Legal
Privacy Policy
The short version
- We do not sell your personal information.
- We do not use your content to train AI models.
- Sharing with another person happens only when you grant it, and you can revoke it.
- You can download everything, and you can delete everything.
1. Who is responsible
Axis Align, LLC, a Louisiana company, is the controller of personal data processed through the Services. Contact: privacy@axisalign.life.
Where you use an AxisAlign app to hold information about your clients, candidates or contacts, you are the controller of that information and we process it on your behalf.
2. What we collect
- Account data — name, email address, authentication records, plan and billing status.
- Content you create — whatever you put into an app. Depending on the app this can include health and food logs, budgets and transactions, calendar and email content you connect, contacts and clients, invoices, documents and growing plans.
- Assistant conversations — what you ask Axis and what it answers, plus a record of consequential actions it takes for you.
- Technical data — log data, device and browser information, and error reports, used to keep the Services running and secure.
We practise data minimisation: for example, scanned receipt images are not retained, and location metadata is stripped from photos you upload.
3. Why we process it
- To provide the Services you asked for (performance of a contract).
- To keep them secure, prevent abuse and fix faults (legitimate interests).
- To take payment and meet accounting obligations (contract and legal obligation).
- To send service messages you need, and marketing only where you asked for it (consent, withdrawable at any time).
4. What the shared foundation means for your data
AxisAlign apps read and write to one shared foundation. That is what lets a client you invoice in one app be the same person another app already knows, with no export and no duplicate record.
Two things this does not mean. It does not mean other users can see your records: access is enforced per account at the database level, with row-level security. And it does not mean every app helps itself to everything: an app sees the records its function requires, under your account.
5. Sharing with other people
Care circle (My Axis). You choose who to invite, and you choose category by category what each person can see and what they can do. Access takes effect only when you grant it, and you can revoke it at any time. Revoking stops future access immediately.
Workspaces and teams (Pro Axis and business apps). Where you run more than one business, each has its own profile, books and payout settings, and members are granted access per workspace with a role. Records stay scoped to the workspace they belong to.
Your clients. Where you send an invoice, a booking link or a portal invitation, the recipient sees what that document contains. You control what you send.
6. AI and the Axis assistant
Axis is powered by third-party large language models. When you use it, the content needed to answer your request — your message and the relevant records from your account — is sent to that model provider to generate a response.
- Your content is not used to train models, ours or theirs.
- Axis only ever operates within what your account is permitted to see.
- Requests you do not make are not sent. If you do not use the assistant, nothing goes to a model provider.
- Consequential actions taken on your behalf are recorded so you can review them.
7. Payments
Payments are processed by Stripe. Card numbers and bank details are handled by Stripe and never touch AxisAlign servers; we receive only what we need to show your billing status. Where you connect your own Stripe account to take money from your customers, Stripe is also processing their payment details, under Stripe's terms.
8. Service providers
We use a small number of providers to run the Services, including hosting and database infrastructure, email delivery, payment processing and error monitoring. They act on our instructions, are bound by confidentiality, and receive only what their function requires. A current list is available on request.
9. International transfers
We are based in the United States and our providers may process data there. Where data is transferred from the UK, EEA or Switzerland, we rely on appropriate safeguards, including Standard Contractual Clauses.
10. Retention
We keep your content for as long as your account is open. When you delete your account we delete your content, with a short operational window for backups to age out. We keep the minimum records we are legally required to keep, such as invoices for tax purposes.
11. Your rights
- Download your data, in one click, at any time.
- Delete your account and your data, permanently, at any time.
- Correct information that is wrong.
- Object to or restrict processing based on legitimate interests.
- Withdraw consent for marketing, without affecting anything else.
- Complain to your local data protection authority.
We build to GDPR and CCPA/CPRA principles. We do not sell or share personal information as those laws define it, and we do not discriminate against you for exercising a right. To exercise any of these, email privacy@axisalign.life.
12. Children
The Services are not directed at children under 13, and we do not knowingly collect their personal information. If you believe a child has given us data, email privacy@axisalign.life and we will remove it.
13. Security
Encryption in transit and at rest, per-account isolation with row-level security, secrets held outside the codebase, continuous monitoring and tested deployments with rollback. More detail is on the Security and Trust page. Report a concern to security@axisalign.life.
14. Changes
If we change this policy materially we will notify account holders before the change takes effect, and update the date at the top of this page.
15. Contact
Axis Align, LLC — privacy@axisalign.life for data requests, hello@axisalign.life for anything else.