PAIBack

PAI

Privacy Policy

Effective Date: September 3, 2026

This Privacy Policy explains how PAI LC, doing business as PAI (Personal AI Assistant), collects, uses, discloses, retains, and protects information when you use our website, SMS-based assistant service, account features, calendar integrations, reminders, shopping lists, subscriptions, and related services (the “Service”).

1. Information We Collect

We collect information needed to provide, operate, protect, and improve PAI.

This may include information you provide, SMS information, calendar information, reminder information, shopping list information, account information, payment-related information, device and usage information, cookies, analytics information, and information from connected services.

2. Information You Provide

You may provide information such as your name, email address, phone number, account credentials, preferences, support requests, feedback, subscription selections, and other information you choose to share.

You may also provide the text of messages, instructions, reminders, calendar requests, shopping list items, and other content you send to PAI.

3. SMS Information

Because PAI is a text-message-based assistant, we collect and process SMS-related information.

This may include your phone number, message content, message metadata, timestamps, delivery status, opt-in and opt-out status, carrier information, and records needed to operate and troubleshoot messaging. Linq, our messaging delivery provider, processes information needed to transmit and manage service messages.

Mobile numbers and SMS consent information are not sold or shared with third parties for their marketing or promotional purposes.

4. Calendar Information

If you connect Google Calendar or Microsoft Outlook Calendar, we collect and process calendar information needed to provide the features you request.

Calendar information may include the connected account and calendar identifier, event identifier, title, description, date, time, time zone, location, attendees, recurrence and status information, conferencing or meeting-link information, and availability derived from event times. We also process OAuth access and refresh tokens and related permission and expiration information needed to keep the connection working.

PAI limits Google calendar use to events on your primary Google Calendar and Microsoft calendar use to events on your default Outlook calendar. We use calendar data only for the user-facing calendar functions described in Section 12. We do not sell Google or Microsoft calendar data or use it for advertising.

5. Reminder Information

We collect and process reminder information so PAI can create, retrieve, update, delete, and send reminders.

Reminder information may include reminder text, dates, times, recurrence settings, completion status, related message history, and delivery history.

6. Shopping List Information

We collect and process shopping list information so PAI can create, retrieve, update, and delete shopping lists or similar lists.

Shopping list information may include item names, quantities, categories, notes, completion status, and related message history.

7. Usage Information

We may collect information about how you interact with PAI, including pages viewed, features used, message activity, settings, clicks, timestamps, logs, device information, browser type, IP address, approximate location from IP address, error reports, and diagnostic information.

We use this information to operate the Service, understand performance, troubleshoot problems, prevent abuse, and improve features.

8. Cookies and Analytics

Our website may use cookies, local storage, pixels, or similar technologies to keep the site working, remember preferences, understand usage, measure performance, and improve the Service.

We may use analytics providers to help us understand how people use the website and Service. You can control cookies through your browser settings, but some features may not work properly if cookies are disabled.

9. How We Use Information

We use information to provide, operate, maintain, secure, and improve PAI.

This includes responding to messages, generating assistant responses, creating and managing reminders, managing calendar events, maintaining shopping lists, sending SMS messages, handling subscriptions, providing support, debugging issues, preventing fraud and abuse, enforcing our Terms, complying with law, and communicating with you.

We may also use aggregated or de-identified information for analytics, research, and product improvement. We do not use raw or derived connected-calendar data for advertising, marketing, determining creditworthiness, or training generalized AI or machine-learning models.

10. AI Processing

User-origin messages and related context may be processed by OpenAI to understand requests, generate responses, and perform assistant tasks. Depending on your request, the information sent may include selected user-origin message history, reminders, shopping list information, and account settings needed to complete the task. Raw or derived information obtained from Google APIs is not sent to OpenAI.

PAI minimizes the information sent for AI processing. PAI does not send OAuth tokens, provider event identifiers, PAI user identifiers, PAI database identifiers, or Google API-derived data to OpenAI. PAI sends OpenAI Responses requests with application-state storage disabled. OpenAI may still retain limited user-origin request content in abuse-monitoring logs under its standard API controls; separate OpenAI account-level retention controls are not implied by the request setting.

