Privacy Policy
Last Updated: August 2026
This Privacy Policy describes how Second Spring Design Inc. (doing business as Aventide) (“Aventide,” “we,” “us,” or “our”) collects, uses, stores, and shares information when you use the Aventide platform, available at aventide.ai. By using Aventide, you agree to the practices described in this policy.
If you have questions, contact us at support@aventide.ai.
Article 1. Information We Collect
1.1 Account Information
We collect the information you provide when creating and managing your Aventide account, including your name, email address, and subscription and billing information. Account and subscription management is handled through Outseta.
1.2 Business Information
When you use the Business Hub, we collect and store business facts, goals, planner items, and AI-generated documents you create or upload. This information is scoped to your account and is used to power Aventide’s AI agents and business management features.
1.3 Conversation Data
When you interact with Aventide’s AI agents (Think and Sidekick), your conversation messages are sent to Anthropic via their API. Conversations are scoped to your business context only. Anthropic’s API terms prohibit the use of customer API data for training AI models. Conversation data is not used to train any externally shared AI model.
1.4 Integration Credentials
When you connect third-party platforms to Aventide, we store the OAuth tokens required to maintain those connections. Tokens are encrypted at rest. For one-time data imports (such as importing data from platforms like HoneyBook using the switch kit), credentials are used solely to perform the import and are not retained after the import is complete.
1.5 Communication Preferences
If you opt in to proactive communications, we collect the contact details you provide, including your email address, phone number, and Telegram chat ID. All proactive communication features require explicit opt-in and can be disabled at any time.
1.6 Usage Data
We collect log data and information about how you use Aventide features, including device information, browser type, IP address, pages visited, and feature interactions. Feature usage data is anonymized for analytics purposes. We use cookies for session management and usage analytics only. We do not use advertising cookies or cross-site tracking cookies.
1.7 Google Account Data
When you connect your Google account to Aventide, we access only the specific data scopes you authorize. Aventide’s use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
Google account identifiers and OAuth credentials: Used for authentication and to maintain your authorized connection.
Google Calendar (scope: calendar.events): Used to read and write calendar events so that your Aventide calendar features reflect your Google Calendar and so that bookings and scheduled items can be added to your calendar on your behalf.
Gmail (scopes: gmail.readonly and gmail.send): We access your Gmail messages to display them in Aventide’s unified Inbox. We send emails on your behalf only when you explicitly approve the action within Aventide. Gmail data is never used to train AI models and is never shared with third parties.
YouTube (scopes: youtube.upload and youtube.readonly): We use youtube.upload to publish video content you have created within Aventide to your YouTube channel, with your explicit approval before each publish action. We use youtube.readonly to display your channel name and thumbnail within Aventide.
Google user data is used solely to provide the features described above. It is never used for advertising, AI training, resale, or any secondary commercial purpose. It is never transferred to third parties except as necessary to operate the features you have authorized. You can revoke Aventide’s access to your Google account at any time at myaccount.google.com/permissions.
1.8 Financial Connections and Bank Account Data
Aventide is a Stripe platform partner. Aventide is not a bank, not a financial institution, and not subject to banking or financial services regulations. The Financial Connections feature uses the Stripe Financial Connections API to give you a read-only view of your bank account balances and transaction data inside your Aventide dashboard.
How authorization works:
Access is entirely user-initiated. You authenticate directly with your bank through Stripe’s hosted OAuth flow. Aventide never receives your bank login credentials. You must explicitly authorize the connection before any data is accessed.
Categories of data accessed:
Account balances
Transaction history
Account identifiers (tokenized by Stripe)
Institution name and account type
How this data is used:
Financial Connections data is used solely to display financial information and summaries within your Aventide dashboard for financial management purposes. It is not used for advertising, AI model training, resale, data brokering, cross-context profiling, or any purpose beyond displaying your own data back to you.
