ProxyAI

Privacy Policy

Effective September 15, 2026

1. Overview

This Privacy Policy explains how PROXYAI ("ProxyAI," "we," "us") collects, uses, and protects information when you use our website and our AI chatbot platform (the "Service"), including conversations routed through connected channels such as Web Chat, WhatsApp, Telegram, LINE, and others.

2. Information We Collect

  • Account information: name, work email, company, and billing details you provide when you sign up.
  • Conversation data: messages exchanged between your customers and your ProxyAI-powered bots or agents, along with channel metadata (timestamps, channel type, delivery status).
  • Usage data: log data, device and browser information, and product analytics collected automatically as you use the dashboard.
  • Visitor analytics and contacts (only for customers who switch on the Sentry add-on): on that customer's website, the pages a visitor views, time on page, scroll depth, clicks on page elements, the referring page and campaign tags, and whether the visitor opened the chat. Each visit carries the chat widget's visitor id, kept in the browser's local storage (no cookies are set), so a visitor who chats can be linked to their conversation. Web addresses are stored without query strings or fragments. The customer also gets a contact list of the people who wrote to their bot on any channel: the identifier each messaging platform gives them, the name it shows, and any phone number or email they shared, used to recognise the same person across channels. We process this data on behalf of the customer, who is responsible for any notice or consent their visitors need and can delete a contact and their visits at any time. Raw visit data is deleted after 30 days, daily totals after one year, and contacts after 12 months without activity.

3. How We Use Information

We use collected information to operate and improve the Service, route and deliver conversations across connected channels, provide customer support, send account and billing notices, and detect and prevent abuse or security incidents.

We do not sell your data or your customers' conversation data to third parties.

4. Data Sharing

We share data with the messaging platforms you connect (e.g., Meta, Telegram, LINE) as required to deliver messages, with infrastructure and analytics subprocessors under contractual confidentiality obligations, and where required by law.

4a. Google User Data

This section covers data we receive when you sign in with Google or connect a Google service to ProxyAI.

What we access. Sign in with Google gives us your name, email address and profile picture, which we use to create and sign in to your account. A Google service is connected only when a workspace admin connects it from the dashboard, and each one asks for your consent separately:

  • Google Sheets and Google Drive: only the files you pick in the Google file picker.
  • YouTube: comments on your channel's videos, so your agents can read them and post the replies you set up.
  • Google Calendar: your availability and the events your agents create, such as appointments your customers book.
  • Google Ads: your campaigns and their performance, so your agents can report on them and make the changes you instruct, such as pausing a campaign or adjusting a budget.
  • Google Analytics: reports from your properties, the settings changes you instruct (such as key events, custom dimensions and who has access), and purchase or lead events your agents send from your orders.
  • Google Search Console: search performance, index status and sitemap submissions for your sites.
  • Google Business Profile: your business listings, including reviews and replies, posts, photos, hours and performance, and a notification when a new review arrives.

How we use it. We use Google user data only to perform the tasks you configure in ProxyAI and to show you their results in your dashboard. We do not sell it, use it for advertising, or use it to train generalised AI or machine-learning models. Our staff do not read it unless you ask us to (for example in a support request), it is needed for security or to comply with the law, or it has been aggregated and anonymised for internal operations.

Who we share it with. When a task uses an AI model, the data that task needs is sent to our AI model provider, OpenRouter, and the model provider it routes to, solely to perform that task. We do not transfer Google user data to anyone else except as necessary to comply with the law, to protect security, or as part of a merger or acquisition with notice to you.

How we store it. The access tokens Google issues are encrypted at rest. Task results are kept in your workspace's run log until you delete the agent or your workspace.

How to remove access. Disconnecting a Google service in the dashboard deletes our stored tokens. When it is the last Google service you have connected, we also revoke ProxyAI's access with Google. You can revoke access at any time at Google Account permissions.

ProxyAI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. Data Retention & Security

Conversation data is retained according to your workspace's retention setting (12 months by default) and can be exported or deleted on request. Data is encrypted in transit (TLS 1.2+) and at rest (AES-256).

6. Your Rights

Depending on your location, you may have the right to access, correct, export, or delete your personal information. Workspace admins can manage most of these requests directly from account settings; contact us for anything else.

7. Cookies

Our website and dashboard use cookies and similar technologies for authentication, preferences, and product analytics. You can control cookies through your browser settings.

Our public website also loads Google's tag (gtag.js) so we can measure which advertising brought someone to us, for example, that a visit which became a sign-up came from a Google Ads click. This sets Google advertising cookies on our public pages and shares the conversion event with Google Ads. It does not run inside the dashboard or the apps embedded in Shopify, Wix or WordPress, and it never carries your conversation data. You can opt out through Google's ad settings or your browser's cookie controls.

8. Children's Privacy

The Service is not directed to children under 16, and we do not knowingly collect personal information from them.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be announced via the dashboard or by email to workspace admins.

10. Contact Us

Questions about this policy can be sent to [email protected].