PAI does not use connected-calendar data to fine-tune, evaluate, or train generalized AI models. PAI does not currently train an internal model using stored personal information. If that practice changes, we will update this Policy and provide any required notice and choices before the change; connected-calendar data will remain excluded.

AI outputs may be inaccurate. Please review important responses, reminders, calendar actions, and list changes before relying on them.

11. Third-Party Providers

We use service providers to operate PAI. These providers receive only information reasonably necessary to perform services for us and may not use it for their own advertising or unrelated purposes.

Current core providers include Railway for application and database hosting, Linq for SMS delivery, OpenAI for processing user-origin assistant requests, Clerk for authentication and account management, and Stripe for payment processing. Google and Microsoft process information when you choose to connect their calendar services. OpenAI does not receive raw or derived information obtained from Google APIs. We may also use analytics, customer support, security, and infrastructure providers.

PAI limits provider access to the information needed for the provider's assigned role. Provider retention, deletion, backup, security, and contractual terms may differ by provider and account plan; PAI does not treat repository code or draft agreements as proof of a provider's external controls.

12. Google and Microsoft Calendar Access

If you connect Google Calendar or Microsoft Outlook Calendar, PAI uses that access only to provide user-facing calendar features you request. These features may include reading and finding events, calculating your own availability from event times, creating events, updating or rescheduling events, deleting events, handling recurrence and attendee details, answering calendar-related requests, supporting a 24-hour undo window, and sending an optional daily agenda that you separately choose.

For Google Calendar, PAI requests exactly openid and https://www.googleapis.com/auth/calendar.events.owned. PAI uses the stable OpenID subject to bind the authorization to the correct connection; it does not request Google email or profile scopes. PAI applies an additional product limit: it accesses and changes events only on your primary Google Calendar, not secondary, shared, or subscribed calendars.

For Microsoft Outlook Calendar, PAI requests delegated Calendars.ReadWrite, offline_access, and basic sign-in permissions. PAI applies an additional product limit: it accesses and changes events only on your default Outlook calendar, not shared, group, or secondary calendars.

PAI does not sell Google or Microsoft calendar data, use it for advertising or marketing, distribute it to data brokers, use it to determine creditworthiness, or use it to train generalized AI models. PAI complies with the Google API Services User Data Policy, including its Limited Use requirements, when using or transferring information obtained through Google APIs.

You may disconnect a calendar in PAI and revoke Google access at Google Account permissions.

You may manage Microsoft consent at Microsoft account permissions or through your organization’s My Apps portal. Revoking access disables connected-calendar features.

13. Payment Processors

Payments are handled by third-party payment processors. We may receive limited payment-related information such as subscription status, transaction identifiers, billing contact details, plan type, renewal date, and payment status.

We do not store full credit card numbers unless expressly stated. Payment processors handle payment information under their own terms and privacy policies.

14. Data Sharing

We do not sell personal information.

We may share information with service providers that help us operate PAI, with third-party services you connect or direct us to use, with payment processors, and with professional advisors, but only for the purposes described in this Policy.

We may disclose information if required by law, subpoena, court order, legal process, or government request, or if we believe disclosure is necessary to protect rights, safety, security, users, PAI, or others.

We may share information in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to notice and consent where required. Google user data will not be transferred as part of such a transaction without the user’s explicit prior consent.

PAI policy permits human access to connected-calendar content only when you expressly authorize access for a specific support matter, when access is necessary to investigate a security or abuse incident, or when required by law.

15. Data Retention

We keep information only for as long as reasonably necessary for the purpose described below, and longer only when needed for security, fraud prevention, billing, dispute resolution, legal compliance, or enforcement.

OAuth access and refresh tokens are retained in encrypted form only while a calendar connection remains active or while a limited revocation retry is pending. PAI deletes local tokens after successful disconnection or account deletion and asks the calendar provider to revoke the connection.

