Privacy
Last updated: 2026-08-27
This explains what Axzura collects, why, who else sees it, and what you can do about it. It describes the product as built — where something is not yet decided, it says so rather than sounding decided.
Who we are
Axzura is operated by TODO: registered company name, TODO: registered address. For anything about this policy or your data, write to privacy@axzura.io.
Where you use Axzura to hold information about other people — your staff, your clients, their contacts — you are the controller of that information and we process it on your behalf, under your instructions.
What we collect
Because you gave it to us
- Your account. Email address and password hash. We never see your password itself.
- Your workspace. Its name, type, industry, team size, timezone and the goals you picked during setup.
- What you put in it. Documents you upload, pages you write, clients, deals, staff records, attendance, leave, salary figures, transactions and invoices.
Because the product produces it
- Extracted text and embeddings. When you upload a document we read its text and store a numeric representation of it so the assistant can find the right passage. This lives in your workspace and is deleted with the document.
- Usage counters. Voice minutes used per month, so the plan allowance can be enforced.
What we do not collect
- Card details. Payments go through Dodo Payments, our merchant of record. Your card never reaches our servers and we cannot see it.
- Your email. If you connect Gmail, Axzura reads threads from Google at the moment you look at them and keeps nothing — no message bodies, subjects, recipients or attachments. Gmail remains the only copy. The exception is an attachment you explicitly choose to save, which then becomes a document in your workspace like any other.
- Third-party tracking. No advertising pixels, no cross-site trackers, no selling of anything to anybody.
Why we are allowed to
To provide the service you asked for, which is the contract between us; to keep it secure and working, which is our legitimate interest; and to meet obligations such as keeping billing records. We do not rely on consent for any of the above, so there is nothing to withdraw — you end the processing by closing the account.
Who else sees it
These are the only third parties involved, and each sees only what its job requires:
- Supabase — hosts the database and file storage. All of your workspace data lives here.
- OpenAI — receives document text, page text and your questions in order to answer them, categorise files and extract dates. Sent through their API, which is not used to train their models.
- Google — only if you connect Gmail, and only to read and send your own mail with the permission you granted. You can revoke it at any time from Settings or from your Google account.
- Dodo Payments — takes payment, holds the card and issues the invoice as merchant of record.
- Resend — delivers transactional email: reminders, invitations, invoices and billing notices.
We do not sell data, share it for advertising, or hand it to anyone else unless the law compels us — and if that happens we will tell you unless we are forbidden from doing so.
Who can see what, inside your workspace
Access is enforced by the database, not only by the interface. Roles are owner, admin, HR and member, and two rules are worth stating because people ask:
- Salary figures are readable only by owners, admins and HR. A member querying the database directly receives an empty column, not a refusal.
- Finance is owners and admins only. HR is deliberately excluded.
How long we keep it
- While your workspace exists — everything in it, because that is the point of it.
- If you cancel — your data stays and becomes read-only. Nothing is deleted for non-payment.
- If you delete the workspace — it and everything in it go, including files in storage. This is not reversible.
- Billing records — kept by Dodo Payments as long as tax law requires, independently of us.
What you can do
- Export. Settings has a one-click JSON export of your whole workspace, available at any time and without asking us.
- Correct or delete. Everything in the product is editable and deletable by someone with the right role.
- Disconnect Gmail. One click in Settings, which also revokes the grant with Google rather than merely forgetting it here.
- Close the account. Deleting the workspace removes the data. Ask us if you also want the login itself erased.
Depending on where you live you may also have the right to object to processing, to restrict it, or to complain to a data protection authority. Write to privacy@axzura.io and we will answer within 30 days.
Security
Data is encrypted in transit and at rest by our hosting provider. Access between workspaces is enforced at the database with row-level security, so a bug in the interface cannot expose one workspace to another. Gmail refresh tokens are encrypted with AES-256-GCM before storage and are readable by no user session, ours included.
No system is perfect. If we discover a breach affecting your data we will tell you and the relevant authority within the time the law requires, and we will tell you what actually happened.
Where your data lives
On Supabase infrastructure in the region chosen for the deployment, with processing by the sub-processors above, some of whom are in the United States. Transfers rely on the standard contractual clauses those providers offer.
Children
Axzura is a business tool and is not intended for anyone under 16. We do not knowingly collect their data.
Changes
If this policy changes in a way that matters, we will email account owners before it takes effect rather than quietly changing the date at the top.