Legal
Privacy Policy
The Suite exists to read your documents, courses, and videos and hand them back in an accessible form. That means we handle your content. This page says exactly what we hold, why, and for how long.
Last updated August 10, 2026
What we collect
- Account data — name, work email, organization, role, and the institution your license belongs to.
- Content you submit — the PDFs, Office files, videos, and web pages you send for checking or remediation, the files we produce from them, and the accessibility reports for both.
- Job records — what was checked, what changed, when, by whom, and how much quota it used. These are the verification record the product is built around, and administrators can export them.
- Connection data — when you connect an LMS or a storage account, the tokens needed to read the content you point us at.
- Voice input — if you use the voice agent, the audio of the commands you speak while it is listening.
What we do with it
We use your content to run the job you asked for and to show you the result. We use account and job data to operate the service, enforce quota, bill an institution, support you when something breaks, and keep the service secure. We do not sell personal data, we do not run advertising, and we do not use your content to train general-purpose models.
Who else processes it
We use a small number of processors, each limited to what its job requires:
- Amazon Web Services — hosting, file storage, databases, encryption keys, and transactional email.
- Stripe — payment processing. Card details go to Stripe, not to us.
- Speech and language model providers — captioning, transcription, OCR, alternative-text drafting, and the voice agent, for the duration of the job.
Where processing happens outside your country, it is covered by the safeguards those providers offer. An institution can ask us for the current list of processors before signing.
How long we keep it
Content and derived files stay available while you keep them, so you can download a remediated file or re-open a report later. Delete a job or a file and we remove it from the active service and from backups on our normal backup cycle. Close an account and we delete its content; we keep the minimum billing and job-count records the law and our accounting require.
If your institution needs a specific retention window — shorter or longer — set it in your agreement and we will honour it.
Student data
Course content often contains student work and student names. Where we handle records that are covered by FERPA, we act as a school official with a legitimate educational interest under the institution’s direction: we process that content only to perform the service, and we do not disclose it elsewhere. Institutions that need a written data protection addendum should ask for one.
Your choices
- You can download or delete any file or job you submitted, from the dashboard.
- You can disconnect an LMS or storage connection at any time, which revokes our access.
- You can ask us for a copy of the personal data tied to your account, or ask us to correct or delete it, by writing to support@aristai.io.
- The voice agent only listens after you start it, and stops when you stop it.
Security
Traffic is encrypted in transit and content is encrypted at rest. Access to production data is limited to the people who need it to run the service. There is more detail on the Trust & Security page.
Changes
When this policy changes we update this page and the date at the top, and we tell account holders before a material change takes effect.