Calendar action data needed to complete a request is deleted promptly after the request succeeds unless it is needed for the 24-hour undo window. Temporary connected-calendar artifacts and undo data are deleted no later than 24 hours after creation, followed by the next automated cleanup cycle, which normally runs about every five minutes.

PAI schedules connected-calendar message content in its own active systems for deletion after the applicable temporary-use or undo period. PAI also issues deletion requests for supported provider records, but repository behavior does not establish the timing or completeness of deletion from a provider's logs, backups, subprocessors, or a recipient device. A message already delivered to your or another recipient’s device cannot be recalled.

PAI excludes raw and derived Google API data from OpenAI processing. For user-origin content that PAI sends to OpenAI, PAI disables Responses application-state storage; OpenAI's separate abuse-monitoring retention may still apply unless account-level controls are independently verified.

Deleted information may remain temporarily in infrastructure backups until the applicable backup lifecycle expires. Backup schedules, encryption, aging, restore procedures, and post-restore deletion reconciliation are operational controls that PAI verifies separately and does not infer from application code.

Account, billing, consent, support, and security records are retained only as long as reasonably necessary for the applicable operational, contractual, security, or legal purpose.

16. Account Deletion

You may request deletion of your account by contacting us at [email protected] or by using account deletion tools if available.

After verifying a deletion request, PAI disables connected services, ends optional agendas, asks Google or Microsoft to revoke calendar access, deletes OAuth tokens, and deletes connected-calendar artifacts, undo records, and related caches from active systems. PAI also deletes account identifiers, reminders, lists, and other feature data that is no longer required.

If PAI retains user-origin message or parser records for a permitted operational purpose, it removes direct account identifiers, replaces the account link with a random value, destroys the mapping back to your account, and excludes those records from model training. Limited billing, consent, security, fraud-prevention, legal, or support records may remain where reasonably necessary. Deleted information in backups ages out as described in Section 15, and copies already delivered to recipient devices cannot be recalled.

17. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect information.

OAuth tokens are encrypted in transit and stored encrypted at rest. The application receives token-encryption key material separately from the token records. Operational identity, access, key-rotation, logging, and multifactor-authentication controls are verified separately and are not established by this Policy.

No method of transmission or storage is completely secure. We cannot guarantee that information will always remain private or secure. You are responsible for keeping your account, phone, email, login credentials, and connected services secure.

18. Your Rights

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your information, object to or restrict certain processing, withdraw consent, or appeal a decision about your request.

You may disconnect a calendar at any time, choose whether to receive a daily agenda, and revoke provider consent through your Google or Microsoft account settings. You may also contact us to opt out of any future eligible use of user-origin content for internal model training; connected-calendar data is excluded from such use regardless of that choice.

To exercise privacy rights, contact [email protected]. We may need to verify your identity before responding.

19. California Privacy Rights

California residents may have rights under California privacy laws, including the right to know what personal information we collect, use, disclose, sell, or share; the right to access personal information; the right to delete personal information; the right to correct inaccurate personal information; the right to opt out of sale or sharing; the right to limit certain uses of sensitive personal information; and the right not to be discriminated against for exercising privacy rights.

PAI does not sell personal information. If our practices change, we will update this Privacy Policy and provide any required choices.

To exercise California privacy rights, contact [email protected].

20. Children’s Privacy

PAI is not directed to children under 13, and we do not knowingly collect personal information from children under 13.

If we learn that we collected personal information from a child under 13 without required consent, we will take reasonable steps to delete it.

21. International Users

PAI is operated from the United States. If you access the Service from outside the United States, your information may be processed in the United States or other countries where privacy laws may differ from those where you live.

By using the Service, you understand that your information may be transferred to and processed in the United States, subject to applicable legal safeguards.

22. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the effective date and post the revised policy.

If changes are material, we may provide additional notice through the website, account page, SMS, or email. If a change materially expands how connected-service data is used, we will obtain additional consent when required before applying the change.

23. Contact Information

Questions or privacy requests can be sent to [email protected].