Privacy policy
What is kept, where it goes, and how long it stays.
This policy covers Aspire 2: AI at ai.aspire2.app and the apps that open it. It says what the service does today. Effective 2 October 2026.
Who we are
Aspire 2: AI is the product of Mitchell Craig Roemling trading as ASPIRE 2: X (ABN 21 658 558 016), a sole trader in Brisbane, Queensland, Australia. "We" on this page means that business. Write to mitch@mitchellroemling.com about anything here.
What is kept, and where
- Your account. Your email address, a name if your sign-in method gives one, and which method you used, from WorkOS, the sign-in service. We make an account identifier of our own; everything of yours is kept under it.
- Your application. If you apply for the beta: your email address, whether it is for personal or business use, the first job you would hand it, how you heard of it, when suits a call to set you up, the code of the link that brought you if it had one, and our answer. It is joined to your account when you sign in with that address and deleted with it; ask us to delete one made without an account.
- Your conversations. What you type, what your agents answer, the tools they used and what those returned, and the work that leaves a conversation: hand-offs, plans of work, jobs, routines and their runs. They are kept in a store of your own on Cloudflare.
-
Your vault. Kept in Cloudflare's object storage under your account, in
folders that stay apart:
notes/for the notes you upload,imported/for what you import,documents/for the documents you write,files/for the files you upload and the web pages you add by their address, which the service fetches once from their own site, with the text read from each,memory/for what your agents remember, with a version behind every change,conversations/for the notes taken when a conversation is wrapped up,drafts/for what an agent drafts until you keep or discard it, andindex/, an index rebuilt from the rest. What goes to the Bin is hidden from your agents and deleted for good after thirty days. - Your agents and settings. Your agents, each with its name, role, manner, model, abilities and skills; your projects and your Dashboard; your quiet hours and the rest of your settings; and, if you turn notifications on, the push subscription your browser makes (an address and keys), that device's time zone and the grants you give it.
- Your connections. If you connect your calendar, its private address; if you add a plugin, its address and any key it asks for. Each is sealed in your own store, and never shown on a page or given to a model.
- Your plan. Which plan you are on and its period, the identifiers Stripe gives your customer record and subscription, the status Stripe reports, the credits you bought and what is left of them, and any credits we gave you, with the note that came with them. Never a card number: Stripe takes payment details on its own pages and we do not see them.
- Operating records. What each request cost, how long its steps took, and which model answered; and the log lines the service writes, which carry your account identifier and an event or an error, never what you said and never a secret.
- Consent. Whether you ticked the box for launch and product email, and when; and your two confirmations, that you are eighteen or over and that you live in Australia, each with when you gave it, on your application and on your account.
With the desktop app, the files in the folders you join stay on your computer, and a file is copied into your vault only when you import it. Your store keeps each computer's name and when it was last online, the names of the folders you join, and an index of the files in them: each file's path, title, tags, the links it makes, its size and its date, never the file itself. When an agent reads one of those files, your computer sends its text for that answer, and it stays in that conversation like anything else an agent reads.
One measurement runs on these pages: Cloudflare Web Analytics, a small script Cloudflare adds to each page as it is served. It counts page views and load times and records the page, the referrer, the browser and operating system type, the device type and the country, without a cookie, an identifier or a fingerprint, under Cloudflare's own privacy policy; we see totals, never a person. No advertising trackers, no third-party cookies, no contacts, and no location beyond the country Cloudflare reads from your connection.
Every company your words can reach, and why
Whatever an agent reads to answer you (a note, a file, a search result, a calendar event, a mail or a plugin's answer) is sent with your words to the model that agent runs on, and stays in that conversation. Which company that reaches depends on the model you choose for each agent. What each company says it does with what it is sent is taken from its own page, with the day we read it.
