Pallio Privacy Policy

Last updated: March 17, 2026

Google OAuth Compliant Version

Table of Contents

  1. Overview
  2. Information We Collect
  3. How We Use Your Information
  4. How We Share Your Information
  5. Data Retention & Deletion
  6. Data Security & Protection
  7. Your Privacy Rights
  8. Regional Privacy Rights
  9. Third-Party Links & Services
  10. Children's Privacy
  11. Changes to This Privacy Policy
  12. Contact Us
  13. Technical Details

1. Overview

Pallio AI ("we," "our," "us," or "Pallio") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service, including our website (https://pallioai.com), mobile applications, and related services (collectively, the "Service").


2. Information We Collect

2.1 Google Account Information

When you sign in with Google, we collect and store the following information from your Google account:

Scope Requested: We request basic Google profile data (email, name, photo) via Firebase Authentication. We do NOT request access to your Google Drive, Calendar, Gmail, or other Google services.

2.2 Profile Information

You may provide additional personal information when you create or update your Pallio profile:

2.3 Chat & Conversation Data

When you use Pallio to chat with AI personas, we collect:

2.4 Usage & Analytics Data

We collect information about how you use the Service:

2.5 Technical Data

2.6 Payment Information

When you subscribe to Pallio, we collect:

Note: Payment data is processed and stored by Stripe, our PCI-compliant payment processor. We do not directly store credit card information.


3. How We Use Your Information

3.1 To Provide the Service

We use your information to:

3.2 To Improve the Service

We use your information to:

3.3 To Communicate With You

We use your email address to:

3.4 To Detect Abuse & Ensure Security

We use technical data to:

What We Do NOT Use Your Information For

We explicitly do NOT:

  • Sell your personal data to third parties or data brokers
  • Use your conversations to train or fine-tune AI models
  • Use your data for targeted advertising or personalized ads
  • Retarget you with ads across other websites
  • Determine your creditworthiness or eligibility for loans
  • Share your Google account credentials with any third party
  • Create marketing databases or contact lists from your data

4. How We Share Your Information

4.1 Sharing With AI Providers (ESSENTIAL FOR SERVICE)

To generate responses, we send your conversations to third-party AI providers. This is necessary to provide the core functionality of Pallio. The data shared includes:

4.2 Data NOT Shared With Third Parties

We do NOT share with AI providers:

4.3 Legal & Compliance Disclosures

We may disclose your information if required by law:

4.4 Service Providers

We use service providers to operate the Service:

These service providers are contractually obligated to use your information only as necessary to provide services to Pallio.

4.5 Aggregated & De-identified Data

We may use aggregated, de-identified data for analytics, research, and benchmarking. This data cannot identify you individually and is not subject to this privacy policy.


5. Data Retention & Deletion

5.1 How Long We Keep Your Data

Data Type Retention Period
Chat histories & messages Indefinite (until you delete)
User account profile While account is active
Uploaded documents Until you delete or account deleted
AI personas created Until you delete or account deleted
Payment records Per accounting standards (7 years)
Technical/access logs 12 months
IP addresses (rate limiting) 48 hours
Email notifications (read) 30 days
Widget sessions 24 hours
Messaging bot sessions 7 days
Backup copies (in case of accidents) Up to 90 days

5.2 How to Delete Your Data

Delete Specific Chats:

Export Your Data:

Delete Your Entire Account:

Legal Hold Exceptions:

5.3 Data You Cannot Delete


6. Data Security & Protection

6.1 Encryption

In Transit (TLS/SSL):

At Rest:

6.2 Access Controls

6.3 Security Practices

6.4 Security Limitations

No security system is 100% secure. While we implement industry-standard protections:


7. Your Privacy Rights

7.1 Access Your Data

You have the right to:

7.2 Correct Your Data

You have the right to:

7.3 Delete Your Data

You have the right to:

7.4 Object to Processing

You have the right to:

7.5 Data Portability

You have the right to:

7.6 Withdraw Consent

You have the right to:


8. Regional Privacy Rights

8.1 European Users (GDPR)

If you are in the European Union, UK, or EEA:

8.2 California Users (CCPA)

If you are in California:

How to Request: Email privacy@pallioai.com with your request. We will verify your identity and respond within 45 days.

8.3 Other Jurisdictions

We comply with applicable privacy laws in all jurisdictions where we operate. If your region has specific privacy protections, we honor those rights.


9. Third-Party Links & Services

The Service may contain links to third-party websites and services (social media, documentation, external tools). This Privacy Policy does not apply to third-party services. We recommend reviewing their privacy policies before providing information.

Third-party services we link to:


10. Children's Privacy

Pallio is not intended for children under 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected information from a child under 13:

If you believe we have collected information from a child under 13, contact us at privacy@pallioai.com.


11. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:

Material changes will be communicated at least 30 days before becoming effective. Your continued use of the Service after changes indicates your acceptance of the updated policy.


12. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact:

Pallio AI Privacy Team

For data requests (access, deletion, export), please provide:

We will respond to your request within 30 days.

Data Protection Officer: If you need to reach our DPO or compliance team, email privacy@pallioai.com with "Data Protection Officer" in the subject line.


13. Appendix: Technical Details

OAuth Flow

  1. You click "Sign in with Google"
  2. Firebase redirects you to Google's authentication page
  3. You authorize Pallio to access your basic profile (email, name, photo)
  4. Google redirects back to Pallio with an authentication token
  5. We store your email, name, and photo in our database
  6. Your Google account credentials are never sent to us—only the token

AI Response Generation Process

  1. You send a message in Pallio
  2. Your message is sent to our secure backend via HTTPS
  3. We may add context from your chat history and uploaded documents
  4. The message is sent to an AI provider (Google, Anthropic, Azure, etc.)
  5. The AI provider generates a response
  6. The response is sent back to you
  7. Both your message and the AI's response are stored in your chat history in Firestore

Document Embedding Process

  1. You upload a PDF or document
  2. We extract text and split it into chunks
  3. We generate embeddings (dense vectors) using text-embedding-3-large (3072 dimensions)
  4. We generate sparse embeddings using SPLADE
  5. Embeddings are stored in Pinecone (vector database)
  6. When you ask a question, we search embeddings to find relevant document chunks
  7. Relevant chunks are included in the context sent to the AI provider

Data Residency

If you require EU-specific data residency, please contact privacy@pallioai.com to discuss options.