Legal

Privacy Policy

Last updated July 8, 2026

This Privacy Policy describes how Illana collects, uses, and protects information when you use our services. For terms of use, see our Terms & Conditions. Privacy questions: privacy@illana.ai.

1

Introduction

This Privacy Policy (this Policy) describes how Illana (Illana, we, us, or our) collects, uses, discloses, retains, and protects information in connection with our websites, web application, application programming interfaces (APIs), Model Context Protocol (MCP) server, Slack and Microsoft Teams connectors, administrative consoles, documentation, support channels, and related services (collectively, the Services).

Please read this Policy carefully. It explains what information we process, why we process it, who we share it with, and what choices and rights may be available to you. This Policy applies alongside our Terms & Conditions, which govern your use of the Services. If you do not agree with this Policy, you must not use the Services.

1.1 What Illana does. Illana is a memory and retrieval platform. When you connect third-party accounts and data sources—such as email, calendar, documents, messaging platforms, and financial or accounting systems—we sync selected content into a searchable vault and enable you to query that content through natural-language search, AI-assisted responses, APIs, and integrated access channels. We process information to provide, secure, and improve those capabilities.

1.2 Who this Policy is for. This Policy applies to individuals who register for or use the Services, administrators who manage Organization workspaces, authorized users invited to a workspace, individuals who contact us for support or sales, visitors to our websites, and—where their personal information appears in data synced by our customers—individuals whose information is contained in customer-controlled content.

1.3 Controller and processor roles. Illana may act as a controller of personal information relating to account holders, website visitors, and our own business operations. For personal information contained in vault content synced from Connected Services at a customer's direction, the customer is typically the controller and Illana acts as a processor (or service provider) processing data on the customer's behalf. Section 3 and Section 34 describe these roles in more detail.

1.4 No sale of personal information. Illana does not sell personal information. We do not use customer vault content to train foundation models that Illana offers as general-purpose AI products. See Sections 29 and 32.

1.5 Effective date. This Policy is effective as of the “Last updated” date shown at the top of this page. Material changes are described in Section 56.

2

Scope of This Privacy Policy

2.1 Services covered. This Policy applies to personal information processed through:

  • the Illana web application and authenticated product experiences;
  • our public websites, marketing pages, documentation, and status pages;
  • APIs, MCP endpoints, and programmatic access you authorize;
  • Slack and Microsoft Teams Access Connectors that send queries to Illana;
  • account registration, billing, support, and sales interactions; and
  • security, abuse prevention, and operational systems that support the Services.

2.2 What is not covered. This Policy does not apply to:

  1. third-party websites, applications, or services you access through links or integrations (including Google, Microsoft, Slack, Plaid, Intuit QuickBooks, and AI model providers), which have their own privacy policies;
  2. personal information processed entirely offline or outside the Services unless we explicitly state otherwise;
  3. employment applications or recruiting processes not conducted through the Services, if any; or
  4. customer systems or databases that remain under customer control and are not synced into Illana.

2.3 Enterprise agreements. If your Organization has executed a data processing addendum (DPA), enterprise agreement, or other written privacy terms with Illana, those documents govern to the extent they conflict with this Policy for the processing they cover. Otherwise, this Policy applies.

2.4 Customer responsibilities. Organizations that sync employee, customer, or other third-party personal information into Illana are responsible for providing required notices and obtaining required consents before doing so. Section 39 describes customer data rights in that context.

3

Who We Are

3.1 Data controller contact. For questions about this Policy, to exercise privacy rights where Illana is the controller, or to contact our privacy team, email privacy@illana.ai.

3.2 Legal entity. The Services are operated by Illana, a company organized under the laws of the State of Delaware, United States. We do not list a public street address in this Policy; registered agent information for formal service of process may be provided upon request through legal@illana.ai.

3.3 EU/UK representative. If and when Illana appoints an EU or UK representative under applicable law, we will publish their contact details on this page or in an enterprise DPA. Until then, direct inquiries to privacy@illana.ai.

3.4 Security contact. To report security vulnerabilities or suspected incidents affecting the Services, contact security@illana.ai. See also our Security page.

3.5 Processor inquiries. If you are an individual seeking to exercise rights regarding personal information in vault content synced by your employer or another organization, contact that organization first. Illana processes such data on the organization's instructions and will assist the organization as required by contract and law (Sections 39 and 50).

4

Definitions

Capitalized terms used in this Policy have the meanings below or as defined in our Terms & Conditions.

Account means the registered user profile and associated credentials, settings, and entitlements used to access the Services.

Administrator means a user designated to manage an Organization workspace, including members, integrations, shared connections, billing, and security settings.

AI Output means content generated by artificial intelligence features based on queries and retrieved vault content, including summaries, answers, and structured extractions.

Connected Service means a third-party platform you authorize Illana to connect to—such as Google Workspace, Microsoft 365, Plaid, or QuickBooks Online—for sync and retrieval.

Connection means an authorized link between your Account or workspace and a Connected Service, including stored OAuth tokens and sync configuration.

Customer Data means content and metadata synced from Connected Services into your vault, plus queries, labels, configuration, and other information you submit through the Services, excluding Illana's own operational and account data.

Memory Item means an indexed unit of Customer Data stored in the vault (for example, an email message, calendar event, document excerpt, or financial record snapshot).

Organization means a company, team, or other entity that uses a shared workspace with multiple authorized users.

Personal Data or Personal Information means information that identifies, relates to, describes, or could reasonably be linked with an individual, directly or indirectly, as defined under applicable privacy laws.