Storage and infrastructure:
All Financial Connections data is stored and processed in the United States on Supabase/AWS US infrastructure. Stripe is the underlying infrastructure provider for the Financial Connections feature. Stripe’s handling of data during the authorization and connection flow is governed by Stripe’s Privacy Policy, available at stripe.com/privacy.
Disconnection and retention:
You can disconnect your bank account at any time from your Aventide account settings. Upon disconnection, your authorization is revoked with Stripe and your Financial Connections data is deleted from Aventide within 30 days. The maximum retention period for Financial Connections data is one year from the date of access.
1.9 Social Media Publishing Connections
When you connect social media accounts to Aventide for content publishing, we store the encrypted OAuth tokens required for those connections. Aventide supports publishing to Instagram, Facebook, Threads, TikTok, YouTube, Bluesky, LinkedIn, and X.
Content is published only when you explicitly approve it within Aventide. Nothing is published to any connected account without your direct approval.
TikTok: Aventide uses TikTok’s Content Posting API. Video content is sent to your TikTok inbox or drafts, and you complete the publishing action within the TikTok app. We request only the minimum required scopes: video.upload and basic profile information.
OAuth tokens for social media accounts are deleted immediately upon disconnection.
1.10 Uploaded Files and Video Content
Aventide stores files you upload or create on the platform, including team chat attachments, Business Hub files, client-room documents, workspace source files, and video content. Uploaded files are private to your account and are only accessible to people you have authorized in Aventide (your team members, or a client you have explicitly shared a file with). Aventide does not inspect the contents of uploaded files except to produce the features you request (for example, generating a preview, or providing a file to an AI agent when you attach it to a conversation).
Uploaded files are retained while your account is active and for 90 days after cancellation, or until you delete them, whichever comes first. Uploads that are started but never finished are discarded within 24 hours.
Marketing videos created for publishing are handled as a publishing tool, not a video archive:
Published marketing videos are deleted from Aventide’s storage 7 days after a successful publish. Thumbnail images, metadata, and the permalink are retained.
Unpublished marketing video drafts are deleted after 30 days.
1.11 Cloudflare Services (Bot Protection and File Storage)
Cloudflare Turnstile on login, signup, and form endpoints to prevent automated abuse. Cloudflare collects IP addresses, browser signals, and request metadata for security purposes only. This data is not used for advertising or profiling. Cloudflare’s handling of this data is described in the Cloudflare Turnstile Privacy Addendum (cloudflare.com/turnstile-privacy-policy).
Cloudflare R2 object storage to store the contents of files you upload (see §1.10). Files are stored in a private storage bucket that is not publicly accessible, are encrypted at rest and in transit, and are served only through short-lived, account-authorized links generated by Aventide. Cloudflare has no independent right to use the contents of your files; its processing is governed by Cloudflare’s Privacy Policy (cloudflare.com/privacypolicy).
Aventide uses two Cloudflare services:
1.12 Financial Data and Payment Processing
Aventide uses Stripe for payment processing. We do not store your card numbers or raw bank account details. Aventide is PCI DSS Level 1 compliant through Stripe. We retain only the metadata Stripe returns to us, including subscription status, the last four digits of your card for display purposes, and invoice records.
The Money workstation accesses Stripe account data via the Stripe API under the permissions you grant. This data is used only to display financial information within the Aventide platform. No raw financial records are stored by Aventide or shared with third parties outside of what is described in this policy.
Article 2. Team Accounts
2.1 Shared Data
When you use Aventide as part of a team account, the following data is shared and visible to all team members:
Business facts, goals, planner items, and documents in the Business Hub
Client rooms, Money workstation, Calendar, Marketing, Offers, and Smart Compliance features
Business-connected integrations (Stripe, QuickBooks, Zoom, Framer)
Shared credit balance (individual usage is visible to all team members, but all draw from the same shared pool)
2.2 Private Data
The following data remains private to each individual team member and is not visible to other team members:
Your own conversation history with AI agents Think and Sidekick
Your personally connected integrations (Google, Gmail, Canva)
Your own to-do items
2.3 Account Owner Controls
The first person on the account is the account owner. The account owner can invite and manage team members and can restrict access to Smart Compliance to the account owner only.
