Skip to main content
Platform Review
PricingSign in
← All platforms
Workflow & Automation · getanana.com

Anana

Graded against 808 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.

Overall riskLOWReviewed 2026-08-28
Creator: low · GRC: low · Counsel: low
Benchmark

No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.

30 verified findings6 policy surfaces2/2 core docs verified
Risk triage

Lower concern: audit rights dpa residency

Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.

0
high
0
medium
3
low
2/2
docs
Trains on your data?
Not yet assessed
no verified finding covers this surface yet
Who owns outputs?
Not yet assessed
no verified finding covers this surface yet
Commercial use?
Not yet assessed
no verified finding covers this surface yet
Every rating:verbatim-citedsnapshot-datedchange-loggedHow we keep ratings honest →

How to read this page: Overall risk rates what Anana's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.

Fully verifiedWorkflow & Automation

Fully verified — complete core corpus captured and read in full.

Document status
  • Terms of Service
    Verified - read in full - 7 citationsstaticLast captured 2026-08-28
  • Privacy Policy
    Verified - read in full - 23 citationsLast captured 2026-07-19
Tier conditions

Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.

plan language
Privacy & data use

Defines the scope and subject matter of the Privacy Policy, identifying the entity (Anana), the type of platform (AI agent platform for hospitality), and the specific services and domains covered; establishes what processing activities fall within the document's legal framework.

" This Privacy Policy explains how Anana processes personal data in connection with our AI agent platform for hospitality (hotels, restaurants, wellness venues). It covers our website (getanana.com), our application (app.getanana.com), our A..."
📍 Privacy Policy › “Last updated: July 5, 2026”Jump to exact text →
plan language
Privacy & data use

Identifies Omoc, Inc. (doing business as Anana) with its registered address as the data controller for specific categories of data subjects, establishing the legal entity responsible for processing decisions.

" Omoc, Inc (doing business as Anana), 10 Montague Terrace, Apt 1B, Brooklyn, NY 11201, United States, is the controller for personal data processed about: Operator users (staff of our hospitality customers who log into Anana)"
📍 § 1 (Controller)Jump to exact text →
plan language
Privacy & data use

Enumerates the specific purposes for which personal data is processed, the data subjects affected, and the legal bases relied upon for each purpose, including contractual performance for operator users, processor status for guest data, and legitimate interest for security and audit logging.

" Provide the Anana platform to operator users (accounts, authentication, app access, support) Operator users Art. 6(1)(b): performance of contract with the customer Process guest messages, calls, bookings on behalf of the venue End guests..."
📍 Privacy Policy › “Purpose Data subjects Lawful basis”Jump to exact text →
plan language
Privacy & data use

Establishes the right to object to legitimate-interest processing, describes that special category data is not intentionally collected but may be incidentally present, and assigns responsibility for obtaining explicit consent for special category data to the venue as controller rather than Anana, limiting Anana's obligations as processor in that regard.

" Where we rely on legitimate interest, you have the right to object (see Section 10). Special category data. Anana does not intentionally collect special category data (Art. 9). However, free-text guest messages and call content can incide..."
📍 Privacy Policy › “Purpose Data subjects Lawful basis”Jump to exact text →
plan language
Data retention

Sets specific retention periods for operator user account and authentication data (life of contract plus up to 1 year post-termination), voice recordings (per venue configuration; not used for model training; deleted on instruction or within 1 year of contract termination), voice transcripts (deleted with tenant data on instruction or within 1 year of contract termination), and inbound messages (per venue configuration), establishing outer-limit retention obligations and prohibiting use of voice recordings for model training — user-favorable restriction.

" Operator user account and authentication data For the life of the customer contract; deleted within 1 year of contract termination. Voice recordings Retained per the venue's configuration and not used for model training; Anana-held copie..."
📍 Privacy Policy › “Data category Retention”Jump to exact text →
plan language
Audit rights / DPA / residency

Discloses that production data is stored in a specific AWS region and identifies which subprocessors process data in third countries; states the legal mechanisms relied upon for cross-border transfers of personal data, including Standard Contractual Clauses and supplementary measures where required, establishing the procedural basis for lawful international data transfers.

" Anana is established in the United States and our production data is stored in AWS eu-central-1 (Frankfurt). Several sub-processors listed in Section 7 process data in the United States or other third countries (notably OpenAI, OpenRouter,..."
📍 § 8 (International Transfers)Jump to exact text →
plan language
Governing law & disputes

Defines the Customer and Provider parties, the Effective Date, the governing law as Delaware state law, and the chosen courts as state or federal courts in Delaware; these definitions establish jurisdiction and party identity for the entire Agreement.

