AIVA logo
← Back to AIVA

Privacy Policy

Effective Date: May 18, 2026 · Last Updated: May 18, 2026

1. Introduction & Who We Are

5MTMGRPLLC ("AIVA," "we," "us," or "our") operates the AIVA AI-powered learning platform accessible at this website. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our services.

By accessing or using AIVA, you agree to this Privacy Policy. If you do not agree, please do not use our services.

Contact: [email protected] · United States

2. Information We Collect

2.1 Information You Provide Directly

  • Account Registration: First name, last name, email address, phone number, street address, city, state/province, ZIP/postal code, and country.
  • Verification Data: One-time passcodes (OTP) used for 2-step identity verification via email or SMS.
  • Consent Records: Timestamps, IP addresses, and browser information recorded at the time you agree to our Terms of Service, Privacy Policy, FCC consent, Cookie Policy, and Educational Use Disclaimer.
  • Communications: Any messages, feedback, or support requests you send us.

2.2 Information Collected Automatically

  • Log Data: IP address, browser type and version, operating system, referring URLs, pages visited, time and date of visits, and time spent on pages.
  • Cookies & Tracking Technologies: Session cookies, persistent cookies, web beacons, and similar technologies. See Section 6 (Cookie Policy) for full details.
  • Device Information: Device type, unique device identifiers, and mobile network information.
  • Usage Data: Learning progress, lesson interactions, quiz results, and AI conversation metadata (not full conversation content unless you explicitly save it).

2.3 Information from Third Parties

  • Payment Processors: We use Stripe for payment processing. We do NOT receive or store your credit card number, CVV, or full payment details. Stripe provides us only with transaction confirmation and subscription status.
  • Google AdSense: Google may collect data through AdSense cookies as described in Section 6.

3. How We Use Your Information

We use your personal information for the following purposes:

  • Account Management: Creating and maintaining your account, verifying your identity, and providing access to our services.
  • Service Delivery: Personalizing your AI learning experience, tracking your progress, and generating certificates.
  • Communications: Sending transactional emails (account confirmations, billing receipts, password resets). We will NOT send marketing emails without your explicit opt-in consent.
  • Legal Compliance: Maintaining consent records, responding to legal requests, and complying with applicable laws including FCC regulations, CAN-SPAM Act, GDPR, CCPA, and COPPA.
  • Security: Detecting, preventing, and addressing fraud, abuse, and security incidents.
  • Analytics & Improvement: Understanding how users interact with our platform to improve our services.
  • Advertising: Serving relevant advertisements through Google AdSense based on your interests and browsing behavior (you may opt out — see Section 6).

Legal Basis (GDPR): We process your data under the following legal bases: (a) Contract performance — to provide the services you signed up for; (b) Legal obligation — to comply with applicable laws; (c) Legitimate interests — for security, fraud prevention, and service improvement; (d) Consent — for marketing communications and non-essential cookies.

4. How We Share Your Information

We will NEVER sell, rent, or trade your personal information to third parties for their marketing purposes.

We may share your information only in the following limited circumstances:

  • Service Providers: Trusted third-party vendors who assist us in operating our platform (e.g., Stripe for payments, cloud hosting providers, email delivery services). These providers are contractually bound to protect your data and may only use it to provide services to us.
  • Google AdSense: Google receives cookie and usage data to serve personalized ads. See Google's Privacy Policy at policies.google.com/privacy.
  • Legal Requirements: We may disclose your information if required by law, court order, subpoena, or government request, or to protect the rights, property, or safety of AIVA, our users, or the public.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will notify you via email and/or prominent notice on our website before your data is transferred and becomes subject to a different privacy policy.
  • With Your Consent: We may share your information for any other purpose with your explicit consent.

5. Data Retention

  • Account Data: Retained for the duration of your account and for 7 years after account closure for legal and tax compliance purposes.
  • Consent Records: Retained permanently as required by FCC regulations and applicable law.
  • Verification Records: OTP records retained for 2 years for security audit purposes.
  • Payment Records: Transaction records retained for 7 years as required by US tax law.
  • Log Data: Retained for 90 days for security monitoring purposes.

You may request deletion of your account data at any time (see Section 8 — Your Rights). Note that we may retain certain data as required by law even after account deletion.

6. Cookies & Tracking Technologies

We use the following types of cookies:

  • Essential Cookies: Required for the platform to function (authentication, session management). Cannot be disabled.
  • Analytics Cookies: Help us understand how users interact with our platform (e.g., Google Analytics). You may opt out.
  • Advertising Cookies (Google AdSense): Used to serve personalized advertisements. You may opt out at adssettings.google.com or by installing the Google Analytics Opt-out Browser Add-on.

