Privacy Policy
Last updated: August 6, 2026
1. Information We Collect
When you create a Simple AIManager account, we collect your email address, business name, and any other information you provide during signup. We also collect usage data including pages visited, features used, and interactions with our AI tools.
If you connect a third-party service such as Shopify, Facebook, Instagram, Google Calendar, Google Business Profile, or Google Drive (Docs), we collect the data necessary to provide our services, including store information, customer lists, and content performance metrics. We only access the minimum data required for the features you use.
2. How We Use Your Information
We use your information to provide, maintain, and improve our services. This includes generating AI content, scheduling social posts, sending cart recovery emails on your behalf, and providing analytics on your marketing performance.
We may also use your email address to send you product updates, billing notifications, and security alerts. You can opt out of non-essential communications at any time from your account settings.
3. Data Sharing
We do not sell your personal information. We share data only with service providers who help us operate our platform: our hosting provider (Vercel), database and authentication provider (Supabase), payment processor (Stripe), email delivery service (Resend), SMS delivery service (Twilio), background-job infrastructure (Inngest), session and cache infrastructure (Upstash), error-monitoring service (Sentry), mobile push and related services (Firebase), AI-observability service (Langfuse), and AI language model providers (OpenAI for AI features across Media, Cart, and OnBoard products, and Anthropic for Service AIManager's inbound-message classification and reply generation, the AI demo widget on the marketing site, and the AI Support Chat agent in the Portal product — see Section 4 (AI Processing) for details).
Each of these providers is bound by their own privacy policies and data processing agreements. We may also disclose information when required by law or to protect our legal rights.
SMS consent data is subject to an additional restriction — it is never shared with third parties or affiliates for marketing purposes. See Section 5 (SMS Messaging).
4. AI Processing
Simple AIManager uses two third-party AI providers, both based in the United States, to power AI features across our products: OpenAI and Anthropic. Between them these power content generation, business analysis, customer-engagement suggestions, image generation, message classification, and related features. Which provider processes your data depends on which product and feature you use — see Per-product AI use below.
Data transmitted to OpenAI
When you use an AI feature, the content you provide to that feature is transmitted to OpenAI for processing. This includes:
- Text content you enter into AI-powered tools (campaign drafts, brand descriptions, customer messages, business context, and similar inputs)
- Images you upload to image-related AI features
- Business and customer data you choose to include in AI feature inputs
We do not transmit your account password, payment details, or data unrelated to the specific AI feature you are using.
OpenAI data usage
OpenAI processes the transmitted content to generate responses, which are returned to you through our platform. Per OpenAI's API data usage policy effective March 1, 2023, content submitted through the OpenAI API is not used to train or improve OpenAI's models unless the API customer explicitly opts in to share data. Simple AIManager operates on OpenAI's default API path and does not opt in to sharing data for model training. By default, OpenAI retains API content for up to 30 days for abuse monitoring purposes, after which it is deleted, except where longer retention is required by law or is reasonably necessary to protect their services. See OpenAI's current API data usage policy at https://openai.com/policies/api-data-usage-policies/ for the most up-to-date details.
Anthropic data usage
Anthropic processes the transmitted content to generate responses, which are returned to you through our platform. Anthropic's Commercial Terms (effective June 17, 2025) state at Section B that “Anthropic may not train models on Customer Content from Services.” This is an unconditional prohibition — unlike OpenAI, there is no opt-in mechanism by which model training could be enabled.
As to retention, Anthropic's published policy (last updated July 1, 2026) states that it “automatically delete[s] inputs and outputs on our backend within 30 days of receipt or generation.” Content flagged by Anthropic's automated trust-and-safety systems is retained substantially longer — up to two years for the inputs and outputs themselves, and up to seven years for the associated classification scores. This is longer than the equivalent OpenAI retention described above, and we state it explicitly so the difference is not left to inference. Longer retention may also apply where required by law or to enforce Anthropic's usage policy.