Process or Processing means any operation performed on information, including collection, storage, use, disclosure, analysis, retrieval, indexing, encryption, deletion, or transformation.

Query means a search question, prompt, or request submitted through the web app, API, MCP, Slack, Teams, or another access channel.

Shared Vault Data means Customer Data ingested through a Connection marked as shared (is_shared) and made available to permitted workspace members under administrator configuration.

Subprocessor means a third party engaged by Illana to Process personal information on Illana's behalf in connection with the Services.

Vault means Illana's searchable memory store for Customer Data associated with your Account or workspace.

5

Information We Collect

We collect information from several sources depending on how you use the Services. The categories below are described in greater detail in Sections 6–17.

5.1 Summary categories. We may collect:

  1. information you provide directly (Section 6);
  2. account and profile information (Section 7);
  3. organization and business information (Section 8);
  4. information from Connected Services you authorize (Sections 9–14);
  5. usage data and product analytics (Section 15);
  6. device and technical information (Section 16);
  7. log data and security information (Section 17); and
  8. information collected through cookies and similar technologies (Section 18).

5.2 Required vs. optional. Some information is necessary to create an Account, authenticate you, connect integrations, or provide core functionality. Other information—such as certain analytics cookies or optional background processing features—is collected or enabled only where permitted by law and, where applicable, your choices.

5.3 Sensitive information. Customer Data may include sensitive categories of personal information depending on what you sync (for example, financial account details through Plaid, health-related content in email or documents, or employment records). You control what is synced. We Process sensitive information only as needed to provide the Services, secure them, and comply with law. We do not use vault content to infer sensitive characteristics for advertising.

5.4 Information about others. When you sync email, calendar, documents, or other sources, Customer Data may contain personal information about colleagues, clients, vendors, and other third parties. You and your Organization are responsible for ensuring appropriate legal bases and notices for syncing and querying that information.

6

Information You Provide Directly

6.1 Registration and forms. We collect information you submit when creating an Account, joining a workspace, requesting a demo, contacting support, subscribing to communications, or completing in-product forms. This may include your name, email address, job title, company name, phone number, billing address, and messages you send us.

6.2 Queries and prompts. When you submit a Query, we collect the text of the Query and related context (such as selected filters, time ranges, or workspace scope) necessary to execute search and synthesis.

6.3 Configuration and labels. You may provide vault configuration, connection settings, API key labels, user-defined tags, feedback on search results, and feature preferences.

6.4 Support and communications. If you email support, participate in surveys, or interact with sales, we retain the content of those communications and associated metadata to respond and improve the Services.

6.5 Voluntary information. Any additional information you choose to provide—such as attachments to support tickets or details in enterprise procurement questionnaires—is Processed as described in this Policy.

7

Account and Profile Information

7.1 Identity and authentication. We collect identifiers used to authenticate you, which may include email address, password hash, identity-provider subject IDs (when you sign in with Google, Microsoft, or similar), multi-factor authentication status, and session tokens.

7.2 Profile details. Profile information may include display name, avatar, timezone, language preference, and notification settings.

7.3 API and programmatic access. If you create API keys or authorize MCP clients, we store key identifiers, hashed secrets, labels, creation and last-used timestamps, and rate-limit counters associated with your Account.

7.4 Access channel linking. When you link Slack or Microsoft Teams, we store workspace and user identifiers necessary to map incoming messages to your Account and enforce authorization. We do not ingest historical Slack or Teams archives into the Vault through standard Access Connectors.

7.5 Subscription and billing. Paid accounts may include subscription tier, payment method tokens processed by our payment provider, invoices, tax identifiers you provide, and transaction history. We do not store full payment card numbers on Illana systems when a payment processor tokenizes them.

8

Organization and Business Information

8.1 Workspace metadata. For Organization accounts, we collect workspace name, domain verification records, member roster, role assignments (including Administrator status), invitation history, and workspace-level settings.

8.2 Administrator actions. We log administrative events such as member invitations, role changes, connection creation or revocation, shared vault configuration, API key management, and security policy updates for audit and support purposes.

8.3 Business contact information. Organizations may provide billing contacts, technical contacts, legal contacts, and authorized signatories for enterprise agreements.

8.4 Enterprise configuration. Enterprise deployments may include SSO configuration metadata, IP allowlists, data retention preferences, and subprocessor or data residency requirements documented in an enterprise agreement or DPA.

8.5 Shared connections. When an Administrator connects organization-owned sources and marks a Connection as shared, metadata about that Connection (provider, scope, sync status, sharing flag) is visible to permitted administrators and may affect which members can query Shared Vault Data.

9

Information From Connected Services

9.1 Authorization required. We access Connected Services only after you or an Administrator completes an OAuth or equivalent authorization flow and selects scopes. We do not access third-party accounts without your permission.

9.2 Supported integrations. Standard Connections may include:

  • Google: Gmail, Google Calendar, Google Docs/Drive;
  • Microsoft: Outlook, Microsoft Calendar, OneDrive;
  • Plaid: financial account data you link through Plaid's consent flow; and
  • QuickBooks Online: read-only accounting data for the company you connect.

9.3 Credentials and tokens. We store OAuth refresh tokens and related secrets in encrypted form to maintain sync. Token metadata (expiration, scopes, provider account identifiers) is used for connection health and troubleshooting.

