Privacy Policy

How we collect, use, share, and protect personal and financial data in the Asha service.

Last updated
August 4, 2026
Issued by
Joshua Eric, LLC
Applies to
Asha at dash.ldex.co

1.Introduction and scope

This Privacy Policy is issued by Joshua Eric, LLC, a limited liability company (“Joshua Eric,” “we,” “us,” or “our”). It explains how we collect, use, disclose, and protect personal data in connection with Asha, our AI assistant service, together with the web application at dash.ldex.co, its APIs, integrations, and related software (collectively, the “Service”).

Asha is a private service. It is not offered to the general public. Accounts are provisioned by invitation for personnel of the operating businesses we work with and for a limited number of approved individuals. If you are using the Service, an account was created for you deliberately.

By using the Service you agree to the practices described here. If you do not agree, do not use the Service. This Policy should be read alongside our Terms of Use.

Key definitions

  • Workspace means an isolated tenant within the Service. Each organization has its own workspace, and each individual using the Service in a personal capacity has their own separate private workspace.
  • Customer Data means data submitted to, or processed by, the Service on your behalf. This includes connection credentials, conversations and the outputs generated in them, uploaded files, documents Asha produces, financial records retrieved from the institutions you link, scheduled tasks, approval decisions, and service logs.
  • Financial Data means the subset of Customer Data obtained from financial institutions through Plaid, or extracted from financial statements you upload. Section 3 covers it specifically.

2.Information we collect

We collect only what the Service needs in order to operate, secure itself, and do the work you ask it to do.

A. Account and identity information

You sign in with Google. From that sign-in we receive and store your name, email address, and Google account identifier. We also store the organization or personal workspace you belong to, your role, and the permissions granted to you within the Service.

B. Connection credentials

To maintain the integrations you enable, we store OAuth access and refresh tokens, their granted scopes, and their expiry metadata. This includes Google Workspace tokens, Plaid access tokens for each linked institution, and credentials for any other service you connect. All such credentials are held in an encrypted credential store. Plaid access tokens receive the additional per-workspace encryption described in section 8.

C. Content you provide

  • Conversations with Asha, including your messages, her responses, and a record of the tools she invoked to produce them.
  • Files you upload: documents, spreadsheets, images, PDFs, statements, and archives, along with the text extracted from them and the vector embeddings derived from that text for search.
  • Documents, reports, spreadsheets, models, and other deliverables Asha produces for you.
  • Durable facts, preferences, and context extracted from your conversations so that Asha remembers what you have already told her.
  • Scheduled tasks and their configuration, and your approval or denial of the actions Asha proposes.

D. Data from services you connect

When you connect a third-party service, Asha accesses data through that service’s API within the scopes you authorize. Depending on what you connect and what you ask her to do, this may include email messages and attachments, calendar events, files and documents in cloud storage, spreadsheet contents, website analytics, store catalog and order data, and messages in channels she has been added to. Section 4 describes Google data specifically, and section 3 describes financial data.

E. Financial account information

If you link a financial institution, we receive account, transaction, investment, and liability data as described in section 3.

F. Service logs and usage data

We record operational logs (timestamps, request and response metadata, errors) and an audit record of every tool the agent invokes, captured before and after execution. Audit records hold event metadata, not the content of your financial records. We also meter model token usage and external costs per workspace.

G. Communications with us

If you email us, we retain that correspondence and anything you include in it.

What we do not collect

We do not run advertising or marketing trackers on the Service. We do not use third-party advertising networks, and we do not build advertising profiles. We do not ask for, receive, or store your banking username or password: those are entered directly with your institution through Plaid and are never visible to us.

3.Financial account information and Plaid

Asha can connect to your bank, credit card, brokerage, and loan accounts so that she can analyze your finances, prepare tax materials, and answer questions about your own money. This section describes that data in detail, because it is the most sensitive information the Service handles.

A. How a connection is established

Financial connections are made through Plaid Inc., a financial data network. You authenticate directly with your institution inside Plaid’s interface. Your institution credentials go to Plaid and your institution, never to us. Plaid returns an access token that lets us retrieve the data you approved. Plaid’s handling of your information is governed by the Plaid End User Privacy Policy, which we encourage you to read.

