Privacy Policy
1. Who processes your data
Ahaya is operated by 2nd Brain Pte Ltd, a company incorporated in Singapore (“we”, “us”). For personal data under this policy we act as the data controller. Where an organisation — a company, a team or a household — uses Ahaya as a shared space, that organisation is the controller of the client and contact data inside it, and we act as a data intermediary on its behalf.
Registered address: [to be completed: registered office address]. Data protection contact is in section 14.
2. What we collect
2.1 Content you give us
- The records themselves: voice notes and recordings, photos and video, documents you capture or upload, text you type, and email or files you forward in through the share sheet or a connected data source.
- Client and contact profiles: fields you enter yourself, plus fields Ahaya extracts from records and writes to a profile after you confirm them (name, role, company, registration numbers, contact details, compliance dates).
- Your conversations with Ahaya: questions, generated answers, and which records an answer cited.
2.2 Account information
- Email address, display name, space membership and role.
- Password — stored only as an irreversible hash. We cannot see your password.
- Email verification codes and session credentials.
2.3 Device and operational information
- Push tokens, used to deliver task and follow-up reminders through Apple Push Notification service.
- Server logs: request time, endpoint, errors and the diagnostic context needed for troubleshooting and security auditing.
- Audit trail: who changed what and when, so every step can be traced and rolled back.
2.4 Location (optional, off by default)
We only use location when you turn on features such as “remind me when I arrive at the client's building” or the traffic-aware “time to leave” nudge. Geofence evaluation happens on your device. We do not continuously upload or store a location history. You can revoke the permission in system settings at any time; you'll lose those two reminders and nothing else.
2.5 What we don't do
- No advertising, no ad profiling, no data shared with advertisers.
- We do not sell or rent your data.
- No third-party analytics or tracking SDKs embedded in the apps.
3. Why we process it
- To provide the product: storing and retrieving your records, extracting tasks, follow-ups and compliance dates, and answering questions about your own records. Without this there is no product.
- To remind you: push notifications for due tasks, pre-meeting reminders and follow-up signals.
- Security and traceability: login protection, abuse prevention, audit and rollback.
- To communicate with you: necessary account notices and support requests you initiate.
Legal bases: performance of our contract with you, our legitimate interests in operating and securing the service, and your consent where you enable optional features (location, connected data sources).
4. AI processing and model providers
Ahaya understands what you said because record content is sent to a large language model API. That is the core mechanism of the product, so we state it plainly:
- Provider: Google's Gemini API (Google LLC and its affiliates).
- What is sent: the text, audio or image of the record being processed, plus relevant record excerpts retrieved to answer a question.
- Purpose: speech transcription, multimodal extraction (title, summary, people, organisations, action items, keywords), generating vectors for semantic search, and answering questions with citations.
- Not used for training: we call the provider through its paid API. Under the provider's current terms, content submitted this way is not used to train its general models. The provider's official terms govern.
Beyond these model calls, we do not use your records for any other training or analysis in the name of “improving the AI”.
5. Third-party services you connect
If you choose to bind a data source, Ahaya pulls content into your space under the authorisation you grant:
- Google Drive (read-only,
drive.readonly): files in the one folder you designate. Drop a file into that folder and it arrives in your space. We never write to, move or delete anything in your Drive. - Gmail (read-only,
gmail.readonly): mail in your mailbox, from which we extract a title, a summary, the people and things involved, and any follow-up it implies. We cannot send, delete or alter anything. - Outlook and Microsoft 365 mail (read-only permission
Mail.Read): reads the mail in your mailbox, for the same purposes as Gmail. It can't send, delete or change anything. - Lark (Larksuite / Feishu) mail: as above.
- IMAP mailboxes (including iCloud): mail retrieved with the credentials you provide.
Drive and Gmail are authorised separately: connecting your drive does not quietly take mail permission with it, and vice versa. You can revoke either one independently in the app at any time. We then stop pulling new content; records already ingested remain yours to manage.
Google API Services User Data Policy. Ahaya's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use that data solely to provide the features you have asked for within Ahaya. We do not use it for advertising, we do not sell it, and we do not transfer it to third parties except as necessary to provide those features, to comply with applicable law, or with your explicit consent.
