Privacy Policy
Last updated: August 26, 2026
This Privacy Policy explains how AISVY, a service of 17145608 Canada Inc. (“we,” “us”), handles information in connection with the AISVY website and application at aisvy.com and the AISVY Connect browser extension (together, the “Service”). By using the Service you agree to this Policy.
1. Information we collect
- Account information. When you sign up, our authentication provider (Clerk) processes your name, email address, and login credentials. We do not store your password.
- Project & script data. The project name, the target website URL you configure, and the demo scripts you author.
- Recording sessions. To record an authenticated demo of a site you control, you may provide a browser session (a Playwright
storageState/ cookies) — via manual paste or the AISVY Connect extension. This is a credential; see “The AISVY Connect extension” and “Security” below. - Render outputs. The video files, captions, and related assets produced from your scripts.
- Billing. If you purchase credits, our payment processor (Stripe) handles your payment details. We never receive or store full card numbers.
- Usage & logs. Standard operational logs (e.g., request metadata, error diagnostics). We redact sensitive values (URLs, tokens) from stored render errors.
- Cookies & analytics on our website. aisvy.com uses strictly necessary cookies for authentication and security (via our auth provider, Clerk), and Google Analytics to understand aggregate site usage and improve the product. We do not use third-party advertising cookies. You can opt out of Google Analytics with Google’s browser add-on.
2. The AISVY Connect browser extension
AISVY Connect is an optional extension that captures a login session for a website you explicitly choose to connect, so AISVY can record a demo of that site on your behalf. Its data handling is deliberately narrow:
- What it accesses. The session for the site you connect and its subdomains — cookies (including the authentication subdomain your identity provider uses, e.g. a Clerk or Auth0 domain), and, for apps that store the session as a token, the connected page’s
localStorageandsessionStoragefor that one origin (size-limited to small entries). All of this only after you click “Capture session” and approve a per-site permission prompt; each target site is an optional permission you grant and can revoke. - What it does not do. It never receives your password (you sign in on the real site), never reads other sites in the background, and includes no content scripts on arbitrary pages. It minimizes what it sends by dropping common analytics/advertising cookies.
- Where it sends data. The captured session is sent only to AISVY, authorized by a one-time, project-scoped token, and stored encrypted (see Security). It is used solely to render the demo you requested.
- Limited use. We comply with the Chrome Web Store Developer Program Policies, including the Limited Use requirements: data obtained via the extension is used only to provide the Service, is not sold, is not used for advertising, and is not transferred except as needed to run the Service or as required by law.
- Revocation. Remove a stored session anytime with “Disconnect” on the project page, and revoke the extension’s site permission in your browser.
3. How we use information
We use information to:
- provide, operate, and secure the Service;
- authenticate you into the app and, using a session you provide, into your own app to record it;
- render, store, and deliver your demo videos;
- process payments and manage render credits;
- diagnose errors and improve reliability; and
- communicate with you about the Service.
We do not sell your personal information, and we do not use your content or captured sessions to train third-party AI models.
4. How we share information (subprocessors)
We share data with service providers strictly to operate the Service:
- Clerk — authentication.
- Neon — managed Postgres database.
- Cloudflare R2 — storage of render outputs.
- Stripe — payments.
- Vercel and Fly.io — application and render-worker hosting.
- OpenAI and ElevenLabs — text-to-speech for narration.
- Google Analytics — aggregate website usage analytics.
We may also disclose information to comply with law, enforce our terms, or protect rights and safety. If we undergo a merger or acquisition, information may transfer subject to this Policy.
5. Data retention
We keep information for as long as your account is active or as needed to provide the Service. Captured sessions persist until you replace or disconnect them, or your project/account is deleted. One-time connect tokens are single-use and expire within ~10 minutes. You can request deletion as described below.
6. Security
Recording sessions are encrypted at rest with AES-256-GCM; data in transit is protected with TLS. The connect handshake uses high-entropy, single-use, project-scoped tokens (stored only as hashes), and the extension never handles your password. No method of transmission or storage is perfectly secure, but we work to protect your data and to give you controls (like Disconnect) to limit exposure.
7. Your rights & choices
Depending on your location, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise these rights, contact us at info@aqmhub.com. You can also disconnect stored sessions and delete projects directly in the app. We will respond within the timeframe required by applicable law.
As a Canadian business, we handle personal information in accordance with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and any other privacy laws that apply to you.
8. International transfers
We are based in Canada and use service providers located in the United States and other countries, so your information may be processed outside your country of residence. Where required, we rely on appropriate contractual and legal safeguards for these cross-border transfers.
9. Children
The Service is not directed to children and is intended for users 16 years or older (18 where required). We do not knowingly collect personal information from children.
10. Changes to this Policy
We may update this Policy from time to time. Material changes will be reflected by the “Last updated” date above and, where appropriate, additional notice.
11. Contact
Questions? Contact info@aqmhub.com.
This document is a good-faith template describing how AISVY actually operates. It is not legal advice. Have qualified counsel review and adapt it before relying on it.