Legal Information

Privacy Policy

Effective Date: July 8, 2026 Last Updated: July 8, 2026

Utari, LLC ("Utari," "we," "us," or "our") provides utari.ai and Utari Eternal, an AI platform and service for creating, operating, and interacting with authorized AI Instances, knowledge systems, voice features, Community Member experiences, connected applications, and related services (collectively, the "Services"). This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when people use our website, web app, mobile app, desktop app, APIs, AI Instances (including JeremyAI), Utari Eternal, Community Member experiences, voice features, integrations, billing features, and related services. Capitalized terms not defined here have the meanings given in the Utari Terms of Service.

1. Introduction and Key Terms

Scope. This Privacy Policy applies to personal information Utari processes as described above. It should be read together with the Utari Terms of Service.

Key Terms. In this Policy: an "AI Instance" is an AI-powered clone, persona, assistant, or knowledge or voice experience operated through Utari Eternal; an "Instance Owner" is the person or entity that creates, controls, administers, or pays for an AI Instance; a "Source Individual" is the person whose data, likeness, or voice is used to create or configure an AI Instance; and a "Community Member" is a person who interacts with an AI Instance.

2. Information We Collect

Account and Profile Information. Name, email address, login credentials or authentication identifiers, account settings, organization or team information, role, permissions, profile information, and preferences.

Instance and Configuration Information. AI Instance name, subdomain, description, persona, instructions, Source Individual information, authorization status, knowledge sources, memory settings, access and invite settings, Community Member settings, voice settings, connected-application settings, billing plan, and related configuration.

User Content. Chats, prompts, messages, files, documents, images, videos, audio, recordings, transcripts, notes, source materials, knowledge-base materials, memories, skill.md files, connected-application data, AI outputs, and other content submitted, uploaded, imported, connected, generated, or processed through the Services.

Source Individual Data. Where an AI Instance is based on a Source Individual, we may process that person's name, likeness, biography, voice, audio samples, recordings, transcripts, writing style, knowledge, documents, files, messages, public or private materials, and authorization or consent records.

Community Member Information. If you interact with an AI Instance as a Community Member, we may collect your account and invite information, messages, prompts, responses, voice interactions, files, memories you create or update, skill.md files, knowledge materials, session information, and usage information. Depending on product settings, the Instance Owner and authorized administrators may be able to view Community Member conversations, queries, memories, transcripts, usage, and related interaction data.

Voice, Audio, Transcript, and Biometric Information. If voice features are enabled, we may process voice recordings, audio samples, call recordings, call metadata, transcripts, voice settings, voice-clone configuration, voice models, and generated audio. Some of this information may constitute biometric information or biometric identifiers under laws such as the Illinois Biometric Information Privacy Act and similar Texas and Washington statutes. See the Biometric Information section below.

Connected Application Data. If you connect third-party applications, we process information from those applications according to the permissions you grant. This may include data from Google Drive, Google Docs, Google Slides, YouTube, Slack, Shopify, email providers, notification providers, Composio-connected applications, and other integrations.

Google Drive Data. If you connect Google Drive, Utari may process file metadata, file names, folder information, file IDs, MIME types, file sizes, checksums, creation and modification timestamps, file contents, parsed text, sync status, and related metadata for files and folders you authorize, so they can be used as knowledge sources for your AI Instance. See the Google API Services and Limited Use section below.

Billing Information. Subscription plan, invoice information, payment status, billing contact, customer and subscription IDs, credits and Tokens, usage, taxes, entitlements, and transaction metadata. Payment card information is processed by payment providers such as Stripe or RevenueCat and is not stored directly by Utari.

Usage, Device, Cookies, Logs, and Analytics. IP address, device identifiers, browser information, operating system, app version, pages viewed, features used, referral URLs, session identifiers, cookies, local storage, performance data, diagnostics, error logs, event metadata, and analytics events.

Support and Communications. Information you provide through support requests, email, forms, troubleshooting sessions, feedback, surveys, incident reports, privacy requests, or other communications.

3. How We Collect Information

Sources. We collect information:

  • directly from you;
  • from an Instance Owner, team owner, organization, administrator, or authorized representative;
  • from a Source Individual or a person acting on their behalf;
  • from Community Member interactions;
  • from files, recordings, memories, knowledge sources, or connected applications you upload, import, connect, or authorize;
  • from payment, hosting, database, AI, voice, analytics, observability, security, support, and infrastructure providers; and
  • from automated logs and product usage events.

