The short version
- Calls the assistant answers are recorded and transcribed — and every caller is told so, up front, in the greeting. That sentence cannot be turned off.
- Your business data (contacts, jobs, call history, messages) belongs to your business. We process it to run your office; we don't sell it, rent it, or use it to advertise.
- We never train AI models on your data, and our AI providers are contractually barred from doing so too.
- Texting is strictly consent-based: STOP always works instantly, and we keep opt-outs for at least 10 years even if you leave.
- You can export everything, any time, from Settings → Export my data.
What we collect
- Account data— your name, email, and sign-in credentials (passwords are hashed; we can't read them). If you sign in with Google or Apple, see the Google section below.
- Business data you enter — services, prices, hours, policies, team contacts.
- Communications — recordings, transcripts, and metadata of calls the assistant answers; SMS conversations on your business number; voicemails.
- Customer records — names, phone numbers, addresses, and job history of your customers, as captured on calls or imported by you. You are the controller of this data; we process it on your behalf.
- Product & site usage — which pages and features you use inside the app and on our website, so we can understand and improve the product. See Cookies & analytics for exactly which tools do this and what they set.
Call recording & AI disclosure
Every call the assistant answers begins with a disclosure that the call is recorded and that the caller is speaking with an AI assistant. This is machine-appended to every greeting — including custom ones — and cannot be removed, so your business meets two-party consent standards in every US state. Voice audio is used only to run the call; we do no voice biometrics or speaker identification of any kind. Returning callers are recognized by their phone number, never by their voice.
Google sign-in & Google Calendar
Conduit uses Google in two separate, entirely optional ways. Its use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
1. Sign in with Google (optional)
If you choose to create your account or sign in with Google, we receive your basic Google profile — your name, email address, and profile picture — using only the standard openid, email, and profile scopes. We use it solely to create and secure your Conduit account: to identify you, sign you in, and contact you about your account. We never request your Gmail, contacts, Drive, or files. You can skip Google entirely and use an email and password instead.
2. Connect Google Calendar (optional)
If you connect a Google Calendar so your assistant can schedule around your real availability, Conduit requests a single, narrow permission — https://www.googleapis.com/auth/calendar.events— and nothing else. We use it for exactly two things: reading your existing events so the assistant knows when you're busy, and creating, updating, or cancelling the appointments your assistant books on the connected calendar.
Limited Use of Google user data
Conduit's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. For all Google user data — your sign-in profile and any connected calendar data:
- We use it onlyto provide and improve the user-facing features described above (signing you in and running your assistant's scheduling). We do not use it for any other purpose.
- We do not use Google user data for advertising, and we do not sell it.
- We do not transfer Google user data to others except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger or acquisition in which the successor honors this policy, and then only with your prior explicit consent.
- We do not let humans read your Google user data, unless you give explicit consent (for example, for support you request), it is necessary for security such as investigating abuse, it is aggregated or anonymized for internal operations, or we are required to by law.
- We do not use Google user data to develop, improve, or train generalized or non-personalized AI and/or ML models.
The product-analytics and product-improvement uses described elsewhere in this policy do not apply to Google user data — it is used solely as stated in this section. Google user data is never sent to PostHog, Google Analytics, or any other analytics tool.
AI and your Google data
Conduit is an AI assistant, so what the AI does and does not see matters. The content of your Google Calendar — event titles, descriptions, guests, locations, and notes — is never sent to any AI model or AI provider. Your assistant works only from anonymous busy-and-free time windows (start and end times) computed on our own servers. Event titles are stored solely to draw your own schedule page inside Conduit, and are never spoken by the assistant, never included in a prompt, and never transmitted to a third party.
The AI providers Conduit uses are third-party APIs — we do not host our own models. Our language-model routing is configured account-wide for zero data retention, with every endpoint that retains or trains on inputs disabled, so nothing we send can be retained or used to develop or improve generalized or foundational AI/ML models. Conduit's use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
You can disconnect Google Calendar, or revoke Google sign-in, at any time — from Settings, or directly at your Google Account permissions page. On disconnect we stop syncing and delete the stored Google refresh token; calendar events we previously created remain on your calendar unless you delete them.
