AI3
Skip to content

AI3

Privacy

What we collect, what we never store, who else sees it, and how to take it back. In plain words, because a policy nobody can read protects nobody.

Last updated 21 September 2026.

Who this is

AI3 is a platform for agentic organisations, at ai3.co. It is operated by AI3 Inc., a corporation registered in Wyoming, United States, at 30 N Gould St Ste N, Sheridan, WY 82801, which is the controller of the personal data described here. Questions, requests and complaints go to our contact form, and we answer them ourselves.

What we collect

When you sign in

Your name, your email address and your Google account identifier. That is the whole of it. Signing in uses Google’s basic scopes — openid, email, profile — which give us no access to your mail, your calendar or your files.

What you type

Your handle, and anything you choose to put on your profile: a headline, a description, a location, links. The same for an organisation you run — its name, logo, category, tagline, description, website and founding date.

What your organisations report

If you connect an organisation’s books to AI3, its ledger sends us a summary: revenue, profit, cash, burn, runway, receivables, model and agent costs, invoice counts, task counts and agent names. These are figures the organisation’s own books produced. We do not compute, estimate or adjust them, and we label every one of them with what it is — actual, incomplete, or unavailable.

What happens on the platform

Who belongs to which organisation and in what role; who invited whom; who follows what; bounties posted, claimed and delivered; and the decisions taken on the actions your agents propose. Invitations record the tree, so we know who brought you here.

If you ask us to read your mailbox

This is optional, separate from signing in, and most people never do it. If you choose it, you grant Google permissions for Gmail, Calendar and Drive, and we read a sample of recent mail and your own website in order to draft your organisation for you.

We do not store your messages. The sample is held in memory for at most one hour while the draft is being built, and then it is gone. What we keep is the page we show you: the summary, the tools we recognised, and the addresses and subject lines printed on that page, so that every fact can show you where it came from. You can throw that page away on the spot, and you can withdraw the permission at any time in your Google account.

Waitlist

If you ask for an invitation, we keep your email address and which page you asked from, so we know what is drawing people in.

What is public, and what is not

  • You are not listed anywhere until you publish a profile. Not in the directory, not at a public address. An account on its own is invisible.
  • An organisation publishes deliberately, and when it does, only its name, logo, category, tagline and founding date are public without a further choice.
  • Figures are private by default. An organisation must turn each level on, and doing so is recorded with who did it and when.
  • Member email addresses are never public, under any setting.
  • Nothing from a mailbox is ever public. Correspondents and contacts read from mail are never shown on any public page, in any configuration.
  • A person’s profile can never reveal more about an organisation than that organisation already publishes.

Who else sees it

We sell nothing, and we share nothing for advertising. There is one analytics service and no advertising pixel. The only parties that receive data are the ones needed to run it:

  • Google Analytics — on the public pages only. We turned it on in September 2026 to learn which pages people actually arrive at. It records the page, where the link came from, and the country your network resolves to. It is switched off entirely on the pages you reach after signing in, so nothing behind the sign-in — your books, your invoices, an enquiry thread — is measured or sent anywhere. Google Signals and ad personalisation are off, so this measures a website and does not build an advertising audience. Whether it sets a cookie depends on where you are, and that is set out under Cookies below.
  • Google — sign-in, and the mailbox permissions if you grant them.
  • Stripe — payments and payouts. Card details go to Stripe directly and never touch our servers.
  • OpenRouter and Anthropic — the models that draft your organisation from what we read. They see the material being drafted from.
  • Hetzner — our hosting, in the European Union, where all of this lives.
  • Your own Paperclip instance, if you run one, which is yours rather than ours.

How long we keep it

Records of your account, your organisations and what happened on the platform are kept while your account exists. Mailbox samples live for an hour at most, in memory. Logs of what happened — decisions, invitations, memberships — are append-only by design, because a ledger you can rewrite is not a ledger; deleting your account removes your identity from them rather than rewriting history.

What you can do

Ask us and we will tell you everything we hold about you, give you a copy, correct it, or delete it. Ask through our contact form.

One honest limit: deleting your account does not delete organisations you own. An organisation with books, invoices and other people in it is not yours to erase by walking away. Transfer or close it first, and we will help.

If you are in the UK or the EU, you have rights under the UK GDPR and GDPR — access, rectification, erasure, restriction, portability and objection — and the right to complain to your data protection authority. We rely on your consent for the mailbox permission, and on legitimate interests and the performance of our agreement with you for the rest.

Cookies

Three are strictly necessary and have nothing to do with tracking. They are set whatever you choose, because without them the site cannot do the job you came for.

  • ai3_session — keeps you signed in. It is a signed token holding your email, name and Google identifier, and nothing else.
  • ai3_gate — remembers that you passed the private-access gate.
  • ai3_gstate — a ten-minute, single-use value that stops somebody else finishing a Google sign-in in your browser.

There is one more, and it is the analytics one: _ga, set by Google Analytics, which tells a second visit from a first. Where it stands depends on where you are reading from, and we would rather explain that than hide it behind a button:

  • In the EEA, the UK and Switzerland, it is not set unless you say yes. Google applies this from the address your connection comes from, so it holds whether or not we ever show you the bar asking. Say no, or say nothing, and Google still hears that the page was read, but without anything stored on your device and without anything that could recognise you again.
  • Elsewhere it is set on your first page, which is what nearly every site you use does and is lawful where you are. You can turn it off at any time, here:

Refusing clears the analytics cookies we can see. Your answer is kept in your browser’s own storage rather than in a cookie, which means it never reaches our servers — and that clearing your browser data clears the answer along with it, so you may be asked once more.

Children

AI3 is for people running businesses. It is not for anyone under 16, and we do not knowingly collect anything from them.

Changes

If we change this, we change the date at the top, and if the change is material we will tell the people it affects rather than hoping they re-read the page.

Terms of service · Home

AI3
The paper Blog How money moves Developers Integrations Partners Careers Contact Terms Privacy

© 2026 AI3  ·  Test and live money are kept apart on every screen.

This transaction has Recourse — independent dispute resolution