Privacy Policy
Akston Company (“Akston,” “we,” “us,” or “our”) operates the website at www.akston.ai (the “Site”) and the Akston writing workspace (the “Service”). This Privacy Policy describes what personal data we collect, how we use it, who we share it with, and the choices you have.
This policy applies to personal data we collect through the Site and the Service. Your use of the Service is also governed by our Terms of Service.
The essentials, up top
- We do not use your writing to train large language models, and we contractually prohibit our model providers from doing so. See § 4.
- We do not sell your personal data. We do not rent it, and we do not share it for advertising purposes.
- You own your content and can export or delete it. After paid access ends, your account stays active with basic access, and projects you own are retained for at least 90 days. See § 7.
- Akston is for adults. The Service is not directed to anyone under 18.
1Data we collect
We collect data in three ways: (a) data you provide when you sign up, subscribe, or use the Service; (b) data generated by your use of the Service; and (c) data from integrations you explicitly connect.
Account and identity data
- Name, email address, and email verification status.
- Profile image, if you upload one or import it from an OAuth provider.
- Authentication credentials: magic-link email tokens, OAuth account identifiers (Google), and account session tokens.
- Account state, role, and access grants.
Billing data
- Stripe customer and subscription identifiers, plan tier, billing cycle, renewal date, and cancellation flags.
- Invoice records, including amount, status, and a link to the invoice hosted by Stripe.
- Usage summaries: monthly totals of AI usage, turn counts, and budgets against your plan’s limits.
We do not collect or store your full payment card details. Stripe collects and processes payment data directly; we only receive tokenized references and metadata.
Workspace content (your writing)
- Projects, files, and documents you create — including their full content (text, HTML, and ProseMirror JSON), version history, titles, and folder structure.
- Conversations with the AI, including your prompts, uploaded context, intermediate model responses, and final outputs.
- Margin notes and annotations, including references to files and conversations.
- Files you upload, including extracted metadata (word count, summaries, key points) used to make them searchable within the Service.
- Saved prompts and writing samples you choose to store.
Voice and personalization data
To tailor outputs to your individual style, the Service may extract and store the following from writing samples you provide or content you create within Akston:
- Voice profile: signature patterns, vocabulary notes, tone indicators, topics, and audience characteristics derived from your writing.
- Philosophical profile: observations and synthesized themes drawn from your writing samples.
- Preferences you configure: experience level, typical writing types, target audiences, and publication outlets.
This personalization is isolated to your account and not shared with or used for the benefit of other users. You can reset or delete it at any time from your account settings.
Usage and device data
- Activity events: which features you use, when, and in connection with which project or file. We use these to operate the Service, investigate issues, and improve reliability.
- Session identifiers, request identifiers, and timestamps.
- Device and browser information: IP address, user-agent string, device type, operating system, language, and timezone.
- Error and performance data reported through our monitoring tools.
- Onboarding and last-active timestamps (for re-engagement and account-health signals).
Dictation recordings
If you use dictation, we send your audio to a third-party speech-to-text provider (see § 6) for transcription. The resulting transcript is stored in your workspace; raw audio is retained only transiently as required to produce the transcript.
Communications with us
If you email us for support, feedback, or other reasons, we retain the content of that correspondence along with your email address so we can respond and follow up.
Integrations you connect
If you connect a third-party integration (such as Google Drive, X, or Substack), we store the OAuth tokens needed to access that integration and metadata about the content you choose to import, export, or publish through it. We do not access the integration beyond the scopes you authorize and the specific actions you initiate.
Google user data
When you choose Google sign-in or connect Google Drive and Google Docs, we access Google user data only after you grant permission and only for the user-facing features you initiate.
- Data accessed. For Google sign-in, we receive your Google account identifier, name, email address, and profile image. For Google Drive and Google Docs, we request the following scopes:
openid,profile,email,https://www.googleapis.com/auth/drive.readonly, andhttps://www.googleapis.com/auth/documents.readonly. With those scopes, we may access OAuth access tokens and refresh tokens; token-expiration and scope metadata; Drive file metadata needed to show file pickers, search results, or recent files (such as file ID, name, MIME type, modified time, owner display names and email addresses, icon link, web view link, and parent folders); file permissions and metadata when you ask the agent to inspect them; and the content of the specific Google Docs, DOCX, or PDF files you select or ask the agent to read. For Google Docs imports, this can include document text, structure, tabs, images, suggestions, comments, quoted comment text, replies, authors, and timestamps. - Data usage. We use Google sign-in data to authenticate you and connect your account to the Service. We use Google Drive and Google Docs data to display files you can choose from, import selected files into Akston, preserve selected document formatting, images, comments, and suggestions, and let the agent search, read, download, or inspect Drive files only when you ask it to use your connected Drive. The Google Drive integration is read-only; Akston does not create, modify, or delete files in your Google Drive. We do not use Google user data to train or improve generalized AI or machine-learning models, and we do not use it for advertising.
