Legal

Illana Terms & Conditions

Last updated July 8, 2026

These Terms govern access to and use of Illana. For privacy practices, see our Privacy Policy. Questions: legal@illana.ai.

1

Introduction and Acceptance of Terms

These Terms & Conditions (the Terms) constitute a legally binding agreement between you and Illana (Illana, we, us, or our) governing access to and use of the Illana platform, including our websites, web application, application programming interfaces (APIs), Model Context Protocol (MCP) server, Slack and Microsoft Teams connectors, administrative consoles, documentation, and any related services, software, features, or support we make available (collectively, the Services).

Please read these Terms carefully. They contain important information about your legal rights, remedies, and obligations, including disclaimers of warranties, limitations of liability, indemnification obligations, dispute resolution procedures, and a waiver of certain class or collective remedies where permitted by law. By accessing or using the Services, you agree to be bound by these Terms. If you do not agree, you must not access or use the Services.

1.1 What Illana provides. Illana is a memory and retrieval platform that helps you connect third-party accounts and data sources (such as email, calendar, documents, messaging platforms, and financial or accounting systems), sync selected content into a searchable vault, and query that content through natural-language search, AI-assisted assistants, APIs, and integrated access channels. Illana does not replace your underlying third-party services; it indexes, stores, and retrieves information according to your configuration and authorizations. Detailed descriptions of functionality, supported integrations, and technical limitations appear in Section 3 and elsewhere in these Terms.

1.2 Who these Terms apply to. “You” and “your” refer to the individual or legal entity that registers for, accesses, or uses the Services, and, where applicable, any organization on whose behalf that individual acts. If you use the Services on behalf of a company, partnership, government agency, or other organization (an Organization), you represent and warrant that you have authority to bind that Organization to these Terms, and “you” includes both you individually and the Organization.

1.3 How you accept these Terms. You accept and agree to these Terms by any of the following actions (whichever occurs first):

  1. clicking a button, checkbox, or other control indicating acceptance during account registration, checkout, workspace setup, or integration installation;
  2. creating an account, connecting a data source, issuing or using an API key, authorizing an MCP client, linking Slack or Microsoft Teams, or otherwise enabling an access channel;
  3. accessing or using any part of the Services, including sending queries, receiving AI-generated responses, or permitting automated agents to call Illana on your behalf;
  4. executing an order form, statement of work, pilot agreement, or other written or electronic agreement with Illana that incorporates these Terms by reference; or
  5. continuing to use the Services after we post updated Terms and provide notice as described in Section 58.

Your acceptance is effective as of the date of the first qualifying action above (the Effective Date).

1.4 Additional terms and policies. These Terms incorporate by reference, and your use of the Services is also subject to, our current policies and documents, including:

  • our Privacy Policy, which describes how we collect, use, and protect personal data;
  • our Security materials and any security white paper or data-processing addendum executed with your Organization;
  • integration-specific terms, OAuth consent screens, and third-party platform policies governing connected services (Google, Microsoft, Slack, Plaid, QuickBooks, and others);
  • documentation, acceptable use rules, rate limits, and technical requirements published in our product documentation or admin consoles; and
  • any order form, enterprise agreement, pilot terms, beta program terms, or support schedule signed or accepted by you and Illana.

If there is a conflict between these Terms and a signed enterprise or custom agreement between you and Illana that expressly governs the Services, the signed agreement controls for the Organization named in that agreement to the extent of the conflict. Otherwise, these Terms control.

1.5 Eligibility. You may use the Services only if you meet the eligibility requirements in Section 4. By accepting these Terms, you represent that you do, and that your use complies with all applicable laws, regulations, export controls, and third-party contractual obligations.

1.6 No legal, financial, or professional advice. Illana provides software tools for search, retrieval, and AI-assisted summarization. The Services do not provide legal, tax, accounting, medical, investment, or other professional advice. AI-generated outputs may be incomplete, outdated, or incorrect. You are solely responsible for evaluating outputs and for decisions you make based on them, as further described in Sections 13–15.

1.7 Third-party services and AI models. The Services interoperate with third-party platforms, identity providers, data sources, and large language model (LLM) providers that Illana does not control. Your use of those third-party services is subject to their separate terms and privacy practices. Illana is not responsible for third-party outages, policy changes, data handling, model behavior, or actions taken outside the scope you authorize, except as expressly stated in these Terms or a signed agreement with Illana.

1.8 Changes to the Services and Terms. We may modify the Services and these Terms from time to time. Material changes to these Terms will be handled as set forth in Section 58. Your continued use of the Services after the effective date of updated Terms constitutes acceptance of the changes. If you do not agree to updated Terms, you must stop using the Services and may terminate your account as described in Sections 44–45.

1.9 Suspension and termination. We may suspend or terminate access to the Services as described in Section 44, including for violations of these Terms, security risks, non-payment, or legal requirements. Termination does not relieve you of obligations accrued before termination. Sections that by their nature should survive (including ownership, confidentiality, disclaimers, limitations of liability, indemnification, and dispute resolution) survive termination.

1.10 Electronic communications and records. You consent to receive communications from us electronically, including notices about the Services, billing, security, and changes to these Terms. You agree that electronic agreements, signatures, and records satisfy any legal requirement that such communications be in writing, to the fullest extent permitted by applicable law.

1.11 No waiver of statutory rights. Nothing in these Terms excludes or limits rights that cannot be excluded or limited under applicable consumer protection or mandatory laws. Where any provision is unenforceable, it will be modified or severed as described in Section 64 without affecting the remainder of these Terms.

1.12 Questions and legal notices. Questions about these Terms may be directed to legal@illana.ai. Formal notices must comply with Section 62.

2

Definitions and Interpretation

2.1 Purpose. This Section defines capitalized terms used in these Terms and sets rules for interpreting them. Defined terms apply equally to singular and plural forms and to any grammatical variation. If a term is not defined here, it has the meaning given in context or, if none, its ordinary commercial meaning.

2.2 Interpretation rules. In these Terms, unless the context requires otherwise:

  1. Headings and section numbers are for convenience only and do not affect interpretation.
  2. “Including”, “include”, and “includes” mean including without limitation.
  3. “Or” is not exclusive unless the context clearly requires exclusivity.
  4. “Days” means calendar days unless “business days” is specified.
  5. “Written” or “in writing” includes email and other electronic communications to the addresses or portals specified in Section 62, unless a signed physical document is expressly required.
  6. Statutory references include successor laws and regulations.
  7. Conflict among documents: if any incorporated policy, documentation, order form, or Enterprise Agreement conflicts with these Terms, the order of precedence stated in Section 1.4 applies.
  8. No contra proferentem: these Terms are the product of negotiation between sophisticated parties (or, where you are a consumer, mandatory law still applies). They will not be construed against Illana solely because Illana drafted them.
  9. Updates: if we update these Terms and a defined term changes, the updated definition applies from the effective date of the update unless a signed Enterprise Agreement provides otherwise.

2.3 Defined terms. The following terms have the meanings set out below:

Access Channel means a surface through which authorized users or systems query the Services without using the primary web dashboard, including the MCP server, HTTP API, Slack slash commands and app mentions, Microsoft Teams bot interactions, OAuth-linked assistant clients, and any similar channel we make available.

Access Connector means software and configuration that lets users interact with the Services from a third-party workspace (such as Slack or Microsoft Teams), including workspace installation, user account linking, and bot or command endpoints.

Account means the registered Illana user profile and associated credentials, settings, billing relationship, and permissions used to access the Services.

Administrator means a user designated by an Organization to manage workspace settings, member access, connector policies, API keys, billing, or other administrative functions.

Affiliate means an entity that directly or indirectly controls, is controlled by, or is under common control with a party, where “control” means ownership of more than fifty percent (50%) of voting securities or the power to direct management.

AI Output means text, summaries, citations, structured claims, rankings, classifications, or other material generated by the Services using artificial intelligence, machine learning, or automated reasoning, whether returned through search synthesis, chat interfaces, Access Channels, or the API.

API means Illana's application programming interfaces, authentication mechanisms, webhooks, and related developer endpoints described in our documentation.

API Key means a secret credential issued to you for programmatic access to the API, subject to rate limits and scope restrictions.

Assistant Client means a third-party AI assistant, agent, automation, or application authorized by you to call the Services on your behalf (for example, through MCP or OAuth).

Authorized User means an individual permitted by you or your Organization to access the Services under your Account or workspace, including Administrators and end users.

Beta Features means pre-release, experimental, or evaluation functionality identified as alpha, beta, preview, pilot, or similar, as further described in Section 39.

Confidential Information has the meaning given in Section 20 and includes non-public information disclosed by either party in connection with the Services.

Connected Service means a third-party product, platform, or data source you authorize Illana to access on your behalf through OAuth, API tokens, or similar mechanisms (such as Google Workspace, Microsoft 365, Slack, Plaid, Intuit QuickBooks, or other supported providers).

Connection means a distinct authorized link between your Account and a specific Connected Service identity (for example, one mailbox, calendar account, document library, bank link, or accounting company), identified in the Services by a unique connection identifier and associated credentials, sync state, and ingested data scope.

Customer means you, and where applicable your Organization, as the customer of the Services under these Terms.

Customer Data means all data, content, files, metadata, credentials, configuration, queries, and other information submitted to, synced through, stored in, or generated within the Services by or on behalf of you or your Authorized Users, excluding Illana Materials and aggregated or de-identified data that cannot reasonably identify you.

Documentation means the user guides, API reference, security materials, admin help text, and other technical or policy documentation we publish for the Services, as updated from time to time.

Effective Date has the meaning given in Section 1.3.

Enterprise Agreement means a separately executed master services agreement, order form, data processing addendum, statement of work, pilot agreement, or other written contract between Customer and Illana that governs use of the Services and expressly incorporates or supersedes portions of these Terms.

Entity means a person, organization, or other named subject extracted or resolved in the Services (for example, from email senders, calendar attendees, or document content) and used to improve search, linking, and retrieval.

Illana Materials means the Services, software, algorithms, models, prompts, templates, user interfaces, Documentation, trademarks, logos, and all related intellectual property owned or licensed by Illana, excluding Customer Data and AI Output derived solely from Customer Data.

Ingest or “Ingestion” means the process by which data retrieved from Connected Services is normalized, indexed, linked, and stored in the Vault, including creation or update of memory items, typed records, entity mentions, and graph edges.

Integration means the product feature set and UI surface for connecting, managing, and syncing Connections; “Integration” and “Connection” are related but not identical — a Connection is the underlying authorized link, while Integration refers to the customer-facing connect and manage experience.

MCP means the Model Context Protocol server endpoint(s) we provide so Assistant Clients can invoke Illana tools (such as search) against your Vault subject to your authentication and permissions.

Memory Item means a searchable unit of Customer Data stored in the Vault (for example, an email, calendar event, document section, transaction, or accounting record), including associated metadata, timestamps, classification fields, and retrieval indexes.

Organization has the meaning given in Section 1.2 and includes any company, team, workspace, or other legal or operational entity on whose behalf the Services are used.

Order Form means an ordering document, online checkout screen, or subscription selection that specifies plan tier, seats, fees, term length, or enterprise options and is accepted by Customer and Illana.

Personal Data means information relating to an identified or identifiable natural person, as defined by applicable privacy laws, and processed through the Services.

Processing or “Process” means any operation performed on data, including collection, storage, retrieval, use, disclosure, indexing, encryption, deletion, transformation, or transmission.

Query means a natural-language question, keyword search, API request, MCP tool invocation, slash command, or other request submitted to the Services to retrieve or synthesize information from the Vault.

Search Results means Memory Items, snippets, citations, structured rows, task results, or other retrieved data returned in response to a Query, with or without AI Output.

Services has the meaning given in Section 1.

Shared Vault Data means Customer Data ingested under an Organization connection marked or configured as shared company data (for example, admin-connected sources intended for workspace-wide retrieval), subject to access rules in Sections 7 and 21.

Subscription means a paid or trial plan granting access to specified features, usage limits, and support levels for a defined term, as described in Sections 40–43 and any Order Form.

Sync means scheduled or manual retrieval of data from a Connected Service into the Vault through pipeline workers or related background jobs, including backfill and incremental updates.

Third-Party Service means any product, platform, model provider, hosting provider, or service not owned or controlled by Illana that you or we interact with in connection with the Services, including Connected Services, LLM providers, identity providers, and communication platforms.

User Content means queries, prompts, labels, comments, configuration choices, and other material you or Authorized Users submit directly through the Services, excluding content merely synced from Connected Services unless you modify or republish it through Illana.