Article 3. How We Use Your Information
We use the information we collect for the following purposes:
Providing the service: Authenticating your account, maintaining your session, and delivering Aventide’s features.
AI agent context: Business context provided to AI agents is scoped to your business only. It is not mixed with data from other accounts.
Recipe execution and document generation: Processing your inputs to execute automated workflows and generate documents within your account.
Integration connections: Storing and using OAuth credentials to maintain connections to third-party platforms you have authorized.
Publishing content: Publishing content to connected social media accounts, YouTube, or Framer only when you have explicitly approved the specific content and action.
Proactive reminders and communications: Sending you proactive notifications only if you have opted in to receive them.
Security and fraud prevention: Using usage data and bot protection signals to detect and prevent abuse.
Anonymized analytics: Analyzing aggregated, anonymized usage patterns to improve Aventide’s features.
Article 4. Knowledge Graph
Aventide builds an anonymized, aggregated knowledge graph to identify patterns across businesses using the platform. The following protections apply:
No pattern or insight appears until it is derived from a minimum of five businesses.
No individual names, revenue figures, or other identifying information are included.
Google user data is never used for this purpose.
You may opt out of contributing to the Knowledge Graph at any time by contacting support@aventide.ai.
Article 5. What We Do Not Do
We do not sell your personal data or individual business data to any third party.
We do not use your data to train AI models that are shared externally. Anthropic’s API terms prohibit training on customer API data.
We do not share identifiable business information with other users outside your account.
We do not use your data for advertising.
We do not allow third-party advertisers to access your data.
We do not use Financial Connections data for any purpose other than displaying your own financial information back to you within Aventide.
We do not use Google user data for advertising, AI training, or any secondary commercial purpose.
Article 6. Data Sharing
We share data with third-party providers only as necessary to operate the Aventide platform. The table below describes each provider, what data is shared, and the purpose.
Provider Purpose Data Shared Cloudflare Bot protection on login, signup, and form endpoints (Turnstile); private object storage for uploaded files (R2) IP address, browser signals, request metadata (Turnstile); contents of files you upload, encrypted and stored in a private bucket (R2) Google Authentication and connected features (Calendar, Gmail, YouTube) OAuth identifiers and authorized scope data TikTok Video publishing via Content Posting API OAuth tokens, video content, basic profile information Meta (Instagram, Facebook, Threads) Social media publishing OAuth tokens, published content, basic profile information LinkedIn Social media publishing OAuth tokens, published content, basic profile information X / Twitter Social media publishing OAuth tokens, published content, basic profile information Bluesky Social media publishing OAuth tokens, published content, basic profile information QuickBooks Accounting sync for Money workstation OAuth tokens, invoice and expense data Zoom Meeting link generation for bookings OAuth tokens, meeting metadata Canva Design import into Library OAuth tokens, imported design files Framer Blog publishing to connected site OAuth tokens, published blog content Mailchimp Email list sync OAuth tokens, contact list data Anthropic AI conversation and execution Business context shared during sessions only Outseta Account and subscription management Email address, name, subscription data Supabase Database hosting All stored business data (encrypted) Vercel Application hosting and serverless execution Request logs, serverless execution data Twilio SMS and WhatsApp delivery (opt-in only) Phone number, message content Telegram Messaging (opt-in only) Chat ID, message content Slack Sidekick messaging channel (opt-in only) Workspace and channel identifiers, message content Stripe (payment processing) Payment processing for subscriptions Payment intent metadata; no card data stored by Aventide Stripe Financial Connections Bank account data access for the Financial Connections feature OAuth authorization tokens, account identifiers (tokenized), institution metadata (read-only, user-authorized)
We do not share data with any provider not listed above except as required by law.
