Privacy Policy

Last updated: 3 September 2026

1. What we collect

When you sign up, we collect your account email and password (handled entirely by Supabase Auth — we never see or store your raw password). When you set up a business, we collect the business information you provide: name, contact details, hours, services, pricing, and any customer/client list you paste in, upload, or that syncs in from a connected calendar. When your customers text your Atronet number, we store the message content and phone number so Receptionist can hold a conversation and so you can see what was said. If you connect a Gmail inbox, we read incoming messages so Receptionist can reply to them — see "Gmail data specifically" below. As you go through our signup wizard, we also record which steps you reach and your business name and email, so we can see where people get stuck and improve the signup flow — see "Who we share it with" below for where this is stored.

2. How we use it

DataUsed for
Business profile (hours, services, tone)Lets the AI agents draft accurate, on-brand replies
Customer name/phone/appointment historyBooking, reminders, follow-ups, win-back messages
Inbound/outbound SMS contentAnswering customers, showing you the conversation, detecting STOP/START opt-out
Inbound email content (if you connect Gmail)Classifying the message and drafting a reply — see "Gmail data specifically" below for what's actually kept afterward
Account emailLogin, account recovery, service notifications
Billing identifiers (via Stripe)Subscription management — we never see your card number

3. Who we share it with

We use a small number of subprocessors to run the Service, each only for what's needed to operate it:

ProviderPurpose
AnthropicDrafts AI-generated SMS and email replies, client check-in messages, and win-back messages, from message content, your business profile, and (when connected) names/service details synced from your calendar
TwilioSends and receives SMS on your behalf
StripePayment processing and subscription billing
SupabaseAccount authentication (login/signup/sessions), and storing signup-wizard funnel analytics (business name, email, and which step was reached) so we can see where signups get stuck
NetlifyHosting, and the underlying storage (Netlify Blobs) your business data is stored in
Google / Calendly / MicrosoftOnly if you connect a calendar or Gmail inbox — used to read/write your appointments, or to read and send email on your behalf (Gmail only)
Google AdsOnly if you accept the optional cookie banner shown on the site — used to measure which ads led to a signup. See "Cookies" below.

We do not sell your data or your customers' data to anyone.

4. Google Calendar data specifically

If you connect a Google Calendar, Atronet requests exactly two Google OAuth scopes and nothing broader:

ScopeWhat it lets us do
https://www.googleapis.com/auth/calendar.eventsRead your calendar's events (to sync existing appointments in as clients) and create, update, or delete events (to book, move, or cancel appointments Receptionist handles)
https://www.googleapis.com/auth/calendar.events.freebusyCheck when you're free or busy, so Receptionist only offers times that don't conflict with your calendar

We do not request access to any other Google data — not your email, your contacts, your files, or any calendar other than the one you connect.

What we access and why. When you connect Google Calendar, we periodically read your primary calendar's events to keep your Atronet client list in sync (an event's guest name and title become a client record), and we read your free/busy times before offering an appointment slot by text. When Receptionist books, reschedules, or cancels an appointment, we create, update, or delete the corresponding event on your Google Calendar directly.

Whether Google data is shared with third parties. Names and appointment/service descriptions that originate from your connected Google Calendar are used to draft two categories of automated SMS text — post-appointment check-in messages and win-back messages to past clients — using Anthropic's Claude API. In both cases, the information sent to Anthropic is limited to a client's name (or email if no name is on the event) and the service/event title; nothing else from your calendar — the full event list, other attendees, descriptions, locations, or your free/busy schedule — is sent to Anthropic or to any other AI or analytics service. No Google data is sold, used for advertising, or used to train AI models. See "Limited Use compliance" below.

How Google data is protected. Your Google OAuth access and refresh tokens are stored encrypted, never in plain text, and are never exposed to your browser or to anyone other than Atronet's own servers making calendar API calls on your behalf.

Retention and deletion. Calendar-derived client records and stored appointment data are kept for as long as your account is active, the same as other business data described in "Data retention" below. Deleting your Atronet account deletes your stored Google OAuth tokens and all calendar-derived client/booking data immediately and permanently. Atronet does not currently offer a separate "disconnect calendar only" control that leaves the rest of your account intact — to stop Atronet's access to your calendar without deleting your whole account, revoke Atronet's access directly from your Google Account's third-party access settings; deleting your Atronet account revokes that same access automatically.