Managing Cookies: You can control cookies through your browser settings. Disabling essential cookies will prevent you from using the platform. For EU/UK users, we display a cookie consent banner and obtain your consent before setting non-essential cookies.

Do Not Track: We honor Do Not Track (DNT) browser signals for analytics cookies. We do not currently respond to DNT signals for advertising cookies as industry standards are not yet established.

7. Data Security

We implement industry-standard security measures to protect your personal information:

  • All data transmitted between your browser and our servers is encrypted using TLS/SSL.
  • Passwords are never stored — we use OTP-based verification.
  • Payment data is handled entirely by Stripe (PCI DSS Level 1 compliant). We never see or store your payment card details.
  • Access to personal data is restricted to authorized personnel on a need-to-know basis.
  • We conduct regular security reviews and vulnerability assessments.

No method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. In the event of a data breach affecting your rights and freedoms, we will notify you as required by applicable law (within 72 hours for GDPR, promptly for US state laws).

8. Your Rights

8.1 All Users

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your personal data (subject to legal retention requirements).
  • Opt-Out of Marketing: Unsubscribe from marketing communications at any time.

8.2 California Residents (CCPA/CPRA)

Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), California residents have the right to:

  • Know what personal information is collected, used, shared, or sold.
  • Delete personal information held by businesses.
  • Opt-out of the sale or sharing of personal information. We do not sell personal information.
  • Non-discrimination for exercising CCPA rights.
  • Correct inaccurate personal information.
  • Limit use of sensitive personal information.

To exercise your CCPA rights, contact us at [email protected]. We will respond within 45 days.

8.3 EU/UK/EEA Residents (GDPR/UK GDPR)

Under the General Data Protection Regulation (GDPR) and UK GDPR, you have the right to:

  • Access, rectification, and erasure of your personal data.
  • Restriction of processing and data portability.
  • Object to processing based on legitimate interests.
  • Withdraw consent at any time (without affecting prior processing).
  • Lodge a complaint with your local supervisory authority (e.g., ICO in the UK, your national DPA in the EU).

International Data Transfers: Your data may be transferred to and processed in the United States. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission for transfers from the EU/EEA to the US.

8.4 Canadian Residents (PIPEDA/Law 25)

Canadian residents have rights under PIPEDA and Quebec's Law 25, including the right to access, correct, and withdraw consent for the use of your personal information. Contact us at [email protected].

8.5 Australian Residents (Privacy Act 1988)

Australian residents have rights under the Privacy Act 1988 and Australian Privacy Principles (APPs), including the right to access and correct personal information held about you.

9. Children's Privacy (COPPA)

AIVA is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13 years of age. If you are under 13, please do not use our services or provide any personal information.

If we learn that we have collected personal information from a child under 13 without verifiable parental consent, we will delete that information immediately. If you believe we may have collected information from a child under 13, please contact us at [email protected].

For users aged 13–17: We recommend parental guidance. Parents or guardians who believe their minor child has provided personal information without consent should contact us immediately.

This policy complies with the Children's Online Privacy Protection Act (COPPA), 15 U.S.C. §§ 6501–6506.

10. State-Specific Privacy Rights

In addition to California (Section 8.2), the following US state privacy laws may apply to you:

  • Virginia (VCDPA): Rights to access, correct, delete, and opt out of targeted advertising and profiling.
  • Colorado (CPA): Rights to opt out of targeted advertising, profiling, and sale of personal data.
  • Connecticut (CTDPA): Rights to access, correct, delete, and opt out of targeted advertising.
  • Texas (TDPSA): Rights to access, correct, delete, and opt out of sale and targeted advertising.
  • Florida (FDBR): Rights to access, correct, delete, and opt out of sale and targeted advertising (applies to controllers with 100M+ consumers or 50M+ revenue).
  • Nevada (SB 220): Right to opt out of the sale of covered information. We do not sell personal information.
  • All other US states: We comply with all applicable state privacy laws as they become effective.

To exercise any state privacy rights, contact us at [email protected]. We will respond within the timeframe required by your state's law.

11. Third-Party Links

Our platform may contain links to third-party websites (including Stripe's payment pages). We are not responsible for the privacy practices of those websites. We encourage you to review the privacy policies of any third-party sites you visit.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

  • Posting the new Privacy Policy on this page with an updated effective date.
  • Sending an email notification to registered users at least 30 days before the change takes effect (for material changes).
  • Displaying a prominent notice on our website.

Your continued use of AIVA after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.

13. Contact Us

For any privacy-related questions, requests, or complaints, please contact us:

We will respond to all requests within 30 days (or within the timeframe required by applicable law).

Terms of ServiceCookie PolicyFCC ComplianceHome