Vault or “Memory Vault” means the searchable datastore (typically a PostgreSQL database and associated indexes) that holds Customer Data ingested from Connections, including memory items, typed tables, entity records, graph links, and optional embeddings.

Workspace means an Organization's logical tenant within the Services, including its members, policies, shared connections, and administrative settings.

You or “Your” has the meaning given in Section 1.2.

2.4 Product-specific terms. Capitalized product names (such as Gmail, Google Calendar, Google Docs, Outlook, Microsoft Teams, Slack, Plaid, or QuickBooks) refer to third-party services; use of those names does not imply endorsement, partnership, or agency except as stated in separate agreements. Illana's use of such integrations is subject to the applicable Third-Party Service terms and your authorization.

2.5 No agency. Except as expressly stated in an Enterprise Agreement, no defined term creates a partnership, joint venture, employment, or agency relationship between you and Illana or between Illana and any Third-Party Service provider.

3

Description of Illana Services

3.1 Overview. Illana provides a cloud-based software platform that connects to your authorized third-party accounts, syncs selected data into a private searchable Vault, and lets you and your Authorized Users query that data through natural-language search, structured retrieval, and AI-assisted summarization. The Services are designed to augment—not replace—your existing email, calendar, document, messaging, and financial systems. Except where an Access Connector sends a reply in Slack or Microsoft Teams, or where you explicitly configure an action described in the Documentation, Illana does not send email, modify calendar events, edit documents, execute bank transfers, or post journal entries in Connected Services on your behalf.

3.2 Web application and account features. Through the Illana web application, you can:

  • create and manage an Account and profile settings;
  • view and manage Connections (Integrations) to Connected Services;
  • monitor sync status, token health, and integration errors;
  • initiate manual sync or reconnect flows where supported;
  • disconnect sources and request deletion of associated Vault data;
  • configure Access Channels (such as MCP, API keys, Slack, and Teams);
  • manage Assistant Client authorizations and revoke access; and
  • access Documentation, security materials, and support channels we make available.

Organization and enterprise customers may also use administrative consoles to manage workspace members, connector policies, usage, and deployment options as described in Sections 6–7 and 38.

3.3 Connections and synchronization. Each Connection represents one authorized link between your Account and a specific identity in a Connected Service (for example, one Gmail mailbox, one Google Calendar, one QuickBooks company, or one Plaid-linked institution). When you complete OAuth or equivalent authorization, Illana stores encrypted credentials and schedules background sync jobs to retrieve data according to the scopes you grant and the capabilities of that provider.

Supported Connected Services may include, and are limited to, those listed in our Documentation at the time of connection. As of the Effective Date, Illana generally supports connectors such as:

  • Google Gmail, Google Calendar, and Google Docs / Google Drive;
  • Microsoft Outlook mail, Outlook Calendar, and OneDrive;
  • Plaid-linked bank and financial institution accounts; and
  • Intuit QuickBooks Online (read-only accounting data).

We may add, modify, suspend, or retire connectors at any time. A connector labeled beta, preview, or pilot is subject to Section 39. Sync includes initial backfill and periodic incremental updates. Sync timing, depth, and field coverage depend on provider APIs, your plan, system load, and technical constraints described in the Documentation—not every field or historical record in a Connected Service is guaranteed to appear in the Vault.

3.4 Vault storage, indexing, and linking. Ingested data is normalized into Memory Items and, where applicable, typed records (emails, calendar events, documents, transactions, financial records). Illana builds search indexes (including full-text vectors and, when enabled, optional embeddings), extracts Entities (people, organizations, and similar subjects), and creates relationship links between items (such as thread membership, attachments, co-occurrence, and cross-source references). Metadata required for search and retrieval may be stored in forms that differ from raw provider payloads; sensitive content may be encrypted as described in Section 18 and our security materials.

Where your Organization enables shared company connections, Shared Vault Data may be ingested once for workspace-wide retrieval subject to access rules in Sections 7 and 21. Personal Connections remain scoped to the connecting user unless policy and product settings expressly allow broader access.

3.5 Search, retrieval, and AI-assisted answers. The core retrieval pipeline:

  1. accepts a Query in natural language or structured form;
  2. plans one or more retrieval tasks (including domain, time range, and entity filters) using automated interpretation;
  3. executes database and index queries against your Vault;
  4. returns Search Results (rows, snippets, citations, and metadata); and
  5. optionally synthesizes AI Output that summarizes or formats those results for chat, API, or Access Channel presentation.

Search is scoped to Customer Data your Account and permissions entitle you to see. Results depend on what has successfully synced, index freshness, query phrasing, entity resolution accuracy, and known product limitations. Illana does not guarantee that every relevant item will be retrieved or ranked first. AI Output is generated probabilistically and may omit, misstate, or hallucinate information even when underlying data exists—see Sections 13–15.

3.6 Access Channels. Subject to your configuration and applicable fees, Illana may expose the Services through:

  • MCP server — tools (such as search) invoked by Assistant Clients you authorize;
  • HTTP API — programmatic search and account operations authenticated via API Keys;
  • Slack Access Connector — slash commands and app mentions that run search against your linked Account and post replies in Slack (Illana does not ingest your Slack message history into the Vault unless a future feature explicitly says so); and
  • Microsoft Teams Access Connector — similar query and reply behavior within Teams.

Each Access Channel requires separate installation, linking, or OAuth consent. You are responsible for ensuring only intended users and systems can invoke the Services through those channels.

3.7 Administrative, billing, and support features. Depending on your plan, Illana may provide workspace administration, connector policy controls, usage metrics, audit logs, API key management, billing and subscription management, and customer support. Feature availability varies by Subscription tier and Enterprise Agreement.

3.8 Optional background processing. Illana may run optional background workers—for example, to extract entities, build graph edges, generate embeddings, or process file attachments—that improve search quality but are not strictly required for basic retrieval. Such processing may be enabled or disabled based on deployment configuration and may change over time. When disabled, some semantic or attachment-aware features may be limited.

3.9 What the Services are not. Except as expressly stated in an Order Form or Enterprise Agreement, Illana is not:

  • a law firm, accounting firm, financial advisor, or regulated professional service;
  • a system of record for email, documents, accounting, or banking;
  • a guaranteed complete archive or backup of Connected Service data;
  • a data loss prevention, e-discovery, or compliance archiving platform;
  • an email or calendar client for sending, receiving, or scheduling on your behalf;
  • a general-purpose large language model provider (we may call third-party models); or
  • a guarantee of business outcomes, decisions, or regulatory compliance.

3.10 Service changes and availability. We may modify features, interfaces, rate limits, supported connectors, and underlying infrastructure at any time. We strive for high availability but do not guarantee uninterrupted or error-free operation. Maintenance windows, provider outages, and force majeure events may affect sync and search. Detailed availability commitments, if any, appear only in an Enterprise Agreement or SLA—not in these Terms unless Section 24 states otherwise.

3.11 Third-party dependence. The Services rely on Connected Services, hosting providers, identity platforms, LLM vendors, and communication APIs outside Illana's control. If a third party changes APIs, revokes tokens, imposes rate limits, or terminates access, corresponding Illana features may degrade or stop without liability to you except as expressly provided in these Terms or an Enterprise Agreement.

3.12 Your configuration responsibilities. You control which Connections to create, which scopes to grant, which Access Channels to enable, and which Assistant Clients to authorize. You are responsible for aligning Illana configuration with your internal policies, employment agreements, and regulatory obligations, including obtaining any consents required before syncing personal or employee data into the Vault.

4

Eligibility and User Requirements

4.1 Minimum age and capacity. You may access or use the Services only if you are at least eighteen (18) years of age (or the age of legal majority in your jurisdiction, if higher) and have the legal capacity to enter into a binding contract. If you are accessing the Services on behalf of an Organization, you represent that you are authorized to bind that Organization and that all Authorized Users meet applicable eligibility requirements.

4.2 Geographic and regulatory restrictions. You may use the Services only in jurisdictions where Illana makes them available and where your use is lawful. You are responsible for ensuring that connecting financial, accounting, email, calendar, or document sources through Illana complies with applicable laws, including export control, sanctions, banking, employment, and sector-specific regulations described further in Sections 47–50. We may restrict access from certain countries or regions at our discretion.

4.3 Account standing. You must maintain an Account in good standing, including timely payment of applicable fees (Sections 41–43), compliance with these Terms, and cooperation with reasonable identity or security verification requests. We may refuse registration, suspend access, or terminate Accounts that do not meet these requirements as described in Section 44.

4.4 Authorized use only. Access to the Services is limited to you and your Authorized Users for legitimate business or personal productivity purposes consistent with these Terms and the Acceptable Use Policy in Section 16. You may not resell, sublicense, or provide the Services to third parties except as expressly permitted in an Enterprise Agreement.

4.5 Third-party authorization. Before connecting any Connected Service, you must have lawful rights and all necessary consents to grant Illana access to the data you authorize for sync and retrieval. This includes employer policies, workspace admin approval, data subject consent where required, and compliance with the Connected Service's terms of use. Illana is not responsible for your failure to obtain such authorization (Section 8).

4.6 Prohibited persons. You may not use the Services if you are barred under applicable export control, sanctions, or anti-terrorism laws, or if you are listed on any government restricted-party list. You represent that neither you nor your Organization is subject to such restrictions (Section 50).

4.7 Accurate information. You must provide accurate, current, and complete registration information and keep it updated. False or misleading information may result in suspension or termination and may void warranties or remedies to the fullest extent permitted by law.

4.8 Changes to eligibility. We may modify eligibility criteria at any time. If you no longer meet eligibility requirements, you must stop using the Services and may terminate your Account as described in Sections 44–45.

5

Account Registration and Account Security

5.1 Registration. To use most features of the Services, you must create an Account by providing the information we request and accepting these Terms. Registration may require email verification, identity provider sign-in (such as Google or Microsoft), or additional steps for Organization workspaces.

5.2 Credentials and authentication. You are responsible for maintaining the confidentiality of your login credentials, API Keys, OAuth tokens, MCP client authorizations, and any other authentication secrets associated with your Account. You must not share credentials except with Authorized Users who need them for legitimate use under your policies.

5.3 Account security obligations. You agree to:

  1. use strong, unique passwords and enable multi-factor authentication where offered;
  2. promptly revoke access for departed employees or compromised integrations;
  3. monitor API Key usage and rotate or delete keys that are no longer needed;
  4. notify Illana promptly at security@illana.ai if you suspect unauthorized access, credential theft, or a security incident affecting your Account; and
  5. ensure Assistant Clients and Access Channels are configured with least-privilege access.

5.4 Responsibility for activity. You are responsible for all activity under your Account, including Queries, Connections, configuration changes, and API calls, whether authorized or unauthorized, except to the extent caused by Illana's breach of its security obligations in Section 18. We may treat actions authenticated with your credentials as authorized by you.

5.5 Single user accounts. Individual Accounts are intended for a single natural person unless your plan or Enterprise Agreement expressly permits shared login credentials (which we discourage). Organization workspaces use separate member accounts with role-based access (Section 7).

5.6 Account recovery. We may offer account recovery flows through your registered email or identity provider. We are not obligated to restore access if you lose credentials and cannot satisfy our verification procedures. Enterprise customers may have additional recovery options under an Enterprise Agreement.

5.7 Suspension for security. We may suspend your Account immediately if we reasonably believe it has been compromised, is being used in violation of these Terms, or poses a security risk to Illana or other customers (Section 44).

6

Organization Accounts and Administrator Responsibilities

6.1 Organization workspaces. Organizations may create a Workspace that includes multiple Authorized Users, shared policies, and administrative controls. The Organization is the Customer for purposes of billing, compliance, and these Terms when an Administrator registers or accepts on its behalf (Section 1.2).

6.2 Administrator designation. Administrators are users designated to manage Workspace settings, including member invitations, connector policies, shared Connections, API keys, billing contacts, and security configuration. The Organization is responsible for designating trustworthy Administrators and limiting admin privileges appropriately.

6.3 Administrator obligations. Administrators agree to:

  1. ensure Authorized Users comply with these Terms and applicable laws;
  2. configure access controls and shared vault settings consistent with the Organization's policies (Sections 7 and 21);
  3. obtain required consents before syncing employee, customer, or third-party data into the Vault;
  4. promptly offboard users and revoke Connections, API keys, and Access Channels when access should end;
  5. maintain accurate billing and contact information; and
  6. respond to Illana security or abuse notices affecting the Workspace.

