Last updated: May 6, 2026
This Privacy Policy describes how Aliza ("we," "us," or "our") collects, uses, stores, and protects your information when you use the Aliza platform available at agentaliza.com and any related services (collectively, the "Service"). This Privacy Policy is incorporated into and subject to our Terms of Service.
By accessing or using the Service, you consent to the data practices described in this Privacy Policy. If you do not agree with the practices described herein, you must not use the Service.
1. Information We Collect
We collect the following categories of information:
1.1 Account Information
- Email address (used as your login identifier)
- Password (hashed and salted — we never store plaintext passwords)
- Account creation date
1.2 Email Credentials
When you connect your email inbox to the Service, we collect and store:
- Your email address for the connected account
- IMAP/SMTP server credentials (encrypted at rest using Fernet symmetric encryption)
- OAuth2 access and refresh tokens (for Gmail and Microsoft/Outlook providers)
These credentials are used exclusively to monitor incoming student emails and send approved responses on your behalf. We do not access, read, or store any emails unrelated to the Service's core function of processing student questions.
1.3 Course Materials (User Content)
- Documents, PDFs, videos, transcripts, and other files you upload
- Text content extracted from uploaded files for AI processing
- Vector embeddings generated from your content (used for AI retrieval)
1.4 Student Questions and AI Responses
- Email content of student questions received through your connected inbox
- Student email addresses (the sender of questions)
- AI-generated draft responses
- Your approval, edit, or rejection actions on draft responses
1.5 Payment Information
- Subscription status and plan type
- Stripe customer ID and subscription ID
We do not store your credit card number, CVV, or full payment card details. All payment processing is handled by Stripe, Inc. and is subject to Stripe's Privacy Policy.
1.6 Automatically Collected Information
- IP address
- Browser type and version
- Device information
- Pages visited and actions taken within the Service
- Timestamps of access
2. How We Use Your Information
We use the information we collect for the following purposes:
- Providing the Service: Processing student questions, generating AI draft responses, and delivering them through your email
- Account Management: Creating and managing your account, authenticating your identity, and communicating with you about your account
- AI Processing: Indexing your uploaded course materials to generate contextually relevant responses to student questions using retrieval-augmented generation (RAG)
- Payment Processing: Managing subscriptions, processing payments through Stripe, and maintaining billing records
- Service Improvement: Analyzing usage patterns to improve the Service's features, performance, and reliability
- Security: Detecting, preventing, and addressing fraud, abuse, security vulnerabilities, and technical issues
- Legal Compliance: Complying with applicable laws, regulations, legal processes, or governmental requests
3. How We Process Your Email Data
When you connect your email to Aliza, the Service accesses your inbox to identify and retrieve emails that are student questions directed at your courses. Specifically:
- We only read emails received after you connect and activate the Service
- We process the subject line and body of incoming emails to classify whether they are student questions
- Non-question emails are ignored and not stored
- Student questions and their metadata (sender email, timestamp) are stored to provide the Service
- AI-generated draft responses are stored until you approve, edit, or reject them
- Approved responses are sent through your connected SMTP credentials — the reply comes from your email address, not ours
You can disconnect your email at any time through your account settings, which immediately stops all email monitoring and processing.
4. Data Sharing and Third Parties
We do not sell, rent, or trade your personal information. We share data only with the following categories of third-party service providers who assist us in operating the Service:
- AI Processing Providers: We send text content from your uploaded materials and student questions to AI inference providers to generate draft responses. This data is sent for processing only and is not used by these providers to train their models.
- Cloud Infrastructure: Your data is stored on cloud hosting and database services that maintain industry-standard security certifications.
- Payment Processing: Stripe processes your payment information. We share only the minimum information necessary to process transactions (email, subscription details).
- Email Providers: When sending approved responses, we connect to your email provider's SMTP servers using your credentials. We do not share your data with email providers beyond what is necessary to deliver messages.
We may also disclose your information if required by law, court order, subpoena, or governmental request, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
5. Data Security
We implement reasonable administrative, technical, and physical security measures to protect your information, including:
- Fernet symmetric encryption (AES-128-CBC with HMAC-SHA256 authentication) for all stored email credentials at rest
- TLS/SSL encryption for all data in transit
- Hashed and salted passwords (never stored in plaintext)
- OAuth2 token-based authentication where supported by email providers
- Access controls limiting data access to authorized systems only
- Regular security reviews of our infrastructure
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee its absolute security. You use the Service at your own risk, and we are not responsible for unauthorized access resulting from factors beyond our reasonable control.
6. Data Retention
We retain your information for as long as your account is active or as needed to provide the Service. Specifically:
- Account Data: Retained until you delete your account
- Email Credentials: Retained until you disconnect your email or delete your account
- Uploaded Materials: Retained until you delete them or delete your account
- Student Questions and Responses: Retained until you delete your account
- Payment Records: Retained as required for tax and accounting purposes (typically 7 years)
Upon account deletion, we will deactivate your account and begin the process of removing your personal information. We aim to delete or anonymize your data within a commercially reasonable timeframe, except where retention is required by law or for legitimate business purposes (e.g., resolving disputes, enforcing agreements, or complying with legal obligations).
7. Your Rights and Choices
Depending on your location, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate personal information
- Deletion: Request deletion of your personal information (subject to legal exceptions)
- Data Portability: Request a machine-readable copy of your data
- Opt-Out: Disconnect your email at any time to stop data processing
- Withdraw Consent: Where processing is based on consent, you may withdraw consent at any time
To exercise any of these rights, contact us at support@agentaliza.com. We will respond to valid requests within 30 days. We may need to verify your identity before processing certain requests.
8. California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to Know: You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you
- Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions
- Right to Opt-Out of Sale: We do not sell your personal information to third parties. We do not share your personal information for cross-context behavioral advertising
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights
To submit a request, email us at support@agentaliza.com with the subject line "CCPA Request."
9. European Users (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data under the following legal bases:
- Performance of Contract: Processing necessary to provide the Service you signed up for
- Legitimate Interests: Processing necessary for our legitimate interests (e.g., improving the Service, ensuring security) where those interests are not overridden by your rights
- Consent: Where you have given explicit consent for specific processing activities
- Legal Obligation: Where processing is required by law
You have the right to lodge a complaint with your local data protection authority if you believe we have violated your privacy rights. For international data transfers, we rely on standard contractual clauses and other legally approved transfer mechanisms.
10. Cookies and Tracking
The Service uses essential cookies necessary for authentication and session management. We do not use third-party advertising cookies or cross-site tracking technologies. Specifically:
- Authentication Cookies: Used to keep you logged in and maintain your session
- Preference Cookies: Used to remember your settings (e.g., theme preference)
We do not use cookies for advertising, retargeting, or behavioral profiling. You can control cookies through your browser settings, but disabling essential cookies may prevent the Service from functioning properly.
11. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at support@agentaliza.com and we will promptly delete such information from our systems.
12. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have different data protection laws than your jurisdiction. By using the Service, you consent to the transfer of your information to the United States and other countries where we and our service providers operate. We take steps to ensure that your data receives an adequate level of protection in the jurisdictions in which we process it.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. If we make material changes, we will notify you by posting the updated policy on the Service with a new "Last Updated" date and, where required by law, by sending you an email notification at least 30 days before the changes take effect.
Your continued use of the Service after any changes to this Privacy Policy constitutes your acceptance of the revised policy. We encourage you to review this Privacy Policy periodically.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
This Privacy Policy is incorporated into and subject to our Terms of Service.