B. What we request

We request a deliberately narrow, read-only set of Plaid products:

ProductData receivedWhy
TransactionsAccount names, types, masked account numbers, balances, and transaction history including date, amount, merchant, and categorySpending analysis, budgeting, cash-flow work, and tax preparation
InvestmentsHoldings, securities, and investment transactions for brokerage and retirement accountsPortfolio analysis and reasoning about your overall financial position
LiabilitiesMortgage, student loan, and credit card liability detailsSo that analysis accounts for the whole balance sheet rather than one side of it

We do not request Plaid’s identity or authentication products, because the Service does not need your account and routing numbers or the identity records held by your institution.

C. Read-only, with no ability to move money

The Service holds read-only financial access. No part of it can initiate a payment, a transfer, or any other movement of funds. This is not a policy statement alone: the set of permitted Plaid products is enforced in code, and our automated test suite fails the build if anyone adds a write-capable endpoint or widens the product list. Every financial retrieval by the agent is authorization-gated and written to an append-only audit log.

D. How financial data is used

Financial Data is used only to answer your own questions and perform the work you ask for inside your own workspace. It is never used for advertising, never sold, never shared with any third party for that party’s own purposes, and never used to train AI models. It is not visible to any other workspace.

E. Uploaded financial documents

Bank and brokerage statements you upload directly are treated as Financial Data and receive the same encryption, retention, and disposal treatment described in sections 8 and 9.

F. Disconnecting

You may unlink an institution at any time. When you do, we call Plaid’s item removal endpoint to terminate our access at the provider and immediately revoke the stored credential. You choose whether the ledger history already retrieved is kept for continued longitudinal analysis, which is the default, or deleted. You may request deletion of all Financial Data at any time under section 9.

4.Google user data and Limited Use

Signing in to Asha with Google, and connecting your Google Workspace, grants the Service access to Google APIs on your behalf. Google presents the exact scopes on its consent screen before any access is granted, and you may decline any of them.

Depending on the scopes you approve, Asha may access Gmail messages and attachments, Google Calendar events, Google Drive files, Google Docs and Sheets contents, Google Analytics reports, and Search Console data. She uses that access to do the work you ask for: finding the source material for a task, drafting a reply, filing a finished document, writing numbers into a tracker, or pulling a report.

Asha’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use Google user data only to provide and improve features that are visible to you within the Service.
  • We do not transfer Google user data to third parties except as necessary to provide the Service, to comply with applicable law, or as part of a merger or acquisition, and never for advertising.
  • We do not use Google user data for serving advertisements of any kind.
  • We do not allow humans to read Google user data unless we have your explicit consent for a specific message or document, it is necessary for security purposes such as investigating abuse, it is required by law, or the data has been aggregated and de-identified.
  • Google user data is not used to train generalized AI or machine learning models, and our AI providers are contractually prohibited from doing so.

You can revoke the Service’s access to your Google account at any time from your Google account permissions page. Revoking access stops all further collection immediately. It does not by itself delete data already stored; see section 9.

An organization may also run the Service against its own Google OAuth application, so that its own Workspace administrator controls and approves the grant.

5.How we use information

We use the information described above to:

  • Operate the Service. Authenticate you, maintain the integrations you enable, execute the tasks you request, generate outputs, run scheduled work, and preserve context between conversations so that Asha remembers what you have already told her.
  • Do the specific work you ask for. Research a question, analyze your accounts, draft a document, send a message you approved, publish a post to a site you connected.
  • Keep the Service secure. Detect and prevent fraud, abuse, and unauthorized access, investigate incidents, and maintain the audit trail.
  • Meter and manage cost. Track model usage and external spend per workspace and enforce the budget ceilings configured for autonomous work.
  • Maintain reliability. Diagnose errors and improve performance using operational logs and aggregated usage data.
  • Communicate with you. Send service notifications, including the alerts and escalations Asha raises when she needs a decision from you, and respond to your support requests.
  • Comply with law and enforce our Terms of Use.

We do not use Customer Data for advertising, and we do not sell it. See section 7.

6.AI processing

Asha is built on large language models. To answer a request, the portions of Customer Data relevant to that request, which may include your message, retrieved documents, prior conversation context, and retrieved financial records, are sent to our AI provider to generate a response.

  • Our AI provider is Anthropic, whose Claude models power the agent. Image generation, when you invoke it, is performed through Replicate. Voice synthesis and transcription, when invoked, are performed through ElevenLabs.
  • Your data is not used to train models. Our agreements with these providers prohibit the use of data submitted through their APIs to train their general-purpose models. We do not train models on Customer Data ourselves.
  • Requests are isolated. Your data is processed in discrete API requests and is not shared with, or visible to, any other customer of ours or of the provider.
  • Providers may retain data briefly for abuse monitoring in accordance with their API retention policies, and process it in the United States.