- Data sharing. We do not sell Google user data, share it for advertising, or transfer it to data brokers or information resellers. We send requests to Google APIs and Google’s Drive MCP endpoint to perform the read-only actions you initiate. If you import Google content into Akston and later ask an AI feature to process that imported content, the relevant selected content may be routed to the model providers described in § 4 and § 6; Google OAuth tokens are not shared with model providers. We may also process Google user data with the infrastructure, database, monitoring, and security subprocessors described in § 6, strictly to provide and protect the Service.
- Storage and protection. Google OAuth tokens are stored in our integration-token database, not in browser session tokens, and are encrypted at rest using AES-256-GCM. Google user data is transmitted over TLS, access is limited by account permissions and least-privilege operational controls, and decrypted tokens are not returned through customer-facing GraphQL APIs. We do not allow employees or contractors to read Google file content except when you ask us for support involving specific content, when necessary for security or abuse investigation, or when required by law.
- Retention and deletion. We retain Google OAuth tokens while the integration remains connected. You can disconnect Google Drive and Google Docs at any time from account settings; disconnecting revokes the Google tokens where supported and deletes our stored integration-token record, which stops further access. Copies of Google content that you import into Akston are retained as workspace content under § 7 until you delete them, delete your account, or request deletion by emailing team@akston.ai.
Waitlist and marketing-site visits
If you join the waitlist, we collect your email address and any information you submit in the waitlist form. If you visit the marketing site, we collect standard server logs (IP address, user-agent, referrer, timestamps).
2How we use your data
We use your data to:
- Provide the Service. Authenticate you, store your projects and writing, generate AI outputs you request, deliver features like dictation and web search, and give you access to your account.
- Personalize your experience. Use the voice and personalization data in § 1 to tailor outputs to your individual style, within your account only.
- Handle billing. Process subscriptions and renewals through Stripe, and send you invoices and billing notices.
- Support you. Respond to support requests, diagnose problems, and restore your data if something goes wrong.
- Keep the Service secure. Detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms of Service.
- Operate and improve the Service. Analyze aggregated usage patterns, monitor reliability, debug errors, and identify product improvements. We do not use your writing content to train AI models (see § 4).
- Send essential communications. Notify you about billing, security, policy changes, account issues, and other administrative matters.
- Send product updates about features, announcements, and tips — you can opt out of these at any time (see § 8).
- Comply with law. Meet legal obligations, respond to lawful requests from authorities, and enforce our agreements.
3What we do not do with your data
- We do not sell or rent your personal data to anyone, for any purpose. This commitment covers the sale of personal information as defined under the California Consumer Privacy Act.
- We do not share your personal data for cross-context behavioral advertising and we do not run advertising on the Site or in the Service.
- We do not use your writing or other content to train large language models. See § 4.
- We do not use non-personal or aggregated data as a loophole to disclose your information to advertisers. Any data we share in aggregated form is engineered so that individual users cannot be re-identified.
4AI providers and your content
Akston uses a changing mix of third-party AI model providers. When you ask the Service to generate or analyze content, we send the parts of your prompt and context needed for that request to a provider on your behalf. The current provider list is maintained in the subprocessor table in § 6.
Akston does not operate a training pipeline or submit customer content for model training. For inference, we use paid or business API paths and configure available data controls to limit processing to delivering and protecting the Service. Applicable terms, processing, and retention vary by provider and feature, and may include limited storage for service delivery, security, abuse monitoring, or legal compliance.
The account-isolated style and voice personalization described in § 1 is performed on your content within your account and is not shared with model providers as training data.
We may add, change, or remove model providers over time. Where it is material, we will update the subprocessor list. If you have questions about a specific provider’s data practices, email team@akston.ai.
6Subprocessors we use
These vendors process personal data on our behalf. We keep this list current; if we add a subprocessor that materially changes the scope of processing, we will update this policy and, where required, give you advance notice.
We may also use user-directed integrations that you connect (such as Google Drive) to take actions you initiate. Those services act as independent data controllers for data you send them; their own privacy policies apply.
7Data retention and deletion
While your account is active
We retain your account and workspace data for as long as your account is active so you can continue to use the Service. You can delete individual projects, files, conversations, or your entire account from your settings at any time.
After paid access ends
If you cancel your subscription or we cancel it for non-payment, paid features remain available through the end of the billing period. After that, your account stays active with basic access. You can continue to view and edit existing projects and access projects shared with you according to your collaboration permissions, but paid AI features are unavailable.
90-day retention period
We retain projects you own for at least 90 days after paid access ends. After that, we may delete those projects and their User Content from our live systems. Projects owned by other users are not deleted merely because your subscription ended. You are responsible for exporting anything you want to keep.
Backups
Deleted data may remain in encrypted backups for a limited period (typically up to 35 days) before being overwritten in the ordinary course. Backups are not used for any purpose other than disaster recovery.
Data we keep longer
We retain the following beyond account deletion to the extent required by law or necessary for legitimate business purposes:
- Billing and tax records, for the period required by applicable law (typically seven years in the United States).
- Records necessary to enforce our agreements, defend against legal claims, or respond to subpoenas.
