Aithon LLC
Privacy Policy
Effective Date: August 3, 2026
1. Introduction
Aithon LLC (“Aithon,” “OneLoop,” “we,” “us,” or “our”) operates the OneLoop execution platform (the “Service”), a software-as-a-service product for operators and teams to plan, run, and review work across meetings, chat, and automated workflows. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use the Service.
By using the Service, you consent to the practices described in this Privacy Policy. If you do not agree, please do not use the Service. This Privacy Policy is incorporated into and subject to our Terms and Conditions.
1.1 OneLoop Live Privacy Notice
OneLoop Live serves performers and audience buyers. When you use a Live page, we may collect the performer and event page you visited, referral source, device class, buyer or supporter name, email address, request and dedication text, order and refund history, fulfillment status, and the shipping or pickup information needed for the transaction. Stripe collects payment credentials and returns payment, tax, fraud, dispute, and payout status to us; OneLoop does not store full card or bank numbers.
Request names, dedications, amounts, and queue position may be displayed publicly on the event page and stream overlay. Do not submit private information in those fields. For merchandise and performer-action orders, OneLoop shares the buyer name, receipt email, shipping address, order contents, and fulfillment messages with the applicable performer so they can fulfill, support, or refund that order. Performers may use this data only for transaction fulfillment and support unless the buyer separately opts in to marketing.
Joining a performer's fan list is optional and uses confirmation by email. A fan-list address is not added from a purchase alone. After confirmation, the performer may use it for future-show updates until unsubscribe. OneLoop records external tip-link taps and coarse referral/device data, but does not receive the tip amount or confirmation from Venmo, Cash App, PayPal, Zelle, or another external rail.
We use Live data to provide checkout and fulfillment, calculate and report tax, prevent fraud and abuse, operate the public queue and overlay, resolve disputes, send receipts and shipping updates, and maintain legally required transaction records. Live transaction and tax records are retained for seven years; public queue data and operational logs are removed or de-identified when no longer needed, subject to disputes, fraud prevention, and legal holds. Privacy requests may be sent to privacy@aithon.tech, though tax, payment, and dispute records may not be deletable during a required retention period.
2. Information We Collect
2.1 Information You Provide
- Account information: name, email address, phone number, company name, and password when you create an account.
- Workspace information: tenant name, team member emails, roles, and permissions.
- Operational content: meetings, notes, chat messages, tasks, reflections, evaluations, and other workspace content you create or import into the Service.
- Integration credentials: OAuth tokens, API keys, and connection metadata you grant OneLoop in order to connect calendars, messaging platforms, document stores, and other third-party tools.
- Transaction information: plan selections, billing contact, and order metadata.
- Payment information: payment methods are collected and processed by Stripe. We do not store full credit card numbers, bank account numbers, or other sensitive payment credentials on our servers.
- Support communications: messages, emails, and other support correspondence.
2.2 Information Collected Automatically
- Device and browser information: IP address, browser type and version, operating system, device identifiers, and screen resolution.
- Usage data: pages visited, features used, search queries, click patterns, session duration, and referring URLs.
- Cookies and similar technologies: authentication, preferences, and analytics (see Section 7).
- Log data: server logs that record requests, timestamps, error messages, and API call metadata.
- Model and automation telemetry: token usage, model identifiers, and tool-call metadata generated by automations you run inside the Service, used for billing, quota enforcement, and abuse prevention.
- Service-improvement samples: where service-improvement data use applies to your plan, prompts and model responses generated inside your workspace may be captured and stored encrypted at rest to improve model quality (see Section 3.1).
2.3 Information from Third Parties
- Stripe: transaction status, payout confirmations, and fraud signals.
- Connected integrations: calendar events, meeting transcripts, chat messages, documents, and related metadata fetched on your behalf from systems you connect to OneLoop.
- Public sources: business registration records and publicly available professional information for verification purposes.
3. How We Use Your Information
We use collected information to:
- Provide, operate, and maintain the Service.
- Authenticate users and enforce tenant boundaries and access control.
- Deliver OneLoop’s core functions, including meeting preparation, execution tracking, reflections, evaluations, chat, and associated automations.
- Process subscription transactions, manage plan changes, and invoice usage-based fees.
- Send transactional emails (sign-in, billing, security, service announcements).
- With your consent, send product updates and marketing communications you can unsubscribe from at any time.
- Detect, prevent, and investigate fraud, abuse, security incidents, and Terms violations.
- Analyze usage patterns to improve Service features, reliability, and performance.
- Comply with legal obligations and respond to lawful requests.
- Enforce our Terms and Conditions.
3.1 Service Improvement & Model Training
To improve the quality, speed, and cost of the Service, Aithon may use workspace content — including prompts and model responses generated by features you use — to train, fine-tune, and evaluate models that Aithon operates to provide the Service. Content used for this purpose is stored encrypted at rest, is never sold or shared with third parties, and is de-identified to remove names, contact details, and similar identifiers before it is used in any model training run.
You may opt your workspace out of service-improvement data use at any time by contacting privacy@aithon.tech; opt-outs take effect prospectively. Plan-specific or negotiated terms may exclude a workspace from service-improvement data use entirely. When a tenant is closed or offboarded, its service-improvement samples are deleted.