4. How We Use Your Information

Purposes. We use information to:

  • provide, operate, maintain, and secure the Services;
  • create, configure, personalize, and operate AI Instances, including JeremyAI and other subscription experiences;
  • process prompts, messages, files, recordings, memories, knowledge sources, transcripts, connected-app data, and Community Member interactions;
  • provide AI responses, search, retrieval, memory, voice, transcription, parsing, model routing, tool use, and knowledge workflows;
  • manage accounts, organizations, teams, roles, permissions, Instance Owners, Source Individuals, and Community Members;
  • verify authorization, consent, ownership, or rights to create or operate an AI Instance;
  • process billing, subscriptions, credits, Tokens, invoices, taxes, usage, and entitlements;
  • connect and operate third-party integrations you authorize;
  • detect, prevent, investigate, and respond to fraud, abuse, security incidents, policy violations, privacy requests, and technical issues;
  • debug, monitor, analyze, and improve the Services;
  • provide support, including troubleshooting user or Community Member issues;
  • comply with law, enforce our terms, and protect rights and safety; and
  • fulfill other purposes disclosed at collection or with your consent.

5. AI, Model Providers, and Training

Providers. Utari uses AI systems and third-party model, voice, transcription, parsing, search, sandbox, integration, and tooling providers to deliver the Services. These providers may process prompts, outputs, User Content, Community Member content, Source Individual data, files, metadata, audio, transcripts, embeddings, and other information as needed to provide the Services.

Current Training Position. Utari does not currently fine-tune large language models on customer, Instance Owner, Source Individual, or Community Member data. However, third-party provider training, retention, and model-improvement practices vary by provider, account type, contract, configuration, and settings, and Utari does not represent that its providers are configured for zero data retention.

Future Use. Utari may in the future use customer, Source Individual, or Community Member data to train, fine-tune, or improve models to improve its systems. If Utari does so beyond what is necessary to provide the requested Services, Utari will provide notice and obtain consent where required by applicable law.

6. Google API Services and Limited Use

Limited Use. Utari's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements, where applicable.

Google Drive Practices. For Google Drive data:

  • Utari requests Google Drive access only to provide user-facing features, such as connecting selected Drive files or folders as knowledge sources for an AI Instance;
  • Utari may read file metadata and file contents needed to ingest, sync, parse, search, summarize, retrieve, and answer questions from connected Drive sources;
  • Utari does not sell Google user data;
  • Utari does not use Google user data for advertising;
  • Utari does not transfer Google user data except as needed to provide or improve the user-facing feature, comply with law, protect security, prevent abuse, or as otherwise permitted by Google's policies and your consent;
  • Utari does not allow humans to read Google user data unless necessary for security, legal compliance, abuse prevention, support with your consent or direction, or internal operations permitted by applicable policy; and
  • you may disconnect Google Drive through product settings or by revoking access in Google, and may request deletion of ingested Google Drive data by contacting hey@utari.ai. Disconnecting may stop future sync but may not automatically delete previously ingested content unless a deletion process is completed.

7. AI Instances, Clones, Voice, and Likeness

Authorized Instances Only. Utari Eternal is intended for authorized AI Instances. Users may not create AI Instances of other people without the necessary rights, permissions, and consents. Utari may require signed authorization documents, consent records, identity or authority verification, or additional review before creating, enabling, publishing, or operating an AI Instance. Utari does not permit AI Instances of deceased people or deceased public figures unless this policy is changed.

Source Individual Configuration. If an AI Instance is based on or represents a Source Individual, information about that Source Individual may be used to configure the AI Instance, including knowledge, memories, files, voice, likeness, messages, public information, and other authorized data. Users and Instance Owners are responsible for ensuring they have the right to provide and use such information.

8. Biometric Information (Voice)

What We Collect. When you use voice cloning or voice features, we may collect and process voice recordings and generate a voice model derived from them. In certain states, this may be considered biometric information or a biometric identifier.

Consent. Utari obtains affirmative consent before activating voice cloning or creating a voice model, and requires Instance Owners to obtain the consent of any Source Individual whose voice is used. You may decline or withdraw consent, in which case the voice feature will not be available for that voice.

Use and Disclosure. Voice recordings and voice models are used only to provide the voice features you request and are processed by the voice providers described in this Policy. Utari does not sell voice biometric information and does not disclose it except to the providers necessary to deliver the feature, to comply with law, or with your consent.