9.4 Sync behavior. After authorization, Illana periodically retrieves new and updated content according to provider capabilities and your configuration. Sync may lag due to provider rate limits, outages, or indexing queues. Disconnecting a Connection stops future sync and triggers deletion of associated vault content as described in Section 46.

9.5 Read-oriented access. Standard Connections are designed for read and retrieval. Illana does not send email, modify QuickBooks records, or initiate financial transactions through default connectors.

9.6 Third-party policies. Connected Services have their own terms and privacy practices. Your use of those services remains governed by the provider. Illana is not responsible for provider-side logging, retention, or access outside the scopes you authorize.

10

Email Data Collection and Processing

10.1 What we sync. When you connect Gmail or Outlook, Illana may sync message metadata and body content from mailboxes you authorize, including senders, recipients, subject lines, timestamps, thread identifiers, labels or folders, attachment metadata, and message text. Attachment contents may be synced where supported and configured.

10.2 How we use email data. Email data is indexed for full-text and structured search, entity linking, optional embeddings, and AI-assisted synthesis in response to Queries. We do not use your synced email to send marketing on behalf of third parties or to train general-purpose foundation models (Section 29).

10.3 Third parties in email. Email often contains personal information about individuals who are not Illana users. You are responsible for lawful sync and query of that information under your policies and applicable law.

10.4 Shared mailboxes. Organization Administrators may connect shared or delegated mailboxes. Access to resulting Shared Vault Data is governed by workspace permissions you configure.

10.5 Deletion scope. Removing email from your vault or disconnecting email Connections deletes Illana's copy but does not delete messages in Gmail, Outlook, or other provider systems.

11

Calendar Data Collection and Processing

11.1 What we sync. When you connect Google Calendar or Microsoft Calendar, Illana may sync event titles, descriptions, locations, start and end times, recurrence rules, organizer and attendee information, conferencing links, reminders, and calendar metadata for calendars you authorize.

11.2 How we use calendar data. Calendar data supports time-based search, scheduling context in AI Output, conflict detection in queries, and cross-linking with email and documents (for example, associating meetings with related threads).

11.3 Attendee privacy. Events may include names and email addresses of attendees who did not use Illana. Process attendee information only where you have a lawful basis and provide appropriate notice.

11.4 Availability and free/busy. Depending on provider scopes, we may Process availability signals necessary for retrieval features. We do not book meetings or modify calendar events through standard Connections.

12

Messaging and Collaboration Data Collection and Processing

12.1 Access Connectors. Slack and Microsoft Teams integrations primarily function as Access Connectors: they allow authorized users to submit Queries and receive AI-assisted replies within those platforms. Standard connectors do not ingest your historical Slack or Teams message archives into the Vault.

12.2 Query content in channels. When you interact with Illana in Slack or Teams, we Process the text of commands and queries, workspace and channel identifiers, user IDs mapped to your Account, and AI Output returned to the channel. That content may be visible to other channel members according to platform permissions.

12.3 Platform logging. Slack, Microsoft, and other hosts may retain messages, audit logs, and exports under their policies independently of Illana. Configure retention and access on those platforms appropriately.

12.4 Future messaging sync. If Illana introduces optional ingestion of messaging history, we will describe the feature, scopes, and privacy impact in product documentation and update this Policy before or at launch.

13

Document and File Data Collection and Processing

13.1 What we sync. When you connect Google Docs/Drive or OneDrive, Illana may sync file names, paths, MIME types, modification times, sharing metadata, and document text or extracted content from files you authorize. Binary files may be processed to extract text where supported.

13.2 Indexing and search. Document content is indexed for keyword and semantic retrieval, optional vector embeddings, and citation in Search Results and AI Output.

13.3 Shared and external documents. Files shared with you or containing personal data about third parties may enter the Vault when synced. You are responsible for sync scope and downstream query access, especially for Shared Vault Data in Organizations.

13.4 No unauthorized exfiltration. Illana retrieves documents through provider APIs using your authorization; we do not bypass provider access controls.

14

Knowledge Base and Enterprise Data Collection

14.1 Unified vault. Customer Data from multiple Connections is stored in a unified vault scoped to your Account or workspace, enabling cross-source search and synthesis.

14.2 Optional enrichment. Depending on plan and configuration, background workers may extract entities (people, companies, topics), build relationship graphs, or compute embeddings to improve retrieval quality. These processes operate on Customer Data already synced at your direction.

14.3 Enterprise knowledge use cases. Organizations may use Illana as an internal knowledge layer over email, documents, calendar, and financial snapshots. Administrators should align Connection scope and member access with data governance policies, export controls, and regulatory obligations (Sections 34 and 48).

14.4 No public publishing. Illana does not publish your vault content to public indexes or marketplaces. Retrieval is limited to authenticated users and channels you authorize.

15

Usage Data and Product Analytics

15.1 Product usage. We collect information about how you interact with the Services, such as features used, pages viewed, query volume, connection sync status, error rates, latency metrics, and session duration.

15.2 Aggregated analytics. We may aggregate and de-identify usage data to understand adoption, diagnose performance, plan capacity, and improve product design. Aggregated data does not identify you individually.

15.3 Query metadata. We retain metadata about Queries (timestamps, success/failure, retrieval paths, token usage for AI features) for billing, rate limiting, abuse prevention, and quality monitoring. Query text may be logged for support and security; restrict highly sensitive content in Queries where possible.

15.4 No advertising profiles. Illana does not build advertising profiles from vault content or sell usage data to ad networks.

16

Device and Technical Information

16.1 Device and browser data. When you access the web application or marketing sites, we may collect browser type, operating system, device type, screen resolution, language settings, and referring URLs.

