We use a small number of cookies to run this site and to count page views. Choose Accept all to allow the optional ones, or Accept essential for only what the site needs. You can change your choice at any time. Learn more

Aiome
Products
Team chatChannels, threads, and direct messages Projects & tasksLists, boards, owners, and due dates SOPs & trainingDocument how the business runs Time offRequests, balances, and team coverage Time trackingClock in, timesheets, and approvals People & orgDirectory, roles, and org chart
See all features Compare plans Talk to sales
Our roadmapWhat we're building next Knowledge baseGuides, how-tos, and answers
Pricing Contact
Login Start free
Team chat Projects & tasks SOPs & training Time off Time tracking People & org See all features
Our roadmap Knowledge base
Pricing Contact Login Start free

Privacy Policy

Last updated August 9, 2026 Effective August 9, 2026 Aiome Systems LLC
Contents
1. The two roles we play 2. Who we are 3. Information we collect 4. Customer Data 5. How we use information 6. AI and machine learning 7. Cookies and tracking 8. How we share information 9. International transfers 10. Data retention 11. Security 12. UK & EU rights 13. US state rights 14. Sale and sharing 15. If your employer uses Aiome 16. Children 17. Changes 18. Contact us

1.The two roles we play

Aiome processes two very different categories of information, and the rules that apply to each are different. When you browse our website, request a demo, or sign your organization up, we determine how that information is used, and this Privacy Policy governs it. When your team submits messages, tasks, and time records within a workspace, we act solely as custodian. Your employer determines what is submitted and what happens to it. We store it securely and process it in accordance with the customer's instructions.

Data protection law distinguishes between the party that determines the purposes and means of processing personal information (a controller, or business under U.S. state law) and the party that processes personal information on that party's instructions (a processor, or service provider). Aiome acts in both capacities, depending on the information in question:

Aiome as controller
Visitors to aiome.io, individuals who contact us or request a demo, the person who creates a workspace, workspace administrators, and billing contacts. We determine how this information is used, and this Privacy Policy governs it in full.
Aiome as processor
All information submitted into a workspace by our customer or its personnel — messages, projects, tasks, SOPs, time entries, time off requests, organizational structure, files, and member profiles. We refer to this information as Customer Data. Our customer is the controller of Customer Data. We process it solely to provide the Service, pursuant to our Data Processing Addendum, and we do not use it for our own purposes.

Section 4 describes what this distinction means in practice, and Section 15 is addressed to individuals whose employer has enrolled them in the Service.

2.Who we are

Aiome is an all-in-one workspace for teams — team chat, projects and tasks, SOPs and training, time tracking, time off, and people and organizational management in a single product. This Privacy Policy applies to aiome.io, the Aiome application, and our sales and support communications (collectively, the Service).

Legal entity
Aiome Systems LLC, a California limited liability company.
Registered address
1401 21st St Ste R, Sacramento, CA 95811, United States. This is our registered address for legal notices and service of process. For privacy requests, please use the contact details in this Section rather than postal mail — email reaches us the same day and begins the response period for your request immediately.
Contact
aiome.io/contact, or [email protected] for privacy requests and legal notices.

3.Information we collect as a controller

This Section describes information for which Aiome is the controller. Customer Data is addressed separately in Section 4.

Information you give us

  • Contact and demo requests. Your name, work email address, company name, team size, and the contents of the message field on our contact form.
  • Account registration. Name, email address, password credentials, and workspace name when you create an Aiome workspace.
  • Billing information. Billing contact, company details, and tax status. We never receive or store your full payment card number — see Section 8.
  • Support and feedback. The contents of support conversations, bug reports, and feature requests that you submit to us.

Information we collect automatically

  • Device and connection data. IP address, browser type and version, operating system, and referring page.
  • Usage data. Which parts of the product are used and when, and not the content contained in them. We use PostHog for this purpose inside the Aiome application only; the separate, much smaller set of statistics we obtain for this website is described in Section 7. PostHog receives a pseudonymous internal identifier for you, the workspace identifier, the names of actions taken, event properties limited to true/false flags, counts and fixed categories, and standard device and browser information. It does not receive your name, your email address, the text of any message, the title or contents of any task, project or SOP, any leave note, any timesheet note, or any file. There is no screen recording, and no automatic capture of the text you click. See Section 7 for how to disable this processing.
  • Error reports. When an error occurs in the application, PostHog records the technical details of the fault and the location in the application at which it occurred, together with browser information and the same pseudonymous identifier. Your content is not transmitted — including message text, notes, or files — although an error report may incidentally contain a record or workspace identifier that appeared in a web address.
  • Server and error logs. Our hosting provider records requests and application errors. These logs may incidentally include IP addresses, account identifiers, and URLs.

