Privacy Policy
Effective October 1, 2026 · Last updated September 30, 2026
This Privacy Policy describes how Aibrify Technologies Inc. ("Aibrify," "we," "us," or "our") collects, uses, and shares information when you visit our website, send us a brief or a message, or use our services, including the phone receptionist and the dashboard our existing clients use.
1. Information we collect
1.1 Information you provide
- Account information: Name, email address, phone number, company name, and password, for dashboard accounts
- Profile information: Business industry, timezone, brand details, and logo
- Payment information: Billing address, payment method (processed securely by Stripe)
- Content: Posts, images, videos, menus, prices, and other content you create, upload, or give us
- Project information: What you tell us about a job and the access you give us to do it, such as a code repository, a hosting account, an app builder project, or the keys and logins an app uses
- Communications: Messages you send us by text, email, WeChat, the website chat, or our support channels (see section 2)
1.2 Information from connected accounts
When you connect social media or advertising accounts, we collect:
- Account credentials: OAuth tokens (encrypted) to access your accounts on your behalf
- Profile data: Username, profile picture, page/account names
- Content data: Posts, comments, reviews, and messages from connected platforms
- Analytics data: Engagement metrics, follower counts, and performance data
- Ad account data: Campaign performance, spend data, and audience information
1.3 Automatically collected information
- Usage data: Features used, actions taken, and time spent in the dashboard
- Device information: Browser type, operating system, device type, IP address
- Log data: Access times, pages viewed, and referring URLs
- Cookies and similar storage: Cookies and local storage for sign-in, preferences, analytics, and campaign tracking (see section 15)
2. Briefs and messages
You can reach us through the brief at aibrify.com/start, the form at aibrify.com/contact, a text to (949) 237-2690, email, WeChat, or the chat on our website. Here is what each one collects:
- The brief (/start): What you need, anything you add in your own words, a mobile number or an email address, and, if you give them, your name and when you need the work done. It also records the plan you picked, if you came from a plan page, and the language of the page.
- The contact form (/contact): Your name, email address, what you need help with, and your message, and, if you give them, your company, phone number, and budget.
- Texts, email, and WeChat: Your phone number, email address, or WeChat account, and the messages and files you send. Messages sent through WeChat are also subject to WeChat's own terms and privacy policy.
- Website chat: The chat runs on our own chat server. It receives the messages you send and stores identifiers in your browser so a conversation can continue. If you are signed in to a dashboard account, the chat is linked to your name and email address.
How you first found us ("first touch"): On your first visit, our website stores a small record in your browser's local storage: the page you landed on, the website that referred you (without the part of its address after a "?"), any UTM campaign tags in the link, and the time of the visit. The record is kept for 90 days; after that, your next visit starts a new one. It stays in your browser unless you send a brief. A brief includes the landing page, the referring website, and the UTM tags from this record, together with the address of the page you opened the brief from and any UTM tags in the brief's own link, so that we know how you found us. You can remove the record at any time by clearing this website's data in your browser.
We use briefs and messages to reply to you and to do the work you ask about. If you leave an email address in a form, we send you a confirmation email. We do not add you to a newsletter, and we do not share briefs or messages outside Aibrify, except with the service providers that help us receive them and reply (see section 9).
We keep briefs and messages for as long as we need them to reply to you, to do any work that follows, and to keep business records. You can ask us to delete them at any time (see section 11).
3. Phone receptionist
Businesses use our phone receptionist to answer their calls. If you call a business that uses it, we process information about your call on behalf of that business. The business you are calling is responsible for your information, and we act as its service provider.
- What we process: Your phone number, a written transcript of the call and a summary of it, and details you give, such as an order, a booking, your name, or a callback number
- Why: To answer your call, take your order or booking or answer your question, transfer you when needed, and pass the call on to the business, for example as a summary
- Notice: Every call starts with a short spoken notice that the call is answered by an automated assistant and transcribed into text
- Who sees it: The business you called, which receives summaries, orders, bookings, and reports; Aibrify staff who set up and maintain the service; and the service providers that carry and process calls for us
- Service providers: Providers of telephony, speech and language processing, and text messaging (SMS)
- How long we keep it: We do not keep audio recordings of calls; calls are transcribed into text. Transcripts and summaries are deleted 90 days after the call, and within 30 days after the business stops using the phone receptionist, or sooner if the business asks
- Your choices: If you do not want your call transcribed, you can hang up and contact the business another way. To ask about, see, or delete information from a call, contact the business you called. You can also write to privacy@aibrify.com, and we will pass your request to that business and help it respond.