6.4 Shared Connections. Administrators may connect Organization-owned sources (such as shared mailboxes, company calendars, or accounting systems) and mark Connections as shared (is_shared) so that ingested data becomes Shared Vault Data available to permitted Workspace members. Administrators are solely responsible for determining which Connections should be shared and which users may access Shared Vault Data.

6.5 Binding the Organization. Actions taken by an Administrator within the scope of their role bind the Organization, including acceptance of Terms updates, creation of Connections, issuance of API Keys, and installation of Access Connectors in Slack or Microsoft Teams.

6.6 No fiduciary duty. Illana does not act as the Organization's compliance officer, data protection officer, or agent. Administrators remain responsible for internal governance, employee monitoring policies, and regulatory obligations even when using Illana.

6.7 Enterprise and self-hosted deployments. Organizations with Enterprise Agreements or self-hosted deployments may have additional administrative responsibilities described in Section 38, including infrastructure security, network access, and update management for customer-operated environments.

7

User Roles, Permissions, and Access Controls

7.1 Role-based access. The Services support role-based permissions within Organization Workspaces. Roles may include Administrator, member, and other tiers described in the Documentation. Role assignments determine which settings, Connections, Shared Vault Data, and administrative functions a user may access.

7.2 Personal vs. shared data scope. By default:

  • data ingested through a user's personal Connection is searchable by that user (and by Administrators where product settings and policy allow); and
  • Shared Vault Data ingested through an Organization shared Connection is searchable by Authorized Users granted access under Workspace rules.

Search, API, MCP, Slack, and Teams queries are scoped to Customer Data your Account and permissions entitle you to retrieve (Section 3.5). Illana does not guarantee that role configuration alone prevents all unintended disclosure if misconfigured; you are responsible for validating access rules meet your requirements.

7.3 API Keys and programmatic access. API Keys inherit the permissions of the Account or context in which they are issued. Administrators should restrict key creation, document key purpose, and revoke unused keys. API usage is subject to Section 33.

7.4 Access Channels. Slack and Microsoft Teams Access Connectors link individual user Accounts or Workspace installations to third-party workspaces. Only users who complete linking and satisfy Workspace policy may invoke search through those channels. Workspace admins control installation and membership on the third-party platform side.

7.5 Assistant Clients and MCP. When you authorize an Assistant Client via MCP or OAuth, you grant that client the ability to invoke Illana tools (such as search) within the scopes you approve. You must review and revoke Assistant Client access that is no longer needed (Sections 35 and 33).

7.6 Customer responsibility for access reviews. You are responsible for periodic access reviews, least-privilege enforcement, and alignment with internal security policies. Illana may provide audit logs or admin views where available but does not conduct access certifications on your behalf.

7.7 No circumvention. Users may not attempt to bypass permission checks, query data outside their scope, or use another user's credentials or tokens to access restricted Vault content (Section 17).

8

Authorized Use of Connected Services

8.1 Your authorization to Illana. By creating a Connection, you grant Illana a limited authorization to access the Connected Service on your behalf using the OAuth scopes, API permissions, or tokens you approve, solely to provide the Services—including sync, indexing, search, and related processing described in Sections 3 and 10.

8.2 Scope of access by connector type. Access varies by connector. As of the Effective Date, typical scopes include:

  • Google (Gmail, Calendar, Docs/Drive): read mail, events, and documents you authorize for sync;
  • Microsoft (Outlook, Calendar, OneDrive): read mail, calendar, and files you authorize;
  • Plaid: read linked financial account data you authorize through Plaid's consent flow; and
  • QuickBooks Online: read-only access to accounting data in the QuickBooks company you connect—Illana does not post journal entries or modify QuickBooks records through standard connectors.

Exact scopes appear in OAuth consent screens and the Documentation. We may request additional scopes when features require them; you may decline, but related functionality may not work.

8.3 Read-oriented use. Unless expressly described in the Documentation or an Order Form (for example, posting a search reply in Slack or Teams), Illana's standard Connections are read-oriented. Illana does not send email, create calendar events, edit documents, initiate payments, or write to QuickBooks on your behalf through default connectors.

8.4 Compliance with provider terms. Your use of Connected Services through Illana must comply with each provider's terms, API policies, and acceptable use rules (Google, Microsoft, Plaid, Intuit, and others). If a provider prohibits your use case, you must not connect that source to Illana.

8.5 Token maintenance. You are responsible for reconnecting Connections when tokens expire or are revoked, and for responding to provider security prompts. Sync interruptions due to expired or revoked authorization are not Service failures by Illana.

8.6 Disconnect and purge. When you disconnect a Connection, Illana deletes or purges Customer Data associated with that Connection from the Vault according to Section 22, subject to backup retention windows and legal holds. Disconnecting does not delete data in the underlying Connected Service.

8.7 No agency with third parties. Illana is not your agent toward Connected Service providers except as needed to technically access data you authorize. Providers may audit, rate-limit, or terminate API access independently of Illana.

9

Third-Party Integrations and External Platforms

9.1 Third-Party Services generally. The Services interoperate with Third-Party Services you choose to connect or install, including Google Workspace, Microsoft 365, Slack, Microsoft Teams, Plaid, Intuit QuickBooks, identity providers, LLM vendors, and hosting infrastructure. Illana does not control and is not responsible for Third-Party Services except as expressly stated in these Terms or an Enterprise Agreement.

9.2 Separate terms apply. Your use of Third-Party Services is governed by their own terms, privacy policies, and pricing. You must comply with those terms when using Illana integrations. Conflicts between provider requirements and these Terms do not obligate Illana to modify the Services unless required by law or agreed in writing.

9.3 Access Connectors vs. data sources. Slack and Microsoft Teams integrations primarily function as Access Connectors: they let authorized users submit Queries and receive replies within those workspaces. Illana does not ingest your historical Slack or Teams message archives into the Vault through standard Access Connectors unless a future feature explicitly states otherwise in the Documentation.

9.4 Provider changes and outages. Third parties may change APIs, deprecate endpoints, impose new fees, or experience outages. Illana may modify or suspend affected connectors without liability for resulting unavailability, data gaps, or sync delays (Sections 3.11 and 24).

9.5 No endorsement. Reference to third-party names, logos, or products does not imply endorsement, sponsorship, or partnership unless separately disclosed.

9.6 Third-party support. Issues originating in a Third-Party Service (mailbox configuration, Plaid institution linking, QuickBooks permissions, Slack workspace policies) are your responsibility to resolve with the provider. Illana support may assist with Illana-side configuration but cannot guarantee provider-side fixes.

9.7 Data returned to third-party surfaces. When Search Results or AI Output are displayed in Slack, Teams, or other third-party UIs, those platforms may log, index, or retain messages according to their policies. You are responsible for configuring retention and access controls on those platforms.

10

Data Access, Collection, and Processing

10.1 Categories of data. In connection with the Services, Illana Processes:

  1. Account and billing data — registration details, authentication identifiers, subscription status, and support communications;
  2. Connection credentials — OAuth tokens and related secrets stored encrypted for sync;
  3. Synced Customer Data — content and metadata retrieved from Connected Services into the Vault;
  4. Queries and User Content — search questions, prompts, labels, and configuration you submit;
  5. AI Output — generated summaries and responses derived from retrieval; and
  6. Technical logs — operational telemetry, security logs, and usage metrics as described in our Privacy Policy.

10.2 How data is collected. Customer Data is collected when you register, create Connections, sync from providers, submit Queries, use Access Channels, or interact with support. We do not collect Connected Service data without your authorization through OAuth or equivalent flows.

10.3 Processing purposes. Illana Processes Customer Data to:

  • authenticate users and enforce access controls;
  • sync, store, index, and retrieve Vault content;
  • execute search plans, database queries, and optional embeddings or understanding workers;
  • generate AI Output when synthesis is enabled;
  • maintain security, prevent abuse, and enforce rate limits;
  • provide support, billing, and product improvement in accordance with these Terms; and
  • comply with legal obligations.

10.4 Optional processing. Optional background workers (entity extraction, graph linking, embeddings) may Process Customer Data to improve search quality. Availability depends on plan and configuration (Section 3.8). Where required by law or contract, we will describe optional processing in the Documentation or an Enterprise Agreement.

10.5 No sale of Customer Data. Illana does not sell Customer Data. We do not use Customer Data to train foundation models owned or offered by Illana as general-purpose AI products (Section 13).

10.6 Subprocessors. We may use infrastructure providers, LLM API vendors, and other subprocessors to host and Process data as described in our Privacy Policy and any data processing addendum. Enterprise customers may receive additional subprocessor information under an Enterprise Agreement.

10.7 Your instructions. Within the Services, your Connection choices, Queries, and configuration constitute instructions for Processing. Additional instructions may be set forth in an Enterprise Agreement or DPA.

11

Customer Data Ownership and Rights

11.1 Ownership. As between you and Illana, you retain all right, title, and interest in Customer Data, including synced content from Connected Services and User Content you submit. Illana acquires no ownership rights in Customer Data except the limited licenses in Section 30 necessary to operate the Services.

11.2 Responsibility for Customer Data. You are solely responsible for the accuracy, legality, and appropriateness of Customer Data and for ensuring you have rights to sync, store, and query it through Illana. This includes data about employees, customers, patients, financial account holders, or other third parties.

11.3 AI Output. Subject to Illana's rights in Illana Materials and third-party model terms (Sections 26–27 and 32), you may use AI Output for your internal business purposes. Illana does not claim ownership of AI Output generated specifically for you from your Customer Data, but AI Output may not be unique and similar output may be generated for others from their data.

11.4 Export and portability. You may export or retrieve Customer Data using features described in Section 46 and the Documentation, subject to technical limits and your Subscription tier. We do not guarantee any particular export format or completeness.

11.5 Feedback distinction. Suggestions and feedback you provide about the Services are handled under Section 28 and are distinct from Customer Data.

11.6 No duty to monitor content. Illana is not obligated to monitor Customer Data for legality or policy compliance but may do so to enforce these Terms, address security issues, or comply with law (Sections 16–17 and 44).

12

Illana Data Processing Responsibilities

12.1 Processor role. For Customer Data containing Personal Data, Illana generally acts as a processor (or service provider) on your instructions, and you act as controller (or business) for such data, except where Illana acts as controller for Account data relating to your relationship with Illana (see our Privacy Policy).

12.2 Security measures. Illana implements administrative, technical, and organizational measures designed to protect Customer Data, including those described in Section 18 and our Security materials.

12.3 Confidentiality of personnel. Illana personnel and contractors with access to Customer Data are bound by confidentiality obligations appropriate to their role.

12.4 Assistance requests. Where required by applicable privacy law and your Subscription or Enterprise Agreement, Illana will provide reasonable assistance with data subject requests, security incident notifications, and impact assessments, subject to applicable fees and scope limits in an Enterprise Agreement or DPA.

12.5 Deletion and return. Upon disconnect of a Connection or deletion of your Account, Illana will delete or purge applicable Customer Data as described in Section 22, except data we must retain by law or in encrypted backups for a limited period.

12.6 Limitations. Illana's processing responsibilities are limited by the capabilities of the Services, your configuration, and third-party provider behavior. We are not responsible for Processing outside our systems or caused by your misconfiguration, unauthorized users, or compromised credentials (Section 5).

12.7 Enterprise DPAs. Organizations subject to GDPR, UK GDPR, or similar regimes may execute a data processing addendum with Illana. In case of conflict between these Terms and a signed DPA, the DPA controls for Personal Data processing scope.

13

AI Processing and Artificial Intelligence Disclosures

13.1 AI features. The Services use artificial intelligence and machine learning for tasks such as query interpretation, search planning, ranking, entity resolution, optional embeddings, and synthesis of AI Output from retrieved Customer Data. These features may invoke third-party LLM APIs (Section 32).

13.2 No training on Customer Vault data. Illana does not use Customer Data stored in your Vault to train foundation models that Illana offers as general-purpose AI products. Customer Data is Processed to provide search, retrieval, and synthesis for your Account—not to build public models from your synced content.

13.3 Third-party model providers. When AI features call external model providers, prompts may include Query text and retrieved snippets necessary to generate a response. Such providers are subject to their own terms and data handling practices (Section 32). We configure integrations to minimize unnecessary data transmission consistent with product design, but you should review provider policies for your compliance needs.

13.4 Automated decision-making. Illana does not make legally binding decisions about individuals solely through automated processing. AI Output is informational. You must not use the Services as the sole basis for decisions with legal or similarly significant effects on individuals without human review and appropriate safeguards.