Information from others

If a colleague invites you to a workspace, we receive your email address from that colleague in order to send the invitation. We do not purchase personal information from data brokers.

4.Customer Data — information inside a workspace

We do not read your team's messages. We do not mine your workspace to build products, to profile your personnel, or to sell anything. The content belongs to you, your employer controls it, and our access is limited to operating the Service and providing assistance when you request it.

When a customer uses Aiome, its personnel submit content into the workspace. Depending on which parts of the product the customer enables, Customer Data may include:

  • Communications. Chat messages, channel names and membership, and file attachments.
  • Work records. Projects, tasks, assignees, due dates, comments, and SOP and training documents.
  • Time records. Time entries recording when a member started and stopped work and took breaks, any note the member adds to an entry, a reason given for editing an entry, and timesheets with their approval status and any reason given for a decision. Aiome's time tracking records start and stop times only. It does not take screenshots, capture location or GPS data, monitor keystrokes, or measure idle time or activity levels.
  • Time off records. Leave requests, including a leave type, the dates, the approval status, any reason given for a decision, and, where the customer's configuration permits it, a free-text note written by the requesting member. See the warning below.
  • People and org data. Member profiles, job titles, roles and permissions, reporting lines, and organizational structure.

Sensitive information in time off requests

Important. A free-text note attached to a leave request may reveal health information — an illness, a medical procedure, a pregnancy, a disability, or a family emergency. The leave type alone may have the same effect, because a category such as sick leave discloses that a person was unwell. Under the UK GDPR and the EU GDPR this is special category data (Article 9), and several U.S. state privacy laws treat health information as sensitive.

Aiome does not ask for medical information and does not require a reason for any leave request. Where a note is provided, we process it solely as part of hosting the customer's workspace and apply the same access controls as all other Customer Data. The customer, as the employer and controller, is responsible for deciding whether to collect reasons for leave, for establishing a lawful basis for doing so, and for instructing its personnel on what to write. We recommend that customers do not solicit medical detail in this field.

Our access to Customer Data

Aiome personnel do not routinely access the contents of a customer workspace. Access occurs only where it is necessary to: operate and maintain the Service; investigate or remedy a fault, including one the customer has reported; respond to a support request from the customer; or comply with law. Such access is limited to personnel who need it, on a least-privilege basis, and is restricted to the smallest number of people consistent with operating the Service.

5.How we use information

As a controller, we use personal information to:

PurposeUK/EU legal basis
Provide the Service — create and secure accounts, host workspaces, deliver featuresPerformance of a contract
Billing — process subscriptions, invoicing, and taxPerformance of a contract; legal obligation
Service communications — invitations, password resets, security alerts, changes to termsPerformance of a contract; legitimate interests
Support — answer questions and resolve faultsPerformance of a contract; legitimate interests
Security and abuse prevention — detect fraud, abuse, and unauthorized accessLegitimate interests; legal obligation
Improve the Service — understand which features are used, diagnose faultsLegitimate interests
Marketing — send information about Aiome to people who have asked to hear from usConsent, or legitimate interests where permitted
Legal compliance — respond to lawful requests, enforce our terms, establish or defend claimsLegal obligation; legitimate interests

Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights, and you may object at any time (Section 12).

We do not sell personal information, and we do not use Customer Data to build or improve products for anyone other than the customer to whom it belongs.

6.AI and machine learning

As of the date of this Privacy Policy, Aiome does not send Customer Data to any third-party AI or large language model provider, and no AI feature processes the contents of your workspace.

Teams that store employee records are entitled to a direct answer to this question, and we provide one. As of the date of this Privacy Policy:

  • No chat message, task, SOP, time record, leave request, or member profile is transmitted to an AI model provider.
  • No Customer Data is used to train, fine-tune, or evaluate any machine learning model, whether ours or a third party's.
  • No automated decision-making producing legal or similarly significant effects is carried out on any individual.