4. How We Share Your Information
We do not sell your personal information. We share information only as follows:
4.1 Within Your Workspace
Content you create inside a OneLoop workspace (meetings, notes, chat, tasks, reflections, evaluations, and other operational data) is accessible to other members of that workspace according to their role and permissions. Workspace administrators may view activity, membership, and billing information for their tenant.
4.2 Service Providers (Subprocessors)
- Stripe, Inc. — payment processing and billing. See Stripe’s Privacy Policy.
- Hosting providers — cloud infrastructure for Service operation (servers located in the United States).
- Email delivery services — transactional and product email delivery.
- Analytics tools — product analytics and performance monitoring.
- Model providers — depending on your plan and deployment configuration, when you run automations or AI features, prompts and workspace content you submit may be sent to third-party model providers to generate responses. OneLoop does not permit those providers to train on your content except as permitted by their enterprise agreements. Some plans may run some or all model workloads on infrastructure Aithon operates, in which case that content is not sent to third-party model providers for those workloads. Aithon’s own use of workspace content to improve the Service is described in Section 3.1 and is separate from third-party model provider processing.
4.3 Legal Requirements
We may disclose information if required by law, regulation, legal process, or governmental request, or if we believe in good faith that disclosure is necessary to: (a) protect our rights, property, or safety; (b) protect the rights, property, or safety of our users or the public; (c) detect, prevent, or address fraud, security, or technical issues; or (d) comply with a court order or subpoena.
4.4 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email or prominent notice in the Service before your information becomes subject to a different privacy policy.
5. Tenant Data Ownership
As between you and Aithon, your organization owns the operational content it creates or imports into its OneLoop workspace, including meetings, chat, tasks, reflections, evaluations, and associated metadata. You grant Aithon a limited, worldwide, royalty-free license to host, process, display, and transmit that content solely to operate the Service and the features you and your users invoke.
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. After account closure, we retain information as follows:
- Billing and transaction records: 7 years (tax and legal compliance).
- Account and workspace content: 90 days after tenant closure, then deleted or anonymized, except where legally required to retain longer.
- Server and audit logs: 90 days for operational logs; up to 1 year for audit events.
- Terms acceptance records: retained indefinitely for audit compliance.
- Service-improvement samples (Section 3.1): retained while the tenant is active and deleted at tenant offboarding; de-identified datasets derived from them may be retained.
- Anonymized or aggregated data: may be retained indefinitely for analytics.
7. Cookies & Tracking Technologies
- Essential cookies: required for authentication, security, and basic Service functionality. Cannot be disabled.
- Functional cookies: remember preferences, display settings, and workspace context.
- Analytics cookies: help us understand how the Service is used and identify areas for improvement.
We do not use third-party advertising cookies or tracking pixels. You can manage cookie preferences through your browser settings. Disabling essential cookies may prevent you from using certain Service features.
8. Data Security
We implement reasonable administrative, technical, and physical safeguards to protect your personal information, including:
- Encryption of data in transit (TLS/HTTPS) and at rest.
- Secure password hashing (bcrypt).
- Role-based access controls and tenant isolation.
- Regular security monitoring and logging.
- Stripe PCI-DSS compliance for payment data.
No method of transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials.
9. Your Rights & Choices
Depending on your location, you may have the following rights:
- Access: request a copy of the personal information we hold about you.
- Correction: request correction of inaccurate or incomplete information.
- Deletion: request deletion of your personal information, subject to legal retention requirements.
- Portability: request your data in a machine-readable format.
- Opt-out of marketing: unsubscribe from marketing emails at any time via the link in each email or by contacting us.
- Opt-out of service-improvement data use: request exclusion of your workspace from model-training data capture as described in Section 3.1.
- Account closure: close your account at any time through Service settings or by contacting support.
To exercise any of these rights, contact us at privacy@aithon.tech. We will respond within 30 days. We may require identity verification before processing requests.
10. California Residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) provides you with additional rights:
- Right to Know: request disclosure of the categories and specific pieces of personal information we have collected, the sources, the business purposes, and the categories of third parties with whom we share it.
- Right to Delete: request deletion of your personal information, subject to certain exceptions.
- Right to Opt-Out of Sale: we do not sell personal information. There is no need to opt out.
- Right to Non-Discrimination: we will not discriminate against you for exercising your CCPA rights.
To exercise your CCPA rights, contact us at privacy@aithon.tech or submit a request through your account settings.
11. Texas Residents
Under the Texas Identity Theft Enforcement and Protection Act (Texas Business & Commerce Code §521), if we experience a data breach affecting your personal information, we will notify you within 60 days of discovery. Notification will include the nature of the breach, the types of information affected, and steps you can take to protect yourself.
Under the Texas Data Privacy and Security Act (TDPSA), if applicable thresholds are met, Texas residents may have additional rights including access, correction, deletion, portability, and opt-out of targeted advertising. Contact privacy@aithon.tech to exercise these rights.
12. Children’s Privacy
The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us at privacy@aithon.tech.
13. International Users
The Service is operated from the United States. If you access the Service from outside the United States, you consent to the transfer, processing, and storage of your information in the United States, where data protection laws may differ from those in your jurisdiction.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or prominent notice in the Service at least 30 days before taking effect. The “Effective Date” at the top indicates when this policy was last revised. Continued use of the Service after the effective date constitutes acceptance of the updated Privacy Policy.
15. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Aithon LLC
Privacy Inquiries: privacy@aithon.tech
General Support: support@aithon.tech
This Privacy Policy is incorporated into and subject to our Terms and Conditions.