Skip to content
PsPro AI
Legal

Privacy policy

How PsPro AI collects, uses, retains, and protects the personal information handled by our website and by our voice and SMS agents.

Last updated August 22, 2026

Scope

This policy explains how PsPro AI ("PsPro AI," "we," "us," or "our"), operator of psproai.com, collects, uses, and protects information when you visit our website, contact us, or interact with our messaging services. By using our website or opting in to our communications, you agree to the practices described here.

Information we collect

When you interact with our website or messaging services, we collect:

  • Contact information you provide, such as your name, business name, email address, and mobile phone number.
  • Inquiry details you submit through our contact, quote, or scheduling forms, including the service you are interested in and any message content you share.
  • Communication records, including SMS and MMS messages, call details, and appointment or scheduling information generated when you interact with our messaging or voice services.
  • Usage and device data, such as IP address, browser type, pages visited, and referring source, collected automatically through cookies and analytics tools.

Information we process for customers

For customer deployments, our agents process call audio, recordings where the customer has switched recording on, transcripts, SMS message content, phone numbers, and any information a caller chooses to provide during a conversation. This data is processed on behalf of our customer, who is the controller of that data.

Where a caller gives an email address and agrees to an appointment, that address is passed to the customer's connected calendar provider so the caller is invited to the appointment and it appears on their own calendar. If no email address is given, nothing is sent to the calendar provider about the caller beyond what the customer's agent recorded.

Information about people who sign for a business

When someone signs an authorization on behalf of a customer — for example the messaging authorization or the call recording authorization — we record the name and role they typed, the email address on their account, the time, their IP address, and their browser identification, together with the exact wording they were shown and a checksum of it.

This is the evidence that the business authorized what we do on its behalf, so it is kept for as long as we hold any record of the relationship and is not deleted when an individual account is closed.

How we use your information

We use the information we collect:

  • To respond to your inquiries and contact you about the products or services you requested.
  • To qualify your request, answer questions, and schedule appointments or callbacks.
  • To send you transactional and follow-up messages related to your inquiry, where you have consented.
  • To operate, maintain, secure, and improve our website and services.
  • To comply with legal obligations and enforce our terms of service.

How we use conversation data

We use conversation data to deliver the service: routing and answering calls, qualifying the enquiry, writing an appointment to the customer's connected calendar, emailing the customer's own staff when a conversation needs a person or an appointment is booked, and producing the metrics shown on their dashboard.

Message and call content is sent to our model provider to generate the agent's next reply. Data is not used to train third-party foundation models.

Google user data

A customer may connect a Google Calendar so the agent can offer times that are genuinely free and put the appointment on the calendar before it confirms it. Connecting one is optional, the customer authorizes it themselves, and until they do we read nothing from any Google account.

PsPro AI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

  • What we ask for.Five scopes and no more: sign-in, used to identify the Google account authorizing the connection; availability, used to read the free/busy windows on the calendar the customer picked; the calendar list, used to show them which of their calendars the account can write to so they can pick one; calendar events, used to create and cancel the appointments our agent books; and the account's email address, so the setup screen can show which Google account is connected rather than leaving the customer to guess. We do not ask for read access to the contents of a calendar, and we do not request Gmail, Drive, Contacts, or any other Google service.
  • What we can see.A free/busy read returns only the times a calendar is busy. The titles, guests, descriptions and locations of a customer's existing events are never returned to us, never shown to the agent, and never stored. This is a limit of what the customer grants us, not only of what we ask Google for: the access they authorize cannot read the contents of an existing event.
  • What we do with it. Google user data is used only to provide and improve the booking feature the customer connected it for: checking availability, writing the appointment, and showing that appointment on their dashboard.
  • No advertising. Google user data is never used for advertising, and is never sold or transferred to anyone for advertising purposes.
  • No model training. Google user data is not used to develop, improve, or train generalized or non-personalized artificial intelligence or machine-learning models, ours or anyone else's. The times the agent may offer are worked out from a free/busy read and are put in front of our model provider so it can offer one; that provider does not train its models on them, and no event details are included.
  • No transfer. We do not transfer Google user data to others except as necessary to provide or improve this feature, to comply with applicable law, or as part of a merger or acquisition subject to this policy.
  • Nobody reads it. No human at PsPro AIreads Google user data, except with the customer's explicit consent, where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and de-identified.
  • How it is held.The long-lived authorization Google issues is sealed with AES-256-GCM before it is written to our database and is never stored in readable form. Free/busy results are held for up to ten minutes so that a caller waiting on an answer is not made to wait for the same question to be asked of Google again; what is held is the start and end of each busy period and nothing about the events themselves. It is deleted once that period is up, and immediately when the customer changes calendars or disconnects. The connected account's email address and the name of the chosen calendar are erased when the customer disconnects.
  • How to disconnect. Disconnect on the setup screen erases the stored authorization immediately and the agent stops booking. Access can also be withdrawn at any time from the Google account's own permissions page, which has the same effect.

