Skip to content
AIsistants

Privacy policy

AIsistants, Inc. Last updated: September 2026.

This policy explains what information we collect, why, who sees it, and how you stay in control. We wrote it to be read, not skimmed. If anything is unclear, email us at hello@aisistants.com.

"We" means AIsistants, Inc. "You" means the client. "Assistant" means the human executive assistant we assign to you. "AI" means the private AI agent we set up for you.

1. What we collect

Account information

Your name, business name, email, phone, billing address, and the messaging app you pick for your group chat.

Billing

We use a payment processor to charge your card. We do not store your full card number. We keep records of what you paid and when.

Communications

Messages in your group chat, texts and call logs on your provisioned phone number, emails between you and us, and notes your assistant keeps to do their job. Call recordings only if you turn that feature on.

Connected accounts

When you connect a tool (email, calendar, CRM, booking, accounting, or others), your assistant and your AI can read and, if you allow it, write to that account. What they can see depends on the permissions you grant. We ask for the smallest set of permissions that gets the job done.

Examples of what this can include: email contents and attachments, calendar events and invitees, contacts, files you share, and customer records.

We do not ask for your passwords. We connect through the tool's official login (such as "Sign in with Google") or an access token you control.

Technical data

Log data from our systems: timestamps, which actions the AI took, error reports, and device or browser data from our website. We use this to run and secure the service.

What we do not collect

We do not collect biometric data. We do not collect data from your customers except what comes to us through your accounts or your phone number in the course of doing your work.

2. How we use it

  • To do the work you ask for.
  • To set up and run your AI agent.
  • To bill you and support you.
  • To keep the service safe (fraud checks, abuse detection, access logs).
  • To improve the service. This means fixing bugs and improving our processes, not training AI models on your data.
  • To meet legal duties.

We do not sell your data. We do not use it for advertising. We do not share one client's data with another client.

3. How the AI handles your data

Your AI agent runs on Claude models from Anthropic. When your AI reads an email or drafts a reply, that content is sent to Anthropic's API to be processed.

Here is what Anthropic's commercial terms say, as of the date above:

  • No training. Anthropic's Commercial Terms of Service state that Anthropic may not train models on customer content from its commercial services. Anthropic's API documentation also states that retained data is never used for model training without the customer's express permission.
  • Short retention. By default, Anthropic deletes API inputs and outputs from its backend within 30 days, unless longer retention is required by law or to enforce its usage policy.
  • Zero data retention. Anthropic offers a zero-data-retention arrangement for approved organizations, under which it does not store prompts or responses at rest after the response is returned.

Sources: Anthropic Commercial Terms of Service; Anthropic "API and data retention" documentation (platform.claude.com/docs/en/manage-claude/api-and-data-retention); Anthropic Privacy Center.

Your AI instance is separate from every other client's. It does not share memory, prompts, or data across clients.

4. Who we share data with (subprocessors)

We share data only with vendors that help us run the service. Each one is bound by a contract that limits what they can do with it.

VendorWhat they doWhat they see
AnthropicRuns the AI modelContent the AI processes (emails, messages, documents you connect)
Amazon Web Services (AWS)Hosts our systemsEncrypted data at rest and in transit
TwilioYour US phone number, calls, SMSPhone numbers, call metadata, message contents, recordings if enabled
Calendar or booking toolScheduling calls with usName, email, chosen time.
Payment processorBillingCard details (held by them, not us), billing address.
Messaging platforms (Apple iMessage, Telegram, Signal, SMS carriers)Your group chatChat contents pass through the platform you chose, under that platform's own privacy terms
Your connected tools (Google, Microsoft, and others)Your email, calendar, filesGoverned by their terms; we access only what you permit

We will update this list when a vendor changes.

Beyond these vendors we share data only:

  • When you tell us to (for example, sending a quote to your customer).
  • When the law requires it, such as a valid subpoena. We will tell you if we are allowed to.
  • If we sell the company. The buyer would have to honor this policy.

5. Who at AIsistants can see your data

  • Your assistant. Sees what you connect and what you share. Nobody else's client data.
  • A backup assistant. Only when your assistant is out, and only for that time.
  • A small support and engineering team. Only when needed to fix a problem or set up a tool, and access is logged.
  • Nobody else.

All staff sign confidentiality agreements. Assistants pass a background check and drug test before they start. Access is removed the same day someone leaves or is reassigned.

6. You are in control

  • Choose what to connect. Nothing is connected until you say so. You can connect one tool, or ten, or none.
  • Set the scope. For each tool, you choose read-only or read-and-write where the tool supports it.
  • Revoke anytime. Disconnect a tool from your dashboard, or tell your assistant, or revoke it inside the tool itself (for example, in your Google account's security settings). Access ends right away.
  • Opt in or out of AI processing per tool. You can let your assistant use a tool but keep the AI out of it. Tell us and we will set it that way.
  • Get your data. Ask and we will give you a copy of your work product and chat history.
  • Delete it. Ask and we will delete your data on the schedule below.

7. How long we keep data

DataKept for
Account and billing recordsAs long as you are a client, plus 7 years for tax and legal rules
Group chat history, notes, work productWhile you are a client, plus 30 days after you cancel so you can export it. Then deleted.
Connected account accessEnds the day you cancel or disconnect. We do not keep copies of your inbox or calendar.
AI processing logs90 days, then deleted.
Call recordings (if enabled)90 days unless you ask us to keep or delete sooner.
Phone numberReleased or ported 30 days after you cancel
BackupsEncrypted backups roll off within 35 days

8. How we protect it

  • Encryption in transit (TLS) and at rest (AES-256 or equivalent) on AWS.
  • Each client's AI runs in its own isolated environment. No shared memory across clients.
  • Least privilege: assistants and systems get only the access they need.
  • Two-factor login required for all staff and assistants.
  • Managed, monitored work devices for assistants. No client data on personal devices.
  • Access logs for every connected account and AI action.
  • Regular security review. We will publish audit or certification status on our Security page as we complete it.

No system is perfect. If we ever have a breach that affects your data, we will tell you without undue delay and within the time the law requires.

9. Your rights under California law (CCPA/CPRA)

If you are a California resident, you have the right to:

  • Know what personal information we collect and how we use and share it.
  • Access a copy of it.
  • Delete it, with some legal exceptions.
  • Correct it if it is wrong.
  • Opt out of sale or sharing. We do not sell or share personal information for advertising, so there is nothing to opt out of.
  • Limit use of sensitive personal information. We use sensitive information only to provide the service.
  • Not be discriminated against for using these rights.

To use these rights, email hello@aisistants.com. We will confirm your identity and respond within 45 days. You can name someone to act for you.

10. Where data lives

Our systems run in the United States on AWS. Your assistant works from the Philippines and accesses your data over encrypted connections to systems in the US.

11. Children

The service is for businesses. We do not knowingly collect data from anyone under 18.

12. Changes to this policy

If we change this policy in a way that matters, we will email you at least 30 days before the change takes effect. The date at the top always shows the current version.

13. Contact

AIsistants, Inc. hello@aisistants.com