Averroes Privacy Policy

Effective Date: September 2, 2026

Last Updated: September 2, 2026

Introduction

Averroes.ai, Inc. ("Averroes.ai," "we," "our," or "us") values your privacy. This Privacy Policy explains how we collect, use, share, and protect your information when you visit averroes.ai or use any product or service offered by Averroes.ai, including VisionRepo and any other current or future Averroes.ai product (collectively, the "Services"). This policy applies across all Averroes.ai products unless a product-specific privacy notice states otherwise.

Averroes.ai, Inc., 55 E 3rd Ave, San Mateo, CA 94401, USA, is the data controller for personal data collected through our website and for account, billing, and usage data. For Customer Data that our customers upload to the Services, the customer is the controller and Averroes.ai acts as a processor under the terms of our Data Processing Agreement (DPA).

1. Information We Collect

  • Account Information: Name, email, organization, job title, billing details, and account credentials.
  • Customer Data: Data you upload, submit, or generate in any of our Products (Input, Output, datasets, annotations, images, and models).
  • Usage Data: Logs, interactions with the platform, access times, IP address, and device and browser information.
  • Website and Analytics Data: Information collected through cookies, pixels, and similar technologies as described in Section 2.
  • Communications: Information you provide when you contact us, request a demo, or subscribe to our newsletter.
  • Third-Party Integrations: If you connect any of our Products with third-party tools (e.g., cloud storage, enterprise SSO), we collect information from those integrations.

We do not intentionally collect special categories of personal data (such as health, biometric, or political data) and ask that you do not submit such data to us.

2. Cookies, Analytics, and Tracking Technologies

We use the following third-party tools on our website and Services:

ToolPurposeData collectedLegal basis
PostHogProduct analyticsUsage events, page views, feature interactions, session information, device and browser data, IP addressConsent
Microsoft ClaritySession replay and behavioral analytics (heatmaps, session recordings)Clicks, scrolls, mouse movement, page navigation, device and browser data, IP addressConsent
Meta PixelAdvertising and conversion measurementPage views, conversion events, device data, cookie identifiersConsent
LinkedIn Insight TagAdvertising and conversion measurementPage views, conversion events, device data, cookie identifiersConsent
HubSpotForm submissions and CRM analyticsForm data, page views, cookie identifiersConsent (tracking); contract / legitimate interest (form processing)
Strictly necessary cookiesAuthentication, security, session management, remembering your cookie preferencesSession identifiers, security tokensLegitimate interest / contract

Non-essential cookies and tracking tools (all tools listed above except strictly necessary cookies) are only set after you give consent through our cookie banner. You can withdraw or change your consent at any time through the cookie settings link in the website footer. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.

Sensitive fields such as passwords and payment details are masked and are not captured in session recordings.

Microsoft's use of Clarity data is governed by the Microsoft Privacy Statement. Meta and LinkedIn act as independent controllers for data they receive through their tags, and you can manage advertising preferences directly in your Meta and LinkedIn account settings.

3. How We Use Information and Our Legal Bases

PurposeData usedLegal basis (GDPR Art. 6)
Provide, maintain, and operate the ServicesAccount Information, Customer Data, Usage DataPerformance of a contract
Authenticate users and manage accountsAccount Information, Usage DataPerformance of a contract
Process payments and billingAccount Information, billing detailsPerformance of a contract; legal obligation
Security, fraud prevention, and system monitoringUsage Data, Account InformationLegitimate interest (protecting the Services and our users)
Respond to support requests and communicate about updatesAccount Information, CommunicationsPerformance of a contract; legitimate interest
Product analytics and improving user experienceWebsite and Analytics Data, Usage DataConsent
Marketing emails and newslettersAccount Information, CommunicationsConsent (you may unsubscribe at any time)
Advertising measurementWebsite and Analytics DataConsent
Train and improve our AI modelsCustomer Data in anonymized, aggregated, or de-identified form onlyLegitimate interest; governed by the DPA for enterprise customers
Comply with legal obligationsAny category as requiredLegal obligation

Where we rely on legitimate interest, we have assessed that our interests are not overridden by your rights and freedoms. You may object to legitimate-interest processing at any time (see Section 9).

We do not use Customer Data to train models in a form that identifies you, your organization, or any individual. Enterprise customers may exclude their Customer Data from model training entirely under the DPA.

We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.

