Privacy Policy
Last updated: August 2026
This Privacy Policy (“Policy”) outlines how Ankbyte LLC (United States) and Ankbyte S.A. de C.V. (Mexico) (collectively referred to as “Ankbyte,” “we,” “our,” or “us”) collect, use, disclose, and protect personal data when users interact with our websites, platforms, products, and services — especially in relation to our AI Advisory and Generative AI service offerings.
This Policy applies to all individuals accessing our services from the United States, Mexico, or any other jurisdiction where Ankbyte operates or offers its solutions. It also governs data accessed through Google APIs by our scheduling assistant, Leslie™ — see sections 2 and 4 through 7.
1. Data We Collect
We may collect and process the following categories of personal data:
- Identity Data: full name, title, company, professional role
- Contact Data: email address, phone number, mailing address
- Usage Data: browser history, IP address, device identifiers
- Transactional Data: service requests, billing history
- Communications Data: emails, messages, contact form entries
- Google User Data: where you explicitly connect a Google account, the limited calendar and profile data described in section 2
2. Google User Data
Our scheduling assistant, Leslie™, can connect to your Google Calendar so it can book, reschedule, and confirm appointments on your behalf. This connection is optional, is initiated only by you through Google’s own OAuth consent screen, and can be withdrawn at any time.
When you grant access, we request only the scopes required to deliver scheduling. One of these is classified by Google as a sensitive scope:
- calendar.events (sensitive): to create, update, and cancel the appointments Leslie books for you on your calendars
- calendar.events.freebusy: to read availability so Leslie only offers times you are actually free
- calendar.calendarlist.readonly: to list the calendars you are subscribed to, so you can choose which one Leslie books into
- calendar.app.created: to create and manage a dedicated secondary calendar for Leslie bookings
- openid, userinfo.email, userinfo.profile: to identify your account, link it to your Ankbyte workspace, and send booking confirmations
We do not request access to Gmail message content, Google Drive files, contacts, or any other Google service, and we do not read calendar data for any purpose other than scheduling on your instruction.
3. How We Use Your Data
Personal data is processed for the following purposes:
- Delivering AI consulting, engineering, and advisory services
- Operating scheduling, booking, and follow-up features you have asked us to perform
- Communicating about projects, proposals, and engagements
- Improving our website and service offerings
- Complying with legal obligations in the US and Mexico
These services may involve processing data from clients and their users under appropriate legal and contractual frameworks.
4. Limited Use of Google User Data
Ankbyte’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically:
- We use Google user data only to provide and improve the user-facing scheduling features you have enabled.
- We do not sell Google user data, and we do not use it for advertising, retargeting, credit assessment, or lending purposes.
- We do not use Google user data to train, fine-tune, or evaluate generalized or third-party artificial-intelligence or machine-learning models.
- We do not transfer Google user data to third parties except to the service providers named in section 5, to comply with applicable law, or as part of a merger or acquisition with your prior notice and consent.
- We do not transfer Google user data to any third-party service that uses it to train, fine-tune, or improve foundational or generalised artificial-intelligence or machine-learning models. Every provider named in section 5 is contractually bound not to do so.
- Humans do not read your Google user data, except with your explicit consent for a specific issue, where required by law, or where the data has been aggregated and de-identified for security and abuse-prevention purposes.
5. Who We Share Google User Data With
We disclose data received through Google APIs only to the service providers listed below, only to the extent needed to operate the scheduling features you have enabled, and only under contracts that bind them to confidentiality, to the purposes described here, and to Google’s Limited Use requirements. This list is complete: no other party receives your Google user data.
- OpenAI, L.L.C. (United States): Leslie’s replies are generated by OpenAI language models. When Leslie offers an appointment time, the free/busy availability derived from your calendar — start and end times only — is passed to the model so it can compose the message. Event titles, descriptions, locations, attendees, and guest details are never sent. Our OpenAI account operates under Zero Data Retention, so prompts and responses are not stored by OpenAI, and OpenAI does not use data submitted through its API to train or improve its models
- Meta Platforms, Inc. — WhatsApp Business Platform (United States and Ireland): where your customers reach Leslie over WhatsApp, the appointment times Leslie quotes travel through Meta’s messaging infrastructure in order to be delivered to the customer, in the same way any WhatsApp message does
- Microsoft Azure (Microsoft Corporation): hosting, database, and storage for the platform. Your encrypted OAuth tokens, your booking records, and the business documents you upload are stored and processed here; Microsoft acts solely as our infrastructure operator under its data protection terms and does not access this data for its own purposes or use it to train any model
We also want to be explicit about what does not receive your Google user data:
- No other AI or ML provider: OpenAI is the only artificial-intelligence provider in our stack that receives any data derived from Google APIs. We use no model aggregators, gateways, routers, or model hubs, and no other model vendor
- Our observability tooling: we monitor Leslie’s behaviour using Langfuse, which we run self-hosted inside our own infrastructure. Conversation data processed by it is handled locally on systems we control and is never transmitted to the software’s vendor or to any other party, for training or for any other purpose
- Our other vendors: our vector search provider (Zilliz Cloud), transactional email (Resend), and payment processing (Mercado Pago) support other parts of the product and receive no Google user data of any kind
- Advertising and analytics: no Google user data is shared with advertising networks, data brokers, or analytics providers, and none is ever sold
6. Data Protection and Security Measures
We apply layered technical and organisational safeguards to all personal data, and we apply the strictest of them to sensitive data accessed through Google APIs.