" Subscription Period: 1 month(s). We offer custom pricing based on your business's specific requirements, including call volume, number of AI agents, and features needed. Contact us for a tailored quote that fits your budget and operational..."
📍 Terms of Service › “Order Date: The Effective Date”Jump to exact text →
plan language
Governing law & disputes

Specifies the notice delivery addresses for both Provider and Customer, establishing the procedure for formal communications under the Agreement.

" General Cap Amount: The fees paid or payable by Customer to Provider in the 12-month period immediately before the claim."
📍 Terms of Service › “Liability Cap”Jump to exact text →
Conflicting provisions (1)
  • Clause A states Anana acts as an 'agent only' when connected to a venue's systems (e.g., CRM/PMS), while Clause B states Anana acts as a 'processor' for guest and lead data, including data synced from PMS/CRM, creating opposing claims about Anana's role for the same data processing activity.

    " When a venue connects Anana to its own systems (e.g., WebHotelier, Fidelio on-prem, Practice Better, Kanika, Genesys Cloud, HubSpot, Composio), the venue is the controller of that integration and the integration provider is the venue's processor, not ours. Anana acts as the venue's agent only. Other recipients include our professional advisors (legal, accounting) and competent authorities where required by law."
    " For personal data of end guests and leads (people who chat with, call, SMS, or email a venue powered by Anana, or whose booking/profile data is synced from a Property Management System or CRM), our hospitality customer is the controller and Anana acts as their processor under a Data Processing Agreement. Where this policy describes guest data, it does so in our capacity as processor and for transparency only; the venue's own privacy notice governs that processing. Contact: privacy@getanana.com We have not appointed a Data Protection Officer; Art. 37 GDPR does not require us to do so. Privacy questions and rights requests are handled at privacy@getanana.com."
    Within one document

Evidence appendix

Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.

High - 0
Medium - 0
Tier-specific - 0
Total citations - 30
Severity
Surface
Document
Tier
Privacy & data use
High
" Anana does not determine which guests to contact, which fields to ingest, or how long the venue retains guest records — the venue does. The guest should refer to the venue's privacy notice."
Privacy Policy › “Artifact metadata: messages sent, drafts, versions”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Restricts Anana's discretion over guest data processing by stating it does not determine which guests to contact, which fields to ingest, or retention duration — those decisions belong to the venue as controller — directing guests to the venue's own privacy notice, which is user-favorable in limiting Anana's autonomous data use.

AI-generated interpretation, not legal advice.

Data retention
High
" Operator user account and authentication data For the life of the customer contract; deleted within 1 year of contract termination. Voice recordings Retained per the venue's configuration and not used for model training; Anana-held copies are deleted on the venue's instruction or within 1 year of contract termination. Voice transcripts Retained per the venue's configuration as part of the conversation record; deleted with the associated tenant data on the venue's instruction or within 1 year of contract termination. Inbound messages (chat, SMS, email) Retained per the venue's configuration as part of the conversation record; deleted on the venue's instruction or within 1 year of contract termination. Booking/guest profile data synced from PMS/CRM Controlled by the venue; Anana deletes on the venue's instruction or contract end. Embeddings in pgvector Tied to the source artifact; deleted when the source is deleted. Audit logs (artifact create / version / send) 2 years. Server logs / WAF logs Application production logs 30 days; AWS CloudFront/WAF edge logs per their configuration. Database backups Daily backups retained 7 days on a rolling cycle. Business contacts (CRM) Until objection or 2 years of inactivity. Accounting and tax records As required by applicable law (typically 7–10 years). "
Privacy Policy › “Data category Retention”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Sets specific retention periods for operator user account and authentication data (life of contract plus up to 1 year post-termination), voice recordings (per venue configuration; not used for model training; deleted on instruction or within 1 year of contract termination), voice transcripts (deleted with tenant data on instruction or within 1 year of contract termination), and inbound messages (per venue configuration), establishing outer-limit retention obligations and prohibiting use of voice recordings for model training — user-favorable restriction.

AI-generated interpretation, not legal advice.