4. Sharing of Information

We do not sell your personal information. We may share information with:

  • Service Providers: Vendors who process data on our behalf to support hosting and infrastructure (Amazon Web Services), storage, analytics (PostHog, Microsoft Clarity), advertising measurement (Meta, LinkedIn), customer relationship management and email (HubSpot, MailerLite), payments, and security. These providers are bound by contracts that restrict their use of your data.
  • Sign-in Providers: If you sign in or submit a form using Google or Microsoft, those providers receive information about your use of that feature under their own privacy policies.
  • Legal/Regulatory: Where required by law, regulation, court order, or legal process, or to protect our rights, safety, or property.
  • Business Transfers: In case of merger, acquisition, financing, or sale of assets, in which case we will notify you before your data becomes subject to a different privacy policy.
  • With your consent: For any other purpose you direct.

5. Data Ownership & Access

  • You own your Customer Data.
  • You control access to your datasets and Output.
  • Averroes.ai may restrict downloading or exporting Customer Data if subscription fees are unpaid or the subscription has lapsed.
  • You may request deletion of your Customer Data, subject to legal or backup retention requirements.

6. Data Retention

We retain personal data only as long as necessary for the purposes described in this policy:

  • Account Information: For the duration of your account plus up to 90 days after closure, unless a longer period is required by law.
  • Customer Data: While your account is active. Deleted within 90 days of account termination or upon request, except for backup copies which are purged on a rolling basis within 180 days.
  • Usage and security logs: Up to 12 months.
  • Billing and transaction records: 7 years, as required by tax and accounting laws.
  • Analytics data: PostHog and Microsoft Clarity data is retained according to each tool's configured retention period, not exceeding 12 months.
  • Marketing data: Until you unsubscribe or withdraw consent.

When we delete data, we do so securely and consistent with NIST 800-88 standards.

7. Data Security

  • We use industry-standard encryption in transit and at rest.
  • We implement access controls, monitoring, and logging.
  • We require our service providers to maintain appropriate security measures.
  • No system is completely secure; we cannot guarantee absolute security.
  • In the event of a personal data breach that is likely to result in a risk to your rights, we will notify the relevant supervisory authority and affected individuals as required by law.
  • Users are responsible for maintaining backups of their Customer Data.

8. International Data Transfers

We are based in the United States, and your information may be processed in the United States and other countries where we or our service providers operate.

If you are located in the EU, EEA, UK, or Switzerland, we transfer your personal data using one or more of the following safeguards:

  • Standard Contractual Clauses approved by the European Commission (and the UK International Data Transfer Addendum where applicable), which are incorporated into our Data Processing Agreement.
  • Transfer mechanisms maintained by our service providers, including Microsoft, PostHog, Meta, and LinkedIn.

You may request a copy of the relevant safeguards by contacting us.

9. Your Rights

If you are in the EU, EEA, UK, or Switzerland, you have the following rights under the GDPR and UK GDPR:

  • Access: Obtain a copy of the personal data we hold about you.
  • Rectification: Correct inaccurate or incomplete personal data.
  • Erasure: Request deletion of your personal data in certain circumstances.
  • Restriction: Request that we limit processing of your personal data.
  • Objection: Object to processing based on legitimate interest, including direct marketing.
  • Portability: Receive your personal data in a structured, commonly used, machine-readable format.
  • Withdraw consent: Withdraw consent at any time where processing is based on consent, without affecting prior processing.
  • Complaint: Lodge a complaint with your local supervisory authority. A list of EU authorities is available at edpb.europa.eu. In the UK, the authority is the Information Commissioner's Office (ico.org.uk).

If you are a California resident, you have similar rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of the sale or sharing of personal information. We do not sell personal information. Our use of advertising tags may be considered "sharing" under the CPRA; you can opt out through the cookie settings link or by contacting us. We do not discriminate against you for exercising your rights.

To exercise any of these rights, contact us at legal@averroes.ai. We will respond within one month (or 45 days for CCPA requests) and may extend this period where permitted by law. We may need to verify your identity before responding. If you are an employee or user of one of our enterprise customers and your request concerns Customer Data, we may refer your request to that customer as the controller.

10. Children's Privacy

  • The Services are not directed to individuals under 18.
  • We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Changes to Privacy Policy

  • We may update this Privacy Policy from time to time.
  • Updates will be posted on our website with a revised "Last Updated" date.
  • For material changes, we will notify you by email or through a prominent notice on the Services before the changes take effect.

12. Contact Us

For privacy-related questions or to exercise your rights, contact: