

Exceeding limits may result in HTTP 429 responses, throttling, or temporary suspension.

15.4 Permitted use. Use the API to integrate Illana search and retrieval into applications you authorize, subject to the AUP and your permissions on Customer Data.

15.5 Prohibited use. You may not use the API to scrape Illana infrastructure, replicate the Services, bypass Access Channel controls, overload systems, or resell API access except under an Enterprise Agreement.

15.6 MCP. MCP tools expose search capabilities to Assistant Clients under the same authentication, rate, and permission constraints. Tool schemas may change with documentation notice.

15.7 Technical limits. Responses may be subject to row limits, token limits, timeouts, and retrieval quality constraints described in documentation. Illana does not warrant API suitability for every integration pattern.

15.8 Monitoring. Illana monitors API usage for billing, abuse detection, capacity planning, and security.

16

Developer Terms

16.1 Who is a developer. “Developers” are individuals or entities that build applications, automations, or integrations that interact with Illana through APIs, MCP, OAuth, or Access Connectors on behalf of an Account or Organization.

16.2 Relationship to Terms. Developer activity is governed by the Terms, API Terms of Use, Acceptable Use Policy, and this section. If you build for a customer Organization, that Organization is responsible for your compliance and for authorizing your access.

16.3 Authorization. You may access Customer Data only with valid credentials issued by the Account owner and only within the scope of permissions granted. Do not embed API keys in public repositories or client-side code exposed to end users.

16.4 Assistant Clients and MCP. When configuring MCP or other Assistant Clients, apply least-privilege access. You are responsible for how your client handles Queries, errors, and AI Output displayed to users.

16.5 OAuth and linking flows. Slack, Teams, and OAuth authorization flows must be completed by authorized users. Do not circumvent user consent or store refresh tokens insecurely.

16.6 Prohibited developer conduct. Developers may not build tools to exfiltrate vault data beyond authorized scope, automate abusive query loads, misrepresent Illana as an official provider integration without permission, or sublicense API access without an Enterprise Agreement.

16.7 Documentation. Follow current API and MCP documentation. Illana may deprecate endpoints with reasonable notice in documentation.

16.8 Support. Developer support is available through standard support channels unless a separate developer or enterprise support tier applies.

17

Enterprise Agreement Terms

17.1 When an Enterprise Agreement applies. Organizations purchasing enterprise plans, custom deployments, or regulated-industry packages may execute an Enterprise Agreement, order form, or statement of work with Illana that supplements or modifies standard Terms.

17.2 Typical enterprise topics. Enterprise Agreements may address:

  • subscription fees, seat counts, and payment terms;
  • DPA, SCCs, and data residency or subprocessor requirements;
  • custom SLAs, support tiers, and designated contacts;
  • security exhibits, questionnaires, and audit rights;
  • beta feature participation and pilot terms;
  • professional services, onboarding, and training; and
  • confidentiality, marketing references, and termination assistance.

17.3 Order of precedence. If an Enterprise Agreement conflicts with these Terms or this Legal Hub for the Organization named in the agreement, the Enterprise Agreement controls to the extent of the conflict.

17.4 Procurement. Contact legal@illana.ai or your Illana account representative to request an Enterprise Agreement, security pack, or DPA.

17.5 No enterprise terms by default. Self-serve and standard paid plans are governed by the public Terms unless a separate signed agreement exists.

18

Service Level Agreement (SLA)

18.1 Default position. Unless you have a signed Enterprise Agreement or order form that includes a Service Level Agreement (SLA), Illana does not guarantee specific uptime, latency, or support response times for the Services.

18.2 Commercially reasonable efforts. We use commercially reasonable efforts to maintain availability of core search, sync, and authentication functions and to communicate about planned maintenance through email or status channels where feasible.

18.3 Exclusions. SLA credits, if any, under an Enterprise Agreement typically exclude downtime caused by:

  • scheduled maintenance with reasonable notice;
  • Connected Service or third-party provider outages outside Illana control;
  • customer misconfiguration, expired tokens, or quota exhaustion;
  • force majeure events; or
  • suspension for security, abuse, or Terms violations.

