Privacy Policy

Effective August 18, 2026

This Policy describes how Ellis Labs collects, uses, shares, and protects information in connection with Attune.

1. Scope and roles

This Privacy Policy explains how Ellis Labs handles information in connection with Attune. It covers two different relationships. For information about our own customers (the organizations that use Attune) and their users, we act as a controller. For the support data those organizations process through the service — including messages from their end customers — we act as a processor on the organization's behalf, and the organization is the controller.

If you are an end customer who contacted a business that uses Attune, that business decides how your data is used; please direct privacy requests to them. We will support them in responding.

2. Information we collect

Depending on the relationship, we process:

  • Account information: names, work email, organization, role, and authentication identifiers (via our identity provider).
  • Customer support data (processed for our customers): tickets, messages across connected channels, contact and customer profile records, golf-cart or product records, tags, notes, and attachments.
  • Connected-source data: content retrieved from data sources an organization connects (e.g. commerce, shipping, telephony) at the organization's direction, via API keys, OAuth, or MCP servers.
  • AI interaction data: prompts, retrieved knowledge, tool calls, and generated drafts/replies produced by the agents an organization enables.
  • Usage and device data: log data, IP address, timestamps, and diagnostic events used to operate and secure the service.

3. How we use information

We use information to:

  • Provide, maintain, secure, and improve the service;
  • Route conversations, generate AI drafts and auto-responses within an organization's configured rules, and surface reporting;
  • Authenticate users and enforce isolation between organizations;
  • Detect, prevent, and investigate abuse, security incidents, and violations of our Terms;
  • Communicate with our customers about the service and comply with legal obligations.

4. AI processing

When an organization enables AI features, prompts, connected knowledge, and tool results are sent to the model provider the organization configures in order to generate a response. We do not use Customer Data to train foundation models, and we require our model sub-processors to handle Customer Data under confidentiality and not to train on it except as the organization directs. AI-generated customer-facing replies are labeled and operate within the organization's handoff and approval settings.

5. How we share information

We share information with sub-processors that host and power the service (for example cloud hosting, database, email delivery, realtime messaging, and AI model providers), each under contractual confidentiality and data-protection obligations and only to the extent needed to provide the service. We also share connected-source data with the third-party services an organization has connected, at that organization's direction.

We do not sell personal information. We may disclose information if required by law, to protect rights and safety, or in connection with a merger or acquisition (subject to this Policy).

6. Data retention

We retain account information for as long as an organization's account is active and as needed for legitimate business and legal purposes. Customer support data is retained per the organization's configuration and instructions; on termination we make it available for export for a reasonable period and then delete or de-identify it, unless retention is required by law.

7. Security

We use technical and organizational measures designed to protect information, including per-organization data isolation enforced at the query layer, scoped and auditable credentials for agents, encryption in transit, and least-privilege access controls. No system is perfectly secure, but we work to protect information appropriate to its sensitivity.

8. Your choices and rights

Depending on your location, you may have rights to access, correct, delete, or port your personal information, or to object to or restrict certain processing. Where we act as a processor, we will refer your request to the relevant organization and assist them. Where we are the controller, you can contact us to exercise your rights.

9. International transfers

The service is operated in the United States. If you access it from elsewhere, your information may be transferred to and processed in the United States and other countries. Where required, we rely on appropriate safeguards for such transfers.

10. Children

The service is not directed to children and is not intended for use by anyone under 16. We do not knowingly collect personal information from children.

11. Changes and contact

We may update this Policy from time to time; the "Effective" date above will change and material updates will be communicated through the service. For privacy questions or requests, contact Ellis Labs at privacy@ellislabs.ai.