AI output is probabilistic. It can be wrong, incomplete, or misleading, and it is not a substitute for professional advice, including legal, tax, financial, or medical advice. You are responsible for reviewing output before relying on or distributing it. See our Terms of Use.

7.How we share information

We do not sell your personal data. We do not share it for cross-context behavioral advertising. We do not disclose it for any third party’s own commercial purposes.

We share information only where it is necessary to operate the Service, and only with providers engaged under terms that restrict them to that purpose.

A. Service providers

ProviderPurposeData involved
Hetzner Online GmbHDedicated server infrastructure hosting the Service (United States)All Customer Data, at rest and in processing
Cloudflare, Inc.DNS, TLS termination, and edge protectionNetwork metadata and request routing
Plaid Inc.Financial account connectivityAccount, transaction, investment, and liability data you authorize (section 3)
Google LLCSign-in and Workspace integrationsAccount identity, and data accessed within the scopes you approve (section 4)
Anthropic, PBCLanguage model inferencePrompt and context sent to generate a response
Replicate, Inc.Image generation, when invokedThe prompt you supply for the image
ElevenLabs Inc.Voice synthesis and speech transcription, when invokedAudio and text you submit to those features
Zyte Ltd.Web page retrieval and browser rendering for researchThe public URLs being fetched. No Customer Data is transmitted
Twilio Inc.SMS notifications and escalationsYour phone number and the message text
Slack, Shopify, WordPress, and similarIntegrations, only where you have connected themData accessed within the scopes you authorize

Databases, object storage, the vector index, and the log store are self-hosted on our own infrastructure rather than operated by a third-party managed provider.

B. Legal compliance and protection

We may disclose information where required by law or valid legal process, or where we reasonably believe disclosure is necessary to comply with a legal obligation, protect the rights and safety of users or the public, prevent fraud or abuse, or enforce our Terms of Use.

C. Business transfers

If we are involved in a merger, acquisition, financing, or sale of assets, information may be disclosed to advisors and to a successor entity, subject to confidentiality protections and to this Policy.

D. Third-party links

Output produced by Asha may reference third-party websites. We are not responsible for their privacy practices.

8.Data storage and security

A. Where data is stored

Customer Data is stored on dedicated servers located in the United States (Oregon). It is not replicated outside the United States.

B. Encryption in transit

All traffic between you and the Service, and between the Service and Plaid, runs exclusively over TLS 1.2 or higher. Inbound webhooks from Plaid are additionally authenticated by verifying Plaid’s ES256-signed token, including a SHA-256 digest of the raw request body, before any payload is trusted.

C. Encryption at rest, with a separate key per workspace

Financial Data is protected by a two-level key hierarchy. A platform key-encryption key, held only in the production secret store and never written to application storage, wraps a unique, randomly generated AES-256 data-encryption key issued to each workspace. All Plaid access credentials and all raw financial records are encrypted with AES-256-GCM under the owning workspace’s key before they touch the database. Because every workspace’s key is unique, no single stored key can expose more than one workspace, and destroying one workspace’s key affects that workspace alone.

All other integration credentials are held in an encrypted connection store using AES-256-GCM, with rotation and revocation support.

D. Access control and isolation

Every record carries the identity of the workspace that owns it, and all application queries are workspace-fenced. Authorization is capability-based and default-deny: a principal can perform only the operations explicitly granted to it. SQL analysis runs inside a per-workspace database schema behind a dedicated database role that can read only that workspace’s views, so a cross-workspace read is refused by the database itself rather than by a code path someone has to remember to write. Administrative access to production is limited to the smallest number of personnel necessary and is logged.

E. Auditing

Every tool the agent invokes is recorded in an append-only audit log, before and after execution. Audit records contain event metadata and are readable by workspace administrators.

F. Your responsibilities

You are responsible for the security of the Google account you sign in with, for the scopes you grant, for which accounts you link, and for reviewing the approval settings that govern what Asha may do without asking.

G. Incidents

We maintain an incident response process. If a security incident affecting your personal data is confirmed, we will notify you without undue delay and provide the information reasonably necessary for you to meet your own obligations.

9.Data retention and deletion

We retain Customer Data for as long as it is needed to provide the Service and to meet our legal obligations, and no longer.