18.4 Beta and trial. Beta features and free trials are excluded from any SLA unless expressly stated otherwise.

18.5 Enterprise SLA. Enterprise customers may negotiate uptime commitments, service credits, and support response targets in their agreement. Request details through legal@illana.ai.

19

Support Policy

19.1 Support channels. Support is available through in-app help, email to our support address associated with your Account, and documentation at illana.ai. Enterprise customers may have designated support contacts and portals under their agreement.

19.2 Scope. Support covers Illana product functionality, account access, billing questions, integration setup guidance, and good-faith bug reports. Support does not include legal advice, custom development, or troubleshooting third-party platforms (Google, Microsoft, Slack, Plaid, Intuit) except where Illana integration behavior is implicated.

19.3 Response targets. Standard plans receive commercially reasonable response times during business hours. Enterprise tiers may define priority levels and response targets in the Enterprise Agreement.

19.4 Security issues. Report vulnerabilities to security@illana.ai, not general support. See Security Reporting (Section 25).

19.5 Language. Support is provided in English unless otherwise agreed in an Enterprise Agreement.

19.6 Account verification. We may verify identity before providing account-specific support or executing data requests.

20

Beta Features Policy

20.1 Definition. Beta features are pre-release, experimental, or evaluation functionality labeled alpha, beta, preview, experimental, pilot, early access, or similar.

20.2 As-is provision. Beta features are provided “as is” without warranties, SLA commitments, or guarantees of availability, accuracy, or continued existence. They may change or be discontinued without notice.

20.3 Data and AI. Beta AI or sync capabilities may have additional limitations on retrieval quality, logging, or data handling disclosed in product labels or pilot terms.

20.4 Feedback. We may request feedback on beta features. Feedback may be used to improve the Services without compensation unless separate beta program terms say otherwise.

20.5 Opt-in. Participation in beta programs may require explicit opt-in. Do not use beta features for production-critical workflows without contingency plans.

20.6 Separate terms. Some pilots may be governed by additional written beta or pilot agreements that supplement this policy.

21

Export Compliance

21.1 U.S. export controls. The Services and related technology may be subject to U.S. export control laws, including the Export Administration Regulations (EAR) and sanctions programs administered by OFAC.

21.2 User obligations. You represent that you are not located in, organized in, or ordinarily resident in a comprehensively sanctioned country or region, and that you are not a prohibited or restricted party on applicable government lists. You may not use the Services in violation of export or sanctions laws.

21.3 Customer Data. You are responsible for ensuring Customer Data synced through Illana—including technical data, financial information, and personal data of export-controlled persons—is handled in compliance with applicable export and sanctions rules.

21.4 Illana compliance. Illana complies with applicable export and sanctions laws in providing the Services and may restrict access from certain jurisdictions or to certain parties at its discretion.

21.5 No military or prohibited end uses. You may not use the Services for prohibited end uses under applicable export regulations without required authorizations.

21.6 Questions. Export compliance inquiries: legal@illana.ai.

22

International Data Transfer Information

22.1 Global processing. Illana is based in the United States. Personal information may be processed in the U.S. and in other countries where Illana or its subprocessors operate.

22.2 Transfer mechanisms. For transfers from the EEA, UK, and Switzerland, Illana relies on Standard Contractual Clauses incorporated in our DPA, supplementary measures where assessed as necessary, and customer instructions. See also Privacy Policy Section 48.

22.3 Data residency. Specific data residency or regional hosting may be available under Enterprise Agreement. Unless agreed in writing, Illana does not guarantee storage in a particular country.

22.4 Government access. Illana may be compelled to disclose information under U.S. or other lawful process. See Law Enforcement Request Policy (Section 26) and Government Requests Transparency (Section 27).

22.5 Documentation. Request transfer documentation or DPA copies at legal@illana.ai or privacy@illana.ai.

23

Accessibility Statement

23.1 Commitment. Illana is committed to making the Services reasonably accessible to users with disabilities and to improving accessibility over time.

23.2 Standards. We aim to conform with widely recognized accessibility standards, such as WCAG 2.1 Level AA, for core web application flows where feasible. Third-party integrations and Connected Service UIs remain subject to provider accessibility.

