Privacy Policy

1.Introduction

LifePilot AI ("we", "us", or "our") operates the LifePilot AI platform accessible at lifepilotai.co and through our mobile applications (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

By accessing or using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with the terms of this policy, please do not access or use the Service. This policy applies to all users of the Service, including individuals, business workspace administrators, and organization members.

Please read this Privacy Policy carefully. For questions about your personal data or this policy, contact us at privacy@lifepilotai.co.

2.Information We Collect

We collect information you provide directly to us, information generated by your use of the Service, and information from third-party integrations you choose to connect.

2.1 Account Information

When you create a LifePilot AI account, we collect your full name, email address, and phone number. Business workspace administrators additionally provide organization name, business type, and other workspace configuration details. This information is required to create and maintain your account and deliver the Service.

2.2 Authentication Credentials

We collect and store authentication credentials, including hashed passwords and OAuth tokens issued by third-party identity providers such as Google. We never store your plaintext password. Third-party authentication tokens are stored securely and used only to maintain your authenticated session with the connected provider.

2.3 Business Workspace Data and Organization Settings

If you use LifePilot AI as part of a business workspace, we collect information about your organization, including workspace configuration, team member roles and permissions, integration settings, and organization-level preferences. Workspace administrators control much of this data and are responsible for how it is configured within their organization.

2.4 AI Chat Interactions and Conversation History

When you use the AI chat features of the Service, we collect the content of your messages, the AI's responses, and associated metadata such as timestamps and session identifiers. This conversation history is used to deliver the Service, provide context for ongoing interactions, and improve AI response quality. You may delete your conversation history at any time from your account settings.

2.5 Call Recordings and Transcripts

Where you enable AI-assisted calling, we collect recordings of phone calls made on your behalf, along with machine-generated transcripts and call summaries. Call recordings are stored securely and are accessible only to you and, where applicable, designated members of your business workspace. Recording of phone calls may be subject to applicable laws requiring consent from all parties; you are responsible for ensuring compliance with such laws in your jurisdiction.

2.6 Uploaded Files and User-Generated Content

You may upload files, documents, images, and other content to the Service for processing, storage, or use in AI workflows. We collect and store this content to deliver the features you request. You retain ownership of all content you upload, and we process it solely as directed by you.

Bank statements uploaded for Spend Audit (subscription/recurring-charge detection): When you upload a bank or credit card statement as an image or PDF (rather than a CSV export), the entire page image is sent to OpenAI's API to extract transactions. We do not currently crop, mask, or otherwise redact any part of the document before sending it — this means information that may appear on the page alongside the transaction table, such as your account number, routing number, name, address, and balance, is included in what is transmitted to OpenAI, even though only the transaction data (date, merchant, amount) is actually used or retained by LifePilot AI. OpenAI processes this content under the API data-usage terms referenced in Section 5 (AI Processing) — it is not used to train OpenAI's models and is retained by OpenAI only for a limited abuse-monitoring period before deletion. If you would prefer not to transmit this information, you can upload a CSV export of your statement instead, which is parsed locally and never sent to any AI provider, or manually crop the image yourself before uploading to remove any information you do not want to include.

2.7 Payment Information

All payment transactions are processed by Stripe, our third-party payment processor. We do not collect, store, or have access to your full credit card number, CVV, or bank account details. We receive from Stripe only a token representing your payment method, along with billing details such as your name, billing address, and the last four digits of your card. Stripe's handling of your payment information is governed by Stripe's Privacy Policy.

2.8 Usage Data and Analytics

We automatically collect information about how you interact with the Service, including pages visited, features used, actions taken, session duration, error events, and performance metrics. This data helps us understand usage patterns, diagnose issues, and improve the Service. It is collected in aggregate form where possible and is associated with your account for troubleshooting and service improvement purposes.

2.9 Cookies and Similar Tracking Technologies

We use cookies and similar tracking technologies to operate the Service, maintain your session, remember your preferences, and analyze usage. See Section 9 (Cookies) for full details on what types of cookies we use and how to manage them.