DataRetention
Provider credentials (Plaid, Google, and others)Life of the connection. Destroyed on unlink, on revocation, or on a deletion request
Financial ledger, both structured fields and raw recordsLife of the account, because longitudinal history is the point of the analysis. You may request deletion at any time
Conversations, deliverables, and saved uploadsLife of the account, or until you delete them
Staged copies of uploads in transient processingAutomatically deleted 30 days after upload
Operational logsAutomatically deleted after 7 days
Audit records (metadata only)Life of the workspace, for security accountability

How deletion works

You may request deletion of your data at any time by emailing us at joshuaeric@gmail.com. For Financial Data, deletion is executed as a single auditable procedure that, in order:

  1. revokes our access at the provider by removing each linked Plaid item;
  2. deletes every financial record for the workspace from the production database and drops the workspace’s financial views;
  3. hard-deletes the stored provider credentials; and
  4. destroys the workspace’s encryption key. From that moment every ciphertext ever produced under that key, including any copies present in database backups or snapshots, is permanently unreadable. A workspace that later relinks an institution receives a newly generated key, which by construction cannot decrypt any pre-deletion material.

Deletion requests are honored promptly and completed within 30 days at the latest. The key destruction step is immediate. Structured records removed by row deletion age out of backup media as backup generations expire. Derived data such as search indexes and embeddings is deleted or disassociated when the underlying data is deleted.

Where legally permitted, you may request an export of your data before deletion.

10.Your rights and choices

Depending on where you live, you may have some or all of the following rights. We honor these requests regardless of whether the law requires us to.

  • Access. Request a copy of the personal data we hold about you.
  • Correction. Request correction of inaccurate or incomplete data.
  • Deletion. Request deletion of your personal data, including conversations, uploads, deliverables, and Financial Data, as described in section 9.
  • Portability. Request a copy of your data in a machine-readable format.
  • Withdrawal of consent.Disconnect any integration at any time, from within the Service or from the provider’s own permissions page. This stops further collection immediately.
  • Objection and restriction. Where applicable law provides them, object to or request restriction of certain processing.
  • Non-discrimination. We will not treat you differently for exercising any privacy right.

To exercise any of these, email joshuaeric@gmail.com. We may need to verify your identity before acting. We respond within the period required by applicable law, and in any case within 45 days. If we deny a request in whole or in part, you may appeal by replying with “Privacy Appeal” in the subject line.

Residents of California and of other U.S. states with comprehensive privacy statutes have rights to know, access, correct, delete, and opt out of the sale or sharing of personal information. We do not sell or share personal information as those terms are defined, so there is nothing to opt out of, but the remaining rights are available above.

Because a workspace may belong to an organization, we may ask that a request concerning organizational data come from an administrator of that workspace, or direct you to your administrator.

11.Cookies and analytics

The Service uses cookies that are strictly necessary for it to function: a session cookie that keeps you signed in, and a cookie that records which workspace you selected at sign-in. Without these, the Service cannot work.

We do not use advertising cookies, tracking pixels, or third-party analytics or attribution services on the Service. You can clear or block cookies in your browser, though doing so will sign you out.

Asha can read Google Analytics data for websites you own and have connected. That is a feature you invoke, not measurement of your use of the Service.

12.Children's privacy

The Service is not directed to children and we do not knowingly create accounts for anyone under 18. If you learn that a child has provided personal data to us, contact joshuaeric@gmail.com and we will delete it promptly.

Adults may upload documents that concern their own minor children, for example school or medical records in the course of advocacy work. Those documents live in the uploading adult’s private workspace and are structurally inaccessible to any other workspace.

13.International users

Joshua Eric, LLC is based in the United States and processes personal data there. If you use the Service from outside the United States, you understand that your data will be transferred to and processed in the United States.

If you are located in the European Economic Area or the United Kingdom, we process personal data on one or more of the following legal bases: performance of a contract with you, your consent (for example, the OAuth grants that enable an integration), our legitimate interests in securing and operating the Service, and compliance with legal obligations. Where required for a cross-border transfer, we rely on appropriate safeguards such as the Standard Contractual Clauses. You may lodge a complaint with your local supervisory authority.

14.Changes to this Policy

We may update this Policy. If we make a material change, we will notify account holders by email or by notice within the Service before the change takes effect. The “Last updated” date at the top of this page reflects the most recent revision. Continued use of the Service after a change takes effect constitutes acceptance of the revised Policy.

We review this Policy at least annually, and whenever we make a material change to how data is stored, encrypted, or deleted.

15.Contact us

For questions about this Policy, to exercise a privacy right, or to request deletion of your data:

Email: joshuaeric@gmail.com
Mail: Joshua Eric, LLC, 302 Washington St #150-16517, San Diego, CA 92103, United States