16.2 Network identifiers. We may Process IP addresses, approximate location derived from IP, and network information for security, fraud prevention, rate limiting, and regional compliance.

16.3 API clients. Programmatic access may log client user agents, API key identifiers, and request signatures necessary to authenticate and throttle requests (default limits include 60 requests per minute per API key and 1,000 requests per day unless your plan specifies otherwise).

17

Log Data and Security Information

17.1 Operational logs. We maintain server, application, and infrastructure logs that may include timestamps, request IDs, endpoints accessed, error messages, and internal diagnostic data.

17.2 Security logs. We log authentication events, permission changes, connection authorizations and revocations, admin actions, suspicious activity indicators, and incident response records.

17.3 Limited content in logs. We design logging to minimize unnecessary personal data. Query text or vault snippets may appear in logs when required for debugging or security investigations; access to such logs is restricted.

17.4 Retention. Log retention periods vary by log type and legal requirements. See Section 45.

18

Cookies and Tracking Technologies

18.1 Cookies and similar technologies. We use cookies, local storage, session tokens, and similar technologies on our websites and web application for authentication, preferences, security, and analytics.

18.2 Categories. These may include:

  1. Strictly necessary: required for login, session management, CSRF protection, and core functionality;
  2. Functional: remember preferences such as theme or locale;
  3. Analytics: understand traffic and product usage in aggregated form; and
  4. Marketing: measure campaign effectiveness on public marketing pages where enabled and permitted by law.

18.3 Your choices. Browser controls may block cookies; blocking strictly necessary cookies may impair the Services. Where required by law, we provide cookie consent mechanisms for non-essential cookies on marketing sites.

18.4 Do Not Track. Illana does not respond to Do Not Track signals in a uniform way across all browsers. Use the choices described in Section 51 for applicable jurisdictions.

19

How We Use Information

We use personal information for the purposes described in this Policy and as instructed by customers when we act as a processor. Primary purposes include:

  1. providing, operating, and maintaining the Services (Section 20);
  2. AI processing and intelligence generation (Sections 21 and 27);
  3. search, retrieval, and knowledge management (Section 22);
  4. personalization and user experience (Section 23);
  5. security, fraud prevention, and abuse detection (Section 24);
  6. communications and service notifications (Section 25); and
  7. legal and regulatory compliance (Section 26).

19.1 Legal bases (EEA/UK). Where GDPR or UK GDPR applies and Illana is controller, we rely on one or more of: performance of a contract, legitimate interests (balanced against your rights), consent where required, and legal obligation. Details appear in Section 50.

19.2 Compatibility. We use information only in ways reasonably compatible with the context in which it was collected unless we provide notice or obtain consent where required.

20

Providing and Improving Illana Services

20.1 Core service delivery. We use personal information to register Accounts, authenticate users, maintain Connections, sync and index Customer Data, execute Queries, return Search Results, deliver AI Output, and provide customer support.

20.2 Billing and account management. We Process billing contacts, subscription status, and payment-related data to charge for paid plans, send invoices, manage trials, and enforce plan limits.

20.3 Service improvement. We analyze aggregated usage, performance metrics, and feedback to fix bugs, improve retrieval quality, develop features, and prioritize roadmap work. We do not use identifiable vault content for public product marketing without your consent.

20.4 Documentation and onboarding. We may use account information to deliver onboarding emails, in-app guidance, and integration setup instructions.

21

AI Processing and Intelligence Generation

21.1 AI features. Illana uses artificial intelligence and machine learning for query interpretation, search planning, ranking, entity resolution, optional embeddings, and synthesis of AI Output from retrieved Customer Data.

21.2 Inputs and outputs. AI features may send Query text and retrieved snippets to internal systems and third-party model providers (Section 28) solely to generate responses for your Account. AI Output is returned to you through the web app, API, MCP, Slack, Teams, or other channels you use.

21.3 Accuracy limitations. AI Output may be incomplete, inaccurate, or outdated. It is informational, not professional advice. Verify material results against underlying sources. See our Terms & Conditions Sections 13–15.

21.4 No automated legal decisions. Illana does not make legally binding decisions about individuals solely through automated processing. Do not use the Services as the sole basis for decisions with legal or similarly significant effects without human review (Section 31).

22

Search, Retrieval, and Knowledge Management

22.1 Indexing. We Process Customer Data to build searchable indexes, including full-text search vectors, structured fields, optional embedding vectors, and relationship graphs linking related Memory Items.

22.2 Scoped retrieval. Search Results are scoped to Customer Data your Account and permissions allow—personal vault content, Shared Vault Data for permitted workspace members, and Connections you or Administrators authorize.

22.3 Citations. Where feasible, Search Results and AI Output include references to underlying Memory Items so you can verify sources.

22.4 Rate limits. We enforce API and access-channel rate limits to protect service stability and prevent abuse (Section 24).

23

Personalization and User Experience

23.1 Preferences. We use profile settings, timezone, language, and in-product choices to tailor the interface and default behaviors.

23.2 Contextual features. Retrieval may consider your recent Queries, connected sources, and workspace configuration to improve relevance. We do not use vault content to target third-party advertising.

23.3 Communications preferences. We honor marketing opt-out requests for Illana-sent promotional emails. Transactional and security messages may still be sent as necessary to operate the Services.