Microsoft 365 calendar data

A customer on Office 365 or Outlook may instead connect a Microsoft 365 calendar, for exactly the same purpose: so the agent can offer times that are genuinely free and put the appointment on the calendar before it confirms it. Connecting one is optional, the customer authorizes it themselves, and until they do we read nothing from any Microsoft account.

  • What we ask for.Two Microsoft Graph permissions and no more: read and write access to the customer's calendars, used to read when the calendar they picked is taken and to create and cancel the appointments our agent books; and the basic profile of the signed-in account, so the setup screen can show which mailbox is connected rather than leaving the customer to guess. We do not ask for mail, files, contacts, Teams, directory or any other Microsoft service.
  • What we can see. Microsoft offers no permission that returns availability alone, so the authorization a customer grants is necessarily wider than what we ask of it. The request is what is narrow: when we read the calendar we name the four fields we want — the start, the end, whether the time counts as busy, and whether the entry was cancelled — so the subjects, guests, descriptions and locations of a customer's existing events are never sent to us, never shown to the agent, and never stored. We never read the contents of an event, and nothing in the product does.
  • What we do with it. Calendar data is used only to provide and improve the booking feature the customer connected it for: checking availability, writing the appointment, and showing that appointment on their dashboard. It is never used for advertising, never sold, and never used to develop, improve or train artificial intelligence or machine-learning models, ours or anyone else's.
  • Nobody reads it. No human at PsPro AIreads it, except with the customer's explicit consent, where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and de-identified.
  • How it is held.The long-lived authorization Microsoft issues is sealed with AES-256-GCM before it is written to our database and is never stored in readable form. Busy periods are held for up to ten minutes so that a caller waiting on an answer is not made to wait for the same question to be asked again; what is held is the start and end of each busy period and nothing about the entries themselves. It is deleted once that period is up, and immediately when the customer changes calendars or disconnects. The connected mailbox's address and the name of the chosen calendar are erased when the customer disconnects.
  • How to disconnect. Disconnect on the setup screen erases the stored authorization immediately and the agent stops booking. Access can also be withdrawn at any time from the Microsoft account's own app permissions page, or by a tenant administrator, both of which have the same effect.

SMS and text messaging program

Program. PsPro AI operates an appointment and lead follow-up messaging program. When you submit a form on our website and provide your mobile number with consent, you may receive SMS and MMS text messages from us to confirm your request, ask qualifying questions, answer service questions, and schedule appointments.

Consent. You opt in by checking the unchecked SMS and call consent box and submitting your mobile number on either our contact form or our account signup form. These are the only ways we collect messaging consent, the box is never pre-ticked, and one tick covers both text messages and phone calls. Each opt-in is recorded with the wording you were shown and the time you gave it.

It is optional. The box is optional on both forms. Leaving it clear does not stop you sending an enquiry or opening an account — we reply to the email address you gave instead — and consent to receive text messages is not a condition of any purchase.

What it applies to. Your opt-in is recorded against your phone number rather than against the form you gave it on, so you are asked once rather than every time. If you opted in at signup and later send us an enquiry from the same number, we may answer it by text without asking again. If that number has no opt-in on record, nothing is sent to your phone.

Message frequency. Message frequency varies based on your interaction with us.

Quiet hours.A message we start is held outside the quiet-hours window set on the account it is sent for and goes out when that window opens. The default window is 9:00pm to 8:00am in that account's own timezone. A reply to a message you sent, the text after a call we could not answer, and the acknowledgement of a form you have just submitted are answers to something you did, and are not held.

Rates. Message and data rates may apply.

Opt-out. You can opt out at any time by replying STOP to any message. After you reply STOP, we will send a single confirmation and no further messages will be sent unless you re-subscribe. Because the opt-in covered both channels, replying STOP also withdraws it for calls.

Help. Reply HELP for assistance, or contact us at info@psproai.com or +1 (385) 331-0984.

No sharing of mobile data. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Mobile opt-in data and consent are never shared or sold to third parties or lead generators. This includes text messaging originator opt-in data and consent, which will not be shared with any third parties.

Call recording

Calls are not recorded unless the customer has switched recording on for their account, and no account has it on by default. Turning it on requires the customer to sign a separate recording authorization.

