Privacy Policy

Lalvani AI Hub · Last updated 20 August 2026

Lalvani AI Hub (“we”, “us”, “our”) operates Automation Hub (the “Service”), a business automation platform that includes an optional AI Assistant which produces a personalised daily briefing from your connected email and calendar. This policy explains what personal data we process, why, and your rights. It applies to people who use the Service through an account provided to them.

We are a sole-operator business based in the United Kingdom. For any privacy question, or to exercise your rights, contact lalvanishaan5@gmail.com.

1. Information we collect

Account information

When your account is created (by invitation from your organisation’s administrator), we store your name, email address, role, and the organisation (tenant) you belong to. Your password is stored only as a salted, one-way BCrypt hash — we never store or have access to your actual password.

Email and calendar data (AI Assistant only — optional)

The AI Assistant is off by default. If you choose to connect a Microsoft 365 or Google (Gmail / Calendar) account, we access the following strictly to build your briefing:

We request read-only permissions only (Google gmail.readonly and calendar.readonly; Microsoft Mail.Read and Calendars.Read).

Connection tokens

When you connect an email account, the provider issues OAuth access and refresh tokens. These are stored encrypted at rest and are used only to fetch the data described above. You can disconnect at any time, which deletes them.

Generated briefings

The briefing we generate for you (a summary and suggested actions) is stored under your account so you can view past briefings. The underlying raw email and calendar data used to build it is not stored — it is processed in memory and then discarded.

Knowledge graph of derived facts (World Model)

The Service maintains a knowledge graph for each individual user — structured notes about people, organisations, teams, projects, decisions, and commitments relevant to your work. Your knowledge graph is private to your own account: it is not shared with your organisation, and other users — including your organisation’s administrators — cannot read, edit, or search it. Entries can be created manually by you and, when the AI Assistant is enabled, can be suggested automatically: after a briefing runs we extract candidate facts from the same email and calendar summaries described above (never from full message bodies) and store each suggestion together with its provenance — the short source snippet that supports it.

People and organisations you tell us about (roster — optional)

You can optionally declare the people and organisations you work with — your own organisation, colleagues, clients and their contacts, projects, and products — on the World Model setup page. For each entry you may record a name, the kind of thing it is, an optional note, and alternative spellings and email addresses that refer to the same person or organisation.

Security and operational logs

For security we keep audit logs of significant account events (such as sign-in), which include your IP address and browser user-agent, plus counts of AI tokens used. We keep these only as long as needed for security and troubleshooting.

2. How we use your information

We use your information solely to:

We do not use your information for advertising, and we do not sell it.

3. Google API Services — Limited Use

Automation Hub’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Google user data obtained through the Gmail and Google Calendar APIs is used only to provide the user-facing AI Assistant features you have enabled — generating your daily briefing, proposing knowledge-graph entries for you to review, and answering your questions about your own knowledge graph (Ask); is not transferred to others except as needed to provide those features, for security, or to comply with law; is not used for advertising; and is not used to train generalised or broadly-applicable AI / ML models. Any human access to Google user data is prohibited except with your explicit consent, for security purposes, to comply with applicable law, or where the data has been aggregated and anonymised.

4. Third parties that process data for us

To provide the AI Assistant and related account services, we share the minimum necessary with the following sub-processors:

Each processes data only on our instructions. We do not sell personal data to anyone.

5. Data retention

6. How we protect your data

Connection tokens are encrypted at rest using ASP.NET Core Data Protection; knowledge-graph content, including node names, is likewise encrypted at rest using ASP.NET Core Data Protection (its identity is preserved through a keyed one-way index so it stays searchable without exposing the names); passwords are stored as BCrypt hashes; all traffic is served over encrypted TLS connections; and access to email / calendar data is limited to generating the AI Assistant briefing you enabled.

Some operational metadata about your knowledge graph is stored unencrypted so the Service can query, maintain, and draw it safely. This includes entry and relationship types, internal record and owner identifiers, links between entries, timestamps, whether an entry was written by you or derived automatically, proposal status and confidence, and keyed one-way values used for search and deduplication. It does not include entry names, notes, relationship properties, proposal content, or source evidence, which are encrypted. To be clear about the limit of this: someone with direct access to the database could infer how many entries you keep, their categories, the kinds and timing of their relationships, how they cluster together, and whether they were written by you or derived automatically, even though every name, note, and source reference within them is encrypted.

7. Your rights

Because we operate in the United Kingdom, UK GDPR gives you the right to access, correct, delete, restrict, or object to our processing of your personal data, and to data portability. Where processing relies on your consent (connecting an email account), you can withdraw that consent at any time. To exercise any right, contact lalvanishaan5@gmail.com.

8. Revoking access and deleting your data

9. International transfers

Some processors (for example, Anthropic) are located in the United States. Where personal data is transferred outside the UK / EEA, we rely on appropriate safeguards such as the processor’s standard contractual clauses.

10. Children

The Service is intended for business use and is not directed to anyone under 18. We do not knowingly collect data from children.

11. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above and, where appropriate, notifying you.

12. Complaints

If you have concerns about how we handle your data, please contact us first. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk.


See also our Terms of Service.