AivahHelp CenterGo to Aivah
Trust and Safety4 min read

Privacy, consent, and safe data handling

Review knowledge, visitor fields, connected actions, and conversation data before using Aivah with real people.

By the end of this guideIdentify information and actions needing review, limit unnecessary access, and keep a person responsible for sensitive decisions.

Who this guide is for

Workspace owners, administrators, and reviewers responsible for private information or public experiences

Last reviewed 13 September 2026Review consent requirements
On this page
  1. Before you begin
  2. Steps
  3. 1. Review knowledge in Employees
  4. 2. Limit connected tools
  5. 3. Check web access and lead fields
  6. 4. Review phone, messaging, meeting, and voice use
  7. 5. Handle memory, results, and downloads carefully
  8. 6. Keep a person responsible for sensitive decisions
  9. 7. Check removal requirements
  10. Expected result
  11. Status meanings
  12. Usage credit impact
  13. Information stored or shared
  14. Limits and permanent actions
  15. Common problems and recovery
  16. Next step

Use these checks when an employee will handle company information, interact with visitors, or act through connected services. They help prepare a use case for review; they do not replace your organization's policies or Aivah's approved contractual and privacy information.

Before you begin

Identify the purpose, audience, accountable owner, and information needed. Separate public knowledge from internal information. Use your organization's approved requirements for access, consent, retention, and connected services.

Steps

1. Review knowledge in Employees

Open the intended employee under Employees and review Knowledge and its instructions. Use current, approved sources. Remove unnecessary private information from material intended for public questions, and test answers against those sources before sharing the employee.

2. Limit connected tools

Review Library → Connected tools and the employee's Tools. Allow only the actions needed for the job. For sending, booking, changing, or deleting information, define the confirmation and human review required before the action runs.

Use dedicated connection forms for credentials. Do not place them in knowledge, ordinary conversation, or generation preferences.

3. Check web access and lead fields

In Deploy → Web & embeds, review the selected employee, Connected tools, and lead form. Test the actual visitor entry point and its access conditions before using internal information there.

For each lead field, review the purpose, Label, Required field setting, and Consent text. Collect only what the stated task needs. Have the responsible owner review consent and handling requirements; adding text to a form is not legal approval.

4. Review phone, messaging, meeting, and voice use

Review Phone numbers, Messaging channels, and Meetings under Deploy before connecting a new destination or sending an invite. Confirm who may receive or participate in the conversation and what information the employee may use.

Use voice recordings only with appropriate rights or permission. Check your organization's participant and recording requirements, and end active media sessions when finished.

5. Handle memory, results, and downloads carefully

Use Library → Memory & sessions and Insights only for information you are authorized to review. Confirm the correct account, record, and filter scope before editing or exporting.

A download makes another copy. Review its contents and coverage, store it in an approved location, and exclude private records from public screenshots and routine support requests.

6. Keep a person responsible for sensitive decisions

Require a qualified person to review the source, context, and proposed action for sensitive or high-stakes work. A confident answer, completed generation, or Insights signal is not a substitute for that review.

7. Check removal requirements

Before deleting records or using Profile & security → Delete account, arrange any needed handover and review billing, connected services, and retention requirements. Read the confirmation. Do not assume an Aivah action removes copies already held by another service or downloaded elsewhere.

Expected result

The use case has an accountable owner, appropriate knowledge and permissions, a defined purpose for collection, and a clear process for reviewing sensitive actions and information.

Status meanings

A saved setting, connected state, or completed task is a product state. It is not privacy, security, or legal approval. Use the responsible owner's review process for those decisions.

Usage credit impact

Tests, voice, generation, and connected activity can affect usage. Use current account information to set a suitable budget; this guide does not define credit rates.

Information stored or shared

Relevant areas include account details, employee knowledge, conversation content, memory, lead fields, generated work, and information passed to connected services. The exact processing depends on the features used and the applicable service arrangements. Check approved product and policy information for retention, location, and deletion requirements.

Limits and permanent actions

Messages, calls, meeting invitations, and connected actions can affect people or systems outside Aivah. Some changes may be difficult to reverse. The account-deletion screen warns of a permanent action; this article does not establish deletion timing, data location, security certification, or the removal of outside copies.

Common problems and recovery

  • Private information entered public knowledge: stop using the affected source for visitors, follow your organization's handling process, and review a corrected source before retesting.
  • A tool has excessive access: reduce the allowed scope and review the employee's instructions before another test.
  • A form asks for unnecessary details: revise its fields and purpose with the responsible owner before collecting more information.
  • A screenshot or download contains private data: limit access and handle copies under your organization's process.
  • You need an exact retention or security answer: request the current approved information through Aivah support; do not infer it from a screen label.

Next step

Apply the lead and public-action checks, or contact support for the approved information relevant to your use.