Privacy Policy
Last updated 28 September 2026
Official AI Agent answers phone calls, WhatsApp messages and website chats on behalf of local businesses. This page explains, in plain terms, what the service records when it does that — and what it deliberately does not.
There are two kinds of people in this document. Businesses are our customers: they sign up, configure an assistant and pay us. Callers are the people who phone or message those businesses. We process caller information on behalf of the business, as its processor; the business decides why it is collected and for how long it is kept.
What we store about callers
- Phone number — never in the clear. The number is normalised and stored only as a keyed HMAC-SHA256 hash, plus the last four digits so a business owner can recognise a caller in their own panel. There is no fallback that writes the raw number to our database. Your carrier and the telephony provider necessarily see the real number in order to connect the call.
- A written transcript of the conversation — what was said, by whom, in what language, with timings.
- What the assistant captured — for example a booking with the name you gave, the service requested, the date and time, an address for a delivery, or the content of a message you asked to leave.
- Call metadata — direction, duration, outcome, channel, and quality measurements used to review how well the assistant performed.
- A returning-caller profile — keyed on the hashed number: previous services, preferred staff member, language, visit count.
How long we keep it
Business documents that an owner uploads to teach the assistant (price lists, FAQs, policies) can be deleted by that business from its own panel at any time.
Who else processes the data
To answer a call we necessarily pass parts of the conversation to specialist providers. They act as our sub-processors:
- OpenAI — live speech and text for the conversation itself, text used to summarise a call and score its quality, embeddings of the business's own documents, and speech-to-text for WhatsApp voice notes and for Jarvis voice input when browser dictation is unavailable.
- Your browser's speech provider — when a business owner talks to Jarvis in the panel, browser dictation is processed by the browser's own provider (for example Google in Chrome or Apple in Safari). We receive only the resulting text, never the audio.
- Hume AI — live speech for businesses whose assistant runs on that engine; the assistant's configuration is stored on their side.
- Telnyx — telephony: it carries the call and therefore sees the caller's real number.
- Meta (WhatsApp Business Platform) — for the WhatsApp channel.
- An email relay — for notifications and password resets.
- Contabo / Coolify — servers and deployment. Data is stored in a single primary database on infrastructure we operate.
We do not sell personal information, and we do not use caller conversations to train our own models.
AI apps a business connects
A business owner can connect an outside AI assistant to their account — for example Claude or ChatGPT through our connector, or another assistant that speaks the Model Context Protocol (such as Gemini) using an API key the owner creates. That assistant then becomes a recipient of the business's data. We only connect it when the owner approves it on our consent screen or creates the key themselves.
- What it receives: only what the owner allowed. Access is split into separate permissions — reading calls, bookings, customers, reports and settings; changing bookings; changing settings; and emailing customers or sending webhooks — and the app gets just the ones shown on the consent screen (or the scopes of the API key). It receives the answers to the requests it makes, which can include caller details the business already holds, such as a name or the last four digits of a phone number.
- Their privacy terms apply there. Once data reaches the assistant's provider (for example Anthropic, OpenAI or Google), that provider handles it under its own terms, not ours.
- How we hold the connection: we store only a one-way hash of the app's tokens, never the tokens themselves. An access token lasts one hour; a refresh token expires after 30 days without use.
- How to stop it: in the panel go to Settings → Integrations → Connected apps and choose Disconnect; the app is refused on its next request. Keys created for other assistants are revoked in the same place under API keys.
What we store about businesses
- Account details: work email, hashed password, role, business name and slug.
- Assistant configuration: hours, services, prices, staff, greeting, languages.
- Documents uploaded to teach the assistant, and text extracted from them.
- Usage and billing counters: minutes, model usage, plan.
- Channel credentials — for example WhatsApp access tokens — encrypted at rest and never returned in API responses or written to logs.
How the data is protected
- Every business's data is isolated at the database level by row-level security, so one business's queries cannot reach another's rows.
- Caller phone numbers are stored only as keyed hashes, as described above.
- Passwords are stored as PBKDF2-SHA256 hashes; we never see the plain text.
- Third-party channel credentials are encrypted with a separate key.
- All traffic to the service is over TLS.
- Administrative actions are written to an append-only audit trail.
Recording and consent
The assistant produces a written record of every conversation. Some places require callers to be told, or to agree, before a call is recorded or transcribed. Each business is responsible for the disclosures it makes to its own callers; the assistant can be configured to state at the start of a call that it is an AI, and it always answers honestly when a caller asks.
Your choices
If you called a business and want to know what was written down, or want it deleted, contact the business first — the record belongs to them. You can also write to us at support@officialaiagent.com and we will help, including passing the request to the business it concerns. Business owners can request export or deletion of their account data at the same address.
Children
The service is for businesses and is not directed at children.
Changes
If this policy changes materially we will update the date at the top and, for business account holders, send an email.
Contact
Questions about privacy: support@officialaiagent.com.