Legal

Privacy Policy

Last updated: April 22, 2026

This Privacy Policy explains how COSTTRAIL INC (“COSTTRAIL”, “we”) collects, uses, and protects personal information in connection with AI2BI Hub (the “Service”). It applies to the ai2bihub.com website, the AI2BI Hub application, and our per-product domains (e.g. excel.ai2bihub.com, pdf.ai2bihub.com, accounting.ai2bihub.com, askdocs.ai2bihub.com).

1. Controller and contact

For personal information you submit about yourself to use the Service, COSTTRAIL is the data controller. For Customer Data you upload to process through the Service (files, documents, accounting records, cloud logs, etc.), COSTTRAIL acts as a data processor on behalf of your organization, which is the controller.

Questions, access requests, or complaints:
Privacy: privacy@ai2bihub.com
Data Protection Officer: dpo@ai2bihub.com
Mailing address: COSTTRAIL INC, 1900 Pleasant Street, Noblesville, Indiana 46061-0813, USA.

2. What we collect

CategoryExamplesSource
Account informationname, work email, company, country, password hash, two-step-verification secretYou, during sign-up
Authentication and sessionsession cookie, refresh token, IP address, user-agent, sign-in timestampsAutomatically on use
Billing informationplan, invoices, last-four of card, billing addressYou; payment processor (Stripe)
Customer Datafiles, documents, accounting exports, database queries, chat prompts, AI-generated outputsYou
Product telemetryfeature usage counts, error logs, tokens consumed, timingsAutomatically on use
Support communicationsemails, chat transcriptsYou

3. How we use it

  • Provide, maintain, and secure the Service and your account.
  • Process Customer Data on your documented instructions to produce AI-generated answers, reports, or outputs.
  • Bill you for usage, send transactional emails (sign-up, verification, MFA, receipts, incident notices), and meet legal and accounting obligations.
  • Detect and prevent fraud, abuse, and security incidents, including rate-limiting and suspending offending accounts.
  • Improve the reliability and performance of the Service using aggregated, de-identified metrics.
  • With your consent, for purposes stated at the time of collection.

5. PII and sensitive data

We ask Customers not to upload special-category personal data (health, biometric, genetic, sex-life, trade-union, political, religious data) or government identifiers (e.g. full SSN, Aadhaar, passport) unless strictly necessary and unless you have a documented legal basis. The Service is not designed or warranted for use as a system of record for these categories.

Payment card primary account numbers (PAN) should never be uploaded to the Service. Card data entered into our billing flow is transmitted directly to Stripe; we do not store PANs on our servers.

6. PHI and HIPAA

Protected Health Information (PHI) as defined under the U.S. Health Insurance Portability and Accountability Act (HIPAA) has special handling requirements. We do not currently offer a Business Associate Agreement (BAA) on our standard plans. Accordingly, you must not upload PHI to the Service unless and until a BAA has been executed with COSTTRAIL. If your use case involves PHI, contact privacy@ai2bihub.com to discuss private-deployment or on-prem options described at /legal/deployment-modes. See also /legal/data-handling.

7. Model providers and training

AI2BI Hub uses large language models hosted via Amazon Bedrock and, for certain tools, other inference providers listed in our sub-processor schedule. Prompts and outputs are sent to these providers on an inference-only basis under contractual terms that prohibit the use of Customer Data for training foundation models. We do not train models on Customer Data.

8. Sharing and sub-processors

We share personal information with:

  • Infrastructure providers — Amazon Web Services (US), for hosting, storage, authentication (Cognito), and email (SES).
  • Model providers — Amazon Bedrock (Anthropic Claude family and others) for inference.
  • Payment processor — Stripe, Inc. (US), for billing.
  • Authentication providers — Google (for Google SSO, when you choose it).
  • Operational tooling — productivity, ticketing, and monitoring vendors listed at /legal/data-handling.
  • Professional advisors — legal, accounting, and audit firms, under confidentiality.
  • Authorities — when required by law or to protect rights, safety, or property.

We do not sell personal information and we do not share it for cross-context behavioral advertising.

9. International transfers

The Service is hosted in the United States. If you access it from outside the US, personal information will be transferred to and processed in the US. Where required, we rely on EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or comparable safeguards with our sub-processors.

10. Retention

We retain account information for the life of your account and for a reasonable period afterward for legal, tax, and audit purposes. Customer Data is retained per your configuration: files you upload are deleted when you delete them, or when your tenant is closed, subject to short retention in encrypted backups (up to 35 days) and audit logs (up to 400 days). Billing records are retained for up to 7 years.

11. Security

We protect personal information using TLS 1.2+ for transit, AES-256 for storage, least-privilege IAM, MFA for administrators, audit logging, automated backups, point-in-time recovery on critical databases, and vulnerability scanning. SOC 2 Type II is in progress. A full control summary is available at /legal.

12. Your rights

Depending on your location, you may have rights to access, correct, delete, restrict or object to processing, port your data, and withdraw consent. California residents have additional rights under the CCPA/CPRA, including the right to know, delete, and opt out of the sale or sharing of personal information (we do not sell or share as defined by those laws). To exercise rights, email privacy@ai2bihub.com. We will respond within the timeframes required by applicable law.

13. Children

The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided information, contact us and we will delete it.

14. Cookies and Do Not Track

We use strictly necessary cookies for authentication. We honor opt-outs through our cookie banner and the Global Privacy Control (GPC) signal. See our Cookie Policy.

15. Changes

We may update this Policy. Material changes will be posted on this page with a new “Last updated” date and, where appropriate, communicated by email or in-product notice.

16. Contact

COSTTRAIL INC
1900 Pleasant Street, Noblesville, Indiana 46061-0813, USA
Privacy: privacy@ai2bihub.com
DPO: dpo@ai2bihub.com