Article 7. Data Retention
Data Type Retention Period Account and business data Retained while account is active and for 90 days after cancellation Uploaded files (chat attachments, Business Hub files, client documents, workspace source files) Retained while account is active and for 90 days after cancellation, or until you delete them Unfinished uploads Discarded within 24 hours Conversation history 12 months Execution history 24 months Communication messages 12 months Google data (cached) Cached for 24 hours; deleted upon disconnection Social media OAuth credentials Deleted immediately upon disconnection Marketing video files (published) Deleted 7 days after successful publish; thumbnail, metadata, and permalink retained Marketing video files (unpublished drafts) Deleted after 30 days Usage logs 90 days Financial Connections data Maximum 1 year from date of access; deleted within 30 days of disconnection Anonymized Knowledge Graph data Indefinite; contains no identifying information
All personally identifiable data is permanently deleted within 30 days of account deletion.
Article 8. Storage and Security
8.1 Storage Infrastructure
Aventide’s structured data (account records, business facts, documents, conversations, and file metadata) is stored on Supabase PostgreSQL databases hosted on Amazon Web Services (AWS) in the United States. The contents of files you upload are stored in Cloudflare R2 object storage in a private bucket configured with a North American storage location preference. All data is encrypted at rest and in transit using TLS 1.2 or higher. Access to stored files is authorized by Aventide on every request and is never granted through public links. Tenant isolation is enforced at the database level, and file storage access is scoped to your account so that your data is never accessible to other accounts. Encrypted daily database backups are retained for 30 days.
Storage limits by plan:
Free: 1 GB
Starter: 5 GB
Pro: 10 GB
8.2 Security Practices
All OAuth tokens and integration credentials are encrypted at rest.
We apply the principle of least privilege for internal access to data.
We conduct regular security reviews and dependency updates.
To report a security concern, contact support@aventide.ai.
Article 9. Data Breach Notification
In the event of a data breach, we follow the notification requirements applicable to the affected individuals:
GDPR: We will notify the relevant supervisory authority within 72 hours of becoming aware of a breach, as required by Article 33 of the GDPR. Where a breach is likely to result in a high risk to the rights and freedoms of individuals, we will notify affected individuals without undue delay, as required by Article 34.
U.S. state breach notification laws: We will comply with applicable breach notification requirements under California law and the equivalent laws of other U.S. states.
Affected users: We will notify affected users by email using the email address associated with their Aventide account.
Article 10. Not for Healthcare Use
Aventide is not designed for use by HIPAA-covered entities. We do not offer Business Associate Agreements (BAAs). You must not enter protected health information (PHI) into Aventide. Health and wellness coaches who are not licensed medical providers and who do not handle PHI may use Aventide for general business management purposes.
Article 11. Children’s Privacy
Aventide is designed for business owners and is intended for users who are 18 years of age or older. We do not knowingly collect personal data from anyone under the age of 16. If you believe we have inadvertently collected data from a person under 16, contact us at support@aventide.ai and we will delete it promptly.
Article 12. Cookies
Aventide uses cookies for session management and usage analytics only. We do not use advertising cookies. We do not engage in cross-site tracking. You can manage cookie preferences in your browser settings.
Article 13. Communication and Opt-Out
All proactive communications from Aventide require your explicit opt-in. You can manage and disable communication preferences at any time:
In-app: Visit the Connect page in your Aventide account settings.
Telegram: Send /stop to the Aventide Telegram bot.
SMS: Reply STOP to any SMS message from Aventide.
Email: Use the unsubscribe link in any email from Aventide.
Article 14. User Rights
You have the following rights with respect to your personal data:
Access: Request a copy of the personal data we hold about you.
Correction: Request that we correct inaccurate or incomplete information.
Deletion: Request that we delete your personal data, subject to applicable legal requirements.
Export: Request an export of your data in JSON or CSV format.
Withdraw Consent: Withdraw consent for any processing based on consent, including proactive communications and optional integrations.
Object to Knowledge Graph: Opt out of contributing anonymized data to the Aventide Knowledge Graph.
To exercise any of these rights, contact support@aventide.ai. We will respond within 30 days.