23.3 Ongoing efforts. Accessibility improvements include semantic markup, keyboard navigation, color contrast, focus indicators, and screen reader compatibility in prioritized user journeys (authentication, dashboard, search, settings).

23.4 Limitations. Some complex visualizations, third-party embeds, or beta features may not yet meet all accessibility criteria. We welcome feedback to prioritize fixes.

23.5 Feedback and accommodations. If you encounter accessibility barriers, contact legal@illana.ai with a description of the issue, the page or feature affected, and your contact information. We will work in good faith to provide information in an alternative format or address the barrier where practicable.

24

Vulnerability Disclosure Policy

Full document: security

24.1 Purpose. Illana welcomes good-faith security research that helps protect our customers. This policy describes how to report vulnerabilities and what you can expect from us.

24.2 Authorized reporting. Report suspected vulnerabilities to security@illana.ai with sufficient detail to reproduce the issue. Encrypt sensitive details if requested by our security team.

24.3 Safe harbor. If you comply with this policy—make good-faith efforts to avoid privacy violations, data destruction, service degradation, and social engineering—we will not pursue legal action against you for authorized research activities.

24.4 Out of scope. The following are generally out of scope unless they demonstrate clear, exploitable impact on Illana customer data or authentication: physical attacks, social engineering of Illana staff or customers, denial-of-service tests, spam, issues in third-party services outside Illana control, and findings in customer-configured integrations without Illana vulnerability.

24.5 Prohibited testing. Do not access, modify, or delete customer data you do not own. Do not automate scanning at high volume against production without prior written approval.

24.6 Our response. We acknowledge reports within a reasonable time, investigate in good faith, and remediate validated issues according to severity. We may recognize researchers at our discretion but do not guarantee bug bounties unless a separate program is announced.

24.7 Additional materials. See also Security and Trust Center.

25

Security Reporting

Full document: security

25.1 What to report. Report suspected security incidents, unauthorized access, credential compromise, data leaks involving Illana systems, and vulnerabilities as described in the Vulnerability Disclosure Policy.

25.2 Contact. Email security@illana.ai with subject line “Security Report — [brief description].” Include timestamps, affected Accounts (if known), and steps to reproduce.

25.3 Customer account compromise. If you believe your Account credentials or API keys are compromised, rotate or revoke keys immediately, disconnect suspicious Connections, and notify security@illana.ai. Illana may suspend Accounts to contain harm.

25.4 Incident notification. If we confirm a security incident affecting personal information we control, we will notify affected customers and, where required, individuals and regulators in accordance with law and our contracts.

25.5 No emergency service. security@illana.ai is not a 24/7 emergency hotline unless your Enterprise Agreement specifies otherwise. For imminent harm, include “URGENT” in the subject and we will prioritize where feasible.

25.6 Trust center. illana.ai/security

26

Law Enforcement Request Policy

26.1 General principle. Illana respects valid legal process and protects customer data from improper disclosure. We review law enforcement and government requests carefully and respond only as required by applicable law.

26.2 Required process. Except in emergencies involving imminent harm, Illana requires appropriate legal process—such as a subpoena, court order, or warrant—for disclosure of customer content and non-public account information, consistent with U.S. law and applicable international frameworks.

26.3 Customer notice. Where legally permitted, we notify affected customers before disclosing information so they may seek protective measures. We may delay notice when prohibited by law or necessary to prevent harm.

26.4 Narrow disclosure. We disclose only information reasonably responsive to valid legal process and object to overbroad or vague requests.

26.5 Emergency requests. We may disclose information without delay when we believe in good faith that an emergency involving danger of death or serious physical injury requires disclosure, as permitted by law.

26.6 Submission. Law enforcement should submit requests to legal@illana.ai with “Law Enforcement Request” in the subject, agency details, badge or authorization information, and the specific data sought. Illana does not list a public street address in this policy; registered agent information may be provided upon request.

26.7 Customer data ownership. Organizations control most vault content. We encourage authorities to direct requests to customers where appropriate; we will assist customers as required by law and contract.