2.10 WhatsApp Business Messages and Metadata

When you enable the WhatsApp Business integration, we collect the content of messages sent and received through the WhatsApp Business Platform API, including message text, media attachments, sender and recipient identifiers, and message timestamps. We also collect metadata about your WhatsApp Business account, including your phone number ID, business account ID, and messaging templates. This data is used solely to operate the integration and deliver messages on your behalf.

2.11 Meta Platform Data

When you connect Meta integrations (Facebook Pages, Instagram Business accounts, Messenger), we collect data made available through the Meta Marketing API and Meta Graph API, including account identifiers, page access tokens, post and comment content, message threads, and engagement metrics. The specific data collected depends on the permissions you grant when connecting your Meta accounts. You can revoke these permissions at any time through your Meta account settings or through the LifePilot AI integrations panel.

3.How We Use Your Information

We use the information we collect for the following purposes:

  • Service Delivery: To operate, maintain, and provide the features and functionality of the Service, including processing your AI requests, executing calls on your behalf, managing tasks, and delivering messages through connected integrations.
  • AI Personalization: To personalize and improve AI responses based on your conversation history, preferences, workspace context, and usage patterns. This helps the AI better understand your needs and deliver more accurate, relevant assistance over time.
  • Billing and Payments: To process subscription payments, manage your billing plan, issue invoices, handle refunds, and communicate about billing matters in connection with your account.
  • Communications: To send you transactional communications including account confirmations, security alerts, call summaries, task updates, and Service announcements. With your consent, we may also send marketing communications about new features and offerings. You may opt out of marketing communications at any time.
  • Security and Fraud Prevention: To detect, investigate, and prevent fraudulent transactions, unauthorized access, and other malicious or illegal activity. This includes monitoring for abuse of our platform, enforcing our Terms of Service, and protecting the security of user accounts.
  • Service Improvement: To analyze aggregate usage data, identify bugs and performance issues, develop new features, and improve the overall quality of the Service. Where we use your data to train or fine-tune AI models, we will do so only with appropriate anonymization or your explicit consent.
  • Legal Compliance: To comply with applicable laws, regulations, legal processes, or governmental requests, and to enforce our agreements, terms, and policies.

4.WhatsApp Business & Meta Integrations

LifePilot AI offers integrations with the WhatsApp Business Platform and Meta platforms (Facebook, Instagram, and Messenger). This section describes how we handle data in connection with these integrations.

4.1 WhatsApp Business Platform

Our WhatsApp integration is built on the WhatsApp Business Platform API provided by Meta Platforms, Inc. When you enable this integration, LifePilot AI acts as a Business Solution Provider (BSP) to send and receive WhatsApp messages on your behalf. Message content, delivery status, and associated metadata are processed by both LifePilot AI and Meta in accordance with the WhatsApp Business Data Processing Terms. You are responsible for obtaining any required consents from your end users before messaging them through the WhatsApp Business Platform.

4.2 Meta Marketing API

When you connect a Facebook Page or Instagram Business account, LifePilot AI uses the Meta Marketing API and Meta Graph API to read and post content, manage messages, and retrieve analytics on your behalf. Access tokens used for this purpose are stored securely and used exclusively to perform actions you authorize. Meta's collection and use of data through its APIs is governed by Meta's Privacy Policy.

4.3 Data Handling for Connected Meta Accounts

Data retrieved from Meta platforms is used only to operate the integrations you have enabled. We do not sell, share, or use Meta platform data for advertising or profiling purposes. You may disconnect any Meta integration at any time through the LifePilot AI integrations panel, which will revoke our access and stop further data collection from those accounts. Upon disconnection, Meta platform data associated with that integration will be deleted from our systems within 30 days, except where retention is required by applicable law.

5.Third-Party Service Providers

We work with carefully selected third-party service providers to operate the Service. These providers have access to your information only to the extent necessary to perform their functions and are contractually obligated to protect it.

Vercel

Hosting & Edge Infrastructure

Our web application and API are hosted on Vercel's cloud infrastructure. Vercel processes request data, including IP addresses and request logs, to serve the application and provide DDoS protection and performance optimization.