Indemnity & liability
High
" Provider Covered Claims: Any action, proceeding, or claim that the Cloud Service, when used by Customer according to the terms of the Agreement, violates, misappropriates, or otherwise infringes upon anyone else's intellectual property or other proprietary rights. Customer Covered Claims: Any action, proceeding, or claim that (1) the Customer Content, when used according to the terms of the Agreement, violates, misappropriates, or otherwise infringes upon anyone else's intellectual property or other proprietary rights; or (2) results from Customer's breach or alleged breach of Section 2.1 (Restrictions on Customer)."
Terms of Service › “Covered Claims”Jump to exact text →
Source: Terms of Service- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Establishes the general liability cap amount as the fees paid or payable by Customer in the 12-month period immediately preceding the claim, limiting the Provider's maximum financial exposure.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
" We share personal data only with vetted sub-processors under a DPA. An up-to-date list is available on request at privacy@getanana.com."
§ 7 (Recipients and Sub-processors)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Restricts personal data sharing exclusively to vetted sub-processors who are under a Data Processing Agreement, and establishes a procedure for obtaining the current sub-processor list on request, limiting the circumstances under which data may be shared with third parties.

AI-generated interpretation, not legal advice.

Audit rights / DPA / residency
High
" Anana is established in the United States and our production data is stored in AWS eu-central-1 (Frankfurt). Several sub-processors listed in Section 7 process data in the United States or other third countries (notably OpenAI, OpenRouter, Perplexity, Google, Sentry, Vercel, Stytch, Twilio, Resend, AssemblyAI, Deepgram, Firecrawl, Reducto). For transfers of EU/EEA personal data to the United States or other third countries we rely on: Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914, plus supplementary measures where required EU–U.S. Data Privacy Framework where the recipient is certified under it Transfer Impact Assessments documenting the level of protection and any supplementary measures A copy of the SCCs and our TIAs is available on request at privacy@getanana.com."
§ 8 (International Transfers)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Discloses that production data is stored in a specific AWS region and identifies which subprocessors process data in third countries; states the legal mechanisms relied upon for cross-border transfers of personal data, including Standard Contractual Clauses and supplementary measures where required, establishing the procedural basis for lawful international data transfers.

AI-generated interpretation, not legal advice.

Audit rights / DPA / residency
High
" We apply the following measures: Encryption in transit: TLS everywhere; HTTPS-only externally. Encryption at rest: AES-256 via AWS KMS for AWS RDS Postgres 17.4 (including pgvector) and AWS S3 (recordings, attachments, exports). Application-level AES-256-GCM for integration credentials. Multi-tenant isolation: row-level tenant filter enforced in the application data layer. Network protection: AWS WAF with managed rules and rate limiting (2000 requests per 5 minutes). Webhook integrity: HMAC verification on inbound webhooks where the provider supports it. Access controls: multi-factor authentication, role-based access control, least-privilege provisioning. Audit logging: artifact lifecycle events (create, version bump, send) are recorded. Transient stores: Redis is used for sessions and queues; data there is short-lived."
§ 9 (Security)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Enumerates specific technical and organizational security measures the operator commits to applying, including encryption in transit and at rest, multi-tenant isolation, network protection, webhook integrity verification, and access controls, constituting an obligation to implement those safeguards for data protection.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" This Privacy Policy explains how Anana processes personal data in connection with our AI agent platform for hospitality (hotels, restaurants, wellness venues). It covers our website (getanana.com), our application (app.getanana.com), our API (api.getanana.com), and the messaging, voice, and booking workflows that Anana performs on behalf of our customers."
Privacy Policy › “Last updated: July 5, 2026”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Defines the scope and subject matter of the Privacy Policy, identifying the entity (Anana), the type of platform (AI agent platform for hospitality), and the specific services and domains covered; establishes what processing activities fall within the document's legal framework.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Omoc, Inc (doing business as Anana), 10 Montague Terrace, Apt 1B, Brooklyn, NY 11201, United States, is the controller for personal data processed about: Operator users (staff of our hospitality customers who log into Anana)"
§ 1 (Controller)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Identifies Omoc, Inc. (doing business as Anana) with its registered address as the data controller for specific categories of data subjects, establishing the legal entity responsible for processing decisions.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" When a staff member of a hospitality customer is provisioned an Anana account, we process: Identification and account data: name, work email, role, organization/tenant ID Authentication data: login identifiers, session tokens, MFA factors (via Stytch) Usage data: pages viewed, actions taken in the app, artifacts created/sent, IP address, device/user-agent Support communications: messages sent to support@getanana.com"
§ 3.1 (Operator users (Art. 13))Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Enumerates the specific categories of personal data processed for operator users (staff of hospitality customers), including identification, authentication, usage, and support data, defining the scope of personal data handling for this data subject category.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" For transparency, the personal data Anana handles on behalf of venues includes: Inbound messages: chat widget conversations, inbound SMS, inbound email (content, sender identifiers, timestamps) Voice calls: audio recordings of WebRTC and SIP calls, machine-generated transcripts, call metadata (caller number, duration, routing) Booking and guest profile data synced from the venue's PMS/CRM: name, contact details, reservation details, stay history, and any fields the venue chooses to expose Embeddings: vector representations derived from messages and documents, used for retrieval; stored in pgvector"
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Enumerates the categories of personal data Anana handles on behalf of venues for end guests and leads, including inbound messages, voice call recordings, transcripts, booking and profile data, and vector embeddings, defining the scope of processor-level personal data handling.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Server logs (IP address, user-agent, timestamps, requested URL) processed by AWS and Vercel for security, abuse prevention, and basic operation. Cookies: our websites use cookies. The categories and purposes of cookies in use, and the controls available to you, are described in our separate Cookie Policy and managed via the cookie banner displayed on first visit."
§ 3.3 (Website visitors)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Describes the categories of data collected from website visitors (server logs processed by infrastructure providers, cookies) and references the separate Cookie Policy and cookie banner as the mechanism for disclosure and control.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" We process standard HR data for employees/applicants and standard B2B contact data for prospects, customers, and suppliers. Employee processing is described in a separate internal notice."
§ 3.4 (Employees, applicants, and business contacts)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

