Privacy Policy

Last updated: July 2026

1. What Data We Collect

When you use Axora, we collect the following information:

  • Account information: Email address and password (stored as a bcrypt hash) when you create an account.
  • API usage data: Request logs including model used, provider, token counts, cost, latency, and timestamps.
  • Conversation content: Messages sent through the chat interface or API, stored in your database.
  • Knowledge base content: Markdown files uploaded for RAG, chunked and stored as embeddings.

2. How We Use Your Data

  • Route your API requests to the configured AI providers (Groq, Gemini, OpenRouter, OpenAI, Claude).
  • Track usage analytics, costs, and rate limits per API key.
  • Provide the chat interface, conversation history, and knowledge base features.
  • Display system health and usage metrics in the admin dashboard.
  • Enforce security measures including brute-force protection and rate limiting.

3. Data Storage

Axora is self-hosted software. Where your data lives depends on how you deploy:

  • Self-hosted: All data is stored on your own infrastructure (PostgreSQL database). No data is sent to Aivorylabs.in or any third party except the AI providers you configure.
  • SaaS (if applicable): Data is stored on our servers. We use industry-standard encryption at rest and in transit.

4. Third-Party Providers

When you send a chat request, your prompt is forwarded to the AI provider you selected (e.g., Groq, OpenAI, Gemini). Each provider has its own data retention and privacy policy:

  • Groq: Requests are processed in real-time. Check Groq's privacy policy for retention details.
  • OpenAI: By default, data is not used for training. Check OpenAI's data usage policies.
  • Google Gemini: Check Google's AI privacy policy for data handling.
  • OpenRouter: Acts as a proxy to underlying providers. Check OpenRouter's privacy policy.
  • Claude: Check Anthropic's privacy policy for data handling.

We recommend reviewing each provider's privacy policy to understand how they handle your data.

5. Cookies and Tracking

Axora uses minimal cookies:

  • Authentication cookies: JWT tokens stored in localStorage to maintain your session.
  • No analytics cookies: Axora does not use Google Analytics, Mixpanel, or any third-party tracking tools.
  • No advertising cookies: We do not serve ads or use advertising trackers.

6. Data Retention

  • Account data: Retained until you delete your account.
  • Conversation history: Retained until you delete the conversation.
  • API request logs: Retained based on your configuration. Default retention is 30 days.
  • Knowledge base: Retained until you remove the source files.

7. Your Rights

You have the right to:

  • Access: View all data associated with your account.
  • Export: Download your conversations and data.
  • Delete: Permanently delete your account and all associated data.
  • Revoke: Instantly revoke any API key from the dashboard.

Since Axora is self-hosted, you have full control over your data at all times.

8. Children's Privacy

Axora is not intended for use by children under 13. We do not knowingly collect data from children.

9. Changes to This Policy

We may update this privacy policy from time to changes. Changes will be posted on this page with an updated revision date. Continued use of Axora after changes constitutes acceptance of the updated policy.

10. Contact

For questions about this privacy policy, contact us at aivorylabs.in.