Security & privacy
Your data
What we store, where it goes, and how it’s protected.
What we store
- Your business settings, services, team and calendar.
- Client profiles, appointments, messages on every channel, and their permissions.
- A record of each assistant reply: which tools it used and which checks it ran — so you can see why it said what it said. The tool details are kept for 90 days.
- A history of important changes (team, settings, payments, merges, exports and erasures).
We never see or store card numbers — those stay with Stripe.
Services we use to run it
| Service | What for | What it receives |
|---|---|---|
| OpenAI (or Anthropic) | Writing the assistant’s replies | The conversation and your business info. With OpenAI, we ask for it not to be stored. |
| Meta | WhatsApp and Instagram | Messages on those channels |
| Twilio | SMS | Text messages and phone numbers |
| Stripe | Deposits (your account) and our subscription billing | Payment details, on Stripe’s own pages |
| Resend | Emails to you and your team | Sign-in codes and notifications |
| Telnyx | SMS and forwarded calls, when your texting number is with them instead of Twilio | Text messages, phone numbers and calls |
| OpenAI | Turning client voice notes into text | The voice note’s audio |
| Cloudflare Turnstile (where switched on) | Telling people from scripts at sign-in and on web chat | A browser check |
| Sentry (where switched on) | Error reports, so we hear about problems | Technical details, with tokens and secrets removed |
How it’s protected
- Connections are encrypted (HTTPS).
- Access tokens for your WhatsApp, Instagram and other connections are encrypted in the database.
- Incoming messages from Meta, Twilio and Stripe are checked for a valid signature before we accept them.
- Strict browser security settings; the dashboard can’t be embedded in other websites (only your chat page and widget can).
- Rate limits on sign-in, web chat and forms.
How long we keep things
| Data | Kept for | Then |
|---|---|---|
| Sign-in codes | 30 days | Deleted |
| Sessions | Until they end, or 30 days unused | Deleted |
| Team invites nobody accepted | 30 days after the link expired | Deleted |
| Records of what the assistant did (which tools it used) | 90 days | Removed; only usage counts are kept |
| Conversations, messages and client records | While your business keeps its account | Erase a client any time |
| Permissions and opt-outs (including STOP) | Kept | They are your proof of consent |
Clean-up runs automatically once a day.
Exports and deletion
- Export or erase any single client — see Client privacy.
- Export your results as CSV — see Results.
Legal pages
Our Privacy Policy, Terms of Service and Data Processing Agreement are published in English and Spanish. They’re still drafts while our lawyer writes the final text, and each page says so at the top.