Skip to content
Aqvitus
ProductChannelsPricingCompareCompany
Sign in Start your trial
  • Product
  • Channels
  • Pricing
  • Compare
  • Company
Sign in Start your trial

Privacy

What we collect, why we have it, and the line between our own records and the customer conversations a business keeps inside its workspace.

Last updated 29 September 2026

On this page

  1. Who we are
  2. Two different things, and the difference matters
  3. What we collect
  4. Why we use it
  5. Cookies and tracking
  6. AI models and your text
  7. Who else touches the data
  8. How long we keep it
  9. Getting your data out, and getting it deleted
  10. Europe, the UK and Switzerland
  11. California
  12. Age
  13. Security
  14. Where the data lives
  15. Changes to this policy
  16. Contact

1 Who we are

Aqvitus is operated by EvolvLabs, LLC, a Maryland limited liability company (“EvolvLabs”, “we”, “us”). This policy covers the website at aqvitus.com and the Aqvitus service at app.aqvitus.com.

EvolvLabs, LLC
6028 Monroe Ave, Sykesville, MD 21784, USA
support@aqvitus.com

2 Two different things, and the difference matters

Aqvitus holds two kinds of personal data, and we do not have the same role for both.

  • Conversations and records about a business’s own customers. When a business runs its support and sales on Aqvitus, the messages, contact details, order references, call recordings and notes inside its workspace belong to that business. It decides what is collected, why, and for how long — it is the controller. We process that data on its instructions, under its subscription, only to run the service for it. We do not sell it and we do not use it for our own purposes.
  • Account data and website visits. For the people who sign in to run a workspace — owners, admins, managers, leads, agents, sales and analysts — and for visitors to this website, EvolvLabs is the controller and this policy is the primary document.

If you are a customer of a business that uses Aqvitus and you want to see, correct or delete what it holds about you, ask that business. It is their record to decide on, and the product gives them the tools to answer you — see section 9.

3 What we collect

On this website

  • What you send us. Your email address and anything you write when you contact us at support@aqvitus.com.
  • Technical logs. Our network provider records the usual request data — IP address, browser and device type, the page requested — to serve the site and to stop abuse.

The website asks for nothing else. There is no analytics, no advertising and no tracking of any kind here.

In the service

  • Your account. Name, work email address, the password hash, your second factor if your role requires one, which workspaces you belong to and your role in each, and the sign-in and approval records the audit ledger keeps.
  • Your workspace’s settings. Rules, procedures, knowledge sources, connected tools and the credentials for them, which live in a vault and are never written into a prompt, an event or a log.
  • Your customers’ conversations. Whatever arrives on the channels you connect — chat, email, SMS, voice and RCS — together with the contact record, attributes and consents your workspace keeps, and the events recording what the AI and your team did. Personal fields are encrypted with keys belonging to your workspace alone.
  • Approximate visitor location. If your workspace uses the live board, the city and country our network provider derives from a visitor’s IP address are shown on a map. It is approximate — a city, not an address — and no precise location is collected.

4 Why we use it

To run the service for the workspace that pays for it: receiving and sending messages on the channels it connected, drafting replies, applying the rules it wrote, holding actions for approval, keeping the audit ledger, reporting on it, and billing for it. To answer you when you write to us. To keep the service up, secure and free of abuse.

We do not sell personal information, and we do not share it for advertising. Nothing in one workspace is ever visible to, or pooled with, another.

5 Cookies and tracking

This website sets no cookies of its own. No analytics, no advertising pixels, no tracking. It loads the Geist typeface from Google Fonts, which means Google receives the IP address of the browser asking for the font file, and it is served through Cloudflare, which may set a cookie to distinguish a person from a bot.

The service sets one necessary cookie: the session cookie that keeps you signed in. It is not used for tracking and there is nothing to opt out of — without it you cannot stay signed in.

6 AI models and your text

Aqvitus sends text to an AI model to classify a conversation, draft a reply and search your knowledge. Three things are true of every one of those calls.

  • Personal details are replaced with tokens before the text leaves. Names, addresses, card and order references and the rest are swapped for placeholders, and are put back only on our own servers, after the model has answered.
  • The model never decides anything. It proposes a reply or an action; deterministic code — schema validation and the rules your workspace wrote — decides whether anything happens. Risky actions wait for a person.
  • Nothing a workspace holds trains a model for anyone else. Inside a workspace the product does learn from its own conversations — an answer a person approves can become a reusable answer — and that stays in that workspace, under the control of its owners.

A workspace can also bring its own model provider key. When it does, that provider processes the text under the workspace’s own agreement with it, not ours.

7 Who else touches the data

A short list of outside services, each doing one job and given only what that job needs. The Trust center names every one of them, what it does and where it runs.

Two things are chosen by the workspace rather than by us: a workspace may bring its own AI model provider key, and SMS, voice and RCS run on the workspace’s own carrier account. In both cases that provider is the workspace’s supplier, under its own agreement.

