Privacy Policy
Effective Date: August 7, 2026
This Privacy Policy (this "Policy") describes how The Experience Company, Inc. ("Company," "GAIA," "we," "us," or "our") collects, uses, stores, processes, and discloses personal information in connection with our artificial intelligence assistant services and platform (the "Service"). This Policy applies to all users of the Service and is incorporated by reference into our Terms of Service Agreement. BY USING THE SERVICE, YOU CONSENT TO THE COLLECTION, USE, AND DISCLOSURE OF YOUR PERSONAL INFORMATION AS DESCRIBED IN THIS POLICY.
1. Information We Collect
We collect several categories of personal information about you through various means:
1.1 Information You Provide Directly
- Account Information: Name, email address, username, password, and other registration information you provide when creating an account;
- Payment Information: Credit card numbers, billing addresses, and other payment-related information processed through our third-party payment processors;
- Profile Information: Optional profile information, preferences, and settings you choose to provide;
- Communication Data: Information you provide when you contact us for support, feedback, or other communications;
- User Content: All text, files, images, audio, and other content you submit to or through the Service.
1.2 Information We Collect Automatically
The information described in this section is linked to your account and is not anonymous.
- Device Information: IP address, device type, operating system, browser type and version, device identifiers, and mobile network information;
- Usage Data: Information about how you use the Service, including features accessed, time spent, interaction patterns, and performance metrics. This data is associated with your account identifier;
- Location Data: General location information derived from your IP address (not precise geolocation unless explicitly consented);
- Cookies and Tracking Technologies: Information collected through cookies, web beacons, pixels, and similar tracking technologies.
1.3 Information from Third Parties
- Authentication Services: If you use third-party authentication services (e.g., Google, GitHub), we may receive basic profile information such as your name, email address, and profile picture;
- Google User Data: When you connect Google services, we may access and collect data from your Google account including but not limited to email, calendar events, contacts, and documents as authorized by you through Google's OAuth consent process;
- Connected Integrations: When you connect a third-party account (such as Slack, Notion, or GitHub), we receive data from that account as authorized by you during the connection process;
- Analytics Providers: Information from third-party analytics services that help us understand Service usage and performance;
- Security Services: Information from fraud prevention and security services to protect against unauthorized access.
2. How We Use Your Information
We use your personal information for the following purposes:
2.1 Service Provision and Operation
- Providing, maintaining, and improving the Service and its features;
- Processing and responding to your requests and interactions with the AI assistant;
- Google User Data Processing: Using Google user data solely to provide and improve our AI assistant functionality, including processing emails, calendar events, and documents to provide relevant assistance and responses;
- Personalizing your experience and delivering relevant content and recommendations;
- Processing payments and managing your account and subscriptions.
2.2 Communication and Support
- Responding to your inquiries, comments, and support requests;
- Sending you service-related communications, updates, and notifications;
- Providing customer support and technical assistance;
- Conducting surveys and gathering feedback to improve our services.
2.3 Analytics and Improvement
- Analyzing usage patterns to understand how the Service is used and to improve functionality;
- Monitoring and analyzing trends, usage, and activities in connection with the Service;
- Developing new features, services, and products.
We may use content you submit to the Service to improve our services and products. We do not use content from your connected third-party integrations — including emails, calendar events, contacts, and other data retrieved from accounts you connect — to improve our services. Content from connected accounts is used solely to operate the Service at your direction.
2.4 Security and Legal Compliance
- Protecting against fraud, unauthorized access, and other security threats;
- Investigating and preventing violations of our Terms of Service;
- Complying with applicable laws, regulations, and legal obligations;
- Enforcing our rights and protecting our property and interests.
3. Data Sharing and Disclosure
We do not sell, rent, or lease your personal information to third parties. We do not sell Google user data to third parties. However, we may share your information in the following limited circumstances:
3.1 AI Model Providers
To generate responses, we share content you submit with third-party AI model providers who process it on our behalf. This may include the contents of messages, files, and data retrieved from accounts you have connected. We do not use content from your connected third-party integrations to improve our services, as described in Section 2.3.
