Privacy Policy
Last updated 1 September 2026
Who we are
LeadPilot ("we", "us") provides software that replies to a business's incoming sales enquiries by text message, qualifies them, and books appointments into that business's calendar. This policy explains what data we handle and why. Contact us at support@leadpilotone.com.
Two kinds of people in this policy
Businesses are our customers — they hold an account with us. Leads are the people who contact those businesses. We process a lead's information on behalf of the business they contacted; that business decides what happens with it.
What we collect
From businesses
- Account details: email address and password (stored hashed — we never see it)
- Business details you enter: name, phone, email, service area, services, hours, time zone
- Settings you configure, including the questions you want asked and your notification preferences
From leads
- Contact details submitted to the business: name, phone number, email address
- What they enquired about, and how they found the business
- The content of text messages exchanged with the assistant
- Appointment times booked
Automatically
- Usage records — how many messages and AI requests each account made, and their estimated cost
- IP addresses of requests to our lead-intake endpoint, used for rate limiting and abuse prevention
We do not use advertising trackers, and we do not sell data to anyone.
Google user data
If a business connects its Google Calendar, we request only two calendar permissions, deliberately the narrowest that do the job:
calendar.freebusy— lets us see when the calendar is busy. It does not reveal what the appointments are, who is attending, or any other detail. We use it to work out which times can be offered to a lead.calendar.events— lets us create, update and cancel appointments. We use it only for appointments booked through LeadPilot.
Access and refresh tokens are encrypted with AES-256-GCM before they are stored, using a key held outside the database. They are never sent to a browser and are never shared with anyone. A business can disconnect at any time from its settings page, which deletes our stored tokens and asks Google to revoke them.
LeadPilot's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to train generalised artificial intelligence or machine learning models, do not sell it, and do not transfer it except as needed to provide the service, comply with the law, or as part of a merger or acquisition.
Who else sees this data
We use the following providers to run the service. Each receives only what it needs.
| Provider | What it receives |
|---|---|
| Supabase | Hosts our database and accounts. Holds everything described above. |
| Vercel | Hosts the application. Processes requests; does not store your data. |
| OpenAI | Receives the conversation with a lead in order to write the next reply, along with the business details you configured. OpenAI states it does not train its models on API data. |
| Twilio | Sends and receives text messages. Receives the phone numbers and message content. |
| Calendar availability and the appointments we create, as described above. | |
| Resend | Sends notification and account emails. Receives the recipient address and message content. |
We do not sell personal information, and we do not share it for advertising.
How we protect it
- Each business's data is isolated at the database level, so one business cannot read another's
- Google tokens are encrypted before storage; API keys are stored only as a hash
- All traffic is encrypted in transit
- Passwords are hashed by our authentication provider and are never visible to us
No system is perfectly secure, and we do not claim otherwise. If we become aware of a breach affecting your data, we will tell you.
Text messages and opting out
A lead can stop messages at any time by replying STOP. We record the opt-out and no further messages are sent to that number — by the assistant or by the business — unless they reply START. Replying HELP returns a short message identifying the sender.
How long we keep it
We keep account and lead data for as long as the business's account is active. When an account is closed we delete its data within 30 days, except records we must keep for legal or accounting reasons. Usage and cost records are retained for billing accuracy.
Your rights
You can ask us for a copy of your data, ask us to correct it, or ask us to delete it. Businesses can export or delete most data from their dashboard. Leads should contact the business they enquired with, since that business controls their information — or write to us and we will pass the request on.
Email support@leadpilotone.com for any of the above.
Children
LeadPilot is a tool for businesses and is not directed at children. We do not knowingly collect information from anyone under 16.
Changes
If we change this policy we will update the date at the top, and tell account holders by email if the change is significant.