← Back to home

Privacy Policy

Last updated: April 2026

1. Data controller

Aylin is operated by Marcel Valentin, based in Zurich, Switzerland. For any questions about how we handle your data, contact us at privacy@aylin.my.

2. Scope

This policy covers all personal data processed through the Aylin website at aylin.my and the Aylin companion bot on messaging platforms (currently Telegram). It applies under the Swiss Federal Act on Data Protection (nFADP) and, where applicable, the EU General Data Protection Regulation (GDPR).

3. What data we collect

Website visitors

We use Vercel Analytics, a cookieless and privacy-friendly analytics service. It collects aggregated page view data without identifying individual visitors. No personal information is collected from browsing alone.

Waitlist signups

When you join our waitlist, we collect:

  • Your email address
  • Your name (optional)
  • Platform preferences (WhatsApp, Telegram, Discord)
  • Demographics such as age range and gender (optional, used for product research)
  • Interests and intended use case (optional)
  • UTM parameters from the URL you used to reach our site (for marketing attribution)
  • Your IP address (used solely for rate limiting, not stored long-term)

Bot users

When you interact with the Aylin companion bot, we collect:

  • Your Telegram user ID (to identify your account across sessions)
  • Your messages and the bot's responses (stored as conversation history)
  • An AI-generated memory profile that summarizes topics you've discussed, your communication preferences, and conversational context — used to make the bot feel more personal over time
  • Interaction logs (timestamps and direction of messages) used to schedule proactive check-ins at appropriate times
  • Records of proactive messages sent to you (content, timing, delivery status)

4. How we use your data

  • To notify waitlist members when early access becomes available
  • To understand which platforms and features our users prefer
  • To power the companion bot — generating contextual responses, maintaining conversation continuity, and personalizing interactions
  • To extract and update your memory profile so the bot remembers what matters to you
  • To schedule proactive messages at times that suit your routine
  • To measure the effectiveness of our marketing channels
  • To protect the service against abuse (rate limiting)

We do not sell your data. Ever.

5. Legal basis for processing

  • Consent — When you sign up for the waitlist or start a conversation with the bot, you consent to the processing described in this policy. You can withdraw consent at any time.
  • Legitimate interest — We process certain data (analytics, rate limiting, service security) based on our legitimate interest in operating and improving Aylin, balanced against your rights.

6. Automated profiling

Aylin uses AI to automatically generate a memory profile from your conversations. This profile may include topics you've discussed, your communication style, emotional context, and preferences. The purpose is solely to personalize your experience — making the companion feel like it genuinely remembers you.

These profiles are never used to make decisions with legal or similarly significant effects. You have the right to object to this profiling at any time by contacting us at privacy@aylin.my. If you object, we will delete your memory profile and disable profiling for your account.

7. Third-party services and data transfers

To provide the service, we share data with the following third-party providers:

  • Google Gemini API(United States) — Your conversation history is sent to Google's Gemini API to generate responses and extract memory profiles. Google's API data processing terms apply.
  • Telegram Bot API— Messages are delivered through Telegram's infrastructure. Telegram's own privacy policy governs their handling of your data.
  • Supabase(AWS eu-central-1, Frankfurt) — Waitlist data and rate limit records are stored on Supabase's EU-hosted infrastructure.
  • Resend — Used to send waitlist confirmation emails. Receives your email address and name.
  • Vercel Analytics — Cookieless page view analytics. No personal data is transmitted.

Some of these providers are located outside Switzerland and the EU (notably Google, in the United States). Where data is transferred to countries without an adequate level of data protection, we rely on the provider's standard contractual clauses or equivalent safeguards to protect your data.

8. Data retention

  • Bot data (conversations, memory profiles, interaction logs) — automatically deleted after 12 months of inactivity. If you stop using the bot for 12 months, all your data is purged.
  • Waitlist data — kept until early access launch or until you request deletion, whichever comes first.
  • Rate limit records — short-lived and automatically expire.

You can request immediate deletion of all your data at any time (see section 9).

9. Your rights

Under the nFADP and GDPR, you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Request a copy of your data in a portable format
  • Object to automated profiling
  • Withdraw consent at any time

To exercise any of these rights, email privacy@aylin.my. We will respond within 14 days.

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland.

10. Data security

We protect your data with TLS encryption in transit, encrypted storage at rest, and strict access controls. Our website enforces security headers including Content Security Policy, HTTP Strict Transport Security, and restrictive permissions policies.

11. Cookies

We do not use cookies. Our analytics are fully cookieless, so no consent banner is needed.

12. Age requirement

Aylin is not intended for users under 16 years of age. We do not knowingly collect data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.

13. Changes to this policy

We may update this policy from time to time. For significant changes, we will notify waitlist members and active bot users by email or in-app message. The “last updated” date at the top of this page always reflects the most recent revision.

14. Contact

Marcel Valentin
Zurich, Switzerland
privacy@aylin.my