Privacy policy

Last updated 15 September 2026. ahel is built and operated by ahel Technologies OÜ, registered in Estonia. Our infrastructure runs in the European Union.

What we store

Your account (email address, password hash or sign-in tokens), your workspace settings (the providers and tools you connect and the setup you configure), your API keys (stored in a form that cannot be turned back into the key; the full key is shown once and never kept), and run records (which jobs ran and when). If you connect your own provider keys, they are encrypted at rest with a key held separately from the database, and we never display them back.

What we do with the work you run

The instructions and inputs you give your AI are forwarded to the providers and tools you connected so the job can run, and the run is recorded in your history so its receipts stay auditable. We do not sell or share your prompts or results, and we do not use them to train models.

Third parties

Payments are processed by Stripe (we never see card numbers). Transactional email is sent through SendGrid. Work that runs on a provider or tool you connect is subject to that service’s own terms. Every company that handles customer data for us, with its purpose and region, is on the subprocessors page.

We use information about how our services are used to understand usage, troubleshoot problems and improve the product. Optional analytics is controlled through your analytics preferences.

Connected apps and Google user data

When you connect an app to your workspace by signing in with that vendor (Google, GitHub, Slack, Notion and others), the vendor gives ahel an access token for the permissions shown on its consent screen. We store that token encrypted, scoped to your workspace, and use it for one purpose: to carry out the request your own AI client makes on your behalf, at the moment you make it. We do not read, copy or analyse your data in the background, we do not use it to train models, we do not sell it, and we do not share it with anyone except the vendor it came from and the AI client you asked. Disconnecting the app in ahel deletes the token and revokes it at the vendor where the vendor supports revocation; you can also revoke it from your account settings at the vendor at any time.

For Google accounts specifically (Gmail, Google Drive, Google Calendar, Google Sheets): ahel’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never used for advertising, never sold, and is accessed by a person on our side only with your consent, for security purposes, or to comply with the law.

Where data lives

Application data is hosted on infrastructure in the European Union. We retain usage records for as long as your account is active; delete your account and we delete your workspace data.

Your rights

Under the GDPR you can ask for a copy of your data, ask us to correct it, or ask us to delete it. Write to privacy@ahel.ai and we will respond within 30 days. You can also complain to the Estonian Data Protection Inspectorate (AKI).

Cookies

We use essential cookies to keep you signed in. Whichever choice you make, one cookie notes which site or campaign sent you here (the referrer or utm labels of your first visit) for 90 days; it names a source, never a person, and a direct visit writes nothing. Optional analytics cookies, and the device identifier on that first-visit cookie, are used only after you accept analytics. Your choice is saved in this browser for 180 days. We may ask you to renew your choice when our analytics changes. Analytics cookies expire after 180 days of inactivity. You can accept or reject analytics equally, and change your choice using the Analytics preferences button on this page. Rejecting after acceptance stops collection, removes the analytics cookies from this browser and drops the device identifier from the first-visit cookie; the source labels stay. Previously collected data is not deleted by changing this preference.

Data processing agreement (DPA)

If you process personal data through ahel on behalf of your own customers, our GDPR Article 28 data processing addendum applies. It is published in full, and a signed copy on your company’s name is one email to privacy@ahel.ai away.

Questions? ahel.ai · privacy@ahel.ai