California: State law requires the consent of all parties before a confidential call is recorded. We treat transcribing a call the same way, so every call to the receptionist starts with the notice above. California residents also have the rights described in section 14; for information from a call, the business you called decides on those requests, and we help it respond.
4. How we use your information
We use collected information to:
- Provide, maintain, and improve our services
- Reply to briefs, messages, and support requests, and do the work you ask for
- Answer calls for businesses that use our phone receptionist and pass the calls on to them
- Publish content to your connected social media accounts
- Manage and optimize your advertising campaigns
- Generate AI-powered content and recommendations in dashboard features
- Aggregate and display analytics and insights
- Process payments and manage subscriptions
- Send service-related notifications and updates
- Understand how visitors find and use our website
- Detect and prevent fraud, abuse, and security issues
- Comply with legal obligations
5. AI and machine learning data processing
This section describes how we use data in connection with artificial intelligence (AI) and machine learning (ML) technologies in our dashboard features. The phone receptionist is described in section 3.
5.1 Use of AI services
Our dashboard features use AI and ML technologies provided by third-party AI service providers, including but not limited to:
- OpenAI (GPT models for text generation)
- Anthropic (Claude models for text generation and analysis)
- Other AI providers as we may add from time to time
When you use AI-powered features of the dashboard, including content generation, content optimization, and automated suggestions, your inputs (prompts, instructions, context information, and brand details you provide) may be transmitted to these third-party AI providers for processing.
5.2 Data transmitted to AI providers
When you use AI features, the following types of data may be processed by our AI providers:
- Content inputs: Text prompts, instructions, and requests you submit for content generation
- Context information: Business information, brand voice descriptions, industry details, and other context you provide to improve AI outputs
- Content for optimization: Existing content you submit for AI-powered editing, optimization, or analysis
- Feedback data: Your ratings, edits, and feedback on AI-generated content used to improve output quality
5.3 AI provider data handling
Our third-party AI providers process data according to their own policies:
- OpenAI: OpenAI's data usage policies are available at openai.com/policies. As a business customer, we use OpenAI's API services which, under OpenAI's current policies, means your data is not used to train OpenAI's models unless you opt in.
- Anthropic: Anthropic's data policies are available at anthropic.com/privacy. We use Anthropic's commercial API services under terms that restrict use of your data for model training.
WE ENCOURAGE YOU TO REVIEW THE PRIVACY POLICIES OF THESE AI PROVIDERS. While we have contractual agreements with these providers regarding data handling, we cannot guarantee their compliance.
5.4 AI model improvement and opt-out
- Aibrify's use: Aibrify may use aggregated, anonymized, or de-identified data derived from your use of AI features to improve our services, including training or fine-tuning AI models. This data is stripped of personally identifiable information before use.
- Opt-out option: You may opt out of having your data used to improve Aibrify's AI features by sending a request to privacy@aibrify.com with the subject line "AI Training Opt-Out."
- Third-party provider training: We use commercial API agreements that restrict our AI providers from using your data to train their general-purpose models. However, data retention and processing by AI providers are governed by their respective policies.
5.5 Limitations
You should not include sensitive personal information, protected health information, financial account numbers, government-issued identification numbers, or other highly confidential information in your AI prompts or content inputs. While we implement appropriate security measures, AI features are not designed for processing such sensitive data.
6. Data storage & security
6.1 Data storage
- Data is stored on our servers and with the service providers listed in section 9
- OAuth tokens are encrypted at rest
- Passwords are stored only as salted hashes (bcrypt)
- Media files are stored in Cloudflare R2 with CDN distribution
6.2 Security measures
- HTTPS encryption for all data in transit
- Two-factor authentication (2FA) available for dashboard accounts
- Access controls that limit who can see personal data
7. Data breach notification
7.1 Definition
A "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed in connection with the Services.