No human reads your data. We do not allow anyone to read the mail or files you bring in from Google, unless: (i) we have your affirmative agreement to view the specific content, such as when you ask us to help with it; (ii) it is necessary for security purposes, such as investigating a bug or abuse; (iii) it is required to comply with applicable law; or (iv) the data, including data derived from it, has been aggregated and de-identified for internal operations.
Model processing. Mail and files you bring in from Google are processed through the model interfaces described in section 4, like any other record, for transcription, extraction and cited question answering. That processing is necessary to provide the features you asked for. It is not used to train general models, and not for anything unrelated to those features.
6. Where your data lives
- Backend services and the database run on Google Cloud in Singapore (asia-southeast1).
- Records are stored in our database; the search indexes can be rebuilt from them.
- Attachments and media files are kept in cloud storage in the same region.
- When calling the model API, content may be transmitted to the provider's processing nodes in other jurisdictions.
- Push notifications are delivered via Apple Push Notification service and contain only the necessary alert text.
7. Who can see it inside a space
- Records are either private or shared. A private record is visible only to its author — space administrators cannot see it either.
- Shared records are visible to members of the same space.
- Capture never publishes. A new record never becomes visible to others through some default setting; visibility is something you set explicitly, at capture time or afterwards.
- Public share links: you can turn a record into a public link. Anyone holding that link can read the record without an account; a record with no link cannot be reached from outside. You create the link and you can revoke it at any time, which takes effect immediately.
- Your card page: your digital card has a public URL. Anyone with the link, or who scans the QR code, sees the fields you chose to put on the card. A scan lands in your inbox first and is only written to a profile once you confirm it.
- Our engineers access data only when troubleshooting or when you request support, limited to what is necessary, and such access is logged.
8. When we disclose data
Only in these situations:
- Processors necessary to run the service: the cloud and model providers listed above, which process data only on our instructions under contract.
- Legal requirements: where compelled by valid legal process. Where the law permits, we will notify you first.
- Corporate change: in a merger, acquisition or transfer of assets, data may transfer as part of those assets, and the recipient must honour this policy. We will tell you in advance.
9. Retention, export and deletion
- Retention: records are kept until you delete them or your space ends its use of the service.
- Trash: deleted records go to a recycle bin and can be restored. Once purged from the bin they cannot be recovered.
- Export: in the app's Settings you can export your account information — sign-in methods, the spaces you belong to, your personal space and so on — but not the content of your records. Export of all your records is still being built; we'll describe it here once it's available.
- Account closure: email us to request deletion of your account and all data. After verifying your identity we complete deletion within 30 days; residual copies in logs and backups are removed on their normal rotation cycle.
- Audit trail: for traceability, audit entries are retained for a period after the corresponding record is deleted, but they do not contain the body of deleted content.
10. Your rights (Singapore PDPA)
Under the Personal Data Protection Act and other applicable law, you may:
- ask what personal data we hold about you, and how it has been used or disclosed in the past year;
- ask us to correct inaccurate personal data;
- withdraw consent you previously gave (some features may stop working);
- request deletion, or object to our processing.
Email [email protected] to exercise any of these. We respond within 30 days; if we need longer we will tell you why and when to expect an answer.
11. Security
- TLS in transit; server-side storage in a controlled cloud environment with provider-managed disk encryption.
- Passwords stored only as irreversible hashes; session tokens carried in HttpOnly cookies.
- Face ID lock available on iOS; local credentials kept in the system keychain.
- Sensitive changes enter the audit trail.
No system is perfectly secure. If a security incident affects your data, we will notify you and the relevant authorities within the timeframes the law requires.
12. Children
Ahaya is not offered to people under 16, and we do not knowingly collect personal data from minors. Where a household space contains information about minors, the adult who created that space is responsible for it.
13. Changes to this policy
When we update this policy we change the “last updated” date at the top of this page. For material changes we will also notify you in the app or by email.
14. Contact us
Questions about data protection, rights requests and complaints all go to
[email protected].
2nd Brain Pte Ltd, Singapore.
If you are not satisfied with our response, you may complain to Singapore's Personal Data Protection Commission (PDPC).