What we collect, who processes it, and what we will and won't do with it. Where a claim needs a caveat to stay honest, we've written the caveat instead of dropping the claim.
This summary is here to be useful. The numbered sections below are the actual policy.
AI Partners, Inc., an Oregon corporation, provides an AI platform for growing businesses. This policy covers:
Our Terms of Service govern use of the platform. Where we act as a service provider processing data on a customer's behalf, that customer's own privacy practices also apply to their employees' data; see Section 12.
The platform has a companion policy with the full detail of our Google API scopes and handling, which Google requires us to publish for app verification: the App Privacy Policy. Nothing here contradicts it; that document is more specific about Google data.
You can read this entire site without giving us anything. We don't run analytics, advertising, or tracking scripts, and this site sets no cookies. Our hosting provider processes standard server request data (such as IP address and user agent) to serve pages and block abuse.
If you choose to use the contact form, we collect exactly what you type into it: your name, email address, company name, an optional website, and your message. It goes to Dave so he can reply to you. We don't add you to a mailing list, we don't put you into an automated sequence, and we don't share or sell it. Ask us at dave@ai-p.ai and we'll delete it.
When your company starts, we collect names, work email addresses, roles, and company details. Authentication runs through Supabase; passwords are hashed and we never see them in plain text. Payments run through Stripe — card numbers never touch our servers and we store only what we need to reconcile an invoice.
Messages with the assistant, documents you upload, your company's business context, agent configurations and run history, meeting recordings and their transcripts and notes, and anything else you and your team put in. We call this your workspace content.
Because we bill AI usage at published rates, we record each billable AI call: who ran it, which feature and model, how many units, and what it cost. This is what makes your itemized statement possible, and it's also how spend caps work.
Email, scheduled calls, and anything you send us when you report a problem — including screenshots you choose to attach.
We do not sell personal data, we don't share it for advertising or cross-context behavioral advertising, and we don't use your workspace content to train models of our own.
For customers in jurisdictions with a lawful-basis requirement such as the GDPR, we rely on: performance of our contract with you; our legitimate interests in securing and improving the service; your consent where we ask for it, such as connecting a Google account; and compliance with law.
The platform works by sending your inputs to third-party AI providers so they can generate the result you asked for. This is the part of a privacy policy where blanket claims are common and often not quite true, so here is the accurate version.
What we can state plainly: AI Partners does not train any model of its own on your data. We access AI providers through commercial and business API tiers, never consumer accounts.
Provider by provider, as of the effective date of this policy:
The current, dated record lives on our Security & trust page. We may change models and providers as the technology moves; when a change materially affects how your data is processed, we update that page and give notice.
We use third parties to provide infrastructure, AI models, and specific tools. They may process your data only to provide their service to us. The complete current list, grouped by what each one does, is maintained on our Security & trust page, and it is regenerated from an audit of every outbound network call in our codebase rather than from memory. In summary it covers platform infrastructure (Cloudflare, Supabase, GitHub, jsDelivr), AI model providers (Anthropic, OpenAI, Google, AssemblyAI, ElevenLabs, Voyage AI), your browser's own speech recognition for in-app note-taking, the third-party services behind individual apps (only the files or data you submit to them), web and SEO data services (Browserbase, Moz, SpyFu, Similarweb, InLinks, SerpAPI, Microsoft Bing Search, Google Search Console and PageSpeed Insights), and business operations (Stripe, Resend, Mailgun).
Several of these receive data only when you use the specific feature they power. If you need a signed data processing agreement, or the hosting regions for a particular provider for your own vendor review, write to us and we'll provide it.
The platform can record meetings and conversations, transcribe them, and generate notes. Audio is captured only when someone in your workspace deliberately starts a recording — nothing records automatically — and a recording indicator is shown while it runs.
Meeting audio is never retained. It is passed to our transcription provider and deleted from our systems as soon as the transcript is produced. Transcripts and notes are delivered into your workspace, where you control who can see them; we also keep a server-side copy of each transcript alongside its usage record, for billing and re-delivery.
Meeting-recorder transcription is performed by AssemblyAI and the notes are generated by Claude. Our in-app note-taker and the live dictation fallback instead use your browser's built-in speech recognition, which in most browsers means your audio is processed by your browser vendor under their terms rather than ours.