- Cloudflare, a United States company, runs all of it on its network: the service, your stores, and the open models, which run on Cloudflare's own hardware in Workers AI whoever made them, among them DeepSeek, Z.ai's GLM, Alibaba's Qwen, Mistral AI, Moonshot AI's Kimi, NVIDIA's Nemotron, Meta's Llama and AI Singapore's Gemma SEA-LION. On one of these, what you say reaches Cloudflare and not the model's maker. Cloudflare's data usage page for Workers AI says your content is not used to train a model and is not kept beyond processing the request (read 13 September 2026). Your stores are placed in the region nearest to us; a model request runs wherever Cloudflare has room, which may be outside Australia.
- Anthropic, in the United States, when an agent runs on Claude Sonnet 5 or Claude Opus 5.5: what that agent is sent goes from Cloudflare's AI Gateway to Anthropic. Anthropic's commercial terms say it may not train models on it, and its retention page says it is deleted within 30 days of receipt or generation, longer only for a usage policy flag or the law (read 1 October 2026).
- OpenAI, in the United States, when an agent runs on GPT-6 Sol or GPT-6 Luna: what that agent is sent goes from Cloudflare's AI Gateway to OpenAI. OpenAI's page on API data says it is not used to train or improve OpenAI's models, and its abuse monitoring logs are kept up to 30 days unless the law needs longer (read 1 October 2026).
- xAI, in the United States, when an agent runs on Grok 4.7: what that agent is sent goes from Cloudflare's AI Gateway to xAI. xAI's enterprise terms say it will not use it to train its models, and it is deleted no later than 30 days after the session, longer only if agreed, for the law, or for safety and abuse prevention (read 1 October 2026).
- Exa, in the United States, answers your agents' web searches and fetches a web page an agent reads. A search's words, or the page's address, go to Exa, with nothing else about you; what comes back is marked as untrusted text. Exa's terms let it use searches and their results to run and improve its own service.
- Google, in the United States, if you sign in with your Google account, when Google tells WorkOS who you are.
- Stripe, in the United States, handles every payment, and sells the subscription to you as the merchant of record (see the terms). It receives your email address, the name and billing country you give it, and your payment details, on its own pages, under Stripe's privacy policy. Stripe tells us who paid for what and nothing more.
- WorkOS, in the United States, provides sign-in. It holds your email address, a name if any, your sign-in method and its own sign-in records, under its own privacy policy.
- Your browser's push service, only if you turn notifications on. Each ping goes to the address your browser gave, at the push service it uses, usually its maker's: Google for Chrome, Apple for Safari, Mozilla for Firefox and Microsoft for Edge, each in the United States and under its own privacy policy: Google's, Apple's, Mozilla's and Microsoft's. A ping is encrypted so that only your device can read it: the push service learns only that the service sent your device something, and when.
We do not sell your data, show you advertising, or share your data with anyone beyond the companies above and the plugins you add yourself, except where the law requires it.
The gateway's log
Every model request passes through Cloudflare's AI Gateway, which counts requests and cost. It keeps a log of each request, with what was sent, the model's answer, the tokens and the cost, so that a failure can be found and a bill checked. The log is bounded by the gateway's storage limit, which we set to hold about a month of use, and older entries roll off as new ones arrive. Only our own Cloudflare account can open it, and nothing in it is used to train a model. Deleting your account does not reach into it: what it holds of you rolls off within about a month.
Your calendar, by its address
Only if you connect it, under Customize, Integrations, by pasting its private address: the secret address your calendar gives for subscribing to it. What is kept is that address, sealed in your own store like a password: it is never shown on a page again, never given to a model and never written to a log. Beside it we keep the calendar's own name, if it gives one, and when it was last read, to show you on its card.
When an agent you have let read your calendar looks at your day, or your Dashboard shows the week ahead, the service fetches the calendar on your behalf from the calendar's own provider, the company that serves the address, and reads each event's time, title and place. Before each fetch it looks up the name of the provider's site, never the secret part of the address, through Cloudflare's public resolver (1.1.1.1), to check that the address leads to the public internet and not to a private network. It holds what it fetched for a few minutes, so it is not fetched twice, and it writes nothing to your calendar. The provider sees the service's request, not you: it comes from Cloudflare's network and carries no cookie or sign-in of yours. Events an agent reads go to the model it runs on, stay in that conversation and pass through the gateway's log, as anything else it reads does.
