Aiome
Products
Team chatChannels, threads, and direct messages Projects & tasksLists, boards, owners, and due dates SOPs & trainingDocument how the business runs Time offRequests, balances, and team coverage Time trackingClock in, timesheets, and approvals People & orgDirectory, roles, and org chart
Compare plans Contact Us
Our roadmapWhat we're building next Knowledge baseGuides, how-tos, and answers
Pricing Contact
Login Start free
Team chat Projects & tasks SOPs & training Time off Time tracking People & org
Our roadmap Knowledge base
Pricing Contact Login Start free

Privacy Policy

Last updated September 1, 2026 Effective August 31, 2026 Aiome Systems LLC
Contents
1. The two roles we play 2. Who we are 3. Information we collect 4. Customer Data 5. How we use information 6. AI and machine learning 7. Cookies and tracking 8. How we share information 9. International transfers 10. Data retention 11. Security 12. UK & EU rights 13. US state rights 14. Sale and sharing 15. If your employer uses Aiome 16. Children 17. Changes 18. Contact us

1.The two roles we play

Aiome processes two very different categories of information, and the rules that apply to each are different. When you browse our website, request a demo, or sign your organization up, we determine how that information is used, and this Privacy Policy governs it. When your team submits messages, tasks, and time records within a workspace, we act solely as custodian. Your employer determines what is submitted and what happens to it. We store it securely and process it in accordance with the customer's instructions.

Data protection law distinguishes between the party that determines the purposes and means of processing personal information (a controller, or business under U.S. state law) and the party that processes personal information on that party's instructions (a processor, or service provider). Aiome acts in both capacities, depending on the information in question:

Aiome as controller
Visitors to aiome.io, individuals who contact us or request a demo, the person who creates a workspace, workspace administrators, and billing contacts. We determine how this information is used, and this Privacy Policy governs it in full.
Aiome as processor
All information submitted into a workspace by our customer or its personnel — messages, projects, tasks, SOPs, time entries, time off requests, organizational structure, files, and member profiles. We refer to this information as Customer Data. Our customer is the controller of Customer Data. We process it solely to provide the Service, pursuant to our Data Processing Addendum, and we do not use it for our own purposes.

Section 4 describes what this distinction means in practice, and Section 15 is addressed to individuals whose employer has enrolled them in the Service.

2.Who we are

Aiome is an all-in-one workspace for teams — team chat, projects and tasks, SOPs and training, time tracking, time off, and people and organizational management in a single product. This Privacy Policy applies to aiome.io, the Aiome application, and our sales and support communications (collectively, the Service).

Legal entity
Aiome Systems LLC, a California limited liability company.
Registered address
1401 21st St Ste R, Sacramento, CA 95811, United States. This is our registered address for legal notices and service of process. For privacy requests, please use the contact details in this Section rather than postal mail — email reaches us the same day and begins the response period for your request immediately.
Contact
aiome.io/contact, or hello@aiome.io for privacy requests and legal notices.

3.Information we collect as a controller

This Section describes information for which Aiome is the controller. Customer Data is addressed separately in Section 4.

Information you give us

  • Contact and demo requests. Your name, work email address, company name, team size, and the contents of the message field on our contact form.
  • Account registration. Name, email address, and workspace name when you create an Aiome workspace. Sign-in uses a one-time code sent to that email address — there is no reusable password.
  • Billing information. Billing contact, company details, and tax status. We never receive or store your full payment card number — see Section 8.
  • Support and feedback. The contents of support conversations, bug reports, and feature requests that you submit to us. If you belong to a paying workspace, opening the Aiome application also identifies you to Featurebase — the tool that hosts help.aiome.io and ideas.aiome.io — so you can message us from those sites. That identification includes your name, email address, a stable profile identifier, and the names of your paying workspaces. Free-only members and visitors are not identified.

