Who this is for
The extension and the optional desktop app are used by AILA's customers (“vendors”) to connect their own accounts. They are not intended for, and do not knowingly collect data from, anyone who is not an authenticated AILA vendor acting on their own accounts. AILA is a business tool and is not directed to children.
People who contact a business using AILA
The sections above describe what we collect from our customers, the businesses that subscribe to AILA. This section is about the other people involved: couples and clients who send an inquiry to one of those businesses.
When someone contacts a business using AILA, we process:
- Contact details they provide: name, partner or co-planner name, email address, phone number.
- Event details they share: event type, date or approximate timeframe, guest count, budget range, location, and preferences.
- The messages themselves, and our assistant's replies, kept as a conversation history so the business has a record and the assistant doesn't ask the same question twice.
- Channel identifiers needed to route a reply back to the right conversation (for example an Instagram-scoped user ID, or a marketplace conversation ID).
- Appointment details if a tour or consultation is booked.
We collect this because the person chose to contact a business and expects an answer. We do not buy contact lists, and AILA never messages anyone who hasn't messaged the business first.
For these conversations we act as a processor on behalf of the business: they decide why the information is collected and how long to keep it, and we handle it on their instructions. For our own customers' account data, we are the controller.
If you contacted a business and want your information removed, you can ask that business directly, or ask us (see Data retention and deletion). You don't need an AILA account.
AILA's replies are AI-generated, and AILA says so if asked. If you ask whether you're talking to a person, the assistant tells you it isn't, and someone from the business can take over the conversation at any time.
What the extension accesses
- Your AILA sign-in.
- When you sign in (with Google or an email and password), the extension receives a Firebase authentication token and your email address to identify your AILA account.
- Your WeddingPro / The Knot Pro session.
-
On those sites, while you are logged in, the extension reads your own session cookie
(
TK_SESSION) so AILA can retrieve and answer your leads. - Your Zola vendor session.
- Zola authenticates its vendor console with tokens sent as request headers rather than a cookie. On zola.com, the extension reads those tokens (an id token, a refresh token, and a CSRF token) from your own outgoing requests for the same purpose.
The extension only reads credentials for accounts you are logged into. It does not read your browsing history, and it does not access any site other than the lead sources listed above and AILA's own services. All communication with WeddingPro / The Knot Pro and Zola runs locally on your own computer, through the extension or the optional desktop app and within your own logged-in session. It never runs from AILA's servers.
The desktop app
AILA also offers an optional desktop app. It runs locally on your computer and, once you set it up, carries out the automations you configure (retrieving and answering your inquiries) even while your browser is closed. To do that, it processes the data needed to manage your inquiries: your leads' contact details (names, email addresses, and phone numbers they provide), inquiry details (event dates, budget, location, and notes), and the conversation history in your vendor dashboard. It operates only on the platforms and accounts you have explicitly connected, and this processing happens locally on your device to carry out the automations you direct. Like the extension, it communicates with WeddingPro / The Knot Pro and Zola only from your own computer, within your own logged-in session.
Calendar access (Google and Microsoft)
To offer tour and consultation times and put booked appointments on your calendar, you can connect a Google Calendar to AILA through the provider's own consent screen (OAuth), with Microsoft (Outlook) calendars coming soon. With that permission, AILA:
- checks availability on the calendars you select, so it only offers times that are open, and
- creates, updates, and cancels events for the tours and consultations booked through AILA.
Calendar access tokens are stored encrypted and used only for the purposes above. Your calendar data is never used for advertising, is never sold, and is not used to develop, improve, or train generalized AI or machine-learning models. Our staff do not read your calendar data except with your permission (for example, to resolve a support issue you raise), when necessary for security or abuse investigations, or where required by law.
AILA's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We apply the same commitments to data accessed from your Microsoft account.
You can disconnect a calendar at any time from the AILA console, or revoke AILA's access directly from your Google Account permissions or your Microsoft account's app permissions.
If a business connects an Instagram professional account, AILA uses Meta's official Instagram API with Instagram Login.
- What we receive: direct messages sent to that business account, the Instagram-scoped user ID of the sender, their username and profile name where Instagram provides them, and message timestamps and IDs. These arrive through Meta's webhooks. We cannot browse the account's message history, and we do not receive followers, posts, insights, or comments.
- What we do with it: generate and send a reply on the business's behalf, and record the conversation in that business's AILA inbox.
- What we send: replies within that conversation, and nothing else. AILA never starts an Instagram conversation. Meta permits a business to reply only within 24 hours of the person's last message, and AILA does not use the extended human-agent messaging window for automated replies.
