Privacy Policy
Last updated: July 28, 2026 — v1.0
1. Data controller
Data controller: Dijitalgardrop, Inc. d/b/a Axen AI / Tryaxen AI, 1111A South Governors Avenue, #49930, Dover, Delaware 19904, USA. Privacy contact: privacy@tryaxen.ai. Where a business customer uploads data about its own users or customers, the customer is the controller and Tryaxen acts as a processor under instructions; a Data Processing Addendum applies.
2. Scope
This policy covers tryaxen.ai, app.tryaxen.ai, Axen Visibility, Axen Instagram pre-orders, support, payment records, email, surveys and beta programs. Third-party sites and apps have their own policies.
3. Data we collect
Identity & account: name, email, password digest, user ID, country, language, role, verification data. Business & brand: company/brand name, website, industry, niche, target market/audience, brand tone, product info, competitors, goals.
Social media: Instagram username, profile link and — only with your permission — profile, content, analytics and publishing data of connected accounts. Pre-order: selected package, price, order time, Founding Access status, source channel, launch notification preference, activation and refund status.
Payments: plan, amount, currency, tax country, billing address, payment result, Stripe customer/transaction ID, invoice and refund records — full card numbers never reach our servers. Product inputs/outputs: brand names, prompts, scan topics, reports, AI outputs, content calendars, scripts and feedback.
Technical & usage: IP, approximate location, device/browser, OS, session, page views, clicks, errors, performance, login and security logs. Communication: support conversations, emails, survey answers and attachments. Marketing preferences: opt-in/out records, campaign source, email engagement, cookie preferences.
4. Sources
Directly from you; from your account activity; from payment, verification, hosting and analytics providers; from social accounts you connect; from publicly available web pages; and from technical device/cookie signals. Public brand, product and website information may be processed as part of a visibility scan; where such data relates to real persons, applicable data protection rules are observed.
5. Purposes and legal bases
Contract performance: account creation, providing scans/outputs, billing, support, pre-orders and activation. Legitimate interests: security, fraud prevention, debugging, service performance, essential product analytics, business records and B2B relationships — balanced against your rights. Consent: optional analytics/marketing cookies, certain marketing communications, permissioned social account access and transfers requiring consent. Legal obligation: tax, accounting, consumer, sanctions and record-keeping duties. Establishment/exercise/defense of legal claims: disputes, chargebacks, fraud, breach of contract.
6. AI providers and inputs
Brand, prompt or content data you enter may be sent — limited to what the task requires — to AI providers such as OpenAI, Google, Anthropic, Perplexity AI, xAI (Grok) and DeepSeek, or other providers disclosed in the product, to run scans and generate outputs. Do not include confidential or special-category data in AI inputs. Providers' data retention and model-training practices vary by product, contract and settings; Tryaxen prefers enterprise/API data protection options where available.
7. Automated decisions
We do not aim to make fully automated decisions with legal or similarly significant effects. Visibility scores, recommendations, classifications and content plans are informational and do not replace human judgment.
8. Sharing and recipients
Data may be shared to the extent necessary with: hosting/database providers (e.g. Hostinger — our VPS hosting, Supabase), payments (Stripe), transactional email (Resend), AI providers (OpenAI, Google, Anthropic, Perplexity AI, xAI, DeepSeek), error monitoring/analytics, customer support and professional advisers. In a merger, investment, asset sale or restructuring, data may be transferred to a prospective or final acquirer under confidentiality obligations. We may share with competent authorities where legally required. We do not sell your personal data.
9. International transfers
Data may be processed in the USA and other countries where our providers operate. For EEA/UK data we rely on adequacy decisions, Standard Contractual Clauses, the UK addendum or other valid mechanisms. Transfers out of Türkiye follow the current provisions of Law No. 6698 (adequacy, appropriate safeguards such as standard contracts, or exceptional explicit consent).
10. Retention
Data is kept only as long as needed for the purpose, the contract and legal obligations, then deleted, anonymized or access-restricted. Indicative periods: account/product data — while active plus a 30–90 day backup cycle after deletion requests; invoices — statutory tax periods; security/login logs — 6–24 months; support threads — 24 months from last contact; pre-order records — 24 months after activation/refund plus statutory periods (to prove Founding price rights); marketing consent/opt-out — for the consent period and as needed to honor opt-outs; AI inputs/outputs — per plan and product settings with user deletion options.
11. Security and breach
We apply appropriate technical and organizational measures: access control, encryption, secret management, backups, logging, vulnerability management, staff/vendor confidentiality and incident response. No system is absolutely secure. In case of a personal data breach we assess scope and risk and notify authorities and affected persons within the periods required by applicable law.
12. Your rights
Depending on your location you may have rights of access, copy, rectification, erasure, restriction, objection, portability, withdrawal of consent and complaint to a supervisory authority. Where California thresholds apply: rights to know, delete, correct, opt out of sale/sharing, limit sensitive data use and non-discrimination — we do not aim to sell personal data. Send requests to privacy@tryaxen.ai; identity verification or proof of authority may be required and requests are answered within statutory periods.
13. Children
The service is not directed at people under 18. If we learn we have collected a child's data we delete it appropriately; a parent or guardian can notify privacy@tryaxen.ai.
14. Marketing communications
Marketing emails are sent based on a legal basis and your preference; every message contains an easy unsubscribe link. Transactional messages (receipts, security, password, activation, contract notices) may be sent independently of marketing opt-out.
15. Cookies
We currently use strictly necessary cookies only: authentication/session (Supabase), security and payment-flow cookies (Stripe on checkout), and language preference. Our page-view analytics are first-party and cookieless. If optional analytics or marketing cookies are introduced, they will run only after consent where required, and this section plus a preference tool will be updated.
16. Changes and contact
Material changes are announced via the website, panel or email; the updated date appears at the top. Privacy requests: privacy@tryaxen.ai · KVKK: kvkk@tryaxen.ai · Mail: Dijitalgardrop, Inc. d/b/a Axen AI / Tryaxen AI, 1111A South Governors Avenue, #49930, Dover, Delaware 19904, USA. You may also complain to your data protection authority.