24

Security, Fraud Prevention, and Abuse Detection

24.1 Protecting the Services. We Process information to detect unauthorized access, credential stuffing, API abuse, scraping, malware, spam queries, and violations of our Terms. We may block IPs, suspend Accounts, or revoke tokens when we reasonably believe abuse is occurring.

24.2 Monitoring. Security monitoring may include analysis of authentication logs, anomalous query patterns, and administrator actions affecting shared Connections.

24.3 Incident response. If we confirm a security incident affecting personal information, we will notify affected customers and, where required, individuals and regulators in accordance with law and our contracts. Report concerns to security@illana.ai.

25

Communications and Service Notifications

25.1 Transactional messages. We send emails or in-app notices about account verification, password resets, connection failures, billing events, security alerts, policy updates, and scheduled maintenance.

25.2 Product communications. With your consent where required, we may send feature announcements, surveys, or educational content about Illana. You may opt out of promotional emails.

25.3 Support. We use contact information and message content to respond to support requests and follow up on unresolved issues.

26

Legal and Regulatory Requirements

26.1 Compliance. We may Process and retain information to comply with applicable laws, regulations, legal process, and governmental requests, including tax, accounting, export control, and sanctions obligations.

26.2 Disputes. We may preserve information relevant to litigation, arbitration, or enforcement of our Terms.

26.3 Records. Certain account and billing records are retained for statutory periods even after Account closure where required.

27

How Illana Uses Artificial Intelligence

27.1 Overview. AI is integral to Illana's search and synthesis features but operates within boundaries designed to protect customer data and individual privacy.

27.2 Retrieval-first design. AI Output is grounded in Customer Data retrieved from your vault for your Query. The system is designed to cite or reference sources rather than invent facts about your organization, though hallucinations remain possible.

27.3 Human oversight. You should apply human review before relying on AI Output for important decisions. Illana personnel may review anonymized or sampled interactions for quality assurance as described in Section 30.

27.4 Beta features. Experimental AI capabilities may have additional limitations disclosed in product documentation. Use beta features with caution.

28

AI Models and Third-Party AI Providers

28.1 Third-party LLMs. Illana may transmit Query text and retrieved snippets to third-party large language model providers to generate AI Output. These providers act as Subprocessors under contractual terms requiring confidentiality and use limitations.

28.2 Data minimization. We configure integrations to send only information reasonably necessary for the requested feature. We do not send your entire vault to model providers for routine queries.

28.3 Provider policies. Third-party model providers maintain their own privacy and security practices. Enterprise customers may request additional information about Subprocessors and configuration options under an Enterprise Agreement or DPA.

28.4 Model changes. We may change model vendors or versions to improve quality, cost, or safety. Material changes affecting data handling will be reflected in this Policy or enterprise notices where required.

29

AI Training and Model Improvement Practices

29.1 No vault training. Illana does not use Customer Data stored in your Vault to train foundation models that Illana offers as general-purpose AI products. Your synced email, documents, calendar entries, financial snapshots, and other vault content are Processed to provide search and synthesis for your Account—not to build public models from your content.

29.2 Third-party training. We contractually require AI Subprocessors not to use Customer Data sent through Illana integrations for training their general models except where the provider's enterprise terms explicitly prohibit such use and we have configured the integration accordingly. Review provider terms for your compliance requirements.

29.3 Product improvement. We may use aggregated, de-identified usage statistics and feedback not derived from identifiable vault content to improve ranking, UI, and reliability.

29.4 Opt-in research. If Illana ever offers optional programs to use customer data for research or model improvement, they will be separate, explicit opt-in programs with additional terms—not part of standard Service use.

30

Human Review and Quality Assurance

30.1 Quality assurance. Authorized Illana personnel and contractors may access personal information when reasonably necessary to provide support you request, investigate bugs, reproduce errors, or improve retrieval and AI quality.

30.2 Access controls. Access is limited by role, logged, and subject to confidentiality obligations. Personnel do not browse vault content without a legitimate business need.

30.3 Support reproduction. If you report an issue involving a specific Query or result, support staff may review the relevant Query, logs, and retrieved snippets to diagnose the problem.

30.4 Enterprise restrictions. Enterprise agreements may impose additional restrictions on support access or require notification before access to production Customer Data.

31

Automated Processing and AI-Assisted Decisions

31.1 Automated processing. Illana automatically Processes Queries, ranks results, and generates AI Output without human intervention in the request path.

31.2 No solely automated legal effects. Illana does not intend its Services to produce legal or similarly significant effects on individuals without human involvement. Customers must not deploy Illana as the sole decision-maker for credit, employment, housing, insurance, or comparable high-impact decisions about individuals.

31.3 GDPR Article 22. Where GDPR applies, individuals may have rights regarding solely automated decision-making. Contact privacy@illana.ai or your employer (if Illana processes data on their behalf) to exercise applicable rights.

32

Data Sharing and Disclosure

32.1 General principle. Illana shares personal information only as described in this Policy, as instructed by customers when we act as processor, with your consent where required, or as permitted by law.

32.2 No sale. We do not sell personal information. We do not share vault content with data brokers for their independent commercial purposes.

32.3 Categories of recipients. Recipients may include Subprocessors (Section 33), enterprise customer administrators (for workspace data), Connected Application providers (Section 35), professional advisors, acquirers (Section 36), and authorities (Section 37).

32.4 Customer-directed sharing. When you query through Slack, Teams, or shared workspaces, AI Output and cited snippets may be visible to other users permitted on those channels or in your Organization.

33

Service Providers and Subprocessors

33.1 Infrastructure and operations. We use cloud hosting, database, monitoring, email delivery, payment processing, customer support, and security vendors that Process personal information on our behalf.