Information we collect automatically

  • Device and connection data. IP address, browser type and version, operating system, and referring page.
  • Website page views. Which pages on aiome.io are opened, the referring page, and coarse location, browser, and operating-system information. This is collected by PostHog. If you accept analytics cookies, PostHog can also record the session (clicks, scrolls, and the pages you visit — not the contents of the contact form) and remember you across pages on this site. If you decline, we still count page views without storing a cookie. PostHog does not receive your name, email address, or anything you type into the contact form.
  • Usage data. Which parts of the product are used and when. We use PostHog for this purpose inside the Aiome application only; what we record when someone visits this website is described just above and in Section 7. After you are signed in, PostHog may also record the session — clicks, navigation, and what appears on screen — so we can see where people get stuck. On-screen text, including what you type, is masked before it is recorded. We do not record the sign-in page, and there is no automatic capture of each click as a separate event. PostHog receives a pseudonymous internal identifier for you, the workspace identifier, the names of actions taken, event properties limited to true/false flags, counts and fixed categories, and standard device and browser information. It does not receive your name or your email address as analytics properties, and the readable text of messages, tasks, projects, SOPs, leave notes, and timesheet notes is not captured. Pictures shown in the application, such as images in chat, are hidden before they are recorded. See Section 7 for how to disable this processing.
  • Error reports. When an error occurs in the application, PostHog records the technical details of the fault and the location in the application at which it occurred, together with browser information and the same pseudonymous identifier. Your content is not transmitted — including message text, notes, or files — although an error report may incidentally contain a record or workspace identifier that appeared in a web address.
  • Server and error logs. Our hosting provider records requests and application errors. These logs may incidentally include IP addresses, account identifiers, and URLs.

Information from others

If a colleague invites you to a workspace, we receive your email address from that colleague in order to send the invitation. We do not purchase personal information from data brokers.

4.Customer Data — information inside a workspace

We do not read your team's messages. We do not mine your workspace to build products, to profile your personnel, or to sell anything. The content belongs to you, your employer controls it, and our access is limited to operating the Service and providing assistance when you request it.

When a customer uses Aiome, its personnel submit content into the workspace. Depending on which parts of the product the customer enables, Customer Data may include:

  • Communications. Chat messages, channel names and membership, and file attachments.
  • Work records. Projects, tasks, assignees, due dates, comments, and SOP and training documents.
  • Time records. Time entries recording when a member started and stopped work and took breaks, any note the member adds to an entry, a reason given for editing an entry, and timesheets with their approval status and any reason given for a decision. Aiome's time tracking records start and stop times only. It does not take screenshots, capture location or GPS data, monitor keystrokes, or measure idle time or activity levels.
  • Time off records. Leave requests, including a leave type, the dates, the approval status, any reason given for a decision, and, where the customer's configuration permits it, a free-text note written by the requesting member. See the warning below.
  • People and org data. Member profiles, job titles, roles and permissions, reporting lines, and organizational structure.

Sensitive information in time off requests

Important. A free-text note attached to a leave request may reveal health information — an illness, a medical procedure, a pregnancy, a disability, or a family emergency. The leave type alone may have the same effect, because a category such as sick leave discloses that a person was unwell. Under the UK GDPR and the EU GDPR this is special category data (Article 9), and several U.S. state privacy laws treat health information as sensitive.

Aiome does not ask for medical information and does not require a reason for any leave request. Where a note is provided, we process it solely as part of hosting the customer's workspace and apply the same access controls as all other Customer Data. The customer, as the employer and controller, is responsible for deciding whether to collect reasons for leave, for establishing a lawful basis for doing so, and for instructing its personnel on what to write. We recommend that customers do not solicit medical detail in this field.

Our access to Customer Data

Aiome personnel do not routinely access the contents of a customer workspace. Access occurs only where it is necessary to: operate and maintain the Service; investigate or remedy a fault, including one the customer has reported; respond to a support request from the customer; or comply with law. Such access is limited to personnel who need it, on a least-privilege basis, and is restricted to the smallest number of people consistent with operating the Service.