If this changes

We are developing features that would use third-party AI models to assist teams in working with their own content. If and when any such feature processes Customer Data, we commit that:

  • We will update this Privacy Policy and our Subprocessor List, and give customers advance notice through the subprocessor change procedure in our Data Processing Addendum, before the processing begins.
  • We will contract only with providers whose terms prohibit training on our customers' data. We will not authorize any AI provider to use Customer Data to train its models.
  • We will provide workspace administrators with a control to govern whether these features operate on their workspace.

We separately use AI-assisted tools within our own business operations — for example, for writing and engineering work. Where those tools would process personal information belonging to our customers, they are subject to the same subprocessor controls described above.

7.Cookies and similar technologies

The cookies and similar technologies we use are intentionally limited. This Section describes all of them.

WhatWhereWhyCan it be disabled?
Sign-in cookies In the Aiome application To maintain your authenticated session and keep it secure. These cookies are strictly necessary — without them you cannot use the Service No. Clearing them will sign you out
Your display preferences In the Aiome application To remember choices such as light or dark appearance. Stored on your own device Yes, by clearing your browser storage
Website visitor statistics On aiome.io Our website platform counts page views and the number of distinct visitors to a page, so that we can determine which pages are actually read. It also counts how many people submit our contact form. We do not receive a profile of you, and we do not combine these counts with anything else Yes, through the cookie controls on this site
Product analytics and error reporting In the Aiome application To understand which features are used and to learn about faults. It sets no cookie and stores nothing on your device — the analytics identifier exists only in memory for the length of a single visit Yes, with the analytics opt-out in your account settings

We do not operate advertising pixels or trackers, on this website or in the application. Nothing described in this Section is provided to an advertising network, and we do not build profiles of visitors.

On this website, the statistics described above are produced by the platform that hosts aiome.io, as part of hosting it. They are counts of page views, visitors, and form submissions — not a record of an individual. Where that involves a non-essential cookie, we ask for your consent through the cookie controls on this site before it is set, and you may change your choice at any time.

The Aiome application does not display a cookie banner, for the following reason. The consent rules for cookies apply to storing information on your device. The product analytics described above store nothing on your device — no cookie, no browser storage — so those rules do not apply to them, and we do not ask you to click through a banner that would serve no purpose. The processing itself relies on our legitimate interest in understanding how our own product is used, balanced against your rights as described in Section 5, and you may object at any time using the opt-out in your account settings.

We honor Global Privacy Control (GPC) signals as a valid opt-out of sale and sharing where applicable law requires it.

8.How we share information

We do not sell personal information. We share it only as described in this Section.

Service providers and subprocessors

We use a small number of vendors to operate Aiome — hosting, database and storage, email delivery, product analytics, sign-in protection, support tooling, and payments. Each is bound by a written contract requiring it to protect the information, to process it only on our instructions, and to apply confidentiality and security obligations at least as protective as our own.

Our complete, current list is published at Subprocessors, together with what each vendor does and where it processes data. Workspace administrators are notified before we add a new one.

Payments

Subscription payments are handled by Paddle, which acts as the merchant and seller of record for your purchase — meaning your purchase contract is with Paddle rather than with Aiome. Paddle collects and processes your payment details as an independent controller under its own privacy notice — it is not our subprocessor for that purpose, and Aiome never receives or stores your full card number. We receive confirmation of payment, the billing contact, and limited details such as the card brand and last four digits. Paddle is also responsible for calculating and remitting sales tax and VAT, and your card statement may show Paddle as the seller. See Paddle's Privacy Notice.

At a customer's direction

Where Aiome acts as a processor, we disclose Customer Data as instructed by the customer — including to the customer's own administrators, who can typically view, export, and delete content in their workspace.

Legal and safety

We may disclose information where we believe in good faith that it is required by law, legal process, or a valid governmental request; to enforce our Terms of Service or Acceptable Use Policy; or to protect the rights, property, or safety of Aiome, our customers, or the public. Where we are legally permitted to do so, we will notify the affected customer before disclosing Customer Data in response to a legal request, so that it can seek protective relief.

Business transfers

If Aiome is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. We will give notice before personal information becomes subject to a materially different privacy policy.