When recording is on, a spoken disclosure is played at the start of the call before any audio is captured. The customer sets the wording; where they have not, we speak a default sentence. Both sides of the call are recorded on separate channels from the moment the call is answered. The audio is held by our telephony provider and linked from the customer's dashboard.

If you are called by one of our agents and do not want to be recorded, say so and ask to be transferred to a person, or contact us using the details below and we will delete the recording.

Consent and opt-out records

Consent and opt-out events are timestamped and retained as part of the audit log, together with the wording that was shown or the message that was received.

Opt-outs propagate across voice and SMS channels immediately. Replying STOP to a text also stops calls to that number from the same account.

How we share information

We do not sell your personal information. We share information only in these limited circumstances:

  • Service providers that operate our infrastructure on our behalf, for example our messaging and telephony provider, hosting, and analytics vendors, bound by contract to use the data only to provide services to us.
  • Legal and safety reasons, when required by law, subpoena, or to protect our rights, users, or the public.
  • Business transfers, in connection with a merger, acquisition, or sale of assets, subject to this policy.

Subprocessors

We use a limited set of subprocessors, each bound by contract to use the data only to provide services to us:

  • Twilio — telephony, message delivery, speech recognition on calls, and storage of call recordings where a customer has switched recording on.
  • Anthropic— model inference. Message and call transcripts are sent to generate the agent's replies and are not used to train their models.
  • Google — calendar availability and appointment creation, for customers who have connected a Google Calendar. Where a caller has given an email address it is sent as an attendee.
  • Microsoft — the same, for customers who have connected a Microsoft 365 calendar instead. A customer books on one calendar or the other, so only the provider they connected ever receives anything.
  • Resend— delivery of account email, contact-form notifications, and the alerts we send a customer's own staff when a conversation needs a person.
  • Cloudflare — bot protection on our public forms.

Where data is held

The application and its database run on infrastructure we operate. Call recordings are held by our telephony provider rather than on our own servers, and are reached through links from the customer's dashboard.

As stated above, mobile opt-in data and SMS consent are never shared or sold to third parties or lead generators for any purpose.

Cookies and analytics

We use cookies and similar technologies to operate our website, remember preferences, and understand usage. You can control cookies through your browser settings. We may use third-party analytics tools to measure site performance; these tools may collect usage data as described above.

Data retention

We retain personal information for as long as needed to fulfill the purposes described in this policy, to comply with our legal obligations, resolve disputes, and enforce our agreements. When no longer needed, we delete or de-identify it.

Conversation records, transcripts, lead records and call recordings are retained for the life of the customer account they belong to. We will delete any of them, or all of them, on written request from the customer, and we will delete a recording on request from the person recorded. Consent, opt-out and authorization records are kept beyond that point, because they are the evidence that a message was permitted.

Website inquiry data is retained for up to 24 months unless you request earlier deletion.

The product does not currently offer a self-service retention schedule or automatic redaction. Where a shorter schedule or field-level redaction is required, it is scoped and operated as part of an enterprise agreement rather than configured in the dashboard.

Data security

Traffic between you and this site is encrypted in transit with TLS. Credentials for accounts a customer connects to us, such as a Google Calendar or Microsoft 365 authorization, are sealed with AES-256-GCM before they are written to our database and are never stored in readable form.

Application, database and monitoring hosts reach each other only over a private encrypted network. The database has no public interface. The endpoints that accept a password are rate limited, and every request from our telephony provider is signature-verified before it is acted on.

Access to an account is role-based, and an account that is disabled or removed stops working on the next request. Every call, message, consent change and configuration change is written to an append-only audit log.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Your privacy rights

Depending on your location, you may have the right to access, correct, delete, or port your personal information, to opt out of certain uses, and to withdraw consent. You may opt out of text messages at any time by replying STOP.

To exercise a right, or if a caller wishes to make a request relating to a conversation with one of our agents, contact info@psproai.com. Requests relating to a customer deployment are forwarded to that customer as controller.

Children's privacy

Our website and services are intended for individuals 18 years of age or older and are not directed to children. We do not knowingly collect personal information from children under 13.

Changes to this policy

We may update this privacy policy from time to time. Changes are effective when posted on this page, and we will update the date above.

Contact

PsPro AI
7901 S 3200 W #94, West Jordan, UT 84084
Email: info@psproai.com
Phone: +1 (385) 331-0984

See also our terms of service.

This page is provided for general information and does not constitute legal advice. Contract terms in an executed order form or master services agreement control in the event of any conflict.