AyoAI Privacy Policy
Last updated: 2026-10-01
This policy explains what information AyoAI collects, why we collect it, who helps us handle it, how long we keep it, and the choices you have. It covers the ayoai.com website, the account dashboard at ayoai.com/account, and the AyoAI API. It is the Privacy Policy that the AyoAI Terms of Service refer to.
A Simplified Chinese version is at ayoai.com/zh/privacy.
1. Who we are
AyoAI is run by Zachary Kysar, a sole proprietor in Windham, New Hampshire, USA, who trades as Zak Data Solutions. In this policy, "AyoAI", "we", "us" and "our" mean him.
Vinheim (vinheim.com) and Lodestar (lodestar.wiki) are other Zak Data Solutions sites, built using AyoAI. This policy covers ayoai.com and the AyoAI service. It does not cover vinheim.com or lodestar.wiki, except where it says so.
2. What we collect
When you visit our website
We use our own analytics code. We do not use an outside analytics company. The code runs on every page of ayoai.com, including the dashboard, whether or not you are signed in.
It records an event when you view a page, click a button or link, follow a link that leaves our site, sign in or out, start buying credit, or come back from Stripe after paying or cancelling. It also records errors that happen in your browser. An event can include:
- the date and time;
- the full address of the page, including anything after a "?". For example, when you come back from Stripe after buying credit, the address shows the amount and Stripe's reference for that checkout;
- the page that sent you to us (the "referrer"), if your browser shares it;
- your browser's user-agent text, which names your browser, its version and your operating system;
- your browser's language, your screen size, your browser window size and, for page views, the page title;
- for clicks: the words on the button or link (up to 80 characters), the part of the page it was in, and where a link goes, without anything after a "?". We do not record what you type into forms;
- for credit purchases: the amount you chose;
- which language version of our home page you were shown, and how we chose it;
- campaign tags from the link you arrived by, if it had any (utm_source, utm_medium, utm_campaign, utm_term, utm_content, gclid, fbclid and msclkid);
- a random ID for your browser, a random ID for your visit, and whether you have visited before. The browser ID normally comes from Amazon Cognito, our sign-in service, which gives one to every visitor, even visitors without an account;
- your country, as a two-letter code. Our hosting service works this out from your connection;
- a short code made from your IP address (a "hash"). We do not store your IP address itself in these records. The code is not anonymous: someone could match it back to an IP address by trying every possible address. So we treat it as personal information;
- your account ID, if you are signed in.
If something goes wrong in your browser or on our servers, we send ourselves an error report by email. A report can include the error message and technical details, the page, your browser's user-agent text, and your account ID if you are signed in. Some reports include a copy of an analytics event like the ones above. Before a report is sent, we remove text that looks like an API key, a token or a password. Section 4 says who reads these reports. Our server logs can also hold copies of analytics events and error reports, and account IDs.
Our servers see your IP address each time your browser contacts them, as with any website. We use it to limit how many requests one address can send to our site's API routes (100 a minute). We keep this count in memory only.
When you create an account
- Email and password. Amazon Cognito runs our sign-in. Your password goes to Cognito. It is not sent to our own servers. We email you a code to confirm your email address.
- Account record. When you confirm your email, we create your account record. It holds your email address, your account status, the dates you created and confirmed the account, the time of your last sign-in, how many times you have signed in, your credit balance, your pricing tier and your account roles. We also create a storage folder for your account.
- Lodestar sign-ups. AyoAI and lodestar.wiki use the same sign-in system. If you sign up on lodestar.wiki, you also get an AyoAI account record and an email saying your AyoAI account is ready. Our sign-up system writes to its log which site you signed up through.
- Vinheim sign-ups before 26 August 2026. Until that date, vinheim.com used the same sign-in system too. It now has its own. If you signed up on vinheim.com before then, you have a record in our sign-in system, and you may also have an AyoAI account record. The first time you sign in to vinheim.com after that date, vinheim.com checks your email and password against our sign-in system and copies your email address and account ID into its own. Your record in our sign-in system is not deleted when this happens.
When you use the dashboard and the API
- API keys. We store each key with its status, when it was created and when it was last used. We show a new key's full value only once. To make the dashboard faster, our web server keeps a copy of your dashboard's key in memory for up to 24 hours.
- What you put into AyoAI. This includes your environments, tasks and characters (for example, a character's name, backstory and guidance), and the world data your game or app sends us while a server runs.