13.5 Transparency. Where feasible, Search Results include citations or references to underlying Memory Items. AI Output may summarize or paraphrase retrieved data and should be verified against sources (Sections 14–15).

13.6 Beta AI features. Experimental or beta AI capabilities may have additional limitations and are provided as-is under Section 39.

14

AI Output Accuracy, Limitations, and Human Review

14.1 Probabilistic nature. AI Output is generated probabilistically and may be incomplete, inaccurate, outdated, misleading, or fabricated (“hallucinated”) even when relevant Customer Data exists in the Vault. Retrieval and ranking also have known limitations (Section 3.5).

14.2 Not professional advice. AI Output does not constitute legal, tax, accounting, medical, financial, or other professional advice (Section 1.6). You must consult qualified professionals for decisions requiring licensed expertise.

14.3 Human review required. You should independently verify AI Output and Search Results before relying on them for operational, financial, legal, compliance, employment, or safety-critical decisions. Illana recommends human review for all material use cases.

14.4 Time sensitivity. Sync delays, provider outages, or indexing lag mean Vault data may not reflect the current state of Connected Services. AI Output based on stale data may be wrong without indicating staleness.

14.5 No guarantee of completeness. Illana does not warrant that search will surface every relevant Memory Item or that AI Output will include all material facts from retrieved sources.

14.6 Disclaimers. AI features are provided without warranties as stated in Section 53. Limitations of liability in Section 52 apply to claims arising from AI Output.

15

User Responsibilities for AI-Generated Results

15.1 Your reliance. You are solely responsible for how you use, share, and act on AI Output and Search Results, including decisions made by your employees, agents, and Assistant Clients.

15.2 Internal policies. You should adopt internal policies governing acceptable use of AI-assisted search in your Organization, including review requirements, prohibited use cases, and rules for sharing AI Output in Slack, Teams, email, or external communications.

15.3 Disclosure to third parties. Before sharing AI Output outside your Organization, ensure such disclosure complies with confidentiality obligations, privacy laws, and Connected Service terms. Redact sensitive Personal Data where appropriate.

15.4 Automated agents. If Assistant Clients or automations act on AI Output without human review, you assume all risk of errors, unauthorized actions, and downstream liability (Sections 34–35).

15.5 Reporting issues. You may report materially harmful or unsafe AI behavior through support channels or security@illana.ai. Reports help us improve but do not create an obligation to modify models or outputs for your specific use case.

15.6 Indemnification. Your indemnification obligations in Section 51 include claims arising from your use or misuse of AI Output.

16

Acceptable Use Policy

16.1 Policy scope. This Acceptable Use Policy applies to all use of the Services by you and Authorized Users, including the web app, API, MCP, Slack, Teams, and any other Access Channel.

16.2 Permitted uses. You may use the Services to:

  • connect authorized data sources and sync content into your Vault;
  • search and retrieve Customer Data for legitimate business or personal productivity;
  • generate AI-assisted summaries and answers for internal decision support with appropriate review;
  • integrate Illana into approved workflows via API, MCP, or Access Connectors; and
  • administer Organization workspaces in compliance with these Terms.

16.3 Fair use and rate limits. Use must comply with rate limits and technical constraints in Section 33. Excessive automated querying, scraping the Services, or attempts to circumvent limits are not acceptable.

16.4 Respect for others. You may not use the Services to harass, defame, threaten, or violate the rights of others, including privacy and intellectual property rights.

16.5 Lawful use. Use must comply with all applicable laws and regulations (Section 47), including employment law, financial privacy, healthcare privacy where applicable, and export controls.

16.6 Security respect. You may not probe, scan, or test vulnerabilities of the Services except as expressly authorized in writing by Illana security team via security@illana.ai.

16.7 Enforcement. Violations may result in warning, throttling, suspension, or termination (Sections 17 and 44).

17

Prohibited Activities and Misuse

17.1 Prohibited activities. You may not, and may not permit others to:

  1. access or use the Services without authorization or beyond granted permissions;
  2. reverse engineer, decompile, or attempt to extract source code or models except as permitted by law;
  3. circumvent authentication, rate limits, access controls, or billing mechanisms;
  4. upload malware, interfere with Service operation, or launch denial-of-service attacks;
  5. use the Services to store or process illegal content or to facilitate illegal activity;
  6. use the Services to send spam, phishing, or unsolicited communications through Access Channels;
  7. misrepresent identity or affiliation when registering or connecting sources;
  8. sync or query data you do not have lawful rights to access;
  9. use the Services to build a competing product by systematically extracting Illana Materials or non-public interfaces;
  10. remove proprietary notices or misattribute AI Output as solely human-generated where disclosure is required by law; or
  11. resell or provide the Services to third parties except under an Enterprise Agreement.

17.2 Sensitive and regulated misuse. You may not use the Services in manner that violates HIPAA, GLBA, PCI-DSS, or other regulatory regimes unless you have implemented appropriate agreements, controls, and configurations required for your use case (Sections 48–49).

17.3 Credential abuse. Sharing API Keys publicly, embedding secrets in client-side code, or using production keys in untrusted environments is prohibited.

17.4 Investigation and cooperation. Illana may investigate suspected misuse and cooperate with law enforcement. We may preserve and disclose information as described in Section 19 and our Privacy Policy.

17.5 Reporting abuse. Report suspected abuse to security@illana.ai or legal@illana.ai.

18

Security Practices and Safeguards

18.1 Security program. Illana maintains a security program designed to protect the confidentiality, integrity, and availability of the Services and Customer Data. Details appear in our Security page and related documentation.

18.2 Encryption. Customer Data in transit is protected using TLS. Sensitive content at rest is encrypted using AES-256-GCM (or equivalent industry-standard algorithms we may adopt). Connection credentials and other secrets are stored encrypted.

18.3 Tenant isolation. Customer Accounts and Organization Workspaces are logically isolated in our multi-tenant architecture. Enterprise and self-hosted deployments may offer additional isolation options (Section 21).

18.4 Access controls. Illana restricts employee access to Customer Data on a need-to-know basis for support, operations, and security, subject to confidentiality obligations.

18.5 Monitoring and incident response. We monitor for security events and maintain incident response procedures. If we become aware of a confirmed security incident affecting Customer Data, we will notify you without undue delay as required by applicable law and any Enterprise Agreement or DPA, and you should notify us at security@illana.ai of suspected incidents affecting your Account.

18.6 Your security responsibilities. Security is shared: you must follow Section 5, manage Access Channels safely, and configure Organization policies appropriately. Illana is not liable for incidents primarily caused by weak customer credentials, misconfiguration, or third-party platform compromise except as expressly provided in an Enterprise Agreement.

18.7 No absolute security. No system is perfectly secure. Illana does not guarantee that unauthorized access, loss, or alteration will never occur (Section 53).

19

Privacy and Personal Data Protection

19.1 Privacy Policy. Our Privacy Policy explains how we collect, use, disclose, and protect Personal Data relating to Account holders and individuals whose data appears in Customer Data. The Privacy Policy is incorporated into these Terms by reference (Section 1.4).

19.2 Roles. For Personal Data in Customer Data synced from Connected Services, you are typically the controller and Illana is the processor. For Account and marketing data, Illana may act as controller as described in the Privacy Policy.

19.3 Your privacy obligations. You must provide required notices and obtain required consents before syncing Personal Data into the Vault, including employee email, calendar, and document content. You are responsible for responding to data subject requests for data you control, with Illana assistance as stated in Section 12.

19.4 International transfers. Cross-border data transfers are addressed in Section 49 and the Privacy Policy. Enterprise customers may use EU Standard Contractual Clauses or other mechanisms via DPA.

19.5 Cookies and analytics. Our websites and app may use cookies and similar technologies as described in the Privacy Policy.

19.6 Privacy inquiries. Direct privacy questions to legal@illana.ai or the contact method in the Privacy Policy.

20

Confidential Information

20.1 Definition. “Confidential Information” means non-public information disclosed by one party to the other in connection with the Services that is marked confidential or would reasonably be understood as confidential, including Customer Data, non-public product roadmaps, pricing, security information, and business plans. It excludes information that is publicly available without breach, already known without restriction, independently developed, or rightfully received from a third party.

20.2 Customer Data as confidential. Customer Data is your Confidential Information. Illana will use and disclose Customer Data only as permitted by these Terms, the Privacy Policy, and applicable law.

20.3 Illana confidential information. Non-public aspects of the Services, pricing, and security documentation are Illana's Confidential Information. You may not disclose them except to Authorized Users and advisors bound by confidentiality who need to know for permitted use.

20.4 Protection obligations. Each party will protect the other's Confidential Information using at least reasonable care and no less than the care it uses for its own similar information.

20.5 Compelled disclosure. A party may disclose Confidential Information when required by law, regulation, or court order, provided it gives notice where legally permitted and cooperates on protective measures.

20.6 Duration. Confidentiality obligations survive termination for so long as the information remains confidential, except Customer Data which is handled under Sections 22 and 45.

21

Enterprise Data Separation and Isolation

21.1 Multi-tenant architecture. Standard cloud Services use a multi-tenant architecture with logical separation per Account and Organization Workspace. Customer Data is associated with your tenant identifiers and access-controlled per Sections 7 and 18.

21.2 Shared Vault within Organizations. Shared Vault Data from admin Connections is available only to Authorized Users permitted by Workspace configuration. Misconfiguration may expose data more broadly than intended; Administrators are responsible for validating sharing settings.

21.3 Enterprise deployment options. Enterprise customers may be offered dedicated environments, private networking, or self-hosted deployment where Customer Data resides in infrastructure you control or designate (Section 38). Isolation characteristics depend on the chosen deployment model and Order Form.

21.4 No commingling for other customers. Illana does not intentionally merge Vault content across unrelated customers. Search and API queries are scoped to your tenant except for aggregated, de-identified analytics that cannot reasonably identify you.

21.5 Subprocessors and regions. Data location and subprocessor restrictions may be specified in an Enterprise Agreement or DPA. Standard SaaS may process data in regions described in the Documentation.

21.6 Customer-side isolation. For self-hosted deployments, you are responsible for network isolation, patch management, and access to underlying infrastructure unless otherwise agreed in writing.

22

Data Retention and Deletion Policies

22.1 Active Account retention. While your Account is active, Illana retains Customer Data as needed to provide the Services, including synced Vault content, indexes, optional embeddings, and logs per our retention schedules.

22.2 Connection disconnect. When you disconnect a Connection, Illana purges Customer Data associated with that Connection from active Vault storage, including Memory Items and related indexes derived from that source, subject to the backup exception in Section 22.4.

22.3 Account deletion. When you delete your Account (or we terminate and delete per Section 45), Illana purges your Vault and associated Customer Data from production systems, except as retained in backups, logs, or as required by law.

22.4 Backup retention. Encrypted backups may retain deleted data for a limited rolling window (typically up to thirty (30) days unless otherwise stated in Documentation or Enterprise Agreement) before overwrite. Backups are not used to restore deleted Accounts except where required for disaster recovery of remaining customers or by law.

22.5 Logs and billing records. Operational, security, and billing records may be retained longer where necessary for security, fraud prevention, accounting, or legal compliance, often in de-identified or aggregated form where feasible.

22.6 Legal hold. We may preserve data when required by law, litigation hold, or governmental request, notwithstanding deletion requests, and will notify you where permitted.

22.7 No retention in Connected Services. Deletion in Illana does not delete data in Gmail, Outlook, QuickBooks, Plaid institutions, or other Connected Services. You must manage source systems separately.

23

Backup, Recovery, and Data Availability

23.1 Backup practices. Illana maintains backup and recovery procedures for cloud-hosted Vault infrastructure designed to protect against data loss from system failures. Details may be described in Security materials or an Enterprise Agreement.

23.2 Not a substitute for archival. The Services are not a guaranteed archive or backup of your Connected Service data. Sync gaps, connector errors, or retention limits may mean the Vault does not contain complete history. You should maintain independent backups of critical records in source systems (Section 3.9).

23.3 Recovery objectives. Except as stated in an Enterprise SLA, Illana does not commit to specific recovery point or recovery time objectives. Disaster recovery for standard SaaS is commercially reasonable efforts.

23.4 Customer export. You are responsible for exporting Customer Data you wish to preserve before Account deletion (Section 46).

23.5 Self-hosted responsibility. For self-hosted Enterprise deployments, backup and recovery of the Vault database and indexes are your responsibility unless otherwise specified in an Order Form.

23.6 Provider data loss. Illana is not liable for data loss in Third-Party Services or for Customer Data never successfully synced due to authorization failures or provider limits.

24

Service Availability and Performance

24.1 Commercially reasonable efforts. Illana uses commercially reasonable efforts to make the Services available. We do not guarantee uninterrupted, timely, or error-free operation for standard SaaS subscriptions.

24.2 Scheduled maintenance. We may perform maintenance that temporarily affects availability. Where practicable, we will provide advance notice through the app, status page, or email (Section 25).

24.3 Third-party and connector dependencies. Sync and search depend on Connected Services, LLM providers, and network infrastructure. Outages or rate limiting at those providers may degrade performance without constituting Illana downtime.

24.4 Performance variability. Query latency, sync speed, and AI response time vary based on Vault size, query complexity, optional processing, system load, and plan tier. We do not guarantee specific response times except in an Enterprise SLA.

24.5 SLA. Any uptime or support SLA applies only if expressly set forth in an Enterprise Agreement or Order Form, not in these Terms alone.

24.6 Force majeure. Availability may be affected by events beyond our reasonable control (Section 54).

25

Maintenance, Updates, and Changes to Services

25.1 Service evolution. Illana may modify, add, or remove features, connectors, Access Channels, APIs, and underlying technology at any time, including changes to search planning, indexing, optional embeddings workers, and supported integrations.

25.2 Updates and patches. We deploy updates, security patches, and bug fixes on an ongoing basis. Self-hosted Enterprise customers may receive update packages according to their agreement.

25.3 Breaking changes. We strive to avoid breaking API changes without notice. Material API deprecations will be communicated through Documentation or developer notices when practicable. You are responsible for updating integrations before sunset dates.

25.4 Beta and experimental features. Beta Features may change or be withdrawn without notice (Section 39).

25.5 Terms changes. Changes to these Terms are handled under Section 58, not this Section.

25.6 No obligation to maintain features. We are not obligated to continue offering any particular connector, model provider, or Access Channel. Retirement of a feature does not entitle you to refunds except as stated in Section 43 or an Order Form.

26

Intellectual Property Rights

26.1 Reservation of rights. Except for limited licenses expressly granted in these Terms, Illana and its licensors reserve all rights in the Services and Illana Materials. No implied licenses are granted.

26.2 Customer rights. You retain rights in Customer Data and, subject to third-party terms, in your use of AI Output as stated in Section 11.

26.3 Third-party content. Customer Data may include third-party intellectual property. You are responsible for ensuring your sync and use through Illana does not infringe third-party rights.

26.4 Trademarks. Illana names, logos, and product marks are Illana trademarks. You may not use them without prior written consent except as allowed in brand guidelines or Documentation.

26.5 DMCA and copyright complaints. If you believe content in the Services infringes copyright, notify legal@illana.ai with information required by applicable law. We may remove or disable access to material alleged to be infringing.

26.6 Feedback. Feedback is addressed in Section 28 and may be used by Illana without restriction.

27

Illana Technology Ownership

27.1 Illana Materials. Illana owns or licenses all rights in the Services software, user interfaces, Documentation, search planning and retrieval algorithms, prompts, templates, workflows, and related technology (Illana Materials), excluding Customer Data.

27.2 Aggregated data. Illana may create aggregated or de-identified statistics about Service usage and performance that do not reasonably identify you or disclose Customer Data content, and may use such data to improve and market the Services.

27.3 No transfer of underlying models. Third-party LLM weights and provider models remain owned by their respective vendors (Section 32). Illana does not grant you ownership in those models.

27.4 Open source. Illana Materials may incorporate open source software subject to Section 31. Open source licenses may grant you additional rights in those components only.

27.5 Restrictions. You may not copy, modify, distribute, sell, or lease any part of Illana Materials except as expressly permitted in these Terms or an Enterprise Agreement.

28

Customer Feedback and Suggestions

28.1 Feedback welcome. We welcome feedback, ideas, enhancement requests, and suggestions about the Services (Feedback).

28.2 License to Feedback. If you provide Feedback, you grant Illana a perpetual, irrevocable, worldwide, royalty-free license to use, modify, and incorporate Feedback into the Services and other products without obligation or compensation to you.

28.3 No confidentiality for Feedback. Unless covered by a separate signed agreement, Feedback is not Confidential Information and may be used without restriction.

28.4 No obligation to implement. Illana is not obligated to implement Feedback or respond to submissions.

29

Customer Content and User Contributions

29.1 User Content. User Content includes Queries, prompts, comments, labels, and configuration you submit directly through the Services. Synced content from Connected Services is Customer Data but not User Content unless you modify or republish it through Illana interfaces.

29.2 Your representations. You represent that you have all rights necessary to submit User Content and that it does not violate these Terms or third-party rights.

29.3 Processing of User Content. User Content is Processed to execute Queries, improve retrieval within your Account, provide support, and enforce policies. Queries submitted through Slack, Teams, API, or MCP may be logged for security and debugging per retention policies.

29.4 No public publishing. Unless a feature explicitly allows it, Illana does not publish User Content to other customers or the public.

29.5 Removal. We may remove or disable User Content that violates Sections 16–17 or that we must remove to comply with law.

30

License to Operate and Provide Services

30.1 Customer grant to Illana. You grant Illana a worldwide, non-exclusive, royalty-free license to host, copy, transmit, display, Process, and use Customer Data and User Content solely as necessary to provide, maintain, secure, and improve the Services in accordance with these Terms and your configuration.

30.2 Sublicense to subprocessors. The license includes the right to sublicense to hosting providers, LLM API vendors, and other subprocessors performing Processing on Illana's behalf under contractual confidentiality and security obligations.

30.3 License to you. Subject to these Terms and payment of applicable fees, Illana grants you a limited, non-exclusive, non-transferable, revocable license to access and use the Services for your internal business purposes during your Subscription term.

30.4 Restrictions. You may not use the Services except as permitted in these Terms, the Documentation, and your Order Form. No rights are granted to Illana Materials beyond this license.

30.5 Termination of licenses. Licenses end when your access terminates, except Illana may retain copies as allowed in Sections 22 and 45 and use de-identified aggregated data as permitted in Section 27.

31

Third-Party Software and Open Source Components

31.1 Open source components. The Services may include or depend on third-party open source software. Use of those components is subject to the applicable open source licenses, which may grant you rights separate from these Terms.

31.2 License compliance. Illana endeavors to comply with open source license requirements, including attribution and source offer obligations where applicable. A list of notices may be available in the Documentation or repository notices we publish.

31.3 Third-party commercial software. The Services may integrate commercial third-party libraries and services (databases, identity SDKs, communication APIs). Your use of the Services does not grant a direct license to those third-party products except through Illana's integration.

31.4 No warranty from third parties. Open source and third-party components are provided without warranties from Illana to the extent permitted by their licenses (Section 53).

31.5 Self-hosted components. Enterprise self-hosted deployments may require you to obtain separate licenses for underlying infrastructure or third-party software as described in Section 38.

32

Third-Party AI Models and Providers

32.1 Use of external models. AI features may send Query text and retrieved context to third-party LLM and embedding providers to generate AI Output or optional embeddings. Providers may change over time without notice.

32.2 Provider terms. Your use of AI features is subject to applicable provider terms and acceptable use policies. Illana selects providers and configurations designed for enterprise SaaS use, but does not control provider model behavior, training data, or policy changes.

32.3 Data handling by providers. Illana configures API integrations to limit retention and training on Customer Data consistent with provider enterprise or zero-retention options where available. You should review current provider documentation for your compliance requirements. Illana does not train its own foundation models on your Vault data (Section 13.2).

32.4 Output variability. Different models may produce different AI Output for the same Query. Illana may switch models for cost, quality, latency, or availability without liability (Sections 14 and 25).

32.5 Enterprise controls. Enterprise Agreements may offer approved provider lists, regional restrictions, or bring-your-own-key arrangements where technically feasible.

32.6 No provider endorsement. Reference to a model provider does not imply partnership or guarantee of suitability for regulated use cases.

33

API Usage and Technical Limitations

33.1 API access. Programmatic access to search and related endpoints requires a valid API Key and compliance with the API documentation. MCP access requires authorized Assistant Client configuration.

33.2 Default rate limits. Unless your Order Form or Enterprise Agreement specifies otherwise, default rate limits apply as follows (subject to change with notice in Documentation):

  • Per API Key: sixty (60) requests per minute and one thousand (1,000) requests per day; and
  • IP backstop: one hundred twenty (120) requests per minute per IP address across API traffic as a abuse-prevention measure.

Exceeding limits may result in throttling, HTTP 429 responses, or temporary suspension. Higher limits may be available on enterprise plans.

33.3 Fair use. You may not use the API to scrape Illana infrastructure, replicate the Services, overload systems, or bypass Access Channel authentication intended for interactive use.

33.4 Query scope and pagination. API and MCP search tools return results scoped to your permissions and may impose row limits, token limits, and timeout thresholds described in Documentation. Large Vaults or broad Queries may require refinement or return partial results.

33.5 Authentication and secrets. API Keys must be kept confidential. Rotate compromised keys immediately. Keys may be revoked by you or Illana for security or policy violations.

33.6 MCP tools. MCP exposes tools such as search for Assistant Clients. Tool schemas, parameters, and behavior are defined in Documentation and may change. Clients must handle errors and respect the same rate and permission constraints as API access.

33.7 Technical limitations. Search planning, entity resolution, sync completeness, optional embeddings, attachment processing, and AI synthesis have inherent limits described in Sections 3, 13–15, and the Documentation. API responses reflect those limits; Illana does not warrant API suitability for every integration pattern.

33.8 Monitoring. Illana may monitor API usage for billing, abuse detection, capacity planning, and security. Anomalous patterns may trigger review or suspension under Section 44.

34

Automation, Agents, and Actions Performed by Illana

34.1 Scope. This Section describes how Illana may perform automated, programmatic, or agent-driven operations in connection with the Services, including background sync, indexing, AI-assisted retrieval, and responses initiated through Access Channels (as defined in Section 2). Unless expressly stated in an Order Form or Enterprise Agreement, Illana's default connectors and integrations are designed for read-only access to Connected Services; Illana does not modify, delete, send, or execute transactions in third-party systems except where you explicitly enable a feature that performs a write or outbound action and you authorize that scope.

34.2 Automated ingestion and processing. When you create a Connection, Illana may automatically retrieve, normalize, index, and store data from Connected Services according to your configuration, connector scopes, and sync schedules. This includes optional background workers described in Section 3.8 (for example, entity extraction, embedding generation, graph linking, and attachment processing). You acknowledge that automated processing may occur without manual review of each item and that processing logic may evolve as we improve the Services.

34.3 AI agents and Assistant Clients. You may authorize Assistant Clients (including MCP-compatible agents, OAuth-linked assistants, and custom automations) to query your Vault, invoke search tools, and receive AI Output on your behalf. Illana acts as an intermediary: it executes queries and returns results according to your authentication, permissions, and rate limits. Illana does not control how third-party Assistant Clients interpret, combine, or act upon AI Output outside the Services.

34.4 Access Channel responses. When you enable Slack, Microsoft Teams, or similar Access Connectors, Illana may automatically respond to authorized commands or mentions by running search against your linked Account and posting replies within the third-party workspace. Such responses are AI-assisted and subject to the accuracy and limitation disclosures in Sections 13–15. Illana does not monitor all workspace conversations unless you explicitly configure features that require it.

34.5 No autonomous decision-making. Except where a specific feature you enable expressly performs an automated action you configure (and then only within the bounds of that configuration), Illana does not make binding legal, financial, employment, medical, or regulatory decisions on your behalf. AI Output and automated summaries are informational tools only. You remain solely responsible for human review and for any action taken based on automated results, as further described in Sections 15, 35, and 52.

34.6 No training on Customer Data. Illana does not use Customer Data stored in your Vault to train generalized artificial intelligence or machine learning models for the benefit of other customers, except as you expressly authorize in writing or as required to provide the Services to you (for example, generating embeddings or indexes scoped to your Account). Aggregated or de-identified usage metrics that cannot reasonably identify you or your Customer Data may be used to improve reliability and security. See also Sections 11–13 and our Privacy Policy.

34.7 Third-party model subprocessors. To generate AI Output, Illana may transmit portions of Customer Data or queries to third-party LLM providers under contractual restrictions. Those providers process data to deliver inference results to Illana and, under our standard configurations, do not retain your Vault content for model training. Third-party AI behavior is further described in Section 32.