Retention and Destruction. Utari retains voice recordings and voice models only as long as needed to provide the voice feature, and will delete them upon account closure or when the voice feature is disabled, subject to a limited backup window, and in no event later than three (3) years after your last interaction with the voice feature, except where a longer period is required by law.

9. How We Share Your Information

Recipients. We may disclose information:

  • to service providers and subprocessors that help us provide the Services;
  • to AI, model, voice, transcription, parsing, search, sandbox, hosting, database, storage, payment, analytics, observability, security, support, and integration providers;
  • to connected applications at your direction or according to permissions you authorize;
  • to Instance Owners, organization administrators, or authorized administrators where applicable to their account, workspace, AI Instance, or Community Members;
  • to comply with law, legal process, court orders, subpoenas, or government requests;
  • to enforce our terms, investigate abuse, protect rights, prevent harm, and maintain security;
  • in connection with a merger, acquisition, financing, reorganization, or sale of assets; and
  • with your consent or at your direction.

Advertising and Analytics Sharing. Utari uses advertising and analytics technologies on its marketing website, which may include the Meta (Facebook) pixel and Google Ads tags. When these technologies are active, certain online identifiers and activity may be shared with those providers for measurement and advertising, which may constitute "sharing" (and, in some cases, a "sale") of personal information under California and other state privacy laws. See the California Privacy Rights section for how to opt out.

No Sale of Google User Data. Utari does not sell Google user data and does not use Google user data for advertising.

10. Service Providers and Subprocessors

Categories. Utari uses vendors and subprocessors in categories including hosting and infrastructure; authentication, database, storage, and backend services; payment processing; AI and model providers; voice, transcription, and audio providers; document parsing, embeddings, vector search, and knowledge processing; connected-application providers; analytics, observability, and error monitoring; email, notification, support, and security providers; and sandbox, web search, scraping, media, and automation tools.

Current Providers. Current providers may include AWS, Vercel, Supabase, Stripe, RevenueCat, Google, OpenAI, Anthropic, OpenRouter, AWS Bedrock, Cerebras, Vapi, ElevenLabs, Deepgram, AssemblyAI, Llama Cloud / LlamaParse, PostHog, Sentry, Langfuse, Braintrust, Umami, Google Analytics, Meta, and Google Ads. The current subprocessor list is maintained by Utari and may be updated from time to time.

11. Organization, Instance Owner, and Community Member Visibility

Administered Accounts. If you use Utari through an organization, team, business account, or AI Instance controlled by another person or entity, that organization, team owner, Instance Owner, or authorized administrator may have access to information associated with the account, AI Instance, or Community Member interaction.

Community Member Notice. Community Members should understand that their interactions may be processed by Utari and may be visible to the relevant Instance Owner or authorized administrators, depending on product settings and applicable law, including messages, queries, memories, transcripts, and usage. Instance Owners are not currently expected to directly delete Community Member data on their own; Community Members may contact Utari at hey@utari.ai to request deletion or other privacy assistance.

12. Cookies and Tracking Technologies

Use. We use cookies, local storage, pixels, SDKs, analytics tools, and similar technologies to operate the Services, keep users signed in, remember preferences, secure the platform, measure usage, debug performance, improve features, and support analytics and advertising where applicable.

Advertising Technologies. Our marketing website may use advertising technologies, including the Meta pixel and Google Ads tags, and analytics tools such as PostHog, Umami, and Google Analytics. Where these technologies result in sharing of personal information for cross-context behavioral advertising, we honor opt-out choices as described in the California Privacy Rights section, including recognized Global Privacy Control signals.

13. Data Retention

General. We retain information for as long as reasonably necessary to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, maintain security, support business operations, handle billing and tax requirements, and fulfill the purposes described in this Policy. Our current retention targets are set out below and may be adjusted to meet legal, security, or operational needs.

Data typeRetention target
Account dataDuration of account plus 1 year
Chat and conversation logsDuration of account plus 90 days
Files and documentsDeleted on account closure, plus a 30-day backup window
Memories and knowledge-base entriesDeleted on account closure, plus a 30-day backup window
Voice recordings and voice modelsDeleted on account closure or feature disable, plus 30 days; 3-year maximum from last use
Embeddings / vector dataDeleted when the source content is deleted
Connected-app OAuth tokensRevoked on disconnect; deleted within 30 days
Billing records7 years (tax and legal standard)
Server and application logs90 days
Backups30 days after deletion from production

Some data may be retained after account closure or integration disconnect where required for legal, billing, security, backup, fraud-prevention, dispute, or operational reasons. Data sent to third-party providers may be subject to those providers' deletion and retention processes.