7.2 Detection and response
Aibrify maintains security monitoring systems and procedures designed to detect and investigate potential Personal Data Breaches. Upon detection or notification of a potential breach, we will:
- Promptly investigate the nature, scope, and cause of the incident
- Take immediate steps to contain the breach and prevent further unauthorized access
- Assess the types of data affected and the individuals potentially impacted
- Evaluate the potential risks and harms to affected individuals
7.3 Notification to affected users
If we determine that a Personal Data Breach has occurred that is reasonably likely to result in a risk to the rights and freedoms of affected individuals, we will notify you without undue delay:
- For EU/EEA users: Within seventy-two (72) hours of becoming aware of the breach, as required by GDPR Article 33, where feasible
- For US users: In accordance with applicable state breach notification laws, which generally require notification within thirty (30) to sixty (60) days
- For other jurisdictions: In accordance with applicable local data protection laws
7.4 Content of notification
Breach notifications will include, to the extent known:
- A description of the nature of the Personal Data Breach
- The name and contact details of our privacy team
- A description of the likely consequences of the breach
- A description of the measures taken to address the breach
- Recommendations for actions you can take to protect yourself
8. Information sharing
We do not sell your personal information. We share information only in these circumstances:
- With your consent: When you explicitly authorize sharing
- Service providers: Third parties who help us operate our services, such as hosting, payment processing, email delivery, telephony and messaging, and website analytics (see section 9)
- Social media platforms: To publish content and retrieve data as you've authorized
- Businesses you call: If you call a business that uses our phone receptionist, information from your call goes to that business (see section 3)
- Ad measurement: If you created a dashboard account after clicking one of our ads, a purchase you make in the dashboard may be reported to that ad platform (Google or Meta) with the ad's click identifier and, for Meta, a one-way hash of your email address, so that we can measure our ads
- Legal requirements: When required by law, legal process, or to protect our rights
- Business transfers: In connection with a merger, acquisition, or sale of assets
- Agency clients: If you're managed by an agency using our dashboard, your data is accessible to that agency
All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
9. Sub-processors and service providers
This section provides detailed information about the third-party sub-processors and service providers who may process your personal data.
9.1 Infrastructure and hosting
- Server hosting: Servers that run our website, dashboard and database, rented from a hosting provider - USA
- Amazon Web Services (AWS): Cloud computing for dashboard features such as video rendering - USA
- Cloudflare: CDN, DDoS protection, R2 storage - Global
9.2 Payment and billing
- Stripe, Inc.: Payment processing, subscription management - USA. Processes payment method details, billing address, transaction history.
9.3 AI and content services
- OpenAI, LLC: AI content generation, text optimization - USA. Processes content prompts, context information, generated outputs.
- Anthropic, PBC: AI content generation, analysis - USA. Processes content prompts, context information, generated outputs.
- Other AI model providers: Dashboard features may also use Google (Gemini and Imagen models), xAI (Grok models), and fal.ai (image models). Processes content prompts, context information, generated outputs.
9.4 Communications
- Resend: Transactional and marketing email delivery - USA. Processes email address, name, email content.
- Chatwoot: Customer support chat - Self-hosted. Processes support conversations, name, email.
- Phone and messaging providers: Telephony, speech and language processing, and SMS for our texting line and the phone receptionist. Process phone numbers, messages, the audio of calls while it is transcribed, and call transcripts and summaries.
- Slack: Internal notifications to our team, for example about sign-ups, payments, and errors. Processes the names and email addresses in those notifications.
9.5 Analytics and monitoring
- Google Analytics (through Google Tag Manager): Website analytics. Processes pages viewed, referring sites, device and browser information, and events such as sending a brief (see section 15).
- Internal analytics: Usage analytics - USA. Processes anonymized usage data, feature interactions.
