Back to home

AskPAi

Privacy Policy

Effective 6 August 2026

This Privacy Policy describes how Exilon S.r.l., Italy (“Exilon,” “AskPAi,” “we,” “us” or “our”) processes personal data in connection with the AskPAi Early Access service.

1. Data Controller

The data controller for the AskPAi service is:

Exilon S.r.l., Italy. Website: askpai.com

Privacy contact: privacy@askpai.com

2. What AskPAi Is

AskPAi is an AI-powered personal assistant designed to operate persistently and interact with services authorized by the user.

AskPAi currently follows a Bring Your Own Key model in which users connect supported third-party AI-model providers using credentials associated with their own accounts.

AskPAi may operate through supported channels including Telegram, WhatsApp, email and other interfaces.

3. Information We Process

Depending on how you configure and use AskPAi, we may process the following information.

Account Data

Including:

  • name;
  • email address;
  • authentication information;
  • account identifier;
  • account settings.

Conversations

We process conversations and instructions you send to AskPAi, including communications through supported interfaces such as Telegram, WhatsApp and other AskPAi interfaces.

Conversation History and Memory

AskPAi may retain conversation history so the assistant can maintain context and provide a persistent personalized experience.

AskPAi may periodically process, summarize, compress, restructure or optimize previously stored conversational information into derived memory or summaries intended to preserve useful context and improve operation of the assistant.

Information from an earlier interaction may therefore continue to be represented in the assistant's persistent memory even after the original conversational context has been compressed, summarized or reorganized.

Connected Email

If you connect a personal Gmail or another supported email account, AskPAi may process information made available under the permissions you authorize, including:

  • sender and recipient information;
  • email addresses;
  • subject lines;
  • message contents;
  • timestamps;
  • thread information;
  • attachments where supported.

Personal Gmail connectors identified as Read Only are configured to allow access to authorized information without allowing AskPAi to modify or delete messages through that connector.

Connected emails may contain personal information relating to people other than the AskPAi user.

AskPAi processes such information only where relevant to providing the functionality requested by the user and subject to applicable data-protection requirements.

Calendar Information

Where authorized, AskPAi may process calendar information including:

  • event names;
  • dates and times;
  • participants;
  • descriptions;
  • locations;
  • meeting links;
  • related metadata.

Other Integrations

AskPAi may process information from other services that you choose to connect, including services such as Slack, GitHub and other supported integrations.

Third-party integration infrastructure currently includes Composio.

The information accessible to AskPAi depends on the permissions granted through each integration.

AI Provider Data

When you connect your own AI-provider account or API credentials, AskPAi may send relevant context to that provider so the AI model can generate responses, reason about requests and assist in performing authorized tasks.

That context may include portions of:

  • your current conversation;
  • conversation history;
  • persistent or derived memory;
  • email or calendar information;
  • information retrieved through a connected service;
  • tool outputs;
  • relevant instructions and context.

The third-party AI provider's own terms, privacy practices, security arrangements, data-use rules and retention practices also apply to its processing.

Technical and Security Information

We may process technical and operational information including:

  • IP address;
  • authentication activity;
  • timestamps;
  • device or browser information;
  • integration activity;
  • AI-agent actions;
  • tool calls;
  • application errors;
  • audit information;
  • security events;
  • infrastructure and diagnostic logs.

4. Why We Process Information

We process personal data where necessary to:

  • create and operate your AskPAi account;
  • provide the persistent AI-assistant service;
  • maintain useful context and memory;
  • execute your instructions;
  • operate integrations you authorize;
  • allow the AI model you select to process appropriate context;
  • send communications through enabled AskPAi functionality;
  • maintain and secure the Service;
  • identify abuse, attacks and security threats;
  • investigate technical failures and security incidents;
  • provide support;
  • comply with applicable legal requirements;
  • establish, exercise or defend legal claims.

6. Data Used for AI Training and Evaluation

Exilon does not use your AskPAi conversation history, connected personal Gmail contents, private connected-service information or persistent assistant memory to train generalized AI models.

Exilon does not currently use this personal content for AI-model evaluation.

AskPAi operates under a Bring Your Own Key model.

Information sent to the third-party AI provider selected by you may therefore be subject to that provider's independent terms, privacy practices, retention settings and data-use policies.

You should review the policies and configuration of the AI provider you choose before connecting it to AskPAi.

7. Credentials and Secrets

AskPAi uses dedicated mechanisms intended to separate supported secrets and credentials from ordinary conversational context.

Where the applicable integration supports it, credentials may be injected into an authorized operation without exposing the underlying credential directly to the AI model.

These protections apply to credentials submitted through supported AskPAi Secrets or credential-management functionality.

If you send a credential directly through ordinary chat, Telegram, WhatsApp, email or another conversational interface, that information may be processed as ordinary conversational content.

Users should therefore use designated AskPAi Secrets functionality wherever available.

8. Cloud Infrastructure

AskPAi is hosted using Amazon Web Services (AWS) infrastructure.

AWS may process information on behalf of Exilon as a service provider or data processor in accordance with applicable agreements and data-protection requirements.

AskPAi may also use other infrastructure, security, authentication, monitoring and communication providers necessary to operate the Service.