3.2 Service Providers
We may share your information with trusted third-party service providers who assist us in operating our business, including:
- Cloud hosting and infrastructure providers;
- Payment processing companies;
- Integration platforms that connect the Service to your third-party accounts;
- Customer support and communication platforms;
- Analytics and monitoring services;
- Security and fraud prevention services.
Google User Data: We only share Google user data with service providers who are necessary for providing our AI assistant functionality and who have agreed to appropriate data protection measures. We do not transfer Google user data to third parties for advertising or other unrelated purposes.
3.3 Legal Requirements
We may disclose your information when required by law or when we believe in good faith that disclosure is necessary to:
- Comply with a legal obligation, court order, or government request;
- Protect and defend our rights or property;
- Prevent or investigate possible wrongdoing in connection with the Service;
- Protect the personal safety of users of the Service or the public.
3.4 Business Transfers
In the event of a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred to the acquiring entity, subject to the same privacy protections outlined in this Policy.
4. Google User Data and Limited Use
GAIA's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular:
- We use Google user data only to provide or improve user-facing features that are prominent in the Service;
- We do not use Google user data to develop or improve generalized artificial intelligence or machine learning models;
- We do not transfer or sell Google user data for advertising, marketing, or any other unrelated purpose;
- We do not allow humans to read Google user data unless we have your affirmative consent for specific messages, it is necessary for security purposes or to comply with applicable law, or the data has been aggregated and anonymized for internal operations;
- You may disconnect any Google integration at any time from your account settings, and you may revoke our access directly through your Google Account permissions page.
5. How the Assistant Acts on Your Behalf
5.1 Autonomous Actions
GAIA is an agentic assistant. When you connect an integration, the assistant can read from and write to that account on your behalf. Depending on the integrations you enable and the instructions you give, this may include:
- Reading, drafting, sending, labelling, and archiving email;
- Creating, modifying, and deleting calendar events;
- Posting messages and reading conversations in connected chat platforms;
- Creating, updating, and deleting records in other connected tools;
- Running scheduled workflows and background tasks that act without you being present.
Certain actions we classify as destructive require your explicit approval before they are carried out. You can review connected integrations, disable them, and revoke their access at any time from your account settings.
5.2 Automated Decision-Making
The Service uses automated processing to decide which content is relevant to you, which notifications to send, and which actions to take or suggest in response to your instructions. We do not use automated decision-making to produce legal effects concerning you or effects of similarly significant impact, such as decisions about credit, employment, insurance, or access to essential services. You may contact us at any time to request human review of an automated action taken by the Service.
6. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to collect information about your use of the Service. These technologies include:
6.1 Types of Cookies
- Essential Cookies: Required for basic Service functionality and cannot be disabled;
- Analytics Cookies: Help us understand how you use the Service and improve its performance;
- Preference Cookies: Remember your settings and preferences for a better user experience;
- Third-Party Cookies: Placed by our service providers for analytics and security purposes.
6.2 Cookie Management
You can control cookies through your browser settings. However, disabling certain cookies may limit your ability to use some features of the Service. For more information about managing cookies, please refer to your browser's help documentation.
7. Data Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit and at rest using industry-standard protocols;
- Access controls and authentication mechanisms to limit access to personal information;
- Regular security assessments and monitoring of our systems;
- Employee training on data privacy and security best practices;
- Incident response procedures to address potential security breaches.
- Google User Data Protection: Enhanced security measures for Google user data including restricted access on a need-to-know basis, secure API connections, and compliance with Google's security requirements.
However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee its absolute security.
8. Data Breach Notification
If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to your personal information, we will notify the relevant supervisory authorities within seventy-two (72) hours of becoming aware of it, where required by applicable law. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay. Our notice will describe the nature of the breach, the categories of data affected, the likely consequences, and the measures we have taken or propose to take in response.
9. Your Rights and Choices
Depending on your location, you may have certain rights regarding your personal information:
9.1 Access and Portability
You have the right to:
- Access the personal information we hold about you;
- Receive a copy of your personal information in a structured, commonly used format;
- Request information about how we use and share your data.
9.2 Correction and Deletion
You have the right to:
- Correct or update inaccurate or incomplete personal information;
- Request deletion of your personal information in certain circumstances;
- Withdraw consent where our processing is based on your consent.