33.2 AI providers. Large language model API vendors Process Query and snippet data to generate AI Output (Section 28).

33.3 Contractual protections. Subprocessors are bound by written agreements requiring appropriate security, confidentiality, and use limitations consistent with this Policy and applicable DPAs.

33.4 Subprocessor list. Enterprise customers may request a current Subprocessor list and advance notice of material changes under an Enterprise Agreement or DPA.

33.5 No unauthorized subprocessors. We remain responsible for Subprocessor Processing performed on our behalf subject to applicable law and contract.

34

Enterprise Customer Data Handling

34.1 Customer as controller. For personal information in Customer Data, the enterprise customer typically determines purposes and means of Processing and is responsible for notices, consents, and data subject requests. Illana Processes such data on documented instructions in the Terms, this Policy, and any DPA.

34.2 DPAs and SCCs. Organizations subject to GDPR, UK GDPR, or similar laws may execute a DPA incorporating Standard Contractual Clauses or other transfer mechanisms. The DPA controls Processing scope to the extent of conflict with this Policy.

34.3 Assistance. Where required by law and contract, Illana will provide reasonable assistance with data subject requests, security assessments, and breach notifications, subject to scope and fees in the Enterprise Agreement.

34.4 Regulated industries. Customers in regulated sectors (healthcare, financial services, education) are responsible for determining whether Illana meets their compliance requirements and for executing any required business associate or supplemental agreements.

35

Connected Application Providers

35.1 OAuth and API access. To sync data, Illana calls Connected Service APIs using tokens you authorize. Providers may log API access according to their policies.

35.2 Data flowing to providers. Standard Connections retrieve data from providers; they do not upload your vault to Google, Microsoft, Plaid, or Intuit except as necessary for API operations (for example, token refresh or file download requests initiated by sync).

35.3 Access channel hosts. When you use Slack or Teams, Microsoft or Slack may Process messages containing Queries and AI Output. Their privacy policies govern that Processing.

35.4 Revocation. You may revoke Illana's access through Illana settings or the provider's account permissions page. Revocation stops future sync; vault deletion is described in Section 46.

36

Business Transfers and Corporate Transactions

36.1 Transactions. If Illana is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal information may be transferred to the successor entity subject to this Policy or equivalent protections.

36.2 Notice. We will provide notice of any material change in ownership or use of personal information as required by law and, for enterprise customers, as specified in contract.

36.3 Continued protections. The receiving entity will honor commitments made in this Policy and active DPAs unless you are notified otherwise and consent where required.

37

Legal Disclosures and Law Enforcement Requests

37.1 Legal process. We may disclose personal information if we believe in good faith that disclosure is necessary to comply with applicable law, regulation, legal process, or governmental request.

37.2 Protection of rights. We may disclose information to establish, exercise, or defend legal claims, enforce our Terms, prevent fraud or abuse, or protect the rights, property, or safety of Illana, our customers, or others.

37.3 Law enforcement. We review law enforcement and government requests for legal validity and scope. Where permitted, we notify affected customers before disclosure so they may seek protective measures.

37.4 Emergency disclosure. We may disclose information without delay when necessary to prevent imminent harm where permitted by law.

38

Data Ownership and Control

38.1 Customer ownership. As between you and Illana, you retain ownership of Customer Data. Illana does not claim ownership of content synced from Connected Services or submitted through Queries.

38.2 Limited license to operate. You grant Illana a limited license to Process Customer Data solely to provide and improve the Services as described in our Terms and this Policy.

38.3 Your controls. You control which Connections to create, whether to mark them shared, which workspace members may access Shared Vault Data, and when to disconnect or delete data.

38.4 Illana IP. Illana retains ownership of the Services, software, indexes, algorithms, and aggregated de-identified analytics, excluding Customer Data itself.

39

Customer Data Rights

39.1 Your rights as an account holder. Depending on your location, you may have rights to access, correct, delete, restrict, or object to Processing of personal information Illana controls (such as account and billing data). See Sections 49–52.

39.2 Vault content controlled by customers. If your personal information appears in Customer Data synced by an employer or other organization, that organization is typically the controller. Direct requests regarding vault content to Illana may be forwarded to the organization or handled jointly as required by law and contract.

39.3 How to exercise rights. Email privacy@illana.ai with your request, Account email, and sufficient information to verify identity. We respond within timeframes required by applicable law.

39.4 Authorized agents. Where permitted by law, you may designate an authorized agent to submit requests on your behalf with proof of authorization.

39.5 Non-discrimination. Illana will not discriminate against you for exercising privacy rights where prohibited by law.

40

User Content Rights

40.1 Queries and submissions. You may delete or export Queries and configuration stored in your Account subject to technical capabilities and retention rules in Section 45.

40.2 AI Output. Subject to our Terms and third-party model terms, you may use AI Output generated for you for internal business purposes. AI Output may not be unique; similar responses may be generated for others from their data.

40.3 Feedback. If you provide product feedback or suggestions, we may use them without restriction as described in our Terms, separate from Customer Data.

40.4 Third-party content. Customer Data may include content owned by third parties. Your use of that content through Illana must comply with applicable law and provider terms; Illana does not grant you additional rights in third-party content.

41

Data Security Practices

41.1 Security program. Illana maintains administrative, technical, and organizational measures designed to protect personal information against unauthorized access, loss, misuse, alteration, and disclosure. Details appear on our Security page and in enterprise security documentation.