5.How we use information

As a controller, we use personal information to:

PurposeUK/EU legal basis
Provide the Service — create and secure accounts, host workspaces, deliver featuresPerformance of a contract
Billing — process subscriptions, invoicing, and taxPerformance of a contract; legal obligation
Service communications — invitations, sign-in codes, security alerts, changes to termsPerformance of a contract; legitimate interests
Support — answer questions and resolve faultsPerformance of a contract; legitimate interests
Security and abuse prevention — detect fraud, abuse, and unauthorized accessLegitimate interests; legal obligation
Improve the Service — understand which features are used, diagnose faults, and (after you are signed in) review session recordings in which on-screen text is masked and photos are hiddenLegitimate interests
Understand this website — which pages on aiome.io are visited, and (if you accept) session recordings and heatmaps so we can see where the site is confusingConsent, for cookies and session recordings; legitimate interests, for cookieless page-view counts if you decline
Marketing — send information about Aiome to people who have asked to hear from usConsent, or legitimate interests where permitted
Legal compliance — respond to lawful requests, enforce our terms, establish or defend claimsLegal obligation; legitimate interests

Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights, and you may object at any time (Section 12).

We do not sell personal information, and we do not use Customer Data to build or improve products for anyone other than the customer to whom it belongs.

6.AI and machine learning

As of the date of this Privacy Policy, Aiome does not send Customer Data to any third-party AI or large language model provider, and no AI feature processes the contents of your workspace.

Teams that store employee records are entitled to a direct answer to this question, and we provide one. As of the date of this Privacy Policy:

  • No chat message, task, SOP, time record, leave request, or member profile is transmitted to an AI model provider.
  • No Customer Data is used to train, fine-tune, or evaluate any machine learning model, whether ours or a third party's.
  • No automated decision-making producing legal or similarly significant effects is carried out on any individual.

If this changes

We are developing features that would use third-party AI models to assist teams in working with their own content. If and when any such feature processes Customer Data, we commit that:

  • We will update this Privacy Policy and our Subprocessor List, and give customers advance notice through the subprocessor change procedure in our Data Processing Addendum, before the processing begins.
  • We will contract only with providers whose terms prohibit training on our customers' data. We will not authorize any AI provider to use Customer Data to train its models.
  • We will provide workspace administrators with a control to govern whether these features operate on their workspace.

We separately use AI-assisted tools within our own business operations — for example, for writing and engineering work. Where those tools would process personal information belonging to our customers, they are subject to the same subprocessor controls described above.

7.Cookies and similar technologies

The cookies and similar technologies we use are listed below.

WhatWhereWhyCan it be disabled?
Sign-in cookies In the Aiome application To keep you signed in No. Clearing them signs you out
Support identity In the Aiome application, and on help.aiome.io and ideas.aiome.io (Featurebase) To recognize paying members on help and ideas No
Display preferences In the Aiome application To remember appearance settings Yes, by clearing browser storage
Hosting logs On aiome.io To serve the website No
Website analytics On aiome.io (PostHog) Page views and, if you accept, a cookie and session recordings of this website (not of the Aiome application) Yes. Use the banner, or a Global Privacy Control signal
Contact form On aiome.io (HighLevel) To receive inquiries Leave the contact page
Product analytics In the Aiome application Feature use, error reporting, and session recordings after you are signed in. The analytics identifier is kept in memory and is not written as a cookie Yes, in your account settings

We do not operate advertising pixels or trackers.

This website shows a cookie banner because analytics cookies and website session recordings require consent. Decline still lets us count page views without a cookie.

The Aiome application does not show a cookie banner: product analytics do not set an analytics cookie. You can turn analytics and session recordings off in your account settings. That opt-out does not turn off sign-in or support-identity cookies.

We honor Global Privacy Control (GPC) signals as a valid opt-out of sale and sharing where applicable law requires it.

8.How we share information

We do not sell personal information. We share it only as described in this Section.

