Privacy Policy

Last updated: March 13, 2026

This Privacy Policy describes how AI Exporter and its affiliates ("we", "our" or "us") collect, use, and share information in connection with your use of our websites, services, and applications (collectively, the "Services"). This Privacy Policy does not apply to information our customers may process when using our Services.

We recommend that you read this Privacy Policy in full to ensure you are fully informed. If you have any questions about this Privacy Policy or AI Exporter's data collection, use, and disclosure practices, please contact us at [email protected].

1. DATA CONTROLLER

AI Exporter acts as the Data Controller for the personal data we collect via our Services. For any privacy-related inquiries, you can reach us at: [email protected].

2. INFORMATION WE COLLECT

2.1. Information You Provide

Account Registration: When you register for an account, we may ask for your contact information, including your name and email address.

Payment Data: Payments are processed via our third-party payment processor, Stripe. We do not store your financial account information on our systems, but we may have access to subscriber information through our payment processor.

Communications: If you contact us directly, we may receive additional information about you such as your name, email address, the contents of the message, and any other information you may choose to provide.

2.2. Information We Collect Automatically

As is true of most websites, we gather certain information automatically. This information may include internet protocol (IP) addresses, browser type, internet service provider (ISP), referring/exit pages, operating system, and system-level metrics. We use this data to operate our Services, protect security, provide customer support, and understand how users engage with our Services.

2.3. Conversation Content Processing

We do not store or analyze your conversation content. Your privacy is important to us, and we are committed to protecting your conversation data.

PDF Export Processing: For PDF exports, we send conversation data to our backend API for processing. However, this data is processed only in memory and is not saved or analyzed. Once the PDF generation is complete, the original conversation data is immediately discarded from memory, and the generated PDF file is securely deleted from our servers after you download it.

Other Format Processing (e.g., Markdown, Text, JSON, Docx, Image): For all other export formats, all processing is completed locally in your browser. Your conversation content data is never sent to our servers or any third-party services.

3. HOW WE USE AND PROCESS INFORMATION

We use the information we collect based on:

  • Contractual Necessity: To provide, operate, and maintain our Services.
  • Legitimate Interest: To improve our service, ensure security, prevent fraud, and understand how you use our Services.
  • Consent: Where you have explicitly opted-in (e.g., newsletters or marketing communications). We may also process data to comply with legal obligations.

4. HOW WE SHARE INFORMATION

We may share the information we collect in various ways, including the following:

  • Vendors and Service Providers: We may share information with third-party vendors that provide services on our behalf, such as hosting, analytics, and customer service tools.
  • As Required By Law: We may share information to satisfy any applicable law, regulation, legal process, or governmental request.
  • Business Transfers: Information may be transferred to any potential acquirer, successor, or assignee as part of any proposed merger, acquisition, or sale of assets.
  • With Your Consent: We may share information with your consent.

5. DATA RETENTION, SECURITY & INCIDENT HANDLING

We retain personal information only as long as we have an ongoing legitimate business need to do so (for example, while your account is active). When we have no ongoing legitimate business need, we will either delete or anonymize your data.

We employ a variety of industry-standard security technologies to protect your information. Data Security Incidents: In the event of a data breach, alteration, or loss that may affect your personal information, we will take immediate remedial actions and, where required by applicable law, notify relevant regulatory authorities and affected users promptly.

6. AUTOMATED DECISION-MAKING AND PROFILING

We do not engage in automated decision-making or profiling that produces legal or similarly significant effects on you without human intervention. We will not process your personal information solely through automated means in a way that adversely affects your rights.

7. YOUR PRIVACY RIGHTS

Subject to applicable data protection laws, you have the right to access, correct, update, or request deletion of your personal information. You may also object to processing, ask us to restrict processing, request data portability, or withdraw your consent at any time. We will not discriminate against you for exercising these privacy rights.

You can exercise any of these rights by emailing us at [email protected]. We will respond to all privacy-related requests within a reasonable timeframe (typically 30 days).

8. COOKIES AND TRACKING TECHNOLOGIES

We use cookies and similar tracking technologies to keep you logged in, remember your preferences, and understand how you interact with our Services. As is true of most websites, these essential cookies are necessary for authentication and the core functionality of our platform. Many browsers have an option for disabling cookies; however, if you choose not to accept cookies, certain features—such as maintaining your login session—may no longer work properly for you.

Analytics: We use analytics providers such as Google Analytics and Mixpanel. Google Analytics and Mixpanel use cookies to collect non-identifying information. Google provides some additional privacy options regarding its Analytics cookies at http://www.google.com/policies/privacy/partners/. Mixpanel provides some additional privacy options at https://mixpanel.com/legal/privacy-overview/.

9. CHILDREN'S PRIVACY

Our Services are not designed for, and we do not knowingly collect personal information from, children under the age of 13. If we learn that we have collected information from a child under 13 in violation of applicable laws, we will take steps to delete that information as quickly as possible.

10. INTERNATIONAL DATA TRANSFERS

We operate globally. Your personal information may be transferred to and processed in countries other than your own. When we transfer your personal information across borders, we implement appropriate safeguards to ensure your data receives an adequate level of protection according to applicable privacy laws (such as Standard Contractual Clauses).

11. CHANGES TO THIS PRIVACY POLICY

We may modify this Privacy Policy from time to time. If we make material changes, we will notify you through our Services, by email, or other communication mechanisms before the change becomes effective.

12. CONTACT US

For any requests, questions, or concerns about this Privacy Policy, please contact us at [email protected].

REGULATORY ANNEX

This Regulatory Annex explains how we fulfill our obligations under applicable data protection laws in various jurisdictions. This Annex is supplementary and only applies where the respective laws are applicable.

Appendix A: EU / EEA / UK (GDPR / UK GDPR)

Legal Basis for Processing: We rely on contractual necessity, legal obligations, your consent, and our legitimate interests.

Additional Rights: You have the right to lodge a complaint with a supervisory authority in your country of residence or workplace.

Data Transfers: Transmissions outside the EU/EEA/UK are safeguarded via Adequacy Decisions, Standard Contractual Clauses (SCCs), or the equivalent UK mechanisms (IDTA).

Appendix B: Japan (APPI)

Purpose of Use: We strictly specify and handle personal information within the scope of our disclosed purposes of use.

User Rights: You may request the disclosure, correction, addition, deletion, or suspension of use of your personal information.

Transfers to Third Parties Overseas: We ensure any foreign third party receiving personal data implements continuous security management measures meeting APPI standards.

Appendix C: California, USA (CCPA / CPRA)

Your Rights: You have the Right to Know, Right to Access, Right to Delete, and the Right to Opt-Out of the sale or sharing of your personal info.

No Sale or Sharing: We do not sell your personal information, nor do we share it for cross-context behavioral advertising.

Non-Discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights.

Appendix D: South Korea (PIPA)

Data Delegation and Provision: We clearly stipulate the purpose, scope, and safeguards when entrusting data to third parties, and carefully supervise them.

Cross-Border Transfers: We ensure all cross-border data transfer processes uphold the stringent security measures mandated by PIPA.

Data Breach Notification: In the event of a breach, we take immediate remedial actions and report to the Personal Information Protection Commission (PIPC) and notify affected users as required by PIPA.