AI PlazaAI Plaza

AI Plaza Privacy Policy

Last updated: July 23, 2026

This Privacy Policy describes how WISE INTERNATIONAL LLC, a Wyoming limited liability company, doing business as AI Plaza (“AI Plaza,” “we,” “us,” or “our”) processes personal information when you use AI Plaza (https://aiplaza.app) and related services we operate (the “Service”). For purposes of the GDPR/UK GDPR where applicable, WISE INTERNATIONAL LLC is the controller of personal data processed for the Service. By using the Service, you acknowledge this Policy. If you do not agree, do not use the Service.

1. Information We Collect and Why

We collect and process personal information as needed to operate accounts, provide AI features, meter fair use, bill subscriptions, prevent abuse and fraud, improve reliability, and comply with law. Categories include:

Account information

When you create an account (including via Clerk or third-party login such as Google or Apple), we process identifiers such as email address, display name, authentication provider IDs, and an internal user ID. We use this to authenticate you, communicate about the Service, troubleshoot, enforce Terms, and perform our contract with you. Age confirmation at sign-up is your representation; we do not verify government ID as part of ordinary registration.

Device and technical information

We process device type, browser, operating system, IP address, timestamps, request paths, and diagnostic or security logs. Our host or CDN may associate coarse network location with an IP—including an ISO country or territory code (for example via Vercel’s `x-vercel-ip-country` header)—which we may use to enforce geographic eligibility for new account registration, to comply with sanctions and AI Model provider regional restrictions, and for security and fraud prevention. We do not promise precise geolocation (city-level or GPS). Legal bases (where GDPR applies): contract performance and our legitimate interests in operating, securing, complying with law and provider terms, and defending the Service.

Usage and plan data

We process message counts, model selections, Auto routing features (such as estimated difficulty, language lane, and a short hashed/preview form of the prompt—not full conversation dumps by default), tool/template and free-prompt usage, feature flags, plan tier, fair-use metering signals, limit events, complimentary residual-access signals, and related product telemetry to enforce limits, operate and support the Service, improve Auto model routing, and detect abuse. For Team Enterprise, this may also include organization ID, membership and role, seat count, workspace IDs and visibility, member quotas, organization usage, wallet credit and top-up records, and administrative actions. Metering figures shown in the product (including percentages or marketed “included value”) are administrative estimates for platform operations—not a cash balance, store of value, point pack, or guarantee of equivalent third-party API spend. Complimentary residual access after fair-use, when offered, is logged the same way as other usage for abuse prevention and is not a refundable credit.

Interactions with AI models and tools

When you use Chat or scenario tools, we process content you submit (prompts, messages, form fields, and files you upload) and model outputs returned to you. That content is transmitted to third-party AI model providers you select or that Auto routing selects—currently including, as shown in the product, OpenAI, Anthropic, Google, xAI, Perplexity, DeepSeek, Qwen, Mistral, Hugging Face, and other providers we may add or remove—so they can generate responses. Any information and files you provide may be shared with those providers for processing under their own terms and policies. Do not submit highly sensitive personal information (for example full payment card numbers, government ID numbers, protected health information, unreleased trade secrets, or classified data). Text and spreadsheet uploads may be extracted into prompts; images and PDFs may be sent as file inputs. Conversation history we store generally keeps message text and attachment filenames, not original binary files, unless a feature expressly requires otherwise.

Content-safety filtering (sensitive topics)

Before a prompt is sent to an AI Model, we may run automated content-safety checks on the text you submit (and, for some features, on related transcript text). These checks look for clear harmful or transactional intent—such as facilitating terrorism or violent crime; illegal firearms activity; pornography or sexual violence; hate or discriminatory violence; illegal drug acquisition, manufacture, or trafficking; illegal gambling facilitation; and personal medical diagnosis or prescribing requests. Educational questions (for example, harms of a substance or general ingredients of a medicine) are generally not refused solely for mentioning a sensitive topic, but filters and AI providers may still refuse or limit responses. When a request is refused, we may show a soft in-product notice and a link to our Terms of Service (Acceptable Use). We process the prompt text for this purpose on our systems; refused prompts are typically not forwarded to AI Model providers. Filtering is imperfect and may change. Legal bases (where GDPR applies): legitimate interests in safety, abuse prevention, and compliance with our Terms and provider policies; contract performance where filtering is part of operating the Service you request.