9.International data transfers

Aiome is based in the United States and our infrastructure is located there. Your workspace content is stored in the western United States, our application runs on United States infrastructure, and our product analytics are hosted in the eastern United States. If you are in the United Kingdom, the European Economic Area, or another jurisdiction with data transfer restrictions, your information will be transferred to and processed in the United States and other countries where our subprocessors operate. Our Subprocessors page lists the location of each one.

For transfers of UK and EEA personal data, we rely on the European Commission's Standard Contractual Clauses and, for the UK, the UK International Data Transfer Addendum, together with supplementary technical and organizational measures including encryption in transit and at rest. These clauses are incorporated into our Data Processing Addendum, which is available to every customer without negotiation.

You may request further information about our transfer mechanisms, including a copy of the relevant clauses, through aiome.io/contact.

10.Data retention

We retain personal information only for as long as we need it for the purposes described in this Privacy Policy, or for as long as required by law.

InformationRetention
Customer Data in an active workspaceFor as long as the workspace is active, and as directed by the customer
Customer Data after cancellation30 days from the end of the subscription, so that you can export your data or reactivate. After 30 days it is deleted from live systems
Inactive free workspacesRetained. We do not delete a Free workspace because it has become inactive, and we have no plans to do so. If that ever changes we will publish the policy and give notice first
BackupsDeleted data can persist in encrypted backups until those backups expire on our database provider's ordinary rolling cycle, after which it is gone. We do not extend that cycle or keep separate copies of our own
Contact and marketing recordsUntil you unsubscribe or ask us to delete them, and for a reasonable period afterwards to honor your preference
Billing and tax recordsAs required by law, generally seven years
Server and security logsRetained by our hosting provider for the period set by its platform, which is a matter of days to weeks rather than months, and then deleted automatically. We do not archive them
Product analytics eventsRetained by our analytics provider for the period set by its plan, which ranges from 12 months to 7 years. We do not extend it, and we keep no separate copy of these events ourselves

11.Security

We maintain technical and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure, and destruction. These include encryption in transit using TLS 1.2 or higher, encryption at rest using AES-256, role-based access controls enforced in the database itself rather than only in the interface, least-privilege access for Aiome personnel, and an append-only record of every change made to a time entry.

Our Security page describes these measures in detail. If we become aware of a personal data breach affecting Customer Data, we will notify the affected customer without undue delay and in any event within 72 hours of becoming aware of it, as set out in our Data Processing Addendum.

No system is perfectly secure. You are responsible for keeping your account credentials confidential and for the security of the devices you use to access Aiome.

12.Your rights in the UK and EEA

If you are in the UK or the EEA, you have the following rights in relation to personal information for which Aiome is the controller:

  • Access — to obtain a copy of your personal information.
  • Rectification — to have inaccurate information corrected.
  • Erasure — to have your information deleted in certain circumstances.
  • Restriction — to limit how we process your information.
  • Portability — to receive your information in a portable format.
  • Objection — to object to processing based on legitimate interests, and to direct marketing at any time.
  • Withdraw consent — where we rely on consent, at any time, without affecting prior processing.
  • Complain — to your local supervisory authority. In the UK this is the Information Commissioner's Office. We would appreciate the chance to address your concern first.

To exercise a right, contact us at aiome.io/contact or [email protected]. We respond within one month and may extend by two further months for complex requests, telling you if we do. We may need to verify your identity. Exercising these rights is free unless a request is manifestly unfounded or excessive.

If your employer uses Aiome, your rights over the content of that workspace are exercised against your employer, not us — see Section 15.

13.Your rights under US state privacy laws

Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Tennessee, Maryland, Indiana, Kentucky, Rhode Island, and other states with comprehensive privacy laws have rights that may include:

  • To know what personal information we collect, use, disclose, and — where applicable — sell or share.
  • To access and obtain a copy of your personal information in a portable form.
  • To correct inaccurate personal information.
  • To delete personal information we hold about you.
  • To opt out of the sale or sharing of personal information, targeted advertising, and certain profiling.
  • To limit the use and disclosure of sensitive personal information.
  • To appeal a refusal of your request, where your state provides for it. If we deny a request, our response will explain how to appeal.
  • Not to be discriminated against for exercising any of these rights. We will not deny you service, charge a different price, or provide a different quality of service because you exercised a privacy right.

How to submit a request. Use aiome.io/contact or email [email protected]. We will verify your request using the information we already hold about you, and will respond within the period your state's law requires — generally 45 days, extendable once where permitted.