See Anthropic's current commercial terms at https://www.anthropic.com/legal/commercial-terms and their data-retention policy at privacy.claude.com for the most up-to-date details.
Consent
AI processing requires your explicit consent. You provide consent when you create your account or when prompted via Simple AIManager. You can review, withdraw, or re-grant your consent at any time from Settings → AI Processing Consent.
Withdrawing consent disables AI features across all Simple AIManager products; non-AI features remain available. Consent withdrawal does not affect the lawfulness of processing based on consent before its withdrawal (GDPR Article 7(3)).
If we materially update this AI Processing disclosure, we will prompt you to re-consent before AI features remain available under the updated terms.
Per-product AI use
The following describes the AI features in each Simple AIManager product and the categories of data they process:
- Media AIManager: Campaign content generation, brand audit, business classification, social-media caption generation (Facebook, Instagram, Google Business Profile), hashtag suggestions, image generation, and bio-suggestion generation. Data processed: business description, brand voice settings, campaign drafts, optional uploaded images.
- Cart AIManager: Cart-recovery message generation, post-purchase message sequences, win-back campaign content, event follow-up content, referral nudge content, flash-sale announcement content, and campaign optimization suggestions. Data processed: store name, merchant business context, anonymized cart contents, product information.
- OnBoard AIManager: Customer intervention generation, template generation, customer nudges, ROI report drafts, and weekly digest generation. Data processed: customer profile data, onboarding flow context, engagement metrics.
- Service AIManager: Service AIManager uses Anthropic (Claude), not OpenAI, for both of its AI features: (1) classifying an inbound customer reply to decide how the conversation should be routed, and (2) generating the text of a reply to that customer. The model is Claude Sonnet by default, and Claude Opus where the associated estimate exceeds $5,000. Data processed: the customer's inbound message text, the conversation history for that thread, and shop context (shop name and contact details). Proactive first-contact messages are not AI-generated — they are rendered from fixed templates by our own code, with no AI provider involved, so the only messages an AI writes are replies to customers who have written to the shop first.
- Simple AIManager Portal: AI surfaces in the Portal product use Anthropic (Claude), a separate third-party AI provider from OpenAI. These surfaces are (1) the AI demo widget on the marketing site, which generates sample content (social media posts, cart-recovery messages) for prospective users evaluating Simple AIManager; and (2) the AI Support Chat agent that helps authenticated users get help across all Simple AIManager products. Data processed by the demo widget: prospective-user-supplied sample business context only (not associated with an authenticated account). Data processed by the AI Support Chat agent: user message content + authenticated session context. Both surfaces operate independently of the AI Processing consent that gates the products listed above.
International data transfers
Both OpenAI and Anthropic are based in the United States. If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with cross-border data transfer regulations, the transfer of your data to either provider for AI processing constitutes an international data transfer. We rely on each provider's data processing agreement and Standard Contractual Clauses (SCCs) for such transfers where applicable.
Your rights regarding AI processing
In addition to the general rights described in the Your Rights section, you have the right to:
- Withdraw consent to AI processing at any time (see Settings → AI Processing Consent)
- Request a record of your consent history (visible in Settings)
- Object to automated processing for direct-marketing purposes (GDPR Article 21)
5. SMS Messaging (Service AIManager)
Service AIManager lets a home-services business — a plumbing, HVAC, electrical or similar company, referred to here as “the shop” — send text messages to its own customers. The shop is the sender and holds the relationship with the recipient. Simple AIManager operates the platform that delivers those messages on the shop's behalf.
Phone numbers and where they come from.We do not collect phone numbers from consumers directly, and we do not purchase, rent, or scrape them. Every number in Service AIManager is supplied by the shop from its own customer records — imported from the shop's spreadsheet, synced from the shop's field-service software, or entered by the shop by hand.