41.2 No absolute guarantee. No method of transmission or storage is completely secure. We cannot guarantee absolute security but work to maintain industry-appropriate safeguards and respond to incidents promptly.

41.3 Your responsibilities. You are responsible for safeguarding credentials, rotating API keys, enabling multi-factor authentication, and configuring workspace access appropriately. See our Terms Section 5.

41.4 Reporting. Report suspected vulnerabilities or incidents to security@illana.ai.

42

Encryption and Protection Measures

42.1 Encryption in transit. Data transmitted between your devices, Illana services, and Connected Service APIs is protected using TLS or equivalent transport encryption.

42.2 Encryption at rest. Sensitive content at rest, including vault data and connection credentials, is encrypted using AES-256-GCM or comparable algorithms on Illana infrastructure.

42.3 Key management. Encryption keys are managed using industry-standard practices with restricted access and separation from application data where feasible.

42.4 Hashing. Passwords and API secrets are stored using one-way hashing or encryption appropriate to the credential type.

43

Access Controls and Permissions

43.1 Authentication. Access to the Services requires valid authentication via password, identity provider, or API credentials. Multi-factor authentication may be offered or required for certain accounts.

43.2 Authorization. Role-based controls govern workspace administration, shared Connections, and access to Shared Vault Data. Queries and API calls are authorized against your Account and permissions.

43.3 Least privilege. Illana personnel access production systems on a least-privilege basis with logging and review.

43.4 Token scope. OAuth Connections are limited to scopes you approve during authorization. Review scopes carefully before connecting financial or organization-wide sources.

44

Data Isolation Between Customers

44.1 Logical separation. Customer Data is logically isolated per Account and workspace. Retrieval, indexing, and AI processing are scoped so one customer's vault content is not returned in response to another customer's Queries.

44.2 Shared infrastructure. Illana may use multi-tenant infrastructure with logical controls rather than separate physical hardware per customer, unless an Enterprise Agreement specifies dedicated deployment.

44.3 Workspace boundaries. Within an Organization, Administrators control which members may access Shared Vault Data. Personal Connections remain scoped to the connecting user unless explicitly shared.

45

Data Retention Practices

45.1 Active accounts. While your Account is active, we retain Customer Data, account information, and logs as needed to provide the Services and comply with law.

45.2 Connection data. Synced content persists until you delete it, disconnect the Connection, or close your Account, subject to backup retention below.

45.3 Logs and analytics. Security and operational logs are retained for limited periods appropriate to their purpose—typically months, unless longer retention is required for security investigations or legal compliance.

45.4 Backups. Deleted data may persist in encrypted backups for a limited period before being overwritten. Backups are not used to restore deleted data except for disaster recovery of active systems.

45.5 Legal holds. We may retain information beyond standard periods when required by law or reasonably necessary for disputes or investigations.

46

Data Deletion and Removal Requests

46.1 Disconnecting Connections. When you disconnect a Connection, Illana stops syncing and deletes or purges associated Customer Data from active vault storage, subject to backup retention in Section 45.4.

46.2 Account deletion. You may request Account closure through settings or by contacting privacy@illana.ai. Upon deletion, we delete or anonymize personal information we control, except data we must retain by law or in backups for limited periods.

46.3 Provider copies. Deletion in Illana does not delete data in Gmail, Outlook, QuickBooks, Plaid institutions, Google Drive, OneDrive, Slack, Teams, or other Connected Services. Remove data at the source separately if needed.

46.4 Organization offboarding. Administrators should revoke member access, disconnect shared Connections, and export needed data before terminating a workspace.

46.5 Verification. We may verify identity before processing deletion requests to prevent unauthorized removal.

47

Data Export and Portability

47.1 Export features. Depending on your plan, Illana may offer export or retrieval of Customer Data and account information through in-product tools or upon request. Formats and completeness depend on technical capabilities documented in our product guides.

47.2 Portability rights. Where GDPR or similar laws grant data portability, we will provide personal information in a structured, commonly used, machine-readable format when feasible and when Illana is controller.

47.3 Enterprise export. Enterprise customers may have enhanced export and transition assistance under contract during termination or migration.

48

International Data Transfers

48.1 Global operations. Illana is based in the United States and may Process personal information in the U.S. and other countries where we or our Subprocessors operate.

48.2 Transfer mechanisms. When we transfer personal information from the EEA, UK, or Switzerland to countries without an adequacy decision, we rely on appropriate safeguards such as Standard Contractual Clauses incorporated in our DPA, supplementary measures where assessed as necessary, and your Organization's instructions.

48.3 Data residency. Specific data residency or regional hosting requirements may be available under Enterprise Agreement. Unless agreed in writing, Illana does not guarantee storage in a particular country.

48.4 Copies at request. Contact privacy@illana.ai or your account representative for information about transfer mechanisms applicable to your Organization.

49

Privacy Rights by Location

49.1 Overview. Privacy laws vary by jurisdiction. This Policy describes practices globally; Sections 50–52 summarize additional rights for residents of certain regions. Other laws may provide similar rights.

49.2 Determining applicability. Your rights depend on where you live, where you work, and whether Illana is controller or processor for the information at issue.

49.3 Contact. Submit requests to privacy@illana.ai. We will respond according to applicable law and may need to verify identity or coordinate with your employer for processor-held data.