14. Data Security

Measures. We use administrative, technical, and organizational measures designed to protect information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Your Role. We encourage you to protect your account credentials, use secure devices, and promptly report suspected unauthorized access or security issues to hey@utari.ai.

15. Your Rights and Choices

General Rights. Depending on your location and relationship to Utari, you may have rights to request access, correction, deletion, portability, restriction, objection, withdrawal of consent, or to opt out of certain processing, or to receive information about how your data is used.

How to Exercise. You may submit a request by contacting hey@utari.ai. We may need to verify your identity, account ownership, relationship to an AI Instance, and authority before fulfilling a request. If your information is controlled by an organization, team, Instance Owner, or business customer, we may direct your request to that party or coordinate with them.

Limits. Deletion requests may not result in immediate deletion in all systems. Some information may be retained where permitted or required by law, for security, billing, fraud prevention, dispute resolution, backups, or logs.

16. California Privacy Rights (CCPA/CPRA)

Categories Collected. In the preceding twelve months, Utari may have collected the following categories of personal information: identifiers (such as name, email, and IP address); account and commercial information (such as subscription and billing records); internet and network activity (such as usage and device data); audio and voice information (including voice recordings and, where applicable, biometric information); geolocation inferred from IP address; and the contents of communications and User Content you provide.

Purposes and Recipients. We use these categories for the business and commercial purposes described in this Policy and disclose them to the categories of service providers, subprocessors, and other recipients described above.

Sale or Sharing. Because advertising technologies such as the Meta pixel and Google Ads tags are present on our marketing website, Utari may "share" (and in some cases "sell") identifiers and internet activity information for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA. Utari does not knowingly sell or share the personal information of individuals under 16, and does not sell Google user data.

Your California Rights. California residents have the right to know, access, correct, and delete personal information; the right to opt out of the sale or sharing of personal information; the right to limit the use of sensitive personal information; and the right to non-discrimination for exercising these rights.

How to Opt Out. You may opt out of the sale or sharing of your personal information by using the Do Not Sell or Share My Personal Information link or by contacting hey@utari.ai. We honor recognized Global Privacy Control (GPC) browser signals as a valid opt-out request. You may use an authorized agent to submit requests, subject to verification.

17. European Privacy Rights (GDPR / UK / EEA)

Roles. For personal information about Instance Owners and Source Individuals who sign up directly with Utari, Utari acts as a controller. For personal information about Community Members who interact with an AI Instance, Utari and the Instance Owner act as joint controllers: the Instance Owner decides to deploy the AI Instance and can view interactions, while Utari determines the technical means of processing. Where Utari processes data solely on behalf of a business customer under a written agreement, Utari acts as a processor and the Data Processing Agreement governs.

Legal Bases. Where required, Utari relies on one or more of the following legal bases: performance of a contract; your consent (for example, for voice biometric processing and certain advertising technologies); Utari's legitimate interests in operating, securing, and improving the Services; and compliance with legal obligations.

Your Rights. If you are in the EEA, United Kingdom, or Switzerland, you may have rights to:

  • access your personal data;
  • correct inaccurate data;
  • request deletion;
  • restrict processing;
  • object to processing;
  • request portability;
  • withdraw consent where processing is based on consent; and
  • lodge a complaint with a supervisory authority.

Data Protection Officer. Utari has not appointed a Data Protection Officer, as it is not required to do so under current law. Privacy inquiries may be directed to hey@utari.ai.

18. International Data Transfers

Transfers. Utari and its providers may process information in the United States and other countries, which may have data-protection laws different from those in your location. Where required, Utari uses appropriate transfer mechanisms, such as the European Commission's Standard Contractual Clauses, for transfers of personal data out of the EEA, United Kingdom, or Switzerland.

19. Children's Privacy

Minimum Age. The Services are intended for users who are at least 18 years old. The Services are not directed to children, and we do not knowingly collect personal information from anyone under 18. If we learn that we have collected personal information from a person under 18, we will take steps to delete it.

20. Changes to This Policy

Updates. We may update this Privacy Policy from time to time. If we make material changes, we will provide notice as required by law. We will not materially expand our use of previously collected personal information without appropriate notice and consent where required.

21. Contact Us

How to Reach Us. Legal Entity: Utari, LLC (state of formation: Delaware). Mailing Address: 1900 N Miami Ave, Miami, FL 33136. Privacy and Support Contact: hey@utari.ai. Security Contact: hey@utari.ai.