27

Government Requests Transparency

27.1 Transparency commitment. Illana believes customers should understand how often governments request user data and how we respond.

27.2 Reporting. We intend to publish periodic transparency reports summarizing the number and types of government and law enforcement requests received, the number of accounts affected where permissible, and the percentage of requests where we disclosed data, produced no data, or challenged the request.

27.3 Gag orders. Some requests may be accompanied by non-disclosure orders. We will include legally permitted information in transparency reports and notify customers when gag orders expire or when notice is allowed.

27.4 National security. Where prohibited from disclosing specific national security requests, we may report using permitted aggregate bands or delayed reporting as allowed by law.

27.5 Availability. When published, transparency reports will be linked from this Legal Hub and our Security page. Until the first report is published, direct inquiries to legal@illana.ai.

28

Data Request Process

28.1 Types of requests. This section describes how to submit privacy, data access, correction, deletion, and portability requests relating to information Illana controls. For vault content controlled by an employer or Organization, contact that organization first; Illana processes such data on their instructions.

28.2 How to submit. Email privacy@illana.ai with:

  1. your full name and Account email;
  2. the type of request (access, correction, deletion, portability, objection, restriction);
  3. sufficient detail to locate the information; and
  4. proof of identity as we may reasonably require to prevent unauthorized disclosure.

28.3 Authorized agents. Agents may submit requests on your behalf with signed authorization where permitted by law.

28.4 Response timelines. We respond within timeframes required by applicable law (for example, 30–45 days under many U.S. state laws, with permitted extensions). Complex requests may require additional time; we will notify you.

28.5 Limitations. We may deny requests where an exception applies (legal retention, ongoing disputes, third-party rights, or requests directed to the wrong controller). We explain denials where required.

28.6 Appeals. Where state law provides appeal rights, reply to our decision with “Appeal” in the subject line.

28.7 Full rights detail. See Privacy Policy Sections 39 and 49–52 for regional rights descriptions.

29

Account Closure and Data Removal

29.1 Closing your Account. You may request Account closure through in-product settings or by contacting privacy@illana.ai or support. Organization Administrators may terminate workspace membership for individual users without closing the entire Organization.

29.2 Before closure. Export Customer Data you wish to retain using available export features. Revoke API keys, disconnect Connections, and unlink Slack or Teams Access Connectors.

29.3 What Illana deletes. Upon Account deletion, Illana deletes or anonymizes personal information we control in active systems, including synced vault content, connection tokens, and profile data, except information we must retain by law or in encrypted backups for a limited period as described in the Privacy Policy.

29.4 What Illana does not delete. Deletion in Illana does not delete data in Gmail, Outlook, Google Drive, OneDrive, QuickBooks, Plaid-linked institutions, Slack, Teams, or other Connected Services. Remove data at the source separately if needed.

29.5 Billing records. Transaction and invoice records may be retained for tax, accounting, and legal compliance after Account closure.

29.6 Enterprise termination. Enterprise Agreements may specify data return, deletion certificates, and transition assistance upon termination.

29.7 Irreversibility. Account deletion may be irreversible after backup purge periods. Confirm before proceeding.

30

Contact Legal

30.1 General legal inquiries.

Email: legal@illana.ai
Subject: “Legal Inquiry — [topic]”

30.2 Privacy and data rights.

Email: privacy@illana.ai
See Data Request Process (Section 28) and Privacy Policy.

30.3 Security and vulnerabilities.

Email: security@illana.ai
See Vulnerability Disclosure Policy (Section 24) and Security Reporting (Section 25).

30.4 Law enforcement. Submit law enforcement requests to legal@illana.ai with “Law Enforcement Request” in the subject (Section 26).

30.5 Enterprise and DPA. Procurement, DPA, SLA, and Enterprise Agreement requests: legal@illana.ai with your organization name and primary contact.

30.6 Formal service of process. Illana is organized under Delaware law. Registered agent information for service of process may be provided upon request through legal@illana.ai. We do not list a public street address in these materials.

30.7 Related documents. Terms & Conditions · Privacy Policy · Security

Privacy: privacy@illana.ai. Security: security@illana.ai.