50

European Privacy Rights (GDPR)

50.1 Scope. If you are in the European Economic Area, UK, or Switzerland and Illana is controller of your personal data, you may have the following rights under GDPR or UK GDPR, subject to exceptions:

  1. Access — obtain confirmation and a copy of personal data we hold about you;
  2. Rectification — correct inaccurate data;
  3. Erasure — request deletion in certain circumstances;
  4. Restriction — limit Processing in certain circumstances;
  5. Portability — receive data you provided in a portable format where applicable;
  6. Objection — object to Processing based on legitimate interests or for direct marketing; and
  7. Withdraw consent — where Processing is based on consent, without affecting prior lawful Processing.

50.2 Legal bases. When Illana is controller, we Process personal data based on contract performance (providing the Services), legitimate interests (security, improvement, communications balanced against your rights), consent where required (certain cookies or marketing), and legal obligations.

50.3 Supervisory authority. You may lodge a complaint with your local data protection authority. We encourage you to contact us first at privacy@illana.ai so we can address your concern.

50.4 Processor data. Personal data in Customer Data is primarily Processed on instructions of your employer or organization. Direct your request to them; Illana will assist as required by our DPA.

51

California Privacy Rights (CCPA/CPRA)

51.1 California residents. If you are a California resident, the California Consumer Privacy Act as amended by the CPRA may provide additional rights regarding personal information Illana collects as a business.

51.2 Categories collected. In the preceding twelve months, we may have collected identifiers, commercial information, internet activity, professional information, and inferences from the categories described in Sections 5–18, depending on how you use the Services.

51.3 Sale and sharing. Illana does not sell personal information. We do not share personal information for cross-context behavioral advertising as defined under CPRA.

51.4 Your rights. Subject to exceptions, California residents may request to know, delete, and correct personal information, and to limit use of sensitive personal information where applicable. Submit requests to privacy@illana.ai.

51.5 Shine the Light. California Civil Code Section 1798.83 permits California residents to request certain information regarding disclosure of personal information to third parties for direct marketing. Illana does not disclose personal information to third parties for their direct marketing purposes.

51.6 Verification and agents. We verify requests as required by law. Authorized agents may submit requests with proof of authorization.

52

Other Regional Privacy Rights

52.1 Additional jurisdictions. Residents of Virginia, Colorado, Connecticut, Utah, Texas, and other U.S. states with comprehensive privacy laws may have rights to access, delete, correct, and opt out of certain Processing, similar to those described for California where applicable.

52.2 Canada. Canadian residents may have rights under PIPEDA and provincial laws, including access and correction requests contactable at privacy@illana.ai.

52.3 Brazil and other regions. If you are subject to LGPD or other national laws, contact privacy@illana.ai. We will honor applicable rights and may require verification or coordination with your organization when Illana acts as processor.

52.4 Appeals. Where required by state law, you may appeal a denied request by replying to our decision with “Appeal” in the subject line.

53

Children's Privacy

53.1 Age restriction. The Services are not directed to children under eighteen (18) years of age (or the age of majority in your jurisdiction, if higher). We do not knowingly collect personal information from children.

53.2 Parental notice. If you believe we have collected personal information from a child without appropriate consent, contact privacy@illana.ai. We will investigate and delete information as required by law.

53.3 School use. If an Organization uses Illana in an educational context involving minors, the Organization is responsible for compliance with applicable student privacy laws and for obtaining required consents.

54

Third-Party Websites and Services

54.1 Links. Our websites may link to third-party sites (documentation hosts, identity providers, payment processors, social media). Those sites have independent privacy practices. Review their policies before providing information.

54.2 No endorsement. Links do not imply endorsement of third-party privacy or security practices.

55

External Integrations

55.1 Integrations you enable. When you connect Google, Microsoft, Plaid, QuickBooks, Slack, Teams, or other platforms, those integrations are governed by the provider's terms and privacy policies in addition to this Policy.

55.2 MCP and API clients. If you authorize third-party applications to access Illana via MCP or API keys, those applications may Process Queries and results according to their own policies. Review client permissions and revoke keys you no longer trust.

55.3 Illana responsibility. Illana is responsible for Processing on our systems as described here. We are not responsible for third-party applications or Connected Services outside our control.

56

Changes to This Privacy Policy

56.1 Updates. We may update this Policy to reflect changes in the Services, legal requirements, or our practices. We will post the revised Policy with an updated “Last updated” date.

56.2 Material changes. If we make material changes that reduce your rights or expand how we use personal information in a way that requires notice under applicable law, we will provide additional notice—such as email to your Account address or an in-app banner—before or when the change takes effect.

56.3 Continued use. Your continued use of the Services after the effective date of an updated Policy constitutes acceptance where permitted by law. If you disagree, stop using the Services and contact us to close your Account.

56.4 Prior versions. Prior versions may be available upon request to privacy@illana.ai for a reasonable period after updates.

57

Contacting Illana About Privacy

57.1 Privacy inquiries. For questions about this Policy, privacy practices, or to exercise rights where Illana is controller, contact:

Email: privacy@illana.ai
Subject line: “Privacy Request — [brief description]”

57.2 Security issues. Report security vulnerabilities or incidents to security@illana.ai, not privacy@illana.ai.

57.3 Legal notices. Contractual or legal notices unrelated to privacy may be sent to legal@illana.ai.

57.4 Response times. We aim to acknowledge privacy requests promptly and respond within timelines required by applicable law. Complex requests may require additional time; we will notify you if an extension is needed.

57.5 Related documents. Also see our Terms & Conditions, Security page, and any DPA executed with your Organization.

Legal inquiries unrelated to privacy may be sent to legal@illana.ai.