Disconnect, in the same place, removes the address here. Anyone who holds the address can read the calendar, so to stop it working everywhere, reset it in your calendar too.
Plugins
A plugin is a server you add yourself, under Customize, Plugins, by its address and, where it asks, a key. Adding it lets no agent use it; you let each agent use it on that agent's setup. When an agent calls one of its tools, the server receives what the agent sends it, and its answer goes to the agent's model as untrusted text. A call that would act waits for your approval first, unless you chose Always for that tool, which you can take back on the agent's setup, or marked the plugin read-only when you added it. Each server is run by whoever made it, under their own terms and privacy policy, not ours.
Mail to your agents, when it is on
Where the service takes mail, each agent has an address of its own, shown in Settings, Account. Mail sent there comes in through Cloudflare's email routing and is kept in your own store: from a sender the agent takes mail from, as a Work item on its conversation; from anyone else, held until you allow the sender or bin it, and a binned mail's words are gone. Nothing in a mail is taken as an instruction, and nothing is ever sent from the address. What an agent reads of a mail goes to its model like anything else it reads.
Cookies
The service sets two cookies, both necessary to work: aspire2_session, which
keeps you signed in for up to thirty days and is sealed so that only the service can read
it, and aspire2_auth, which lives for ten minutes while you sign in. These
pages set none. Because nothing beyond what is necessary is set, there is no cookie banner
and nothing to choose. Stripe's and WorkOS's own pages set their own cookies under their
own policies.
What we never do
- Train on your data. We train no model and build none from anything of yours. Your agents' memory is a set of files in your vault, not a model, and you can read, undo and delete it. What each model company says of training is in the list above.
- Sell it, or use it for advertising.
How long it stays, and how to export or delete it
- While your account exists, so does your data. Nothing of yours is deleted on a timer, save what you put in the Bin.
- An export of everything (your vault, your conversations, your settings and the account's ledgers) is one button in Settings, Privacy, as a ZIP you can take once an hour.
- Deleting your account removes your store, everything in your vault and your rows in the shared database, save the record below, and cancels your subscription at once. "Delete my account" in Settings, Privacy does it at once; or ask us at mitch@mitchellroemling.com and it is done within seven days.
- Afterwards. Cloudflare's point-in-time recovery can hold deleted data for up to thirty days, then it is gone. The gateway's log rolls off within about a month. Stripe keeps its transaction records as long as tax and payment law require. WorkOS keeps your sign-in record until it is deleted there, which we do when we delete your account. We keep a record that the account existed and was deleted, with Stripe's number for you, for our books; a one-way hash of your email address, so an account made again at it gets no second free week; and, apart from any account, a one-way hash of each card that has started a free week, so each card has one.
How it is kept safe
Every request is signed in before it does anything; your store is yours alone and every shared row carries your identifier; the keys the service uses are held by the platform and never reach a model, a log or a page. Your agents read your notes and files and never delete or rewrite them; what they remember is written only through fixed operations, with a version behind each. An agent acts outside the service only through a plugin you added, as the section on plugins says. If a data breach likely to cause you serious harm ever occurred, we would tell you and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires.
Your choices
- See and correct. Your conversations, vault, memory and settings are all in the app; for anything you cannot change there, ask us.
- Email. We send you email about the service only with the box ticked, and you can untick it in Settings; every such email has a way to stop. Receipts come from Stripe and sign-in email from WorkOS.
- Complain. Write to us first at mitch@mitchellroemling.com; we answer within thirty days. If you are not satisfied, the Office of the Australian Information Commissioner takes complaints about privacy.
- Age. The service is for people eighteen and over, and during the beta for people who live in Australia. If you are younger, please do not sign up; if we learn an account belongs to someone younger, we delete it.
Changes to this policy
When this policy changes, the new version is published here with its date, and a change that matters to you is emailed to the address on your account before it applies.
Who to ask
Mitchell Craig Roemling trading as ASPIRE 2: X (ABN 21 658 558 016), Brisbane, Queensland, Australia. Support and privacy: mitch@mitchellroemling.com.