View Privacy Policy →

Supabase

Database & Authentication

Supabase provides our primary database, row-level security, real-time subscriptions, and authentication services. Your account data, conversation history, call records, and workspace data are stored in Supabase-managed PostgreSQL databases with encryption at rest.

View Privacy Policy →

OpenAI

AI Processing

AI chat, voice transcription, and content generation features are powered by OpenAI's API. Your messages and uploaded content sent to AI features are processed by OpenAI subject to their API data usage policies. We use OpenAI's zero-data-retention API settings where available.

View Privacy Policy →

Meta / WhatsApp

Messaging Integrations

When you enable WhatsApp Business, Facebook, Instagram, or Messenger integrations, Meta Platforms, Inc. processes messages and account data through their APIs. See Section 4 for full details on Meta integration data handling.

View Privacy Policy →

Stripe

Payment Processing

All payment card transactions are processed by Stripe, Inc. Stripe is a PCI DSS Level 1 certified payment processor. We share only the minimum information necessary to process your payments. We do not store your full payment card details.

View Privacy Policy →

Google

Gmail Integration

When you connect a Gmail account to LifePilot AI, we use Google OAuth 2.0 to send, read, and manage email on your behalf. We do not use Google Sign-In for account authentication and do not integrate Google Analytics. Gmail connection data is used solely to operate the email integration you have enabled.

View Privacy Policy →

6.Data Security

We take the security of your data seriously and implement a range of technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction.

6.1 Encryption in Transit

All data transmitted between your device and our Service is encrypted using Transport Layer Security (TLS 1.2 or higher). This includes API requests, file uploads, and real-time connections. We enforce HTTPS across all endpoints and reject unencrypted connections.

6.2 Encryption at Rest

Data stored in our databases and storage systems is encrypted at rest using AES-256 encryption. Call recordings, uploaded files, and other sensitive content stored in Supabase Storage are encrypted at the storage layer. Database backups are also encrypted.

6.3 Access Controls

Access to your data is restricted on a need-to-know basis. Our internal systems use role-based access controls, and database access employs row-level security policies to enforce user and workspace data isolation. Production systems are accessible only to authorized personnel through multi-factor authenticated connections.

6.4 Security Practices

We conduct regular security reviews of our application and infrastructure. Third-party service providers are evaluated for their security posture before integration. Despite our efforts, no method of transmission over the Internet or electronic storage is 100% secure. If you become aware of a security vulnerability or incident, please report it to security@lifepilotai.co.

7.Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service. Specific retention periods vary by data type:

  • Account Data: Retained for the duration of your account. Upon account deletion, account data is permanently deleted within 30 days, except where retention is required by law.
  • Conversation History: Retained for the duration of your account or until you delete individual conversations. You may clear your conversation history at any time from account settings.
  • Call Recordings and Transcripts: Retained for 12 months by default, after which they are automatically deleted. You may delete individual recordings at any time. Business workspace administrators may configure custom retention policies within their workspace settings.
  • Uploaded Bank Statements and Spend Audit Data: The original uploaded file (a bank statement PDF, image, or CSV export) is automatically deleted from storage 90 days after upload, regardless of whether extraction succeeded. Transactions and recurring-charge findings extracted from your statements are retained separately, for as long as your account or workspace remains active, so we can continue detecting recurring charges across your upload history. In a business workspace, this data belongs to the workspace, not the individual member who uploaded it — removing a member from a workspace does not delete data they contributed.
  • Payment Records: Billing records and transaction history are retained for 7 years to comply with applicable tax and financial reporting obligations.
  • Usage and Analytics Data: Aggregate usage analytics are retained for up to 24 months. Event-level data linked to your account is retained for 12 months.
  • Legal Hold: Notwithstanding the above, we may retain data for longer periods where necessary to comply with applicable laws, resolve disputes, enforce our agreements, or respond to legal process. In such cases, retained data will remain subject to the security protections described in this policy.

To request deletion of your account and associated data, please visit our Data Deletion page or contact us at privacy@lifepilotai.co.