- Abuse-prevention records (such as terminated-account identifiers) for as long as needed to prevent re-abuse.
Account-termination requests
To delete your account and associated data outside of the normal flow, email team@akston.ai with “Account deletion” in the subject line. We will verify the request and confirm when deletion is complete.
8Your choices
Access, export, and deletion
You can access and export your workspace content at any time from the Service. You can delete projects, files, and your account from your settings. If you cannot accomplish something through the Service, email team@akston.ai.
Correcting your data
You can update your name, email, and other account details in your settings. Contact us if you need help correcting data you cannot edit directly.
Marketing emails
You can unsubscribe from product updates and marketing emails at any time using the unsubscribe link in those emails or in your account settings. We will continue to send you essential transactional emails (billing, security, policy changes) for as long as you have an account.
Push notifications
If you enable browser push notifications, you can disable them in your browser settings or in the Service’s notification settings.
Integrations
You can disconnect any third-party integration at any time from your account settings. Disconnecting revokes our stored OAuth tokens and stops further data exchange with that service.
Personalization reset
You can reset the voice and personalization data described in § 1 from your account settings, or delete specific writing samples individually.
9California residents
If you are a California resident, this section describes your rights under California law and how to exercise them.
Categories we collect
In the last 12 months, we have collected the following categories of personal information, as defined by the California Consumer Privacy Act (CCPA/CPRA):
- Identifiers: name, email, account identifier, IP address, device identifier.
- Commercial information: subscription and billing records.
- Internet or network activity: pages visited, features used, session data, referral URLs.
- Audio data: dictation recordings you submit for transcription.
- Professional information that you voluntarily provide (e.g., experience level, writing types, audiences).
- Inferences: personalization profiles (voice, style, preferences) derived from content you provide.
- User content: writing, documents, and conversations you create in the Service.
Purposes and recipients
We collect this information for the purposes described in § 2 and share it with the categories of recipients described in § 5 and § 6.
No sale or share of personal information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
Your rights
You have the right to:
- Know what personal information we have collected about you, why, and with whom we have shared it.
- Delete personal information we have collected from you, subject to legal exceptions.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information (not applicable to us — see above).
- Limit our use of sensitive personal information (not applicable — we do not use sensitive personal information for purposes that require this right).
- Non-discrimination: we will not deny you the Service, charge you a different price, or provide a different quality of service because you exercised your rights.
How to exercise your rights
Email team@akston.ai with “California privacy request” in the subject line and tell us which right you want to exercise. We will verify your identity (usually by confirming you control the email on file) and respond within the timeframes required by law (typically 45 days, with a possible 45-day extension). An authorized agent may submit a request on your behalf with your written authorization.
Shine the Light
California Civil Code § 1798.83 permits California residents to request information about our disclosure of personal information to third parties for their direct marketing purposes. We do not make such disclosures.
10International users
Akston is operated from the United States and our subprocessors are primarily based in the United States. If you access the Service from outside the United States, you consent to the transfer of your personal data to, and processing in, the United States.
If you are located in the United Kingdom, the European Economic Area, or another jurisdiction with data-protection laws that grant you rights similar to those described in § 9, contact team@akston.ai to exercise them. We will respond consistent with applicable law.
11Do Not Track and cookies
Do Not Track
Some browsers send a “Do Not Track” (DNT) signal. There is currently no industry standard for responding to DNT signals, and we do not alter our data practices based on them. We do not permit third parties to collect personally identifiable information about your activity on the Site over time and across third-party websites.
Cookies we use
We use a small set of cookies and similar technologies that are strictly necessary to operate the Service:
- Authentication cookies that keep you signed in.
- Session and security cookies used to route requests and protect against fraud.
- Preference cookies that remember things like your theme.
We do not use third-party advertising or cross-site tracking cookies. You can block or delete cookies in your browser settings; doing so may prevent you from signing in or using the Service.
12Children's privacy
The Site and the Service are intended for adults. They are not directed to anyone under 18 years old, and we do not knowingly collect personal data from children under 18. If you believe a child has provided us with personal data, contact team@akston.ai and we will delete it promptly.
13Security
We use administrative, technical, and physical safeguards designed to protect personal data, including encryption in transit (TLS) and at rest where practical, access controls for our systems, least-privilege principles for employees, and monitoring for unauthorized access. Integration tokens, including Google OAuth tokens, are encrypted at rest using AES-256-GCM. No system is perfectly secure, and we cannot guarantee the security of data in transit to us or stored by us. We will notify you of a data breach involving your personal information consistent with applicable law.
14Changes to this policy
We may update this Privacy Policy from time to time. If we make a material change, we will provide reasonable advance notice by email to the address associated with your account and/or by prominent notice on the Site before the change takes effect. Non-material changes or clarifications take effect on posting. The “Last updated” date at the top of this page always reflects the current version.
15Contact us
For questions about this Privacy Policy, to exercise any of the rights described above, or to report a privacy concern:
Akston Company
Attn: Akston Team
4967 Newport Avenue, Ste 12 Box 539
San Diego, California 92107
Email: team@akston.ai