9.6 Sub-processor agreements
We have entered into data processing agreements with each sub-processor that include:
- Obligations to process personal data only on our documented instructions
- Confidentiality obligations for personnel processing data
- Appropriate technical and organizational security measures
- Restrictions on engaging additional sub-processors without authorization
- Obligations to assist us in responding to data subject requests
- Obligations to delete or return data upon termination of services
10. Data retention
- Active accounts: Data is retained while your account is active
- Deleted accounts: When you ask us to delete your dashboard account, the account and its data are permanently deleted 30 days after your request. Cancelling a paid plan does not by itself delete your account
- Briefs and messages: Kept as described in section 2
- Phone receptionist: Kept as described in section 3
- Text messages: Kept as described in section 21
- Content: Published content may remain on third-party platforms even after account deletion
- Backups: Backup data may be retained for up to 90 days
- Legal requirements: Some data may be retained longer if required by law
11. Your rights & choices
11.1 Access & portability
You have the right to:
- Access your personal data through your account dashboard
- Export your data in machine-readable format (JSON/CSV)
- Request a copy of all data we hold about you
11.2 Correction & deletion
You can:
- Update your account information at any time
- Request correction of inaccurate data
- Request deletion of your account and associated data
- Disconnect any linked social media or advertising accounts
If you do not have a dashboard account, email privacy@aibrify.com to make any of these requests.
11.3 Marketing communications
You can:
- Opt out of marketing emails via unsubscribe links
- Manage notification preferences in your account settings
- Disable web push notifications through your browser
12. GDPR rights (EU/EEA users)
If you are in the European Union or European Economic Area, you have additional rights under GDPR:
- Right of access: Request a copy of your personal data
- Right to rectification: Request correction of inaccurate data
- Right to erasure: Request deletion of your data ("right to be forgotten")
- Right to restrict processing: Request limitation on how we use your data
- Right to data portability: Receive your data in a structured, machine-readable format
- Right to object: Object to processing based on legitimate interests
- Right to withdraw consent: Withdraw consent at any time
To exercise these rights, contact us at privacy@aibrify.com. We will respond within 30 days.
13. Automated decision making and profiling (GDPR Article 22)
This section provides information about our use of automated decision-making and profiling, as required by GDPR.
13.1 How we use automated processing
We use automated processing in the following ways:
- Content recommendations: Our AI systems analyze your content history, brand profile, and engagement data to suggest content ideas, optimal posting times, and content improvements. This profiling helps personalize your experience but does not produce legal effects.
- Fraud detection: We use automated systems to detect potentially fraudulent activity, abuse, or terms of service violations. Accounts may be temporarily suspended pending human review based on automated risk scoring.
- Subscription and billing: Automated systems process subscription renewals, failed payment retries, and usage-based billing calculations.
- Content moderation: AI systems may scan content for policy violations before publishing. Flagged content is typically subject to human review.
- Analytics and insights: Automated systems analyze your social media performance data to generate reports and recommendations.
13.2 Decisions with significant effects
We do NOT make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you, without human oversight, EXCEPT:
- Where the decision is necessary for entering into or performing a contract with you (e.g., automated subscription processing)
- Where the decision is authorized by law
- Where you have given explicit consent
13.3 Your rights
Under GDPR, you have the right to:
- Obtain information: Request meaningful information about the logic involved in automated decisions that significantly affect you
- Express your view: Contest automated decisions and express your point of view
- Obtain human review: Request that a human being review any automated decision that significantly affects you
- Opt out: Object to automated decision-making and profiling in certain circumstances
To exercise any of these rights or to request human review of an automated decision, contact us at privacy@aibrify.com with the subject line "Automated Decision Review Request."
14. CCPA rights (California residents)
If you are a California resident, you have additional rights under CCPA:
- Right to know: Request information about data collection, use, and sharing
- Right to delete: Request deletion of your personal information
- Right to opt-out: We do not sell personal information
- Right to non-discrimination: We will not discriminate against you for exercising your rights
To submit a CCPA request, contact us at privacy@aibrify.com or use the data export feature in your account settings. For information from a call to a business that uses our phone receptionist, see section 3.