9.3 Restriction and Objection
You have the right to:
- Restrict the processing of your personal information in certain circumstances;
- Object to processing based on our legitimate interests;
- Opt-out of marketing communications.
9.4 How to Exercise Your Rights
To exercise any of the rights described above, email us at support@heygaia.so from the email address associated with your account, or submit a request through our contact page, and tell us which right you wish to exercise.
- For requests from the EEA, UK, or Switzerland, we will acknowledge your request and respond within one month, with a possible extension of up to two additional months for complex or numerous requests (as permitted by the GDPR);
- For all other requests, we will acknowledge your request and respond within forty-five (45) days. If we need more time, we will tell you why and how much longer we need;
- We may ask you for additional information to verify your identity before acting on a request, but we will not require access to the email address on your account as a precondition;
- Exercising these rights is free of charge, and we will not discriminate against you for doing so;
- You may request deletion of your account and the personal information associated with it at any time, and we will process deletion requests through the process described above.
10. Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, including:
- Account information: Retained while your account is active and for a reasonable period after closure;
- Usage data: Typically retained for up to 24 months for analytics and improvement purposes;
- Payment information: Retained as required by law and for legitimate business purposes;
- Support communications: Retained for up to 3 years for quality assurance and legal compliance.
- Google User Data: Retained only as long as necessary to provide our services or as required by law. You can request deletion of your Google user data at any time by contacting us or submitting a request through the process in Section 9.4.
We may retain certain information for longer periods when required by law or for legitimate business purposes such as fraud prevention and security. Google user data is deleted when no longer necessary for providing our AI assistant services.
11. Children's Privacy
The Service is not directed to, and is not intended for use by, anyone under the age of eighteen (18). We do not knowingly collect personal information from children. If we learn that we have collected personal information from a person under 18, we will delete that information and terminate the associated account. If you believe a child has provided us with personal information, please contact us at support@heygaia.so and we will act promptly.
12. International Data Transfers
Your personal information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws than your country. When we transfer your information internationally, we implement appropriate safeguards to protect your information, including:
- Standard contractual clauses approved by relevant data protection authorities;
- Adequacy decisions confirming that the destination country provides adequate protection;
- Other appropriate safeguards as required by applicable law.
13. Third-Party Services and Links
The Service may contain links to or integrate with third-party websites, applications, or services. This Privacy Policy does not apply to these third-party services. We encourage you to review the privacy policies of any third-party services you use in connection with our Service.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. When we make material changes, we will:
- Post the updated Policy on our website;
- Update the "Effective Date" at the top of this Policy;
- Provide notice through the Service or via email for significant changes;
- Obtain your consent where required by applicable law.
Your continued use of the Service after any changes become effective constitutes your acceptance of the updated Policy.
15. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
The Experience Company, Inc.
Email: support@heygaia.so
16. Jurisdiction-Specific Provisions
16.1 United States State Privacy Rights
If you are a resident of a US state with a comprehensive consumer privacy law (including California, Texas, Virginia, Colorado, Connecticut, Delaware, and others), you have the following rights, which we extend to all US residents regardless of whether the law of your state currently applies to us:
- Right to know what personal information is collected and how it is used;
- Right to access and obtain a portable copy of your personal information;
- Right to correct inaccurate personal information;
- Right to request deletion of personal information;
- Right to opt-out of the sale or sharing of personal information. We do not sell or share personal information, and we have not done so in the preceding twelve (12) months;
- Right to opt-out of targeted advertising. We do not use your personal information for targeted advertising;
- Right to non-discrimination for exercising your privacy rights;
- Right to appeal a denied request by replying to our response.
To exercise any of these rights, follow the process in Section 9.4.
16.2 European Economic Area (EEA) and United Kingdom Residents
If you are located in the EEA or the United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR) and the UK GDPR:
- Legal basis for processing: We process your data based on consent, contract performance, legitimate interests, or legal obligations;
- Response timeline: Requests from the EEA, UK, or Switzerland are handled within one month, extendable by up to two months for complex or numerous requests, as described in Section 9.4;
- Right to lodge a complaint with your local data protection authority;
- Right to data portability in machine-readable format;
- Enhanced rights regarding automated decision-making and profiling, as described in Section 5.2.