- Server records. For each server, AyoAI keeps logs, a record of what your world sent and what AyoAI sent back, and the prompts AyoAI sent to AI models, with their responses and token counts. You can see these in the dashboard.
- Usage and billing. We record each server's running time, the AI tokens it used and its cost. We check each API request against your rate limits using your API key.
- Chat. Users with an administrator role can chat with characters from the dashboard. The messages go to your AyoAI server, which may use an AI model to reply.
- Accepting our Terms. When you accept the Terms of Service, we keep a record of it. The record includes your account ID, the version you accepted, and your browser's user-agent text.
Information about the players of your game
If you connect a game or app to AyoAI, it can send us information about the people who play it. Our integration guide tells you to use each player's ID on their platform (for example, a Roblox player ID) as their key, and to send us what players do. Players can chat with characters. Those chats include the player's display name and message, and characters may use an AI model to reply. Characters keep memories of what happened and who did it. A character record can also hold the Roblox ID of the player who created the character.
You decide what your game sends us. We use it to run AyoAI for you, as our Terms of Service describe.
Payments
To add credit, you pay on Stripe's own checkout page. Your card details go to Stripe, not to us. Stripe then sends you back to our site with the amount and a reference for the checkout. It also tells our servers when your payment is complete, so we can add the credit to your balance.
Emails we send
- A code to confirm your email address when you sign up.
- A welcome email, in English and Chinese, when you confirm.
- If your game uses our player-notification feature, emails to you about events your game reports. Your game writes the message, up to 300 characters.
Cookies and similar storage
We use one cookie, ayoai_locale. It is set only when you click one of the two Vinheim buttons near the top of our home page. It remembers the language of the button you clicked, so our home page shows that language next time. It lasts one year.
We also keep some information in your browser's local storage and session storage:
- for analytics: your browser ID; your visit ID and when the visit started (a visit ends after 30 minutes without activity); and, until you close the browser tab, any campaign tags from the link you arrived by, whether we have checked if your account visited before, and whether we have warned you that your device's clock looks wrong;
- for sign-in: Amazon Cognito's sign-in tokens, which keep you signed in;
- for the dashboard: the environment, server, unit and tab you last picked, and whether you closed certain notices.
We do not use advertising cookies. We do not load outside analytics, advertising or session-recording scripts. Our site does not ask your browser for your location, camera or microphone.
3. Why we use it
We use the information above to:
- create your account, sign you in and keep your account secure;
- run AyoAI for you: your environments, servers, characters and dashboard;
- bill you: measure your usage, keep your balance and take payments through Stripe;
- enforce rate limits and protect the service from abuse;
- find and fix problems;
- understand how people use our website and improve it. For example, we looked at which countries and languages our visitors use to decide which language our home page shows first, and we count how many people start and finish buying credit;
- keep a record that you accepted our Terms;
- send you the emails listed above.
We do not sell your personal information. We do not give it to advertising companies, and we do not use it to show you ads.
4. Who handles it for us
- Amazon Web Services (AWS). AWS hosts our website (AWS Amplify and Amazon CloudFront), runs sign-in (Amazon Cognito), stores our data (Amazon DynamoDB, Amazon EFS and Amazon S3), runs our back-end code (AWS Lambda), runs your AyoAI servers (Amazon EC2), keeps our server logs (Amazon CloudWatch), and sends and receives our email (Amazon SES). We use AWS's us-east-2 region, in Ohio, United States. If you use AyoAI from outside the United States, your information is sent to and stored in the United States.
- Stripe. Stripe takes card payments. It handles your card details under its own privacy policy.
- OpenAI. AyoAI's servers send some prompts to OpenAI's AI models and receive the responses. Prompts can include your characters' details, your world data and players' chat messages. Some AI work runs instead on models that we host on the AyoAI server itself, and that text does not go to an outside provider. The dashboard shows which provider handled each saved prompt.
- Anthropic. We use AI agents built on Anthropic's Claude models to help us run AyoAI. The error reports described in section 2 go by email to us and to these agents, which read them to find and fix problems. The agents can also read the other records this policy describes when they need to, to run, fix and improve AyoAI. Anthropic processes what they read.
- Google. Email sent to zak@ayoai.com is forwarded to the owner's Gmail mailbox, where he reads and answers it. Google holds that copy under its own terms.
- People who run AyoAI. People we give administrator access can see account data, including other accounts' data, to run and support the service.