Article 15. GDPR (European Economic Area and United Kingdom)
15.1 Data Controller
Second Spring Design Inc. is the data controller for personal data processed through Aventide.
15.2 Legal Bases for Processing
We process personal data on the following legal bases:
Contract Performance: Processing necessary to provide the Aventide service to you under our Terms of Service.
Legitimate Interests: Processing for anonymized analytics, fraud prevention, and security, where these interests are not overridden by your rights.
Consent: Processing for proactive communications, optional integrations, and non-essential cookies, where you have given explicit consent.
15.3 Automated Decision-Making
Aventide’s AI outputs are informational tools that assist you in making decisions. They do not constitute automated decisions with legal effects or similarly significant effects on you under Article 22 of the GDPR. All AI-generated content requires your review and approval before any action is taken.
15.4 International Data Transfers
Aventide stores and processes all data in North America, primarily in the United States. For users in the European Economic Area and the United Kingdom, transfers of personal data to the United States are made on the basis of Standard Contractual Clauses (SCCs) approved by the European Commission under Chapter V of the GDPR. Copies of the applicable SCCs are available upon request at support@aventide.ai.
15.5 Data Processing Agreement
A Data Processing Agreement (DPA) is available upon request at support@aventide.ai.
15.6 Supervisory Authority
You have the right to lodge a complaint with the data protection authority in your country of residence or establishment.
Article 16. CCPA and CPRA (California Residents)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
Right to Know: The right to know what personal information we collect, use, disclose, and sell.
Right to Delete: The right to request deletion of your personal information.
Right to Correct: The right to request correction of inaccurate personal information.
Right to Opt-Out of Sale: The right to opt out of the sale of your personal information. Aventide does not sell personal information.
Right to Limit Use and Disclosure of Sensitive Personal Information: The right to limit our use of sensitive personal information to purposes permitted under the CPRA.
Right to Non-Discrimination: The right not to receive discriminatory treatment for exercising your privacy rights.
To exercise any of these rights, contact support@aventide.ai.
Article 17. Other U.S. State Privacy Laws
Residents of Virginia (CDPA), Colorado (CPA), Texas (TDPSA), Connecticut, and other U.S. states with applicable privacy laws have similar rights to access, correct, delete, and opt out of certain processing of their personal data. To exercise these rights, contact support@aventide.ai.
Article 18. Changes to This Policy
We will notify you of material changes to this Privacy Policy by email or through an in-app notice at least 30 days before the changes take effect. The “Last Updated” date at the top of this policy reflects the most recent revision. Continued use of Aventide after a change takes effect constitutes your acceptance of the updated policy.
Article 19. Contact
If you have questions, concerns, or requests relating to this Privacy Policy, contact us at:
Second Spring Design Inc.
aventide.ai
Google Search Console and Google Analytics data
If you connect Google Search Console or Google Analytics to Aventide (Marketing → SEO/AEO → Connect Google), Aventide asks for read-only access to the properties you choose, using Google’s Search Console read-only scope (webmasters.readonly) and Analytics read-only scope (analytics.readonly).
What we access. From Search Console: search performance for your own website, meaning clicks, impressions, average position, the search queries your site appears for, and your top pages. From Analytics: traffic for the one property you pick, meaning sessions, engaged sessions, and top landing pages.
How we use it. Only to show you your search and traffic performance inside your Aventide workspace and to suggest pages to improve and posts to write. We do not use this data for advertising, do not sell it, do not share it with third parties, and do not use it to train AI or machine-learning models.
What we store. Small summaries only: 28-day totals, up to ten top pages, and up to forty search queries. Summaries refresh when you open the page (automatically no more than once a day) or when you press Refresh. We never store raw responses from Google’s APIs. Access tokens are encrypted at rest.
Your control. You can disconnect at any time in Business Hub → Integrations, or remove Aventide from your Google Account permissions page. Disconnecting stops all access, and you can ask us to delete stored summaries at any time.
Limited Use. Aventide’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.