34.8 Logging and audit. Depending on your plan, Illana may log API calls, Access Channel invocations, sync events, and administrative actions for security, billing, and troubleshooting. Log retention and audit features vary by Subscription tier and Enterprise Agreement. Logs may contain metadata about automated actions but are not a complete record of your business decisions.

34.9 Changes to automation. We may add, modify, or retire automated features, agent tools, and Access Channel behaviors. Material reductions in core automation for paid plans will be handled consistent with Section 58 and any applicable Enterprise Agreement or SLA.

35

User Authorization for Automated Actions

35.1 Your authorization. By connecting a data source, issuing an API Key, installing an Access Connector, linking an Assistant Client, or otherwise enabling programmatic access, you represent and warrant that you have all rights, consents, and internal approvals necessary for Illana and your Authorized Users to perform automated retrieval, processing, and response actions described in Section 34 on your behalf.

35.2 Scope of OAuth and API grants. You are responsible for reviewing and limiting the scopes, permissions, and credentials you grant to Illana and to third-party Assistant Clients. Read-only connector configurations reduce—but do not eliminate—risk that retrieved data includes sensitive, regulated, or third-party personal information. You must align scopes with your policies and applicable law, including employment, privacy, and sector-specific rules in Sections 47–49.

35.3 Agent and API key custody. API Keys, MCP tokens, OAuth refresh tokens, and workspace installation credentials must be treated as confidential secrets. You must restrict issuance to trusted personnel and systems, rotate or revoke credentials upon compromise or personnel change, and configure least-privilege access consistent with Section 5. Illana may suspend credentials that appear compromised, abusive, or out of policy.

35.4 Organization responsibility. If you are an Organization, Administrators control which users and automations may authorize Connections and Access Channels. You are responsible for internal governance, including approving Assistant Clients that can query Customer Data and ensuring automated workflows comply with your acceptable use rules in Sections 16–17.

35.5 Prohibited delegation. You must not configure automations to:

  1. bypass authentication, rate limits, or access controls of Illana or Connected Services;
  2. exfiltrate Customer Data to unauthorized recipients or public channels;
  3. impersonate individuals without disclosure where required by law or platform policy;
  4. perform unlawful surveillance, harassment, or discrimination; or
  5. execute financial, legal, or HR actions in third-party systems unless you have independently verified authorization and appropriateness.

35.6 Revocation. You may revoke authorization at any time by disconnecting Connections, deleting API Keys, uninstalling Access Connectors, or disabling Assistant Client links. Revocation stops future automated actions but may not immediately delete data already ingested; deletion is governed by Sections 22 and 45–46.

35.7 Indemnity for unauthorized automation. You indemnify Illana for claims arising from automated actions performed at your direction or through credentials you issued, except to the extent caused by Illana's uncured material breach of these Terms, as further described in Section 51.

36

Communication and Notification Features

36.1 Service communications. Illana may send you transactional and operational communications related to the Services, including account verification, security alerts, sync failures, billing notices, connector status, policy updates, and responses to support requests. You consent to receive such communications by email, in-app notification, or other contact methods associated with your Account, as described in Sections 1.10 and 62.

36.2 Marketing communications. With your consent where required by law, we may send product announcements, newsletters, or promotional messages. You may opt out of marketing emails using the unsubscribe mechanism in those messages or by contacting legal@illana.ai. Opting out of marketing does not affect transactional or legally required notices.

36.3 Access Channel replies. When you use Slack, Teams, or similar channels, Illana may post AI-assisted replies visible to participants in the triggering conversation or channel, subject to your workspace configuration. You are responsible for ensuring recipients are authorized to receive the information disclosed in those replies and for redacting or restricting channels that may expose Confidential Information or personal data inappropriately.

36.4 No guarantee of delivery. Email and third-party messaging platforms may delay, filter, or fail to deliver notifications. Illana is not liable for losses arising from undelivered or misdirected communications except as expressly stated in an Enterprise Agreement. Critical security issues should also be reported to security@illana.ai.

36.5 User-configured alerts. If Illana offers configurable alerts (for example, sync errors or usage thresholds), they are provided as a convenience. You must not rely solely on Illana alerts for compliance, security monitoring, or business-critical workflows without independent verification.

36.6 Third-party platform policies. Messages sent through Connected Services or Access Channels remain subject to those platforms' terms, retention rules, and acceptable use policies. Illana does not control how Slack, Microsoft, Google, or other providers store, moderate, or deliver messages.

37

Email, Messaging, and Document Processing Terms

37.1 Read-only email and messaging access. Unless a feature explicitly states otherwise, Illana's email and messaging connectors retrieve content for indexing and search within your Vault. Illana does not send email, calendar invitations, or chat messages on your behalf through those default connectors and does not modify labels, folders, or message state in the source system except as required for technical sync metadata maintained by Illana.

37.2 Document and attachment processing. Illana may download, parse, and index documents and attachments from Connected Services, including text extraction from PDFs, office files, and similar formats. Processing may use automated OCR or AI-assisted parsing. Extracted text may be incomplete or inaccurate; original files remain authoritative. You represent that you have rights to ingest and process such content under Section 29.

37.3 Metadata and headers. In addition to message bodies and file content, Illana may index metadata such as senders, recipients, timestamps, subject lines, calendar attendees, and folder paths to enable search, entity resolution, and temporal filtering described in Section 3.

37.4 Sensitive content. Your Vault may contain legally privileged, confidential, health-related, financial, or personal information depending on what you connect. You are solely responsible for determining whether Illana is appropriate for such content, implementing access controls under Section 7, and complying with restrictions in Sections 47–48. Illana does not provide legal hold, e-discovery, or records-management certification unless expressly agreed in an Enterprise Agreement.

37.5 Third-party mailbox policies. Connected email and messaging providers may impose rate limits, scope restrictions, or policy changes that affect sync completeness or latency. Illana is not responsible for provider-side filtering, encryption limitations, or retention deletions at the source.

37.6 No spam or unsolicited messaging. You must not use the Services to send bulk unsolicited communications or to harvest addresses in violation of CAN-SPAM, GDPR, CASL, or similar laws. Features that post replies in Access Channels must be used only in workspaces and contexts where recipients expect automated responses.

38

Enterprise Deployment and Configuration

38.1 Enterprise offerings. Organizations may purchase enhanced deployment, security, support, and configuration options under an Enterprise Agreement or Order Form. Those agreements may specify dedicated environments, custom domains, single sign-on (SSO), IP allowlists, data residency choices, enhanced audit logs, custom retention, service level commitments, and professional services.

38.2 Configuration responsibility. Even under Enterprise plans, you remain responsible for workspace design, connector policies, user provisioning, Assistant Client approval, and alignment with internal IT and compliance requirements. Illana will configure features you order according to mutually agreed specifications but does not assume responsibility for your overall compliance program.

38.3 Customer-managed credentials. Depending on deployment model, you may supply or rotate certain credentials, certificates, or identity provider settings. You must maintain those elements in good working order and notify Illana promptly of changes that affect integration.

38.4 Precedence of Enterprise Agreement. If an Enterprise Agreement conflicts with these Terms regarding enterprise-specific topics (SLA, support, data processing, security exhibits, or fees), the Enterprise Agreement controls for the named Customer to the extent of the conflict, as stated in Section 1.4.

38.5 Pilot and proof-of-concept deployments. Limited pilots may be governed by separate pilot terms. Unless otherwise stated, pilots use production infrastructure with Beta or evaluation limitations and may be terminated on short notice under Section 39 or 44.

38.6 Change management. Enterprise Customers may request advance notice of material infrastructure or API changes when specified in an Enterprise Agreement. Standard self-serve plans receive notice through Documentation updates and Section 58.

39

Beta Features and Experimental Functionality

39.1 Identification. Beta Features include functionality labeled alpha, beta, preview, experimental, pilot, early access, or similar, and any feature Illana designates as pre-release in Documentation or the admin console. Beta Features may be enabled by default for some accounts or require opt-in.

39.2 As-is evaluation use. Beta Features are provided for evaluation and feedback on an AS IS and AS AVAILABLE basis without the warranties in Section 53 (except where non-waivable by law). They may contain defects, change without notice, or be discontinued at any time.

39.3 No production reliance. You should not rely on Beta Features for production-critical, compliance-critical, or safety-critical workflows unless Illana expressly agrees in writing. Illana disclaims liability for issues arising from Beta Feature use except for death or personal injury caused by negligence where such disclaimer is prohibited.

39.4 Feedback license. Feedback you provide about Beta Features may be used by Illana without restriction under Section 28. Illana may contact you for usability or security follow-up.

39.5 Separate beta terms. Some Beta Features may require acceptance of additional terms. If you accept those terms, they apply to the Beta Feature in addition to this Section and, on conflict regarding the Beta Feature, control over this Section 39.

39.6 Graduation to general availability. When a Beta Feature becomes generally available, it becomes subject to standard Terms and your Subscription plan. Illana may migrate configurations or require re-authorization.

40

Free Trials and Evaluation Accounts

40.1 Trial offers. Illana may offer free trials, evaluation workspaces, or promotional access to paid features for a limited period (a Trial). Trial eligibility, duration, feature limits, and conversion terms are stated at signup or in an Order Form.

40.2 One trial per customer. Unless Illana authorizes otherwise, Trials are limited to one per Customer, organization, or payment instrument. We may refuse or terminate Trials that appear duplicative, abusive, or fraudulent.

40.3 Payment method. Some Trials require a valid payment method. Unless you cancel before the Trial ends, your Subscription may automatically convert to a paid plan at the then-current rates disclosed at signup, subject to Section 41–43.

40.4 Trial limitations. Trials may impose caps on Connections, storage, API usage, seats, or AI query volume. Data ingested during a Trial remains subject to these Terms, including retention and deletion in Sections 22 and 45–46.

40.5 No SLA during Trial. Trials and free evaluation accounts do not include service level commitments unless expressly stated. Availability and support are provided on a commercially reasonable efforts basis.

40.6 End of Trial. When a Trial expires, Illana may suspend access, downgrade features, or require purchase to continue. You are responsible for exporting Customer Data before expiration if you do not convert, as described in Section 46.

41

Subscription Plans and Billing

41.1 Plans and ordering. Illana offers Subscription plans (and optional add-ons) described on our website, in-app checkout, or Order Forms. By subscribing, you order the selected plan for the stated term (monthly, annual, or as specified). Plan features, seat counts, usage limits, and pricing are those in effect at order unless locked by an Enterprise Agreement.

41.2 Account billing contact. You must provide accurate billing contact information and keep payment methods current. Organizations designate Administrators authorized to manage billing under Section 6.

41.3 Upgrades and downgrades. Upgrades may take effect immediately with prorated charges where applicable. Downgrades may take effect at the next renewal and can reduce available features, retention, or limits. You are responsible for adjusting usage and Connections before downgrade to avoid data loss or access issues.

41.4 Auto-renewal. Unless you cancel before the end of the current Subscription term, paid Subscriptions automatically renew for successive periods of the same length at then-current rates (subject to any price protection in an Enterprise Agreement). Renewal charges apply to the payment method on file unless you update billing or cancel under Section 43.

41.5 Usage-based components. Some plans include metered usage (API calls, AI queries, storage, or seats). Overage fees, if any, are disclosed at purchase or in Documentation. We may throttle or suspend usage that substantially exceeds purchased limits to protect platform stability.

41.6 Free and community tiers. Illana may offer free or limited tiers with restricted features. Free tiers may be modified or discontinued with notice under Section 58. Liability for free accounts is capped as stated in Section 52.

41.7 Invoicing for Enterprise. Enterprise Customers may receive invoices with payment terms specified in an Order Form. Late payments may accrue interest and trigger suspension under Sections 42 and 44.

42

Fees, Payments, and Taxes

42.1 Fees. You agree to pay all fees for your Subscription, add-ons, overages, and professional services as quoted at checkout, in an Order Form, or in a renewal notice. Fees are non-refundable except as expressly stated in Section 43 or required by law.

42.2 Payment processing. Payments may be processed by third-party payment providers (such as Stripe). Your use of those services may be subject to the provider's terms. Illana does not store full payment card numbers on its own systems except as permitted by PCI-compliant processors.

42.3 Taxes. Fees are exclusive of taxes, duties, levies, and similar governmental charges (Taxes), except where Illana is required to collect them. You are responsible for all applicable Taxes associated with your purchase, excluding taxes based on Illana's net income. If Illana must withhold Taxes, you will gross up payments unless valid exemption documentation is provided.

42.4 Currency. Unless otherwise stated, fees are quoted and payable in U.S. dollars. Your bank or card issuer may apply conversion fees for non-USD payments.