9. Composio and Third-Party Connectors

AskPAi currently uses Composio as infrastructure for certain third-party integrations.

When you connect an external service, information and authorization metadata necessary to establish and operate that integration may be processed through the relevant integration infrastructure.

External services such as Google, GitHub, Slack, Telegram, WhatsApp and the AI-model provider selected by you may process personal information according to their own terms and privacy practices.

10. Data Retention

AskPAi is designed to provide persistent memory.

Conversation history and derived assistant memory may therefore be retained while your AskPAi account remains active where this is necessary to maintain context and provide the Service.

AskPAi may periodically summarize, compress, restructure or optimize stored memory. This can create derived representations of information contained in earlier conversations.

Technical, security and audit logs may be retained separately where necessary for security, reliability, abuse prevention, debugging and incident investigation.

We seek to retain personal data only for as long as reasonably necessary for the purposes for which it is processed, subject to applicable legal, security and operational requirements.

If you delete your AskPAi account or submit a valid deletion request, we will delete or de-identify personal information associated with your account unless continued retention is required or permitted for purposes such as:

  • security;
  • fraud or abuse prevention;
  • compliance with legal obligations;
  • dispute resolution;
  • establishment, exercise or defence of legal claims;
  • temporary backup retention.

11. Data Minimisation

AskPAi seeks to configure integrations using permissions appropriate to the relevant functionality and, where possible, minimum necessary access.

During Early Access, we strongly encourage users not to provide or connect information that is unnecessary for the functionality they wish to test.

In particular, users should avoid providing highly sensitive personal, financial or business information unless necessary.

12. Security

AskPAi uses technical and organizational measures intended to reduce the risk of unauthorized access, disclosure, alteration, loss and misuse.

Current controls may include:

  • credential separation;
  • credential injection;
  • connector-level permissions;
  • read-only access for supported connectors;
  • policy enforcement;
  • infrastructure hardening;
  • cloud security controls;
  • logging and monitoring;
  • separation of capabilities.

No software, cloud infrastructure or AI system can guarantee complete security.

AI agents may also be exposed to risks such as prompt injection, malicious third-party instructions, unintended tool use and attempts to cause unauthorized disclosure of information.

Our safeguards are intended to reduce these risks but cannot guarantee that every attack or unintended behavior will be prevented.

13. Payment Information

AskPAi is designed so that supported payment credentials can be handled through designated credential mechanisms rather than being directly exposed to the AI model.

However, AskPAi does not need to know a payment-card number in order to cause a transaction through an account that is already authorized to make purchases.

For example, an external merchant account may contain a stored payment method that can be used without revealing the underlying card number to AskPAi.

Users should not send payment-card information through ordinary conversational interfaces.

During Early Access, users testing purchasing functionality should consider using independent controls such as dedicated virtual or prepaid cards, low spending limits, additional authentication and transaction approval mechanisms.

14. How We Share Personal Data

Personal data may be made available to processors or service providers necessary to operate AskPAi, including:

  • Amazon Web Services;
  • Composio;
  • authentication and infrastructure providers;
  • communication providers;
  • the AI provider selected by the user;
  • third-party services connected at the user's direction.

We may also disclose information where required by applicable law or where reasonably necessary to:

  • investigate security incidents;
  • prevent fraud or abuse;
  • protect users or third parties;
  • protect the AskPAi service or infrastructure;
  • establish, exercise or defend legal claims.

We do not sell your AskPAi conversation history or connected personal content.

15. International Data Transfers

Some service providers selected by Exilon or services independently connected by users may process information outside Italy or the European Economic Area.

Where Exilon is responsible for an international transfer of personal data and applicable law requires safeguards, Exilon uses or will use an appropriate legal transfer mechanism in accordance with applicable data-protection law.

Third-party services independently selected or connected by the user may operate under their own international-transfer arrangements.

16. Your Data Protection Rights

Subject to applicable law, you may have rights including:

  • access to your personal data;
  • correction of inaccurate personal data;
  • deletion;
  • restriction of processing;
  • data portability;
  • objection to certain processing;
  • withdrawal of consent where processing is based on consent.

You may also have the right to lodge a complaint with a competent data-protection supervisory authority.

Requests concerning your personal data can be sent to privacy@askpai.com.

We may need to verify your identity before processing certain requests.

17. Account Deletion

You may request deletion of your AskPAi account and associated personal information by contacting privacy@askpai.com.

Account deletion may not immediately remove limited information retained temporarily in backups or information that Exilon is permitted or required to retain for legitimate security, legal, fraud-prevention, dispute or compliance purposes.

18. Children

AskPAi Early Access is intended only for persons aged 18 or older.

Do not register for or use AskPAi if you are under 18 years old.

19. Changes to This Privacy Policy

AskPAi is evolving during Early Access.

We may update this Privacy Policy as the Service, integrations, infrastructure, applicable law or our data-processing practices change.

Where required by applicable law, we will provide appropriate notice of material changes.

20. Contact

AskPAi is operated by:

Exilon S.r.l., Italy. Website: askpai.com

  • Privacy: privacy@askpai.com
  • Security: security@askpai.com
  • Legal: legal@askpai.com
  • Support: support@askpai.com