You can have any transcript exported or permanently deleted, including our server-side copy. Email dave@ai-p.ai and we will do it within 5 business days.
Consent is the customer's responsibility. Recording laws vary by state and country, and some require every participant's consent. Under our Terms of Service, the customer is responsible for giving notice and obtaining consent from the people in a recording. The first time someone records on a device, the meeting recorder shows a reminder to tell everyone present, and a recording indicator stays on screen while it runs. These are reminders for the person recording — the platform does not collect, record, or verify consent from participants, and using them doesn't move the legal obligation to us.
You can connect outside services — Gmail, Google Calendar, Google Search Console, property management systems, and others. Connecting anything is optional and is never required to sign in or use the core platform, and you can disconnect at any time.
We request the narrowest permissions that make each feature work, and OAuth tokens are held server-side, encrypted at rest, and never exposed to your browser. Full scope-by-scope detail is in the App Privacy Policy.
Google Limited Use disclosure. AI Partners' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to train generalized or large-language models, and we do not sell Google user data. Our staff do not read your connected Gmail, Calendar, or Search Console content except at your affirmative request, where necessary to investigate a security or abuse issue, or where required by law.
You can review or revoke access at any time in your Google Account permissions, or by disconnecting inside the platform, which revokes the grant and deletes the stored tokens and any cached data derived from that connection.
If we become aware of a breach affecting your data, we will notify you promptly with what we know and what we're doing about it.
Data is hosted by Cloudflare and Supabase and processed by the providers in Section 5. For specific hosting regions, ask us.
Whatever your location, you can ask us to: access the personal data we hold about you; correct it; delete it; export your company's data; or stop a particular use. Some of this is self-serve in the product and some is not yet — either way, email dave@ai-p.ai and a human will handle it, normally within 5 business days. We will not refuse a deletion or export request on the grounds that a self-serve control doesn't exist.
If you're in California, you have rights to know, delete, and correct personal information, to receive it in a portable form, and not to be discriminated against for exercising them. We do not sell personal information and we do not share it for cross-context behavioral advertising, so there is no opt-out to offer you.
If you're in the UK, EU, or a similar regime, you also have rights of access, rectification, erasure, restriction, portability, and objection, and you may withdraw consent where we relied on it. You may lodge a complaint with your supervisory authority, though we'd appreciate the chance to fix it first.
We don't use your data for automated decision-making that produces legal effects about you. The platform produces AI output for people to review; under our Terms, decisions that affect individuals require a qualified human.
This marketing site sets no cookies and loads no analytics, advertising, or tracking scripts. There is no consent banner because there is nothing to consent to.
The platform itself uses essential browser storage — a sign-in session and your interface preferences. That's functional, not tracking: it isn't shared with advertisers and isn't used to profile you. We don't use third-party advertising or cross-site tracking anywhere.
When your employer subscribes, we process your workspace content on their behalf and under their instructions. Practically, that means: your employer controls the workspace, including who has which role, what agents run, whether recording is used, and what happens to content when someone leaves. Administrators at your company may have access to billing, usage, and governance views, and to content according to the roles they've configured.
Your assistant's private memory is scoped to you rather than shared across your company by default. If you have a question about what your employer can see, ask them first — they set those controls — and we'll help them answer it. If you want to exercise a privacy right and aren't sure who to ask, write to us and we'll point you to the right party and, where we're permitted, act ourselves.
The platform is for business use and isn't directed to children under 13. We don't knowingly collect their personal information. If you believe a child has given us data, tell us and we'll delete it.
We're based in the United States and our providers may process data in the United States and other countries. If you're outside the US, using the platform involves transferring your data to the US, where privacy laws differ from your own. Where a transfer mechanism such as the EU Standard Contractual Clauses is required, we'll put one in place as part of a data processing agreement — write to us.
We may update this policy. We'll change the effective date and version at the top and post the new version here. For changes that materially affect how we handle your data, we'll give you at least 30 days' notice by email to your account contact or in the product. We'd rather tell you than have you discover it.
Questions, requests, a privacy right to exercise, or a vendor review to complete: dave@ai-p.ai, or AI Partners, Inc., Portland, Oregon. A human reads it.
For platform-specific and Google-scope questions, the App Privacy Policy has the deeper detail, and support is at support@pmaipartners.ai.