42.5 Failed payments. If payment fails, we may retry, notify you, and suspend access after a reasonable grace period. You remain liable for unpaid amounts and reasonable collection costs permitted by law.

42.6 Fee changes. We may change standard list prices for self-serve plans on renewal with advance notice under Section 58. Enterprise pricing changes require agreement under the Enterprise Agreement or Order Form.

42.7 Disputes. Billing disputes must be reported in writing to legal@illana.ai within sixty (60) days of the charge. Undisputed amounts remain due.

43

Refunds and Cancellation Policy

43.1 Cancellation by you. You may cancel a self-serve Subscription through account settings or by contacting support. Cancellation is effective at the end of the current prepaid billing period unless otherwise stated at purchase. You will retain access until that date and will not receive a refund for unused time except where required by law or expressly offered.

43.2 Refund policy. Except for Trials converted in error within any stated grace period, or as required by mandatory consumer laws, all fees are final and non-refundable, including partial-month or partial-year periods and unused seats or credits. Enterprise refund terms, if any, appear in the Order Form.

43.3 Chargebacks. Initiating a chargeback without first attempting resolution with Illana may result in immediate suspension and termination under Section 44. You agree to cooperate in good faith to resolve billing errors.

43.4 Effect of cancellation. Cancellation stops future renewals but does not automatically delete Customer Data. Data handling after cancellation is governed by Sections 22, 45, and 46. You remain responsible for fees accrued before cancellation.

43.5 Promotional credits. Promotional or referral credits have no cash value, may expire, and are non-transferable unless stated otherwise. Credits apply only to future fees and do not extend liability caps in Section 52.

44

Suspension and Termination of Accounts

44.1 Termination by you. You may terminate your Account at any time through account settings or by written request to legal@illana.ai. Termination is subject to outstanding fees and the effects in Section 45.

44.2 Suspension by Illana. We may suspend access immediately (with or without notice where permitted) if we reasonably believe:

  1. you breached Sections 16–17 or other material Terms;
  2. your Account poses a security risk or is involved in suspected fraud or abuse;
  3. payment is overdue after notice;
  4. your use threatens platform stability or other customers;
  5. we must comply with law, court order, or third-party platform requirement; or
  6. continued access would expose Illana to undue legal or regulatory liability.

44.3 Termination by Illana. We may terminate your Account upon written notice if:

  1. a material breach remains uncured thirty (30) days after notice (or immediately for incurable breaches such as fraud or illegal use);
  2. required by law or a Connected Service provider;
  3. you become ineligible under Section 4; or
  4. we discontinue the Services generally, in which case we will provide reasonable advance notice and a data export window under Section 46 where feasible.

44.4 Free and Trial accounts. We may suspend or terminate free, Trial, or inactive accounts with shorter notice or none where permitted by law, especially for abuse prevention or cost management.

44.5 Enterprise termination. Termination rights for Enterprise Customers may differ as set forth in an Enterprise Agreement, including termination for convenience, transition assistance, and wind-down periods.

44.6 No liability for suspension. Illana is not liable for damages arising from reasonable suspension or termination permitted by these Terms, subject to Section 52 and any non-waivable rights.

45

Effects of Termination

45.1 Cessation of access. Upon termination or expiration, your right to access the Services ends. API Keys, Access Connectors, and Assistant Client links may be revoked immediately. Active sync from Connections will stop.

45.2 Accrued obligations. Termination does not relieve you of payment obligations for periods before termination, indemnification duties, or confidentiality commitments. Sections that by their nature should survive will survive, including Sections 11, 20, 22 (for retention period), 26–27, 45–46 (for export window), 51–57, 58–66, and other provisions referenced as surviving in Section 1.9.

45.3 Customer Data retention. Following termination, Illana will retain Customer Data only as needed to provide export under Section 46, comply with law, resolve disputes, enforce these Terms, or as stated in our Privacy Policy and Section 22. Thereafter, Illana will delete or de-identify Customer Data in accordance with our deletion procedures, except for encrypted backups that roll off on their normal cycle or archives required by law.

45.4 No refund on termination for cause. If Illana terminates for your material breach, you are not entitled to refunds of prepaid fees except where required by law.

45.5 Third-party connections. You should revoke OAuth grants and uninstall Access Connectors in third-party platforms after termination. Illana is not responsible for continued third-party access you fail to revoke.

46

Data Export and Customer Data Retrieval

46.1 Export rights. Customer owns Customer Data as stated in Section 11. During an active Subscription and for a reasonable period after termination (typically thirty (30) days unless a longer period is specified in an Enterprise Agreement), you may export Customer Data using features we make available (such as API export, bulk download, or support-assisted export for Enterprise plans).

46.2 Export format and completeness. Exports are provided in formats Illana reasonably supports. Exports may not include all derived indexes, embeddings, internal graph structures, or Illana Materials. They are intended to retrieve your substantive Customer Data, not to replicate every internal representation used for search optimization.

46.3 Your responsibility. You are responsible for initiating export before the post-termination window expires and for verifying completeness. Illana is not liable for data loss after expiration of the export window except as prohibited by law or expressly stated in an Enterprise Agreement.

46.4 Fees for assisted export. Standard self-serve export is included where technically available. Custom or large-scale migration assistance may require professional services fees.

46.5 Legal holds. If Illana receives a valid legal hold notice affecting your Account, export or deletion may be delayed for affected data until the hold is released, consistent with Section 22 and applicable law.

46.6 No source-system restoration. Export from Illana does not restore data to Connected Services. Your Vault is a derivative index; authoritative records remain with source providers unless you separately back them up.

47

Compliance With Laws and Regulations

47.1 Your compliance obligations. You are solely responsible for determining whether use of the Services satisfies laws and regulations applicable to you, including privacy, employment, records retention, sector-specific rules, and contractual duties to third parties. Illana provides software tools; it does not provide legal or compliance advice (Section 1.6).

47.2 Lawful use. You will use the Services only for lawful purposes and in compliance with these Terms, Connected Service terms, and Sections 16–17. You will not use the Services to violate intellectual property, privacy, export control, or anti-corruption laws.

47.3 Personal data. Where Customer Data includes personal data subject to GDPR, UK GDPR, CCPA/CPRA, or similar laws, you are the controller (or equivalent) for most processing, and Illana acts as processor/service provider as described in our Privacy Policy and any data processing addendum. You must provide required notices and obtain required consents for ingestion and AI processing.

47.4 Illana compliance program. Illana maintains reasonable administrative, technical, and organizational measures described in Section 18 and our security materials. Illana may update practices to address new legal requirements without materially degrading security.

47.5 Cooperation. Each party will reasonably cooperate with the other regarding lawful requests from regulators or data subjects, subject to confidentiality and Section 62. You will not request Illana to process data in ways that violate law or third-party rights.

47.6 Reporting violations. Notify legal@illana.ai if you believe use of the Services violates applicable law so we can investigate and respond.

48

Industry-Specific Compliance Requirements

48.1 No implied certification. Unless expressly stated in an Enterprise Agreement or Order Form, Illana is not certified, accredited, or designated as compliant with HIPAA, GLBA, PCI-DSS, SOX, FISMA, FedRAMP, ITAR, or other industry-specific frameworks. The Services are general-purpose software not tailored to regulated industries by default.

48.2 Regulated data. You must not ingest or process regulated data categories (such as protected health information, payment card data, or classified information) unless you have determined Illana is appropriate, implemented required safeguards, and executed any required supplemental agreements. Illana may refuse or suspend processing of data it reasonably believes violates this Section.

48.3 Financial data connectors. Connections to financial or accounting platforms (such as Plaid or QuickBooks) retrieve data you authorize for search and analysis. Illana is not a bank, broker-dealer, or money transmitter. You remain responsible for regulatory obligations associated with that data.

48.4 Professional services restrictions. Law firms, healthcare providers, and other regulated professionals must independently assess conflicts, privilege, and client confidentiality before syncing content into a shared Vault or exposing it through Access Channels.

48.5 Enterprise compliance addenda. Organizations requiring business associate agreements, enhanced subprocessors lists, or audit rights may negotiate those in an Enterprise Agreement or DPA. Self-serve plans are governed by standard Terms and Privacy Policy only.

49

International Users and Cross-Border Data Transfers

49.1 Global access. Illana may be accessed from many countries. You are responsible for compliance with local laws where you access or use the Services and where your Authorized Users and data subjects are located.

49.2 Data location. Customer Data may be processed and stored in the United States and other countries where Illana or its subprocessors operate, unless an Enterprise Agreement specifies particular data residency options. Those locations may have different data protection laws than your jurisdiction.

49.3 Transfer mechanisms. Where required, Illana relies on appropriate transfer tools such as Standard Contractual Clauses, UK IDTA addenda, or other lawful mechanisms described in our Privacy Policy and DPA. You authorize transfers necessary to provide the Services.

49.4 Restricted jurisdictions. You must not use the Services if you are located in, or acting on behalf of entities in, countries subject to comprehensive sanctions or export restrictions under Section 50, except as authorized by law.

49.5 Language. These Terms are provided in English. Translations, if any, are for convenience; the English version controls to the extent permitted by law.

49.6 Local mandatory rights. Nothing in these Terms limits non-waivable consumer or employee rights under the laws of your country of residence where applicable.

50

Export Control and Sanctions Compliance

50.1 Export laws. The Services and related technology may be subject to U.S. export control laws, including the Export Administration Regulations (EAR), and economic sanctions programs administered by the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) and similar laws in other jurisdictions.

50.2 Your representations. You represent and warrant that:

  1. you are not located in, organized under the laws of, or ordinarily resident in a country or region subject to comprehensive U.S. sanctions (currently including, without limitation, Cuba, Iran, North Korea, Syria, and the Crimea, Donetsk, and Luhansk regions of Ukraine, as sanctions lists may change);
  2. you are not listed on any U.S. or applicable restricted-party list (such as the SDN List);
  3. you will not use the Services for prohibited end uses under export laws, including nuclear, missile, or chemical/biological weapons proliferation; and
  4. you will not export, re-export, or transfer the Services or technical data except as authorized by law.

50.3 Illana compliance. Illana complies with applicable export and sanctions laws and may block access, terminate Accounts, or refuse transactions where required.

50.4 Government end users. U.S. government end users acquire the Services only with rights specified in these Terms and applicable federal acquisition regulations unless a separate government contract applies.

51

Indemnification

51.1 Your indemnity. To the fullest extent permitted by law, you will defend, indemnify, and hold harmless Illana, its Affiliates, and their officers, directors, employees, and agents (collectively, Illana Indemnitees) from and against any third-party claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising out of or related to:

  1. your Customer Data or AI Output use, including allegation that Customer Data infringes or misappropriates third-party rights;
  2. your breach of these Terms, Connected Service terms, or applicable law;
  3. your Connections, Access Channels, or Assistant Client configurations;
  4. disputes between you and your employees, clients, or data subjects regarding use of the Services; or
  5. negligent or wrongful acts by you or Authorized Users in connection with the Services.

51.2 Procedure. Illana will promptly notify you of a claim subject to indemnification and give you reasonable control of the defense and settlement, provided that you may not settle any claim in a manner that admits fault by or imposes non-monetary obligations on Illana without Illana's prior written consent. Illana may participate with its own counsel at its expense.

51.3 Illana indemnity (IP). Illana will defend you against third-party claims that the Services, when used as authorized, directly infringe a U.S. patent, copyright, or trademark, and pay damages finally awarded or agreed in settlement, provided you notify Illana promptly, give reasonable cooperation, and allow Illana to control the defense. Illana may modify the Services, procure rights, or terminate affected functionality with a refund of prepaid unused fees for that functionality. This Section 51.3 is Illana's sole obligation and your exclusive remedy for IP infringement claims. It does not apply to claims based on Customer Data, combinations with non-Illana products, Beta Features, or modifications not made by Illana.

51.4 Exclusions. Indemnification does not apply to the extent a claim arises from the other party's material breach or where prohibited by mandatory consumer law.

52

Limitation of Liability

52.1 Exclusion of indirect damages. TO THE FULLEST EXTENT PERMITTED BY LAW, NEITHER PARTY NOR ITS AFFILIATES WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOSS OF PROFITS, REVENUE, GOODWILL, DATA (EXCEPT AS EXPRESSLY PROVIDED IN SECTION 46), OR BUSINESS INTERRUPTION, ARISING OUT OF OR RELATED TO THESE TERMS OR THE SERVICES, EVEN IF ADVISED OF THE POSSIBILITY AND EVEN IF A REMEDY FAILS OF ITS ESSENTIAL PURPOSE.

