Where your data ends up
Security, transparency, and regulatory compliance. Every technical decision is made to protect your data.
Our principles
Three fundamental pillars guide every decision we make about data management.
Your Data Never Used for Training
Your conversations are NEVER used to train AI models. We use third-party APIs that guarantee the same commitment.
Real deletion
When you ask to delete your data, we really delete it. No tricks, no hidden backups, no secret retention.
You're in Control
Export all your data at any time. Clear companion memory. Delete your account. Control is always yours.
- Servers in Europe
- No training on your data
- Permanent deletion
Technical security
Concrete implementations to protect your data at every level.
TLS/HTTPS Encryption
All data in transit is protected with TLS encryption. Insecure connections are automatically redirected.
Secure passwords
Passwords are always encrypted. We never store passwords in plain text, not even in logs.
JWT Authentication
Secure session tokens with automatic expiration. Google OAuth support for even more secure access.
Servers in Europe
Your data is stored on servers in Europe. No unnecessary transfers to non-EU countries.
Row Level Security
Every database query is filtered at the row level. It's technically impossible to access other users' data.
Secure OAuth Tokens
Tokens for Outlook and Calendar are encrypted at rest. Automatic refresh ensures always valid sessions.
Regulatory compliance
Full compliance with European data protection and artificial intelligence regulations.
GDPR
- Right to access your data (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure (Art. 17)
- Right to portability (Art. 20)
- Documented legal basis for each processing
- DPA with all sub-processors
AI Act
- Clear disclosure: companions are AI, not humans
- No emotional or behavioral manipulation
- System classified as low risk
- Transparency about models used
- No social scoring or surveillance
- Complete technical documentation
What We DON'T Do
Explicit commitments about practices we will never adopt.
- We don't sell your data to third parties
- We don't show ads in the service
- We don't use your data to train AI
- We don't track your external browsing
- We don't share data with data brokers
- We don't create profiles for third-party marketing
- We don't retain data after requested deletion
- We don't access your email content without explicit OAuth
What Insieme.AI cannot do
The limits of the service, written down before you need them.
- Does not provide medical diagnoses or health advice
- Does not replace professional psychological therapy
- Does not make financial or legal decisions for you
- Does not access your accounts without explicit OAuth permission
- Does not handle medical or safety emergencies
- Does not replace real human relationships
In an emergency always contact emergency services (112) or a qualified professional.
What we keep, and for how long
What we collect, why, and for how long.
- Email and name
- Identification and communications
- Retention: Until account deletion
- Conversations
- Chat history and AI context
- Retention: Until account deletion
- Uploaded documents
- RAG system for responses
- Retention: Until user deletion
- Notes and reminders
- Personal organization
- Retention: Until user deletion
- Memories
- AI response personalization
- Retention: Until user deletion
- OAuth tokens
- Email/calendar access
- Retention: Until disconnection
- Usage statistics
- Limits and monitoring
- Retention: Daily reset
- AI usage logs
- Cost monitoring and plan limits
- Retention: 12 months
- Proactive message logs
- Deduplication and quality
- Retention: 12 months
- Transcribed audio
- Voice commands
- Retention: Not retained
Because together is better.
One companion on the free plan, no credit card. Your data stays yours, in Europe.