Limited Use compliance. Atronet's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google Calendar data only to provide and improve the specific user-facing features described above — calendar sync, availability checking, appointment booking/rescheduling/cancellation, and the follow-up and win-back messages described here. We do not use Google user data for advertising, we do not sell it, we do not allow humans to read it except where necessary for security, to comply with applicable law, or with your consent, and we do not use it to train or improve generalized/non-personalized AI or machine-learning models.

5. Gmail data specifically

If you connect Gmail, Atronet requests exactly two Google OAuth scopes and nothing broader:

ScopeWhat it lets us do
https://www.googleapis.com/auth/gmail.readonlyRead messages in your inbox, so Receptionist can see new customer emails that need a reply
https://www.googleapis.com/auth/gmail.sendSend an email as you, so Receptionist can reply to that customer directly from your address

We do not request the broader gmail.modify scope (which would also let us archive, label, or delete your mail) or gmail.compose. We never delete, label, or otherwise modify an existing message in your inbox — we only read it and, when appropriate, send a reply.

What we access and why. We periodically check your inbox for new messages so Receptionist can hold an email conversation with your customers the same way it does over SMS. When Receptionist replies, we send that reply from your connected Gmail address using the send scope above.

Whether Gmail data is shared with third parties. The content of an inbound email (sender, subject, and body) is sent to Anthropic's Claude API so it can draft a reply, the same way inbound SMS content is used. No Gmail content is sold, used for advertising, used to train AI models, or shared with anyone beyond what's needed to draft and send that one reply.

How Gmail data is protected. Your Gmail OAuth access and refresh tokens are stored encrypted, never in plain text, and are never exposed to your browser or to anyone other than Atronet's own servers making Gmail API calls on your behalf.

Retention and deletion. We do not permanently store the full body of your emails. An inbound message is fetched, processed to classify it and draft a reply, and then only the sender's address, the subject line, the message and thread id, and the conversation status (open, auto-replied, or handed off to you) are kept, for as long as your account is active — not the email body itself. Deleting your Atronet account deletes your stored Gmail OAuth tokens and that thread metadata immediately and permanently. To stop Atronet's access to Gmail without deleting your whole account, revoke Atronet's access directly from your Google Account's third-party access settings; deleting your Atronet account revokes that same access automatically.

Limited Use compliance. The same Limited Use commitments described above for Google Calendar apply to Gmail data: we use it only to provide the email-answering feature described here, we do not use it for advertising, we do not sell it, we do not allow humans to read it except where necessary for security, to comply with applicable law, or with your consent, and we do not use it to train or improve generalized/non-personalized AI or machine-learning models.

6. Cookies

Your login session is kept in your browser's local storage by Supabase's client library, not a cookie. The site itself sets no cookies by default.

The one exception: if you click "Accept" on the cookie banner shown on your first visit, we load a Google Ads tracking cookie so we can see which ads led to a signup. This is entirely optional — if you click "Decline," or don't respond, nothing loads and no cookie is set. You can change your mind at any time; the banner reappears if you clear your browser's site data, or you can re-open it from the link at the bottom of this page. This cookie is set by Google, used only to measure ad performance, and is covered by Google's own ads policy. See "Who we share it with" above for Google's role as a subprocessor for this.

Change your cookie choice

7. Data retention

7. Data retention

We keep your business's data for as long as your account is active. If you delete your account (available directly from your dashboard's Account & Data panel), your business record, client list, booking history, and message history are permanently deleted, and any connected phone number and active subscription are released/canceled as part of that same action.

8. Your rights

You can export a full copy of your business's data at any time from your dashboard ("Export my data"). You can delete your account and all associated data at any time from the same panel — this is immediate and permanent. Beyond export and deletion, you can also ask us to correct inaccurate data we hold about you, ask us to restrict or object to certain processing, or ask what data we hold — contact jacob@atronet.co for any of these and we'll respond as soon as we can. If you're not satisfied with how we've handled your data, you have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.

9. SMS opt-out

Anyone your business texts can reply STOP (or UNSUBSCRIBE/CANCEL/END/QUIT) at any time to stop receiving automated messages, and START (or UNSTOP) to opt back in. We record opt-out status per phone number and every automated send checks it first.

10. Children's privacy

The Service is intended for business use and is not directed at children. We do not knowingly collect data from anyone under 16.

11. Security

Access to your business's dashboard requires a verified, signed-in session tied to your account — data is never accessible from a bare link or guessed ID alone. OAuth tokens for connected calendars and Gmail inboxes are stored encrypted, not in plain text.

12. Changes to this policy

We may update this policy from time to time; material changes will be reflected by updating the "Last updated" date above.

13. Contact

Questions about this policy or your data: jacob@atronet.co