States that standard HR data is processed for employees and applicants and standard B2B contact data for business contacts, and that employee processing is covered by a separate internal notice, defining the scope and referencing a parallel document.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Provide the Anana platform to operator users (accounts, authentication, app access, support) Operator users Art. 6(1)(b): performance of contract with the customer Process guest messages, calls, bookings on behalf of the venue End guests/leads Processor: venue's lawful basis applies; Anana relies on Art. 28 Generate AI responses, transcripts, summaries, and embeddings to operate the service Operator users, end guests Art. 6(1)(b) (operators); processor for guests Security, fraud and abuse prevention, audit logging All Art. 6(1)(f): legitimate interest in securing the service Service communications (incident notices, billing, product updates) Operator users, customer admins Art. 6(1)(b) and Art. 6(1)(f) Marketing emails to prospects Business contacts Art. 6(1)(f): legitimate interest in B2B outreach; opt-out at any time Compliance with legal obligations (tax, accounting, lawful requests) All Art. 6(1)(c) Recruitment Applicants Art. 6(1)(b) pre-contract / Art. 6(1)(a) consent for retention "
Privacy Policy › “Purpose Data subjects Lawful basis”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Enumerates the specific purposes for which personal data is processed, the data subjects affected, and the legal bases relied upon for each purpose, including contractual performance for operator users, processor status for guest data, and legitimate interest for security and audit logging.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Where we rely on legitimate interest, you have the right to object (see Section 10). Special category data. Anana does not intentionally collect special category data (Art. 9). However, free-text guest messages and call content can incidentally contain health, dietary, or similar details, and the Practice Better integration can surface practitioner-client health records. Anana processes this data solely as a processor on the venue's behalf. The Art. 9(2)(a) explicit consent condition, and the notice to the individual, are the responsibility of the venue (controller); this obligation is allocated to the venue in our Data Processing Agreement."
Privacy Policy › “Purpose Data subjects Lawful basis”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Establishes the right to object to legitimate-interest processing, describes that special category data is not intentionally collected but may be incidentally present, and assigns responsibility for obtaining explicit consent for special category data to the venue as controller rather than Anana, limiting Anana's obligations as processor in that regard.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Operator user data: provided directly by the user or by their employer (the customer) when provisioning an account. Guest/lead data: received from the guest directly (when they message, call, or email the venue) or from the venue's PMS/CRM via integrations the venue has authorized. Website data: collected directly through your browser."
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Identifies the sources from which each category of personal data is obtained (directly from users, from employers, from guests, from venue PMS/CRM integrations, or directly through the browser), defining data collection origins.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Where Anana is the controller, you may exercise the following rights: Access (Art. 15): obtain a copy of your personal data. Rectification (Art. 16): correct inaccurate data. Erasure (Art. 17): request deletion. Restriction (Art. 18): limit processing. Portability (Art. 20): receive your data in a structured, machine-readable format where applicable. Object (Art. 21): object to processing based on legitimate interest, including direct marketing. Withdraw consent (Art. 7(3)): where processing is based on consent, you may withdraw it at any time, as easily as it was given, without affecting the lawfulness of processing carried out beforehand. Not be subject to solely automated decisions with legal or similarly significant effects (Art. 22). Anana generates suggested replies and drafts; final operator review is part of the workflow. To exercise your rights, email privacy@getanana.com , or contact our EU representative at privacy@probo.com (Section 2). We respond within one month (extendable by two further months for complex requests, Art. 12(3)). If you are an end guest and want to exercise rights against a venue, contact the venue directly — they are the controller. We will assist them under Art. 28(3)(e)."
§ 10 (Your Rights (GDPR))Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Grants data subjects a set of enumerated rights over their personal data where Anana acts as controller, including rights to access, rectification, erasure, restriction of processing, data portability in a structured machine-readable format, objection to processing based on legitimate interest, and withdrawal of consent, defining the scope and conditions of each right.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" You have the right to lodge a complaint with a data protection authority. As Anana is established outside the EU/EEA, EU/EEA data subjects may lodge a complaint with the supervisory authority of the EU/EEA member state where they reside, where they work, or where the alleged infringement occurred. You may also contact our EU representative (Section 2)."
§ 11 (Supervisory Authority)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Section header introducing the children's data section, establishing classification context for the policy on processing data relating to children.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Anana is a B2B service intended for hospitality businesses and their staff. It is not directed at children, and we do not knowingly collect personal data from children. Guests who interact with a venue's chat, SMS, voice, or email channel do so under that venue's own policies; venues are responsible for any age-specific obligations relating to their guests."
§ 12 (Children)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-19- View source
Permalink to this finding →
Automated analysis