Authorized agents. You may use an authorized agent to submit a request. We will ask for proof of the agent's authority and may ask you to verify your own identity directly.

California "Shine the Light." California residents may request information about disclosures of personal information to third parties for their direct marketing purposes. We do not make such disclosures.

14.Sale, sharing, and targeted advertising

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not process personal information for targeted advertising, and we do not sell or share the personal information of anyone we know to be under 16.

Some state privacy laws define "sale" and "sharing" broadly enough to capture the use of certain advertising and analytics technologies, even where no money changes hands. As of the date of this Privacy Policy, Aiome does not operate advertising pixels or trackers on aiome.io that would constitute a sale or sharing under those definitions.

If that changes, we will update this Section and provide a clearly labelled "Do Not Sell or Share My Personal Information" link in our website footer, honor Global Privacy Control signals as an opt-out, and offer a means to limit the use of sensitive personal information.

Sensitive personal information. We do not collect or process sensitive personal information for the purpose of inferring characteristics about you. Where Customer Data submitted by a customer's personnel happens to contain sensitive information — for example a health-related note in a leave request (Section 4) — we process it only to provide the Service and never for advertising or profiling.

15.If your employer uses Aiome

This Section applies to you if you did not choose Aiome — your employer did. You may never have visited our website or agreed to anything, and you are nonetheless entitled to understand your position.

When an organization signs up for Aiome and adds you to its workspace, your employer is the controller of the information in that workspace and Aiome is only the processor. That distinction has practical consequences for you:

  • Your employer decides what is collected — which features are enabled, whether time off requests ask for a reason, and what your profile contains.
  • Your employer's administrators can see workspace content. Depending on the permissions they configure, that can include messages in channels they belong to, tasks, time entries, and leave records. Aiome does not control who your employer designates as an administrator.
  • Your employer's own privacy notice governs how it uses this information about you, along with your employment agreement and applicable employment law.
  • Requests should go to your employer first. If you want to access, correct, or delete workspace content about you, your employer is the party that can act on it. If you contact us directly, we will refer you to them and assist them in responding, as our Data Processing Addendum requires.

We make the following commitments to you directly: we do not sell your information; we do not use your employer's workspace content for our own purposes; we do not send Customer Data to AI model providers (Section 6); and Aiome's time tracking records only start and stop times — it does not take screenshots, track your location, or monitor your activity (Section 4).

Where Aiome is the controller of information about you — for example the login credentials and profile you maintain to access the Service — the rights in Sections 12 and 13 apply to us directly.

16.Children

Aiome is a business product and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child under 16 has provided us with personal information, contact us and we will delete it. Customers are responsible for ensuring that they do not add members under 16 to their workspace.

17.Changes to this policy

We may update this Privacy Policy as the Service and applicable law change. We will post the revised policy on this page and update the "Last updated" date above.

If a change is material — for example, a new category of personal information, a new purpose, or the introduction of AI processing of Customer Data (Section 6) — we will give notice before it takes effect, by email to workspace administrators, by notice in the Service, or both. Where the law requires your consent for a change, we will obtain it.

We keep prior versions of this Privacy Policy and will provide one on request.

18.Contact us

For any privacy inquiry, to exercise a right, or to send a legal notice:

Contact form
aiome.io/contact — the fastest method of contact, and monitored on business days.
Email
[email protected] — for privacy rights requests and formal legal notices.
Post
Aiome Systems LLC, 1401 21st St Ste R, Sacramento, CA 95811, United States. This is our registered address, used for legal notices and service of process. It is not the quickest way to reach us — for anything time-sensitive, including a privacy request, please use the contact form or email above.

Related documents: Terms of Service · Data Processing Addendum · Subprocessors · Security · Acceptable Use Policy

Aiome

The all-in-one workspace that brings your team — and every tool it runs on — into one place.

Product Team chat Projects & tasks SOPs & training Time off Time tracking People & org Features Pricing
Company Contact Talk to sales
Get started Start free Compare plans
Legal Privacy Policy Terms of Service Data Processing Addendum Subprocessors Security Acceptable Use Refunds & Cancellation Accessibility
© 2026 Aiome Systems LLC. All rights reserved. Aiome Systems LLC · 1401 21st St Ste R, Sacramento, CA 95811