Skip to main content

Security & privacy

Security and privacy, with the source for each promise

Everything on this page is set out in our terms of service, privacy policy or AI notice. Each document lists the products it covers and gives the details that differ from one product to another.

Belgian company

Original Media BV, Kalmthout. Belgian law.

Hosted in Europe

Every service provider named, per product, in the privacy policy.

Your conversations

Not used for our own purposes. We require model providers not to train on them.

EU AI Act

A transparency notice under Article 50.

Where your data goes

Our products are hosted in Europe. To generate an answer, your question may be sent to an AI model provider, and some of our service providers are based in the United States. The privacy policy names each provider per product, what it does, and the legal basis for any transfer outside the European Economic Area.

  • Transfers to the United States rely on the EU-US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's standard contractual clauses.
  • We announce a change of sub-processor at least 30 days in advance.
  • We do not sell or trade your data.

Privacy policy, points 6 and 7 →

How we protect it

  • Encrypted connections (TLS) with HSTS.
  • Passwords stored only as a salted, slow derived key (scrypt). We cannot read or recover them.
  • Customer data kept logically separate: every query is confined to the signed-in user and their organisation.
  • Sign-in tokens with a limited lifetime, revoked the moment you change your password.
  • Rate limiting on sign-in attempts.
  • Access to production data only for those who need it.
  • Your card details never reach our servers: payments run entirely at Stripe.

Privacy policy, point 10 →

What happens to your conversations

  • For the content of your conversations we are the processor: we use it to answer you, to secure the service and, on your instruction, to check that the right sources were found.
  • To improve our source libraries and search methods we use only material from which personal data has been removed, or aggregate measurements.
  • We require our AI model providers not to use your input to train their own models.
  • Special categories of personal data, such as health data, are never used for improvement.

Privacy policy, point 4 →

Your data, your control

  • Download your account, conversations, preferences and ratings from the settings.
  • Delete your account and its data from the settings.
  • When a contract ends, you have 30 days to export your data.
  • No advertising cookies. Analytics in the app run only with your consent, which you can withdraw with one switch.
  • The data processing agreement required by Article 28 GDPR is part of the terms (Annex B). There is nothing separate to request.
  • If a personal data breach occurs, we notify you within 48 hours of becoming aware of it.
  • We claim no ownership of the answers the service generates for you.

Privacy policy, points 5 and 9 → Terms of service →

AI you can check

  • The answers are generated by a language model. No human sits between your question and the answer.
  • Each answer comes with references to the documents used, so you can open and verify them.
  • Within its intended purpose, the service is not a high-risk AI system under the AI Act.
  • We take no decisions about you based solely on automated processing. The service answers; a human decides.

AI notice →

Found a vulnerability?

Write to privacy@auryth.ai. We investigate every report and will not take legal action against anyone who researches in good faith, causes no damage, and gives us the chance to fix the issue before disclosing it.

Questions from your compliance team?

Send us your security questionnaire or your questions, and we'll answer them.

Contact us