Section header introducing the policy changes section, establishing classification context for the update and notification procedures described below.

AI-generated interpretation, not legal advice.

Clause detail — protections, your obligations, and coverage

Every clause below is a verbatim quote from Anana's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.

✅ Protections found

0 verified clauses

Clauses in Anana's policies that work in your favour — commitments the platform made to you.

No protective clause has been verified in Anana's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.

📋 Rules you must follow

0 verified clauses

What Anana requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.

No user-conduct rule has been verified in Anana's published policies yet.

What the policies actually cover

0 topics

None of Anana's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.

Clause intelligence

Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.

33
clauses
1
patterns
1
stances
data retention · 1
data retentionLOWPrivacy Policy › “Data category Retention”

The clause provides a deletion or time-bounded retention path.

Operator user account and authentication data For the life of the customer contract; deleted within 1 year of contract termination. Voice recordings Retained per the venue's configuration and not used for model training; Anana-held copies are deleted on the venue's instruction or within 1 year of contract termination. Voice transcripts Retained per the venue's configuration as part of the conversati...
Open source citation

Tier matrix

Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.

TierSurfaceVerdictRiskCitations
Team / Businessdata retentionimprovesLOW1

Policy evolution

Open full timeline

Before/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.

Jul 19, 2026retentionLOW

Latest stance: deletion or time bound on data retention

Operator user account and authentication data For the life of the customer contract; deleted within 1 year of contract termination. Voice recordings Retained per the venue's configuration and not used for model training; Anana-held copies are deleted on the venue's instruction or within 1 year of contract termination. Voice transcripts Retained per the venue's configuration as part of the conversation record; deleted with the associated tenant data on the venue's instruction or within 1 year of contract termination. Inbound messages (chat, SMS, email) Retained per the venue's configuration as part of the conversation record; deleted on the venue's instruction or within 1 year of contract termination. Booking/guest profile data synced from PMS/CRM Controlled by the venue; Anana deletes on the venue's instruction or contract end. Embeddings in pgvector Tied to the source artifact; deleted when the source is deleted. Audit logs (artifact create / version / send) 2 years. Server logs / WAF logs Application production logs 30 days; AWS CloudFront/WAF edge logs per their configuration. Database backups Daily backups retained 7 days on a rolling cycle. Business contacts (CRM) Until objection or 2 years of inactivity. Accounting and tax records As required by applicable law (typically 7–10 years).
Open timeline citation

Capture recency

  • Terms of Service:Last captured 2026-08-28· verified 2026-08-28
  • Privacy Policy:Last captured 2026-07-19· verified 2026-07-19verified once — not yet re-verified

Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.

33 findings first captured First scan: July 2026.

Claim this profile

Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Anana's policies — no human edits the data.

Need this for procurement or legal diligence?

Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.

Every finding above is a verbatim quote from Anana's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.