We may also disclose information when the law requires it. If AyoAI is sold or merged, information may pass to the new owner, as section 16.4 of our Terms allows. We do not give your personal information to anyone else, except as this policy describes.
5. How long we keep it
- Website analytics records: each record is deleted automatically about 400 days after we make it. Records made before 27 September 2026 may carry a different expiry date.
- The language cookie: one year.
- Browser storage: local storage stays until you clear it. Session storage is cleared when you close the browser tab. A visit ID stops being used after 30 minutes without activity.
- IP addresses used for rate limits: in memory, for about one minute.
- The copy of your API key on our web server: up to 24 hours.
- Your sign-in record: until you delete your account.
- Your account record (including your balance) and API keys: while your account is open. When you delete your account, we mark them as deleted but keep them. We have not set a time limit for them yet.
- Your environments, tasks, characters and server records: until you delete them. We have not set any other time limit.
- Error-report emails, server logs, usage and billing records, and the record that you accepted our Terms: we have not set a time limit for these yet, so we may keep them for as long as AyoAI runs.
When you delete your account. Your Profile page has a Delete Account button. It first deletes your website analytics records: the ones that carry your account ID, and the other records from the same browsers, including visits made while you were signed out. Then it runs our account deletion process, which marks your account record and API keys as deleted. If that succeeds, it deletes your sign-in record. If the analytics records cannot be deleted, it stops before deleting anything else and shows an error. Deleting your account does not delete your environments, tasks, characters or server records, or the records in the last item of the list above. You can delete environments, tasks, characters and a stopped server's data yourself before you delete your account. For anything else, or to ask what was deleted, email us (see section 6). If you visit our site after deleting your account, the visit is recorded like any other.
6. Your choices
- See your account details. Your Profile page shows the details in your account record.
- Delete things yourself. In the dashboard you can revoke or replace API keys, delete environments, tasks and characters, delete a stopped server's data, and delete your whole account.
- Ask us. Email zak@ayoai.com to ask for a copy of your personal information, or to ask us to correct or delete it. This includes website analytics records. Please write from the email address on your account. If you write from a different address, we will ask you to confirm the request from your account's email address before we act. If you do not have an account, for example because you play a game that uses AyoAI, tell us what your request is about, such as the game and your player ID. We may ask for more details to find your information and to check that it is yours. We can find analytics records that carry your account ID, and the other records from the same browsers. Visits from a browser you never signed in on carry only a random browser ID, so we may not be able to find them.
- Browser settings. You can clear or block cookies and site storage in your browser. This resets the IDs we use to recognize your browser. It does not stop us recording page views and clicks. Our site does not have a setting to turn analytics off, and it does not respond to "Do Not Track" or Global Privacy Control signals.
- Players of games that use AyoAI. If you play a game that uses AyoAI, ask the game's developer about your information first. You can also contact us.
7. Children
AyoAI is a service for people who build games and apps. Our Terms of Service say you must be 18 or older to use it, or accept the Terms for an organization. We do not ask anyone's age when they visit our site or create an account.
Our /developers page is written for people who build Roblox games, and visitors reach it from a "Powered by AyoAI" credit inside those games. Roblox players can be children, so some visitors to that page may be under 18. The page says that you must be 18 or older to create an account. Our analytics records their visits like any other visit. If you are under 18, please do not create an account.
Games built with AyoAI may have young players, and those games can send us information about their players (see section 2).
If you believe a child has given us personal information, email zak@ayoai.com. We will delete the information we can find.
8. How we protect it
- Our site tells browsers to connect to it only over secure (HTTPS) connections.
- Our pages load scripts only from our own site, and connect only to our own services and AWS.
- Passwords must be at least 8 characters long and use upper- and lower-case letters, a number and a symbol. Two-step sign-in is not available yet.
- Before our servers act on an account, they check your sign-in token and check that it belongs to that account.
- We show your full API key once. The key list does not show it.
- Card details go to Stripe, not to us.
- Our analytics store a hash of your IP address, not the address itself.
- Before error reports are emailed, we remove text that looks like an API key, a token or a password.
No website or online service can be made completely secure.
9. Changes to this policy
When we change this policy, we will post the new version on this page and change the "Last updated" date. Each version is also kept at its own address. This version is at ayoai.com/Privacy-2026-10-01.md.
10. Contact
Questions or requests about your information: zak@ayoai.com
ayoai