Memory and optional context (paid features)

If your plan includes company/brand memory or similar features and you save context, we store it in your account and may inject it into later prompts sent to AI providers. Treat memory like chat content. Do not store secrets you cannot send to model APIs. You may edit or delete memory in Account settings when that control is available.

Connected email and calendar accounts (optional)

If you choose to connect Google or Microsoft for Today Briefing, we process OAuth tokens (stored encrypted), your account email identifier, and the mailbox/calendar data we retrieve to show you message lists, full message content you open, calendar events, and AI-generated Focus summaries. Email access is read-only; we do not send email on your behalf. Calendar access includes creating and editing events you request in the product. Connected-account data may be sent to AI model providers when generating Focus summaries. You can disconnect accounts in Account settings; we delete stored tokens and briefing cache for that account. Legal bases (where GDPR applies): contract performance and your consent/legitimate interest in the optional feature you enable.

Organizations, workspaces, and team administration

If you join or administer a Team Enterprise organization, we process organization and membership information such as the organization name, your role, invitations, seat assignment, workspace membership, quota settings, usage records, wallet and billing identifiers, and audit or administrative actions. Private workspace content is made available according to its access controls; shared workspace content may be visible to assigned organization members. Organization owners and authorized administrators may be able to view or manage member lists, workspace configuration, quotas, organization usage, and shared content. If you submit content to an organization workspace, the organization may control that content and its access under its own policies. Contact the organization administrator for organization-controlled records; contact us for rights concerning personal information we control directly.

Subscription and billing data

Individual and Team Enterprise plans are processed by Stripe (or a successor). Stripe may collect name, billing address, payment method details, email, and transaction history. We receive billing-related identifiers (such as customer, subscription, organization, seat, invoice, and one-time top-up session IDs), plan status, seat count, and invoice metadata—not your full card number. For Ultra personal P CASH purchases, we associate checkout sessions with your account to credit purchased service credits. For Team Enterprise, the organization and its authorized billing administrators may control the subscription, seat count, organization wallet top-ups, and related billing records. Legal basis (where GDPR applies): contract performance and legal obligation (tax/accounting) where applicable.

Refer-a-friend and P CASH

If you participate in our referral program or purchase Ultra P CASH top-ups, we process referral codes, invite links, attribution records (which account referred which new account and when), hashed signup IP addresses, P CASH ledger entries (reward and purchased; pending, available, redeemed, revoked, or related), Stripe top-up session identifiers, and related anti-abuse signals (such as duplicate payment-customer patterns or unusual claim volume from the same network). We use this to operate the program and top-ups, credit service capacity, prevent fraud, enforce holds and revocations on refunds or disputes, and comply with our Terms. P CASH balances shown in-product are service credits for the assistant—not a cash balance and not a guarantee of equivalent third-party API spend.

Abuse-prevention and security signals

To protect the Service from bots, fraud, metering abuse, and prohibited content, we may process IP addresses, coarse IP-derived country codes, device or browser tokens (including values stored in local storage or cookies), CAPTCHA/Turnstile results, disposable-email checks, signup and rate-limit signals, ban/block lists, content-safety filter signals (for example that a prompt was refused and a category label such as drugs or firearms, without storing a permanent copy of every refused prompt unless needed for security or legal reasons), and related metadata. We may refuse new registrations from restricted countries or territories based on that coarse location signal. We may hash IP addresses and device tokens before storage and may retain hashed identifiers after account closure as needed to prevent re-registration by banned actors. Turnstile tokens may be verified with Cloudflare (including remote IP). We may block disposable emails, excessive signups from the same network, automated clients, or other abusive patterns, and we may adjust these controls without notice. Legal bases (where GDPR applies): legitimate interests in security, safety, fair use, and compliance with law and provider geographic restrictions; legal obligation where applicable.

Cookies and similar technologies

We use cookies and local storage for authentication, sessions, language preference, guest metering, device tokens used for abuse prevention, and other essential product state. We currently do not load a separate marketing analytics SDK. Hosting, CDN, and security providers may process technical request logs as part of delivering the Service. If we add non-essential analytics or advertising tools later, we will update this Policy and, where required, obtain consent or provide opt-out.