We also disclose data where the law requires it, or to protect the rights and safety of EvolvLabs, our customers and the public; and, if EvolvLabs is ever part of a merger or sale of assets, subject to the commitments in this policy.

8 How long we keep it

Retention is set per workspace, per kind of data. A workspace owner sets how long conversations, recordings, contact records and the rest are kept, and the platform enforces it. We do not impose a single period on everyone, and we are not going to print one here that the product does not apply.

The one default worth naming: the audit ledger — the append-only record of what was done, by whom, under which rule — is kept for seven years where an action cannot be reversed and two years otherwise, and a workspace can change that. It records that something happened; it is not a copy of the personal data behind it.

Email you send us is kept as long as we need it to deal with the matter, then deleted.

9 Getting your data out, and getting it deleted

If you are a customer of a business that uses Aqvitus

Ask that business. They are the controller of their records and the decision is theirs; the product is built so they can act on it. You can also simply say it in the conversation — send me what you hold or delete my data — and Aqvitus recognises the request, opens it and starts its clock for the business to answer. If you do not know who to ask, write to support@aqvitus.com and we will point you at them.

If you run a workspace

  • Export. An owner or admin can export everything the workspace holds about one customer, as JSON.
  • Erasure. An owner or admin can erase a customer. The personal fields are encrypted with keys held per customer, and erasure destroys the keys — the data cannot be read again by us or by anyone. A tombstone is left in its place so the event log stays intact and the history does not silently change shape. Both the export and the erasure are themselves recorded in the audit ledger, and both must complete inside the deadline your workspace sets.
  • Closing a workspace. Write to support@aqvitus.com from the address your account uses. Export what you want first — that is how we confirm the request is yours, and we never ask for your password.

Your own account

To see, correct or delete the personal data we hold about you as an account holder — your name, your email address, your sign-in records — write to support@aqvitus.com from that address. Records that the audit ledger must keep to show an action happened are the exception, and we will say so if that is what is left.

10 Europe, the UK and Switzerland

Where the GDPR or the UK GDPR applies to data we control, our legal bases are performance of a contract (running the service for the account holder), legitimate interests (operating and securing the website and the service) and consent where you gave it. You have the rights of access, rectification, erasure, restriction, objection and portability, the right to withdraw consent at any time, and the right to complain to your supervisory authority.

Where a business uses Aqvitus to handle its own customers, that business is the controller and we are its processor; we act on its documented instructions, and the sub-processors are those named in the Trust center.

11 California

California residents have the right to know what personal information we collect, to access and correct it, to request deletion, and to opt out of sale or sharing. We do not sell personal information and have not done so, and we do not share it for cross-context behavioural advertising. We will never treat you differently for exercising these rights. Where we act as a service provider to a business using Aqvitus, requests about that business’s records are forwarded to it.

12 Age

Aqvitus is a business tool. It is not directed to children, we do not knowingly collect personal information from anyone under 18 for an account, and you must be at least 18 to hold an Aqvitus account. A business using Aqvitus is responsible for whose messages arrive on its channels and for the consents that go with them.

13 Security

Personal fields are encrypted with keys belonging to one workspace; personal details are kept out of logs, out of event metadata and out of prompts; roles are enforced on the server; people who can approve an action must hold a second factor; and every action lands in an append-only, hash-chained ledger you can export. The Security page describes the whole chain, and the Trust center summarises it.

Aqvitus holds no security certification today — not SOC 2, not ISO 27001, not HIPAA, not PCI. No system is perfectly secure, and we will not print a seal an auditor did not give us.

14 Where the data lives

The service runs in the United States, and so do its database and its backups. If you use Aqvitus from elsewhere, your data is transferred to and processed in the United States, where privacy law differs from your own. If your workspace needs a transfer mechanism or a data processing agreement put in place before that is acceptable to you, write to support@aqvitus.com and we will arrange one.

15 Changes to this policy

We may update this policy. The date at the top is the version in force; material changes are posted here, and we will tell account holders by email when a change matters to them.

16 Contact

Privacy requests and everything else: support@aqvitus.com. Our postal address is in section 1.

Related: Terms · Acceptable use · Trust center · Security

Aqvitus

AI-first support and sales. The AI answers first; a person is always one step away.

Product

  • Inbox
  • Live board
  • Approvals
  • AI agent
  • Knowledge
  • Workflows
  • Analytics
  • Sales

Channels

  • Chat
  • Email
  • SMS
  • Voice
  • RCS

Compare

  • vs Intercom Fin
  • vs Zendesk
  • vs Freshdesk
  • vs Tidio
  • vs LiveChat

Company

  • Company
  • Security
  • Contact
  • Pricing
  • Sign in
  • Start your trial
© 2026 EvolvLabs, LLC · Aqvitus is built on Exolvra engineering.
  • Privacy
  • Terms
  • Acceptable use
  • Trust center
  • Security disclosure