8.Your Rights

Depending on your location, you may have the following rights with respect to your personal information. We honor these rights for all users regardless of jurisdiction.

  • Right of Access: You have the right to request a copy of the personal information we hold about you. You can export much of your data directly from your account settings. For a comprehensive data export, contact us at privacy@lifepilotai.co.
  • Right to Correction: You have the right to request correction of inaccurate or incomplete personal information. You can update most account information directly in your account settings. For information you cannot update yourself, contact support.
  • Right to Deletion: You have the right to request deletion of your personal information. You can delete your account and associated data at any time. Visit our Data Deletion page to submit a deletion request.
  • Right to Data Portability: You have the right to receive your personal information in a structured, machine-readable format. Contact us to request a portable export of your data.
  • Right to Opt Out of Marketing: You may opt out of marketing communications at any time by clicking the "unsubscribe" link in any marketing email, or by updating your notification preferences in account settings. Opting out of marketing does not affect transactional communications related to your account.
  • Right to Restrict Processing: In certain circumstances, you may have the right to restrict how we process your personal information. Contact us to discuss your specific situation.

To exercise any of these rights, contact us at privacy@lifepilotai.co or support@lifepilotai.co. We will respond to your request within 30 days. We may need to verify your identity before processing certain requests.

9.Cookies

We use cookies and similar technologies (such as local storage and session storage) to operate the Service and improve your experience. This section describes the types of cookies we use and how to manage them.

9.1 Essential Cookies

These cookies are strictly necessary to provide the Service and cannot be disabled. They include session authentication tokens, CSRF protection tokens, and cookies required for security and basic functionality. Without these cookies, the Service cannot operate correctly.

9.2 Analytics Cookies

We use analytics cookies to understand how users interact with the Service, including which pages are most visited, how users navigate between features, and where errors occur. This data is collected in aggregate and used to improve the Service. We use Vercel Analytics and Vercel Speed Insights, which collect privacy-friendly, aggregated usage data without storing personally identifiable information or setting third-party tracking cookies.

9.3 Preference Cookies

Preference cookies remember your settings and choices, such as your display theme (light or dark mode), language preferences, and notification settings. These cookies enhance your experience by preserving your choices between sessions.

9.4 How to Opt Out

You can control cookies through your browser settings. Most browsers allow you to block or delete cookies, though doing so may affect the functionality of the Service. You may also update your cookie preferences through your account settings. For more information about Vercel Analytics data practices, see Vercel's Analytics Privacy documentation.

10.Children's Privacy

The Service is not directed to, and we do not knowingly collect personal information from, children under the age of 13. If you are under 13 years of age, please do not use or access the Service or provide any personal information to us.

If we learn that we have collected personal information from a child under age 13 without verification of parental consent, we will take steps to delete that information as quickly as possible. If you believe we might have information from or about a child under 13, please contact us at privacy@lifepilotai.co.

11.International Data Transfers

LifePilot AI is based in the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States, where our infrastructure and many of our third-party service providers operate.

The United States may not have data protection laws equivalent to those in your home country. By using the Service, you consent to the transfer of your information to the United States. We take steps to ensure that your information receives an adequate level of protection wherever it is processed, including entering into appropriate data processing agreements with our service providers that incorporate standard contractual clauses or other approved transfer mechanisms.

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland and have concerns about international data transfers, please contact us at privacy@lifepilotai.co.

12.Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes to this policy, we will notify you by:

  • Sending a notice to the email address associated with your account, and/or
  • Displaying a prominent notice within the Service prior to the change becoming effective.

The updated policy will be posted on this page with a revised effective date. We encourage you to review this Privacy Policy periodically. Your continued use of the Service after any changes to this policy constitutes your acceptance of the updated terms. If you do not agree with the updated policy, you must discontinue use of the Service.

13.Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your personal information, please contact us:

Privacy inquiriesprivacy@lifepilotai.co
General supportsupport@lifepilotai.co
Data deletion requestslifepilotai.co/data-deletion

We aim to respond to all privacy-related inquiries within 5 business days and will acknowledge data subject requests within 30 days.