How consent arises. Messages are sent on the basis of an existing business relationship: the recipient received service from the shop, or requested or received a quote from it. Shops agree, as a condition of using the product, that they will only load contacts with whom they have that relationship.
What the messages say.Shipped message templates are transactional — following up on a quote the shop already sent, or checking in after work the shop already performed. The first message a recipient receives always carries this disclosure: “Automated assistant from your service provider. Reply STOP to opt out.”
How to opt out.Reply STOP to any message. STOP, STOPALL, UNSUBSCRIBE, CANCEL, END, QUIT, REVOKE and OPTOUT are honoured at the carrier level by our messaging provider. In addition, our own system recognises plain-language requests that carrier keyword matching misses — such as “stop texting me”, “remove me”, or “no more” — and treats an ambiguous request as an opt-out rather than risk continuing to message someone who asked us to stop.
How opt-outs are enforced. An opt-out is recorded against that phone number, for that shop, on a suppression list, and every outbound message is checked against that list before it is sent. Opt-outs are recorded per channel, so opting out of text messages does not silently apply to email, and vice versa; email carries its own unsubscribe link. Opt-outs are permanent unless the recipient asks the shop to resume.
Message frequency and timing.Messages are sent only between 8:00 a.m. and 9:00 p.m. in the recipient's local time, capped at three messages per recipient in any fourteen-day period, followed by a ninety-day pause once that cap is reached. Recipients who reply are answered conversationally; frequency in an active conversation is driven by the recipient.
No sharing of SMS consent data. SMS opt-in data and consent are never shared with, sold to, or rented to third parties or affiliates for marketing purposes. Phone numbers and consent status are used solely to deliver messages the shop sends to its own customers, and are disclosed only to our SMS delivery provider (Twilio) for the technical purpose of transmitting those messages. This restriction applies notwithstanding anything in Section 3 (Data Sharing).
6. Google Services Integration
Simple AIManager offers optional integrations with Google services. If you connect a Google integration, we request access through Google's OAuth 2.0 authorization flow, limited to the specific data each feature requires.
Google Calendar — With your authorization, we access your Google Calendar availability (free/busy) to propose open appointment times, and create or manage calendar events to record confirmed bookings. We access only the data needed for scheduling; we do not read the contents of your existing calendar events beyond determining availability.
Google Business Profile — With your authorization, we access your Google Business Profile to read your business and location information and to publish posts on your behalf.
Google Drive (Google Docs) — With your authorization, we access documents you select from your Google Drive to ingest their content into your knowledge base, so that AI-generated responses can draw on your own materials. We access documents in read-only form.
What we store
For each connected Google integration, we store an encrypted authorization token that allows Simple AIManager to access the relevant Google service on your behalf. Tokens are encrypted at rest; we never store your Google account password. Where a feature ingests your content (Google Drive/Docs into your knowledge base), that content is stored only to provide the feature and is subject to the deletion terms below.
How we use it
We use Google user data solely to provide the features you enable. We do not sell it, use it for advertising, or use it to train or improve any machine-learning or AI models. We share it only with service providers who process it on our behalf to provide the feature you enabled — for example, our AI provider (see Section 4).
Deletion and disconnection
Where an integration offers an in-app disconnect, you can disconnect it at any time from your integration settings, which deletes the stored authorization token and any content ingested from that integration. You can also remove all of Simple AIManager's access to your Google data at any time from your Google Account permissions page, or by deleting your Simple AIManager account.
Limited Use
Simple AIManager's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace APIs (including Google Drive and Google Docs) will adhere to the Google User Data Policy, including the Limited Use requirements.
7. Your Rights
You have the right to access, correct, or delete your personal data at any time. You can export your data from the dashboard or request a full data export by contacting our support team.
If you are located in the European Economic Area, you have additional rights under the GDPR, including the right to data portability, the right to restrict processing, and the right to object to processing. To exercise any of these rights, contact us at the address below.
8. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us at privacy@simpleaimanager.com or through the support section of your dashboard.