Communications

If you email us (for example privacy@, support@, or legal@), we process the content of that correspondence and associated metadata to respond and keep records of the request.

2. Third-Party AI Model Providers

AI Plaza routes your requests to third-party AI model providers via their APIs or related endpoints. Those providers process prompts, attachments, and related technical metadata to return outputs under their own terms and privacy policies, which may change without notice to you from us.

AI Plaza does not use your prompts or uploads to train its own foundation models. We do not guarantee that every provider, model, region, open-weight endpoint, or aggregator will refrain from training, logging, human review, or retaining content. Review the documentation for the specific model you use before submitting sensitive information. AI Plaza does not sell your personal information.

Your AI Plaza account credentials are not shared with model providers as part of ordinary inference. Limited technical metadata required for the API call, plus the content you choose to send, is shared with the selected provider. Auto routing may select a provider without a separate confirmation step for each message.

3. When We Share Information

We share personal information only as described in this Policy or with your direction:

No sale / no CPRA “share” for cross-context ads

We do not sell personal information as “sale” is defined under CCPA/CPRA, and we do not “share” personal information for cross-context behavioral advertising as those terms are defined under CPRA. If that changes, we will update this Policy and provide any required opt-out mechanism before engaging in such activity.

  • AI model providers — to generate chat and tool outputs, as described above
  • Stripe (or successor payment processors) — to process subscriptions, invoices, refunds where required by law, and payment method updates
  • Clerk (or successor auth providers) — to authenticate users and manage sessions
  • Application database and hosting/CDN providers (currently including Supabase and our host/CDN) — to store and serve account, usage, conversation, and abuse-related data
  • Organization owners and authorized administrators — to administer Team Enterprise memberships, workspaces, quotas, usage, shared content, and organization billing where applicable
  • Cloudflare and similar security vendors — for bot protection such as Turnstile and related edge security
  • Email and support vendors — to send transactional messages and support replies
  • Professional advisers (legal, accounting) under confidentiality — when needed to operate or defend the business
  • Authorities and claimants — when we believe in good faith disclosure is required by law, legal process, or to protect rights, safety, security, or integrity of the Service, users, or the public
  • Business transfers — if we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or asset sale, information may transfer as part of that transaction, subject to this Policy or successor protections where reasonably practicable

4. Data Retention

Guest use may involve a short-lived metering cookie (on the order of about one day), a longer-lived guest identifier cookie (which may persist for up to about one year), a device token in local storage, and hashed IP/device signals used for abuse limits (often on a daily cycle). We may retain security, fraud, and ban-related records—including hashed identifiers—longer when needed to protect the Service. Guest chats are not retained as registered account history on our servers.

Registered account data, conversations you save, memory features, billing identifiers, support tickets, and related records are retained while your account is active and thereafter as reasonably needed to provide the Service, enforce limits, prevent abuse, resolve disputes, and meet legal, tax, and accounting obligations. Team Enterprise organization records—including memberships, workspace configuration, shared content, quotas, wallet and subscription records, and security or administrative audit logs—may be retained while the organization uses the Service and thereafter as reasonably needed for the organization, security, compliance, dispute, tax, and accounting purposes. A browser-local History mirror may be stored on your device while you are signed in; we clear that mirror for your account on this browser when you sign out.

When your Clerk account is deleted (for example via Clerk account deletion, or after we process a verified deletion request), we automatically cascade-delete or anonymize personal data we control for that account: conversations and messages, company/brand memory, usage meters tied to your user id, Stripe customer mapping we store, referral attribution and P CASH ledger records tied to your user id, credit ledgers, and identifiable profile fields (email, display name). If the account is a member of a Team Enterprise organization, organization-owned subscriptions, workspaces, shared content, organization billing records, and organization audit records are not necessarily deleted by that individual account deletion; they may remain under the organization’s control, subject to applicable law. We may keep a minimal anonymized profile stub and limited hashed abuse/ban signals so banned actors cannot immediately re-register. Processors (Clerk, Stripe, hosting, Cloudflare, AI Model providers) may retain residual records under their own schedules. Backup systems may take additional time to cycle out deleted data.

You may also email privacy@aiplaza.app from the address associated with your account to request deletion or other privacy rights. After we verify the request (and, where applicable, an authorized agent’s authority), we aim to complete deletion or anonymization of personal data we control within about 30 days, subject to the exceptions above and applicable law. We may deny or limit requests that are unfounded, excessive, fraudulent, or that we cannot verify.

