Privacy Policy

Last updated: September 17, 2026

This policy explains how OwlThat (Louisville, Kentucky) handles data: for visitors to this website, for the businesses that use our service, and for the people who talk to an AI worker run on behalf of one of those businesses. We wrote it to answer real questions plainly, because our product answers your phone and reads your inbox, and you deserve to know exactly how that data is treated.

1. What we collect

  • From this website: what you submit through the contact form (name, email, message) and standard server logs (IP address, browser type, pages requested). If, and only if, you allow analytics cookies, we also use Google Analytics to measure how the site is used; see section 4. Cookies are covered in our Cookies Policy.
  • From customers of the service: the business information you give us during setup (services, pricing, rules, voice) and the working data your AI workers handle to do their jobs: emails, texts, calendar events, invoices, and conversations with your customers.
  • From people who talk to a customer's AI worker: the contents of the conversation and the contact details shared in it. We process this on the business's behalf so the AI can answer, book, and follow up. If you've spoken with a business's AI and have questions about your data, contact that business, and you can always reach us at info@owlthat.com.

2. Phone calls, recordings, and transcripts

Every call answered by an AI worker begins with a greeting that discloses it's an AI. Calls are transcribed to text so the worker can do its job (take a message, book an appointment, answer a question) and so the business owner can read what was said.

Call audio is not recorded by default. Audio recording happens only when the business has turned on the record-calls setting for a specific phone line. When recording is on, it is disclosed in the call greeting, the audio is stored in the business's own environment, it is kept for a limited retention period rather than indefinitely, and the business can turn recording off at any time.

3. How we use data, and how we don't

  • We use customer data for one purpose: operating the service for that customer.
  • We never sell your data.
  • We never use your business data or your customers' communications to train AI models, ours or anyone else's. When an AI worker generates a response, the relevant text is processed by our model providers under API terms that do not permit training on it.
  • Each customer's workers run in that customer's own isolated environment; customer data is not pooled across customers.
  • Two narrow exceptions: we may disclose information when the law genuinely requires it (a valid subpoena, court order, or similar legal process, and where the law allows, we'll notify the affected customer first), or when disclosure is necessary to protect someone's safety or to establish or defend our legal rights. We interpret both narrowly.

4. Subprocessors

We use a small number of service providers to run the platform, each bound to process data only to provide their service to us:

  • Amazon Web Services: cloud hosting and encrypted secrets storage.
  • Twilio: phone calls and text messaging.
  • Anthropic and OpenAI: AI model providers that process conversation text to generate responses; neither trains on it under our API terms.
  • Google: sign-in and, where a customer connects it, Google Workspace (Gmail and Calendar) integration.
  • Google Analytics: website usage statistics for owlthat.com, only for visitors who allow analytics cookies.

Website analytics. Google Analytics loads only after you allow analytics in our cookie settings. When it does, it collects the pages you visit, how you arrived (for example, a search or a link), approximate location at the city or country level, and device, browser and screen information, using the _ga cookies described in our Cookies Policy. Google Analytics does not log or store IP addresses. We have turned off Google signals and advertising features, we don't use it to build advertising profiles, and it never receives anything from the Cortex service or your business data. Google keeps this data for the limited retention period set in our Google Analytics account. You can withdraw consent at any time with Cookie settings in the footer of any page, which switches analytics off and deletes its cookies; Google also offers a browser add-on to opt out of Google Analytics on every site.

If this list changes materially, we'll update this page and notify customers.

5. Google user data

When a customer connects a Google account to their AI workers ("Connect Google"), OwlThat accesses Google user data through Google's APIs. Here is exactly what that means:

  • What we access: your basic account info (email address) to identify the connected account; your Google Calendar events and the list of your calendars, so workers can check availability and book appointments; and your Gmail messages and labels, so workers can read, organize, and prepare draft replies for the email channel.
  • What we use it for: one thing: providing the features the customer connected it for. Calendar data powers booking; Gmail data powers the email channel. Nothing else.
  • Workers never send email on their own. The Gmail integration can read, label, and create drafts. It has no ability to send. Sending is always a human act in the customer's own Gmail.
  • Where it lives: the Google refresh token and any Google data workers handle are stored encrypted in the customer's own isolated environment (their data plane), not OwlThat's cloud. OwlThat's control plane brokers the connection but does not retain your Gmail messages or calendar events.
  • No ads, no selling, no training: we never use Google user data for advertising, never sell it, never let humans read it (except with your explicit permission, for security investigation, or where the law requires), and never use it to train AI or machine-learning models, ours or anyone else's, generalized or otherwise.
  • Disconnecting: a customer can disconnect Google at any time from their dashboard, and can also revoke OwlThat's access directly at myaccount.google.com/permissions. On disconnect, stored Google tokens are deleted and access stops immediately.

OwlThat's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6. Facebook and Instagram data

When a customer connects their Facebook Page or Instagram professional account to their AI workers ("Connect Facebook & Instagram"), OwlThat accesses that data through Meta's APIs on the customer's behalf. Here is exactly what that means:

  • What we access: the list of Pages the connecting person manages (to identify the one Page and linked Instagram account they choose); messages people send that Page or account, and comments left on its posts; the Page's own posts and basic profile information, so replies have context; and the name and profile picture of people who message the business.
  • What we use it for: answering the people who contact the business. Workers reply to messages and comments, and publish posts, on the customer's behalf. Replies to customers begin with a disclosure that an AI assistant is answering and a person can take over at any time. Anything a worker is not confident about waits for a human at the business to approve.
  • Nothing unsolicited: workers only answer people who message or comment first, and only inside the messaging window Meta's policies allow. We never send marketing messages, never message people who have not written in, and never contact the followers of a Page.
  • Where it lives: message and comment content is stored in the customer's own isolated environment (their data plane), not in OwlThat's cloud. OwlThat's control plane receives Meta's webhook deliveries in order to route them to the right customer and holds a short-lived delivery log for that purpose; it holds the connection token and never retains conversation content.
  • No ads, no selling, no training: we never use Facebook or Instagram data for advertising, never sell it, never let humans at OwlThat read it (except with the customer's explicit permission, for security investigation, or where the law requires), and never use it to train AI or machine-learning models.
  • Disconnecting and deletion: a customer can disconnect at any time from their dashboard, or remove OwlThat under their Page's Business Integrations settings on Facebook. Either way our access is revoked immediately and the stored connection token is deleted. A person who has messaged a connected business can ask Meta to have their data deleted; we receive that request, revoke access to the affected account on arrival, and provide a confirmation code and status page. Message content held in the customer's environment is deleted under the retention rule below, or sooner on request to info@owlthat.com.

OwlThat's use of data received from Meta's platforms complies with the Meta Platform Terms and Developer Policies.

7. Retention and deletion

We keep customer data for as long as the account is active, because the workers need history to do their jobs well. Call recordings, where enabled, are kept only for their limited retention window. When a customer leaves, we provide an export on request and delete their data from the service within 30 days of termination, except where the law requires us to keep something. Website contact-form submissions are kept only as long as needed to respond and follow up.

8. Security

Data is encrypted in transit, secrets are stored encrypted, access is role-based, and every action an AI worker takes is logged and reviewable by the business owner. No system is perfectly secure, and we'll notify affected customers without undue delay if a breach ever affects their data.

9. Changes to this policy

When we make material changes we'll update the "Last updated" date at the top of this page and notify customers of the service directly.

10. Contact us

Questions about privacy, a data-processing agreement, or a deletion request: info@owlthat.com.