Service providers and subprocessors

We use a small number of vendors to operate Aiome — hosting, database and storage, email delivery, product analytics, sign-in protection, support tooling, and payments. Each is bound by a written contract requiring it to protect the information, to process it only on our instructions, and to apply confidentiality and security obligations at least as protective as our own.

Our complete, current list is published at Subprocessors, together with what each vendor does and where it processes data. Workspace administrators are notified before we add a new one.

Mobile information and text messages

No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. Information sharing to subcontractors in support services, such as customer service, is permitted. All other use case categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

Payments

Subscription payments are handled by Paddle, which acts as the merchant and seller of record for your purchase — meaning your purchase contract is with Paddle rather than with Aiome. Paddle collects and processes your payment details as an independent controller under its own privacy notice — it is not our subprocessor for that purpose, and Aiome never receives or stores your full card number. We receive confirmation of payment, the billing contact, and limited details such as the card brand and last four digits. Paddle is also responsible for calculating and remitting sales tax and VAT, and your card statement may show Paddle as the seller. See Paddle's Privacy Notice.

At a customer's direction

Where Aiome acts as a processor, we disclose Customer Data as instructed by the customer — including to the customer's owner and administrators, who can view, export, and delete content in their workspace. Members who are not administrators cannot export the workspace.

Legal and safety

We may disclose information where we believe in good faith that it is required by law, legal process, or a valid governmental request; to enforce our Terms of Service or Acceptable Use Policy; or to protect the rights, property, or safety of Aiome, our customers, or the public. Where we are legally permitted to do so, we will notify the affected customer before disclosing Customer Data in response to a legal request, so that it can seek protective relief.

Business transfers

If Aiome is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. We will give notice before personal information becomes subject to a materially different privacy policy.

9.International data transfers

Aiome is based in the United States and our infrastructure is located there. Your workspace content is stored in the western United States, our application runs on United States infrastructure, and our product analytics are hosted in the eastern United States. If you are in the United Kingdom, the European Economic Area, or another jurisdiction with data transfer restrictions, your information will be transferred to and processed in the United States and other countries where our subprocessors operate. Our Subprocessors page lists the location of each one.

For transfers of UK and EEA personal data, we rely on the European Commission's Standard Contractual Clauses and, for the UK, the UK International Data Transfer Addendum, together with supplementary technical and organizational measures including encryption in transit and at rest. These clauses are incorporated into our Data Processing Addendum, which is available to every customer without negotiation.

You may request further information about our transfer mechanisms, including a copy of the relevant clauses, through aiome.io/contact.

10.Data retention

We retain personal information only for as long as we need it for the purposes described in this Privacy Policy, or for as long as required by law.

InformationRetention
Customer Data in an active workspaceFor as long as the workspace exists, and as directed by the customer
Customer Data after a paid plan is cancelledRetained. Cancelling or downgrading moves the workspace to the Free plan. We do not delete Customer Data because a subscription ended. It stays so it is still there if you upgrade again
Customer Data after the organization is deletedScheduled for 30 days after the owner confirms deletion in Settings → Org Settings. The workspace stays available and the owner can undo until then. After 30 days it is deleted from live systems without undue delay
A deactivated member's data, on the customer's instructionScheduled for 30 days after an administrator confirms the wipe in Settings → Org Settings, during which it can be undone. After 30 days it is deleted from live systems without undue delay. Data of an active member cannot be wiped this way
A member who leaves the workspaceRetained. Leaving from Profile Settings deactivates them — the same as an administrator deactivating them. Their data stays until an administrator schedules a wipe as above, or the organization is deleted
Inactive free workspacesRetained. We do not delete a Free workspace because it has become inactive, and we have no plans to do so. If that ever changes we will publish the policy and give notice first
BackupsDeleted data can persist in encrypted backups until those backups expire on our database provider's ordinary rolling cycle, after which it is gone. We do not extend that cycle or keep separate copies of our own
Contact and marketing recordsUntil you unsubscribe or ask us to delete them, and for a reasonable period afterwards to honor your preference
Billing and tax recordsAs required by law, generally seven years
Server and security logsRetained by our hosting provider for the period set by its platform, which is a matter of days to weeks rather than months, and then deleted automatically. We do not archive them
Product analytics eventsRetained by our analytics provider for the period set by its plan, which ranges from 12 months to 7 years. We do not extend it, and we keep no separate copy of these events ourselves
Website analyticsRetained by PostHog for the period set by its plan, which ranges from 12 months to 7 years — the same as product analytics events. If you decline, there is no lasting cookie; a hash that distinguishes a cookieless visit rotates about once a day, so visits on different days are not stitched together. We do not keep a separate copy