- Access tokens for the connected account are encrypted at rest and used only to receive and send messages for that business.
- Deleted messages: if someone unsends an Instagram message, we drop it rather than keeping a copy.
- Disconnecting: a business can disconnect Instagram at any time from Settings → Channels in AILA, or by removing AILA from their Instagram account settings. We stop receiving messages immediately. Disconnecting stops new messages but does not erase past ones. To delete those too, see Data retention and deletion.
How the information is used
These credentials are used solely to operate the service you signed up for: connecting your lead-source accounts to AILA so the assistant can read incoming inquiries and send replies on your behalf. For WeddingPro / The Knot Pro and Zola, that reading and replying happens locally on your computer. The credentials are not used for advertising, profiling, or any purpose unrelated to running AILA.
How it is stored and transmitted
- All data is sent over HTTPS between your device, AILA's API, and the platforms you have connected, and nowhere else.
- Communication with WeddingPro / The Knot Pro and Zola happens entirely on your own computer: the extension or the desktop app reads and answers those leads locally, within your own logged-in session. AILA's servers never contact those platforms. Every other channel and calendar integration runs through AILA's backend services.
- On AILA's servers, channel and calendar credentials are stored encrypted and used only to operate the service (answering your leads and managing the bookings AILA makes), never for anything else.
- In the extension, your long-lived Zola refresh token is held only in memory and is never written to disk. Only your AILA session token, your vendor identifier, and a non-sensitive “connected” flag are kept in the browser's local extension storage, and they are cleared when you sign out.
- The desktop app processes your lead and conversation data locally on your device, and communicates over HTTPS only with AILA's services and the platforms you have authorized it to operate on.
Sharing
We do not sell your data, and we do not share it with third parties for their own purposes. We use a small number of service providers, each bound by contract to protect the data and use it only to provide their service to us:
| Provider | What it handles |
|---|---|
| Google Cloud Platform | Hosting, database, file storage (United States) |
| Firebase Authentication | Customer sign-in |
| Anthropic | AI reply generation |
| Meta Platforms | Instagram message delivery, for connected accounts |
| Resend | Sending and receiving email |
| Stripe | Subscription payments, with card details going directly to Stripe and never reaching our servers |
| Google / Microsoft | Calendar availability and booking, for connected accounts |
| Firecrawl | Reading a business's own public website and listings during setup |
We do not use conversations to train AI models. Not ours, and not anyone else's. Message content is used to answer that conversation and to build that business's own records. AILA can learn a business's writing style, and when it does it reads that business's own sent replies and applies what it learns only to that business.
If a business connects their own CRM, AILA sends booked-lead details to the address they configure. That is their integration and their choice; once the data arrives there, their CRM's privacy policy governs it.
We may also disclose information if required by law, or as part of a merger or acquisition, in which case we will say so before your data moves.
Your control
You can disconnect a channel or calendar, or pause AILA, at any time from the AILA console; you can revoke calendar access from your Google or Microsoft account settings; and you can sign out of the extension to clear its stored credentials. How to have your account and data permanently deleted is described in the next section.
Data retention and deletion
We keep your data only as long as needed to provide AILA, or as the law requires. You can ask us to permanently erase your personal data and the lead data stored on our systems at any time: email support@bookwithaila.com with the subject line “Data Deletion Request.” Once we've verified the request comes from your account, we permanently delete your records from our databases within 30 days and confirm by email when it's done.
If you contacted a business using AILA, you can ask us directly and you do not need an AILA account. Email support@bookwithaila.com with the subject line “Data Deletion Request,” telling us the name of the business you contacted and the email address, phone number or Instagram handle you used. We will locate your records, notify the business, and permanently delete your personal information within 30 days. You don't have to explain why, and we won't charge you for it.
If you connected Instagram to your AILA account, disconnecting revokes our access immediately, but it does not erase the messages we already hold. To delete those as well, email us as above and say so.
How long we keep things otherwise:
- Account data: while your account is open, then 90 days after it closes.
- Conversations and lead records: while the account is active, so inquiry history stays intact. Businesses can delete individual records at any time.
- Connected-account tokens: until disconnected, then deleted.
- Billing records: as long as tax and accounting law requires, typically seven years.
- Logs: up to 30 days.
Backups are purged on their normal rotation, no later than 90 days after deletion.
Cookies on this website
This website (bookwithaila.com) sets no cookies and runs no third-party analytics or advertising trackers.
Changes to this policy
If we make material changes, we will post the updated policy here and revise the effective date at the top of this page.
Contact
Questions about this policy or your data: support@bookwithaila.com