15. Cookies, local storage & analytics
We use the following cookies and similar browser storage:
- Essential cookies: Keep you signed in to the dashboard and protect your account
- Preferences: Remember your language (a cookie) and display settings such as the theme (local storage)
- Campaign cookies: If you arrive through a link that carries UTM campaign tags or an ad click identifier (gclid or fbclid), we store those values in first-party cookies for 30 days
- First touch: The record of how you first found us, kept in local storage for 90 days (see section 2)
- Analytics: Google Tag Manager loads Google Analytics 4 after the page has loaded. Google Analytics sets its own cookies and receives information about your visit, such as the pages you view, the website that referred you, and your device and browser. We also send it an event when you use a way to contact us (sending a brief, tapping a text or email link, opening WeChat or the chat) and measurements of how fast pages load
- Chat: The website chat loads after you start using a page and stores identifiers in your browser so a conversation can continue
You can block or delete cookies and local storage in your browser settings, and you can stop Google Analytics from collecting data about your visits with Google's opt-out browser add-on (tools.google.com/dlpage/gaoptout). Blocking essential cookies may prevent you from signing in to the dashboard. Our website does not respond to browser "Do Not Track" signals.
16. Children's privacy
Our website and services are not intended for anyone under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
17. International data transfers
Your data may be transferred to and processed in the United States. We use appropriate safeguards for international transfers, including Standard Contractual Clauses for EU data transfers.
18. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified via email or in-app notification at least 30 days before taking effect. The "Last updated" date at the top indicates the most recent revision.
19. Contact us
For questions about this Privacy Policy or to exercise your rights, contact us at:
Email: privacy@aibrify.com
For EU residents, you also have the right to lodge a complaint with your local data protection authority.
20. Google API Services User Data Policy
Aibrify's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
20.1 How we use Google user data
We access Google user data through the following integrations:
- Google Sign-In: We request your email address and basic profile information (name, profile picture) solely to create and authenticate your Aibrify account. We do not use this data for any other purpose.
- Google Business Profile: We request access to your Google Business Profile to enable you to create and publish posts, read and reply to customer reviews, and view performance insights (impressions, clicks, direction requests) directly within our platform.
- YouTube: We request read-only access to your YouTube channel data to display channel analytics (views, watch time, subscriber counts), video performance metrics, and audience demographics within our analytics dashboard.
20.2 Limited Use disclosure
Notwithstanding anything else in this Privacy Policy, our use of data obtained through Google APIs is subject to the following restrictions:
- We only use Google user data to provide and improve the user-facing features that are prominent in our application's user interface.
- We do not transfer Google user data to third parties unless necessary to provide or improve user-facing features, to comply with applicable laws, or as part of a merger/acquisition/asset sale with prior user consent.
- We do not use Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
- We do not allow humans to read Google user data unless we have your affirmative agreement for specific messages, it is necessary for security purposes (such as investigating abuse), to comply with applicable law, or our use is limited to internal operations and the data has been aggregated and anonymized.
20.3 Data storage and security for Google data
- Google OAuth tokens are encrypted at rest. All Google user data is transmitted over HTTPS/TLS. Access to Google user data is restricted to the authenticated user and authorized team members within the same tenant.
- We retain Google user data only for as long as necessary to provide our services. When you disconnect a Google account from Aibrify, we delete the associated OAuth tokens and cached data within 30 days.
- You can revoke Aibrify's access to your Google data at any time by disconnecting your account in the Channels settings page or through your Google Account permissions page at myaccount.google.com/permissions.
21. Text messages (SMS)
We text only people who agreed to receive our texts, as our SMS Terms describe (aibrify.com/sms-terms): one confirmation after you call us and say yes, and our replies when you write back.
- What we collect: Your mobile number, the texts we exchange, and a record of your agreement: when and how you gave it, and when you opted out
- How we use it: Only to send the texts you agreed to receive, to reply to you, and to stop texting you when you opt out
- No sharing for marketing: We do not sell or share your SMS opt-in data or personal information with third parties for marketing purposes. We do not share, sell, or provide your mobile phone number or your text messaging opt-in data and consent to third parties or affiliates for marketing or promotional purposes.
- Frequency and costs: Message frequency varies. Message and data rates may apply.
- Your choices: Reply STOP to any of our texts to opt out, or HELP for help. You can also email support@aibrify.com.
- How long we keep it: As long as we need the texts to reply to you and to keep business records. We keep a record of your opt-out so that we do not text you again.