11.Security

We maintain technical and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure, and destruction. These include encryption in transit using TLS 1.2 or higher, encryption at rest using AES-256, role-based access controls enforced in the database itself rather than only in the interface, least-privilege access for Aiome personnel, and an append-only record of every change made to a time entry.

Our Security page describes these measures in detail. If we become aware of a personal data breach affecting Customer Data, we will notify the affected customer without undue delay and in any event within 72 hours of becoming aware of it, as set out in our Data Processing Addendum.

No system is perfectly secure. You are responsible for keeping access to the email address on your account, and to the devices you use to sign in, secure.

12.Your rights in the UK and EEA

If you are in the UK or the EEA, you have the following rights in relation to personal information for which Aiome is the controller:

  • Access — to obtain a copy of your personal information.
  • Rectification — to have inaccurate information corrected.
  • Erasure — to have your information deleted in certain circumstances.
  • Restriction — to limit how we process your information.
  • Portability — to receive your information in a portable format.
  • Objection — to object to processing based on legitimate interests, and to direct marketing at any time.
  • Withdraw consent — where we rely on consent, at any time, without affecting prior processing.
  • Complain — to your local supervisory authority. In the UK this is the Information Commissioner's Office. We would appreciate the chance to address your concern first.

To exercise a right, contact us at aiome.io/contact or hello@aiome.io. We respond within one month and may extend by two further months for complex requests, telling you if we do. We may need to verify your identity. Exercising these rights is free unless a request is manifestly unfounded or excessive.

If your employer uses Aiome, your rights over the content of that workspace are exercised against your employer, not us — see Section 15.

13.Your rights under US state privacy laws

Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Tennessee, Maryland, Indiana, Kentucky, Rhode Island, and other states with comprehensive privacy laws have rights that may include:

  • To know what personal information we collect, use, disclose, and — where applicable — sell or share.
  • To access and obtain a copy of your personal information in a portable form.
  • To correct inaccurate personal information.
  • To delete personal information we hold about you.
  • To opt out of the sale or sharing of personal information, targeted advertising, and certain profiling.
  • To limit the use and disclosure of sensitive personal information.
  • To appeal a refusal of your request, where your state provides for it. If we deny a request, our response will explain how to appeal.
  • Not to be discriminated against for exercising any of these rights. We will not deny you service, charge a different price, or provide a different quality of service because you exercised a privacy right.

How to submit a request. Use aiome.io/contact or email hello@aiome.io. We will verify your request using the information we already hold about you, and will respond within the period your state's law requires — generally 45 days, extendable once where permitted.

Authorized agents. You may use an authorized agent to submit a request. We will ask for proof of the agent's authority and may ask you to verify your own identity directly.

California "Shine the Light." California residents may request information about disclosures of personal information to third parties for their direct marketing purposes. We do not make such disclosures.

14.Sale, sharing, and targeted advertising

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not process personal information for targeted advertising, and we do not sell or share the personal information of anyone we know to be under 16.

Some state privacy laws define "sale" and "sharing" broadly enough to capture the use of certain advertising and analytics technologies, even where no money changes hands. As of the date of this Privacy Policy, Aiome does not operate advertising pixels or trackers on aiome.io that would constitute a sale or sharing under those definitions.

If that changes, we will update this Section and provide a clearly labelled "Do Not Sell or Share My Personal Information" link in our website footer, honor Global Privacy Control signals as an opt-out, and offer a means to limit the use of sensitive personal information.