Cookies & analytics
Essential cookies.We use a small number of strictly necessary cookies to keep you signed in and protect the app (session, CSRF, and rate-limiting). These can't be switched off without breaking sign-in.
Product & site analytics. To understand how the app and website are used and to improve them, we use:
- PostHog — first-party product analytics that records which pages and features account holders use inside the app. It may set a cookie or local-storage entry to recognize a return visit.
- Google Analytics (GA4) — aggregate website-traffic analytics for our marketing pages (which pages are visited, and from where). It may set cookies.
Both are limited to product and site usage. We do notbuild advertising profiles, run ad-network or remarketing tags, or sell your data, and analytics is never tied to a caller's phone identity or to the contents of your calls and texts. Google user data is excluded entirely — no data received from Google sign-in or a connected Google Calendar is ever sent to PostHog, Google Analytics, or any other analytics tool. The categories of provider that touch data, and how to request the current named list, are on our subprocessors page.
Where your data goes
We use a small set of infrastructure providers (hosting, telephony, AI, email, storage, analytics) to run the service. The categories are on our subprocessors page, and the specific, named list — with what each does and what it sees — is available on request. Data lives in US data centers, encrypted in transit and at rest. Every tenant's data is isolated with database-enforced row-level security — isolation is a property of the database, not of our application code being bug-free.
Retention & deletion
- Call recordings: 90 days by default, then automatically deleted.
- Transcripts and business records: kept while your account is active.
- SMS opt-outs:kept for at least 10 years — a legal obligation we'd keep anyway, so we never text someone who opted out.
When you close your account, export first if you want a copy, then we delete your business's data (contacts, jobs, calls, transcripts, messages, recordings) after a short wind-down grace period. Two things are kept by design: your SMS opt-outs, and a minimal security and audit trailof account actions, both append-only so a deletion can't erase a consent decision or a security record. Nothing kept is used to run your former assistant.
Your rights & choices
Everyone
Email support@conduitapp.ai to access, correct, export, or delete your data — or use Settings → Export my datato download it yourself any time. If you're a customer ofa business that uses Conduit, contact that business first — it controls the records — and we'll help them honor your request.
California (CCPA / CPRA)
California residents have the right to know what personal information we hold, to access and delete it, to correct it, and to opt out of its “sale” or “sharing.” We do not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of — but you can still exercise every other right, and we will never discriminate against you for doing so.
EU / UK (GDPR)
For the account data you give us, Conduit is the controller; for the customer records your business enters, Conduit is a processoracting on that business's instructions. We rely on these lawful bases: performing our contract with you (running your account), our legitimate interests (securing and improving the service), and consent where required (such as optional analytics). You have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your local supervisory authority.
Children's privacy
Conduit is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child's information reached us, email support@conduitapp.ai and we'll delete it.
International processing
We operate in the United States and store data in US data centers. If you use Conduit from outside the US, your data is processed in the US. Where required for transfers of personal data out of the EU/UK, we rely on appropriate safeguards such as the Standard Contractual Clauses; a Data Processing Agreement incorporating them is available on request at support@conduitapp.ai.
Security & breach notice
We protect your data with encryption in transit and at rest, database-enforced tenant isolation (row-level security), hashed passwords, versioned encryption of the tokens we hold on your behalf, and least-privilege access. No system is perfectly secure. If a breach ever affects your data, we'll notify affected account owners — and any regulators the law requires — without unnecessary delay.
Changes to this policy
If this policy changes in a way that matters, we'll email account owners before it takes effect — not after. If we ever want to use Google user data for anything beyond what the Google section allows, we would update this policy and ask for your consent first.
Contact us
Conduit is operated by Brainsmithy LLC (Colorado, USA). Questions, requests, or a Data Processing Agreement: support@conduitapp.ai. Our mailing address is available on request.