52.2 Liability cap. TO THE FULLEST EXTENT PERMITTED BY LAW, EACH PARTY'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THESE TERMS OR THE SERVICES WILL NOT EXCEED THE GREATER OF: (A) THE AMOUNTS PAID OR PAYABLE BY YOU TO ILLANA FOR THE SERVICES IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO LIABILITY; OR (B) ONE HUNDRED U.S. DOLLARS (US $100.00) IF YOU USE A FREE TIER OR HAVE NOT PAID FEES IN THAT PERIOD.

52.3 Cap scope. The cap in Section 52.2 applies collectively to all claims under these Terms, whether in contract, tort (including negligence), strict liability, or otherwise, and applies to Illana Indemnitees collectively.

52.4 Exceptions. The limitations in Sections 52.1–52.2 do not apply to: (a) your payment obligations; (b) your indemnification obligations under Section 51; (c) either party's breach of Section 20 (Confidential Information) caused by willful misconduct; (d) your violation of Section 26 or Illana's IP rights; or (e) liability that cannot be limited under applicable law (such as death or personal injury caused by negligence, or fraud).

52.5 AI and automation. Without limiting the foregoing, Illana is not liable for decisions you or third-party Assistant Clients make based on AI Output, incomplete sync, or Access Channel replies, as described in Sections 13–15 and 34–35.

52.6 Enterprise carve-outs. Higher liability caps or different exclusions may apply only if expressly stated in a signed Enterprise Agreement.

53

Disclaimer of Warranties

53.1 As-is provision. EXCEPT AS EXPRESSLY STATED IN A SIGNED ENTERPRISE AGREEMENT OR SLA, THE SERVICES, BETA FEATURES, AI OUTPUT, DOCUMENTATION, AND ALL RELATED ILLANA MATERIALS ARE PROVIDED AS IS AND AS AVAILABLE, WITH ALL FAULTS.

53.2 Disclaimer. TO THE FULLEST EXTENT PERMITTED BY LAW, ILLANA DISCLAIMS ALL WARRANTIES, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, QUIET ENJOYMENT, ACCURACY, AND ANY WARRANTIES ARISING FROM COURSE OF DEALING OR USAGE OF TRADE.

53.3 No guarantees. Without limiting Section 53.2, Illana does not warrant that:

  • the Services will be uninterrupted, timely, secure, or error-free;
  • sync will be complete, current, or capture all Connected Service data;
  • AI Output will be accurate, complete, unbiased, or suitable for any purpose;
  • defects will be corrected; or
  • the Services will meet your regulatory or industry requirements without additional measures by you.

53.4 Third-party services. Illana disclaims all responsibility for Connected Services, LLM providers, Access Channel platforms, and other third parties referenced in Sections 1.7, 9, and 32.

53.5 Consumer rights. Some jurisdictions do not allow exclusion of implied warranties. In those jurisdictions, implied warranties are limited to the shortest duration permitted by law.

54

Force Majeure

54.1 Events. Neither party is liable for failure or delay in performance (other than payment obligations) caused by events beyond its reasonable control, including acts of God, natural disasters, war, terrorism, civil unrest, labor disputes, government actions, embargoes, epidemics, failures of public utilities or internet backbone, denial-of-service attacks beyond reasonable mitigation, or failures of third-party hosting, identity, LLM, or Connected Service providers not caused by the affected party's negligence.

54.2 Mitigation. The affected party will use commercially reasonable efforts to mitigate impact and resume performance. If a force majeure event continues for more than sixty (60) days, either party may terminate affected Services upon written notice, with a pro-rata refund of prepaid fees for the terminated portion where applicable under Section 43.

54.3 Notice. The affected party will notify the other party of force majeure events materially affecting the Services when practicable, consistent with Section 62.

55

Dispute Resolution

55.1 Good faith resolution. Before initiating formal proceedings (except for injunctive relief or intellectual property claims), the parties will attempt in good faith to resolve disputes by notifying legal@illana.ai and engaging in discussions for at least thirty (30) days.

55.2 Governing procedures. Disputes not resolved informally are subject to governing law in Section 56 and, for eligible U.S. commercial customers, binding arbitration in Section 57. Consumer and non-U.S. users may have additional rights under mandatory local law that Sections 56–57 cannot override.

55.3 Injunctive relief. Either party may seek temporary or preliminary injunctive relief in court to prevent unauthorized use or disclosure of Confidential Information or infringement of intellectual property rights without first completing informal resolution or arbitration, where permitted by law.

55.4 Time limit. To the extent permitted by law, any claim arising out of these Terms must be brought within two (2) years after the claim accrued, except claims for non-payment which accrue when due.

56

Governing Law

56.1 Choice of law. These Terms and any dispute arising out of or related to them or the Services (whether in contract, tort, or otherwise) are governed by the laws of the State of Delaware, United States of America, without regard to its conflict-of-laws principles that would require application of another jurisdiction's laws.

56.2 U.N. Convention. The United Nations Convention on Contracts for the International Sale of Goods does not apply.

56.3 Mandatory consumer laws. If you are a consumer in a jurisdiction that requires local mandatory consumer protection laws to apply, those laws apply to the extent required, and nothing in this Section 56 deprives you of protections you cannot contractually waive.

56.4 Relationship to arbitration. For disputes subject to Section 57, the Federal Arbitration Act (FAA) governs the interpretation and enforcement of the arbitration agreement, to the extent applicable.

57

Arbitration and Class Action Waiver (if applicable)

57.1 Agreement to arbitrate (U.S. commercial). IF YOU ARE A BUSINESS OR COMMERCIAL USER LOCATED IN THE UNITED STATES, YOU AND ILLANA AGREE THAT ANY DISPUTE, CLAIM, OR CONTROVERSY ARISING OUT OF OR RELATING TO THESE TERMS OR THE SERVICES (A Dispute) WILL BE RESOLVED EXCLUSIVELY BY BINDING INDIVIDUAL ARBITRATION RATHER THAN IN COURT, EXCEPT AS SET FORTH IN SECTIONS 55.3 AND 57.6.

57.2 Arbitration rules. Arbitration will be administered by the American Arbitration Association (AAA) under its Commercial Arbitration Rules (or Consumer Rules if you qualify as a consumer under AAA definitions and applicable law). The seat of arbitration will be Wilmington, Delaware, or another location mutually agreed or ordered by the arbitrator. The arbitrator may conduct proceedings remotely. Judgment on the award may be entered in any court of competent jurisdiction.

57.3 Class and representative waiver. TO THE FULLEST EXTENT PERMITTED BY LAW, YOU AND ILLANA WAIVE ANY RIGHT TO PARTICIPATE IN A CLASS, COLLECTIVE, CONSOLIDATED, OR REPRESENTATIVE ACTION OR ARBITRATION, OR AS A PRIVATE ATTORNEY GENERAL. The arbitrator may award relief only in favor of the individual party seeking relief and only to the extent necessary to resolve that party's individual claim, unless applicable law prohibits such waiver.

57.4 Consumer and non-U.S. users. If you are a consumer or located outside the United States, mandatory laws in your jurisdiction may give you the right to bring claims in local courts or restrict class waivers. Section 57 applies only to the extent not prohibited by those laws. Nothing in this Section limits non-waivable statutory rights.

57.5 Fees. Each party bears its own attorneys' fees unless the arbitrator awards fees to the prevailing party as permitted by applicable law and AAA rules. Illana will not seek attorneys' fees from individual consumers unless the claim is frivolous or brought for an improper purpose, as determined by the arbitrator or court.

57.6 Opt-out. U.S. commercial users may opt out of arbitration by sending written notice to legal@illana.ai within thirty (30) days of first accepting these Terms, including your name, organization (if any), and a clear statement of opt-out. Opt-out does not affect other Terms.

57.7 Severability of arbitration. If Section 57.3 or any portion of this Section 57 is found unenforceable, the remainder still applies to the fullest extent permitted, or the Dispute will proceed in courts specified in Section 56 subject to mandatory law.

58

Changes to These Terms

58.1 Right to modify. Illana may update these Terms to reflect changes in the Services, law, or business practices. The Last updated date at the top of this page indicates the latest revision.

58.2 Notice of material changes. For material changes, we will provide notice by email to your Account contact, in-app notification, or prominent posting on our website at least thirty (30) days before the effective date, except where immediate change is required for legal or security reasons.

58.3 Acceptance. Your continued use of the Services after the effective date constitutes acceptance of updated Terms. If you do not agree, you must stop using the Services and may cancel under Section 43 before the effective date.

58.4 Enterprise customers. Material adverse changes to Enterprise Customers may be governed by notice and change clauses in the Enterprise Agreement. If the Enterprise Agreement is silent, this Section 58 applies.

58.5 Prior versions. Upon request, Illana may provide prior versions of these Terms for reference regarding disputes arising before an update.

59

Assignment and Transfer

59.1 Your assignment. You may not assign, transfer, or delegate these Terms or your Account without Illana's prior written consent, except to a successor in connection with a merger, acquisition, or sale of all or substantially all of your assets, provided the successor assumes these Terms and is not a competitor of Illana without our consent.

59.2 Illana assignment. Illana may assign these Terms to an Affiliate or in connection with a merger, acquisition, corporate reorganization, or sale of assets, with notice to you where required by law.

59.3 Effect. Any prohibited assignment is void. These Terms bind and inure to the parties' permitted successors and assigns.

60

Relationship Between Parties

60.1 Independent contractors. Illana and you are independent contractors. These Terms do not create a partnership, joint venture, agency, franchise, or employment relationship.

60.2 No authority. Neither party may bind the other or make representations on the other's behalf without express written authorization.

60.3 Non-exclusivity. Illana may provide similar services to others, including your competitors, subject to confidentiality obligations in Section 20.

61

No Third-Party Beneficiaries

61.1 No beneficiaries. Except as expressly stated (including Illana Indemnitees under Section 51), these Terms confer no third-party beneficiary rights on any person or entity.

61.2 Connected Services. Third-party platform providers are not parties to these Terms and have no obligations to you under them.

62

Notices and Communications

62.1 To you. Illana may provide notices through email to the address associated with your Account, in-app messages, or posting on our website. Notices are deemed received when sent to your email or made available in-app, except where law requires additional delivery.

62.2 To Illana. Legal and contractual notices to Illana must be sent to legal@illana.ai with a subject line referencing “Legal Notice — Terms.” Security vulnerability reports should go to security@illana.ai.

62.3 Formal service. Where applicable law requires physical service of process, Illana will designate a registered agent for service in Delaware upon request through legal@illana.ai. Illana does not list a street address in these public Terms.

62.4 Updates to contact information. You must keep your notice contact information accurate. Illana is not responsible for notices sent to outdated addresses you failed to update.

63

Entire Agreement

63.1 Integration. These Terms, together with documents incorporated by reference in Section 1.4 (including the Privacy Policy, applicable Order Forms, and Enterprise Agreements), constitute the entire agreement between you and Illana regarding the Services and supersede all prior or contemporaneous understandings on that subject.

63.2 Order of precedence. Conflicts are resolved according to Section 1.4. No reseller, partner, or employee statement modifies these Terms unless in a signed writing by Illana's authorized representative.

63.3 No reliance. Each party acknowledges it has not relied on any representation not expressly set out in these Terms.

64

Severability

64.1 General. If any provision of these Terms is held invalid, illegal, or unenforceable, it will be modified to the minimum extent necessary to make it enforceable, or severed if modification is not possible, without affecting the validity of the remaining provisions.

64.2 Essential terms. If an essential element of the bargain (such as limitation of liability, arbitration, or indemnification) is limited or severed, the parties will negotiate in good faith a replacement provision that preserves the original intent to the fullest extent permitted by law.

65

Waiver

65.1 No implied waiver. Failure or delay by either party to enforce any provision of these Terms is not a waiver of that or any other provision. A waiver is effective only if in a signed writing (email from authorized representatives suffices for Illana).

65.2 Remedies cumulative. Except as expressly stated, remedies under these Terms are cumulative and not exclusive of remedies at law or in equity.

66

Contact Information

66.1 General inquiries. Questions about these Terms, the Services, or your Account may be directed to legal@illana.ai.

66.2 Security. Report security vulnerabilities or incidents to security@illana.ai. See also our Security page.

66.3 Privacy. For data protection questions, see our Privacy Policy and contact details therein.

66.4 Legal notices. Formal legal notices must comply with Section 62.

66.5 Website. Current Terms are published at illana.ai/terms.