- Encryption in transit: all traffic between your browser, our services, and Google APIs is encrypted with TLS 1.2 or higher; unencrypted transport is refused
- Encryption at rest: scheduling records, tokens, and backups are stored encrypted at rest with AES-256 using managed cloud key management
- Credential isolation: OAuth access and refresh tokens are held in a dedicated encrypted secret store, never in application source code, logs, or analytics tooling
- Scope minimisation: we request the narrowest set of Google scopes that will deliver scheduling, and only one of them is sensitive; we hold no access to Gmail, Drive, or contacts
- Tenant isolation: every credential and booking record is scoped to a single tenant, and queries are constrained by that tenant so one customer’s data is never reachable from another’s workspace
- Access control: least-privilege, role-based access; production access is restricted to a small number of named engineers, requires multi-factor authentication, and is logged
- Network isolation: databases run inside a private network with no public internet exposure and are reachable only by authorised application services
- Monitoring and auditing: access to production systems is logged and reviewed, with alerting on anomalous access patterns
- Secure development: changes are peer-reviewed, dependencies are monitored for known vulnerabilities, and environments are separated so production data is never copied into development or testing
- Personnel controls: staff are bound by confidentiality obligations and receive data-protection training; access is revoked on role change or departure
- Incident response: we maintain a documented incident-response process and will notify affected users and regulators of a personal-data breach without undue delay, as required by applicable law
7. Data Retention and Deletion
We retain personal data only for as long as it is needed for the purposes described in this Policy, or for as long as required by law. Data accessed through Google APIs is retained only while your Google account is connected and the scheduling service is in use.
- You may disconnect your Google account at any time from within our product, or by revoking Ankbyte’s access at myaccount.google.com/permissions.
- On disconnection, your stored OAuth access and refresh tokens are permanently deleted from our database immediately, and the authorization is revoked with Google in the same operation. Where one Google identity has authorized Leslie for more than one workspace, we delete the credentials for the workspace you disconnected and leave the other workspaces’ authorizations intact.
- Appointment records created by Leslie are retained while your account remains active, so that you keep a usable booking history. Events written to your Google Calendar stay under your control and can be deleted by you in Google Calendar at any time.
- Preview and trial workspaces, and the data created inside them, are automatically deleted 7 days after creation.
- On account closure, or on a deletion request sent to privacy@ankbyte.com, we delete or irreversibly anonymise your personal data within 30 days, except where retention is legally required.
- Encrypted backups are rotated on a defined schedule, and deleted records are purged from backups as those backups expire.
8. Legal Basis
Where applicable under privacy laws (e.g., GDPR, Mexican data protection law), we rely on:
- Contractual necessity
- Legitimate business interests
- Your explicit consent
9. Data Transfers
Your data may be processed in the United States, Mexico, or other countries where Ankbyte or its service providers operate. We implement appropriate safeguards to protect your data during any such transfers. The service providers that receive data obtained through Google APIs are named individually in section 5, and each is bound by contractual confidentiality and security obligations; we do not sell personal data to anyone.
10. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, delete, or restrict the processing of your personal data, and to withdraw any consent you have given — including revoking our access to your Google account. To exercise any of your rights regarding your personal data, contact us at privacy@ankbyte.com.
11. Policy Updates
Ankbyte may update this Policy at any time. Changes will be posted on this page and reflected by a new Effective Date. We encourage you to review this Policy periodically.
12. Acceptance
By accessing or using our websites, platforms, or services, you acknowledge that you have read, understood, and accepted the terms of this Privacy Policy. Continued use of this site constitutes your full acceptance of the latest version of this Policy.
Contact
For privacy-related inquiries: privacy@ankbyte.com
Ankbyte S.A. de C.V. is a registered trademark in Mexico.