5. Your Privacy Rights

Depending on your location (including the GDPR, UK GDPR, and CCPA/CPRA where applicable), you may have rights to request access, correction, deletion, portability, restriction, or objection to certain processing, and to appeal a denial where required by law. You may also have the right to lodge a complaint with a supervisory authority in your jurisdiction.

To exercise these rights, email privacy@aiplaza.app from the address associated with your account (or provide other information sufficient for verification). If the information is controlled by a Team Enterprise organization, we may direct you to that organization or require the organization’s authorization before providing, changing, or deleting organization-controlled records. We may need to verify your identity (and an authorized agent’s authority) before responding. We will respond within the time required by applicable law—generally within about 45 days under CCPA/CPRA and about one month under GDPR, extendable as permitted by law. To appeal a denial where the law provides an appeal right, reply to our decision email with “Appeal” in the subject line.

We do not provide a consumer “do not sell or share” link because we do not sell or share personal information for cross-context behavioral advertising as described above. California residents may designate an authorized agent as permitted by law. We will not discriminate against you for exercising rights afforded by applicable privacy law.

Where GDPR/UK GDPR applies, our primary legal bases are: performance of a contract (providing the Service you request); legitimate interests (security, abuse prevention, service improvement that does not override your interests); consent where we rely on it (and you may withdraw consent without affecting prior lawful processing); and legal obligation where applicable. You may object to processing based on legitimate interests; we will assess whether we have compelling grounds to continue.

6. Security

We use commercially reasonable administrative, technical, and organizational safeguards appropriate to the nature of the Service, including encryption in transit (HTTPS/TLS), production access controls, organization and workspace authorization checks, abuse monitoring, content-safety filters, and automated cascade deletion/anonymization of account content when a Clerk account is deleted. Conversation APIs are scoped to the signed-in user and workspace permissions where applicable. No method of transmission or storage is completely secure. You are responsible for protecting your account credentials and for what you choose to submit to AI models and organization workspaces. Report suspected security incidents affecting the Service to support@aiplaza.app or privacy@aiplaza.app.

7. Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact privacy@aiplaza.app and we will take appropriate steps to delete it as required by law. Parents or guardians who consented to a minor’s use (where permitted by these Terms and local law) remain responsible for that use.

8. International Transfers

We and our processors may process information in the United States and other countries where our vendors and AI providers operate. Those countries may have different data-protection laws than your home country. Where required, we rely on appropriate transfer mechanisms (such as standard contractual clauses) or other lawful bases. In-product “data region” or routing preferences, if offered, are preferences only and are not a contractual guarantee of data residency or exclusive processing in a single country.

9. Automated Processing

We use automated systems for rate limiting, abuse detection, bot challenges, model routing, metering, and content-safety filtering of prompts (including refusals for clear harmful or transactional intent on sensitive topics described in Section 1). These systems may automatically restrict, refuse, or block requests or access when signals indicate abuse, limit exhaustion, or a Terms violation. Soft in-product notices may appear when a related sensitive topic is detected or a request is refused. These systems are not intended to produce legal or similarly significant effects about you solely by automated means without human involvement where such protection is required by law. If you believe you were wrongly blocked, contact support@aiplaza.app.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the “Last updated” date. For material changes, we will provide additional notice when required by law (for example by email or in-product notice) where reasonably practicable. The updated Policy applies from its effective date. If you do not agree, you must stop using the Service and, if applicable, request account deletion.

11. Language; Conflicts

This Privacy Policy may be summarized or translated in the product UI. If there is any conflict between the English version on this page and a translation or summary, the English version prevails. If there is a conflict between this Policy and the Terms of Service on a privacy topic, this Policy controls for that topic.

12. Contact

Controller / operator: WISE INTERNATIONAL LLC, a Wyoming limited liability company, doing business as AI Plaza. Privacy and deletion requests: privacy@aiplaza.app. Legal: legal@aiplaza.app. Product support: support@aiplaza.app. Postal inquiries may be directed to WISE INTERNATIONAL LLC at the registered agent address on file with the Wyoming Secretary of State (request via privacy@aiplaza.app if needed for a formal legal notice).

Also see our Terms of Service.