Sensitive personal information. We do not collect or process sensitive personal information for the purpose of inferring characteristics about you. Where Customer Data submitted by a customer's personnel happens to contain sensitive information — for example a health-related note in a leave request (Section 4) — we process it only to provide the Service and never for advertising or profiling.

15.If your employer uses Aiome

This Section applies to you if you did not choose Aiome — your employer did. You may never have visited our website or agreed to anything, and you are nonetheless entitled to understand your position.

When an organization signs up for Aiome and adds you to its workspace, your employer is the controller of the information in that workspace and Aiome is only the processor. That distinction has practical consequences for you:

  • Your employer decides what is collected — which features are enabled, whether time off requests ask for a reason, and what your profile contains.
  • Your employer's administrators can see workspace content. Depending on the permissions they configure, that can include messages in channels they belong to, tasks, time entries, and leave records. The owner and administrators can also export the workspace, including leave notes. Aiome does not control who your employer designates as an administrator.
  • Your employer's own privacy notice governs how it uses this information about you, along with your employment agreement and applicable employment law.
  • You can leave the workspace yourself from Profile Settings. That deactivates you — the same as an administrator doing it. Your name and history stay. It does not delete the workspace, wipe your data, or close your Aiome login. The owner cannot leave until they transfer ownership to another administrator or delete the organization.
  • Requests should go to your employer first. If you want to access, correct, or delete workspace content about you, your employer is the party that can act on it. You cannot export the workspace yourself. Once your membership is deactivated, an administrator can schedule a wipe of the data held about you in that workspace from Org Settings; that wipe runs after 30 days unless they undo it. If you contact us directly, we will refer you to them and assist them in responding, as our Data Processing Addendum requires.

We make the following commitments to you directly: we do not sell your information; we do not use your employer's workspace content for our own purposes; we do not send Customer Data to AI model providers (Section 6); and Aiome's time tracking records only start and stop times — it does not take screenshots, track your location, or monitor your activity (Section 4).

Where Aiome is the controller of information about you — for example the account and profile you maintain to access the Service — the rights in Sections 12 and 13 apply to us directly.

16.Children

Aiome is a business product and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child under 16 has provided us with personal information, contact us and we will delete it. Customers are responsible for ensuring that they do not add members under 16 to their workspace.

17.Changes to this policy

We may update this Privacy Policy as the Service and applicable law change. We will post the revised policy on this page and update the "Last updated" date above.

If a change is material — for example, a new category of personal information, a new purpose, or the introduction of AI processing of Customer Data (Section 6) — we will give notice before it takes effect, by email to workspace administrators, by notice in the Service, or both. Where the law requires your consent for a change, we will obtain it.

We keep prior versions of this Privacy Policy and will provide one on request.

18.Contact us

For any privacy inquiry, to exercise a right, or to send a legal notice:

Contact form
aiome.io/contact — the fastest method of contact, and monitored on business days.
Email
hello@aiome.io — for privacy rights requests and formal legal notices.
Post
Aiome Systems LLC, 1401 21st St Ste R, Sacramento, CA 95811, United States. This is our registered address, used for legal notices and service of process. It is not the quickest way to reach us — for anything time-sensitive, including a privacy request, please use the contact form or email above.

Related documents: Terms of Service · Data Processing Addendum · Subprocessors · Security · Acceptable Use Policy

Aiome

The all-in-one workspace that brings your team — and every tool it runs on — into one place.

Product Team chat Projects & tasks SOPs & training Time off Time tracking People & org
Company Contact Pricing
Get started Start free Compare plans
Legal Privacy Policy Terms of Service Data Processing Addendum Subprocessors Security Acceptable Use Refunds & Cancellation Accessibility
© 2026 Aiome Systems LLC. All rights reserved. Aiome Systems LLC · 1401 21st St Ste R, Sacramento, CA 95811 · hello@aiome.io · (866) 884-3133