Privacy Policy
Caplexer ("we", "us") provides AI agents that handle customer conversations on behalf of businesses ("clients") over channels such as phone, WhatsApp and SMS, and that act on the client's connected systems, such as Google Calendar and Google Sheets. This policy explains what data we handle, why, and the choices available to you.
1. Data we collect
- Client account data. Business name, contact details, service configuration (services offered, hours, appointment durations) provided by our clients during setup.
- Conversation data. Messages and call transcripts exchanged between a client's customers and the client's agent, processed and stored so the agent can respond, keep context, and so the client can review what was said and done.
- Action logs. A record of each action an agent takes (for example, an appointment created), kept for auditability.
- Technical data. Standard server logs (timestamps, IP addresses of connecting services) used for security and troubleshooting.
2. Google user data
When a client connects a Google account, Caplexer requests only the scopes needed for the features the client uses:
- Google Calendar (read-only, and events) — to check availability and to create or cancel appointments the client's customers request.
- Google Sheets (read-only) — to answer availability questions from a product or stock sheet the client designates.
We use this data solely to provide the agent features described above, on the client's behalf. We do not use Google user data for advertising, and we do not sell it. Access tokens are stored encrypted at rest, are used only by the connector serving that client, and are never shared with other clients or unrelated third parties.
Caplexer's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
3. How data is stored and protected
- Credentials and tokens are encrypted at rest.
- Access to client data is isolated per client; each connector verifies that requests belong to the client whose data is being accessed.
- Data is transmitted over encrypted connections (HTTPS/TLS).
4. Third-party services
To provide the service, we rely on the following processors, which handle data only as needed to deliver the service:
- Anthropic — AI language processing (generation of agent responses).
- Meta — message delivery via the WhatsApp Business API.
- Telephony and hosting providers — call transport and server infrastructure. Data is hosted on servers located in the United States.
We do not sell personal data to anyone.
5. Retention
Client account data, conversation data and action logs are retained while the client's account is active, and deleted or anonymized upon account closure or on the client's request, except where a legal obligation requires longer retention. Google access tokens are deleted when a client disconnects their Google account or closes their account.
6. Revoking access
A client can revoke Caplexer's access to their Google account at any time, either by contacting us at hello@caplexer.com or directly from their Google Account security settings at myaccount.google.com/permissions. Revocation takes effect immediately; the corresponding stored tokens are invalidated and removed.
7. Your rights
Depending on where you are located, you may have rights to access, correct, delete or export data we hold about you. To exercise them, contact us at the address below. If you are a customer of one of our clients, we act on that client's behalf; we will assist them in responding to your request.
8. Changes to this policy
If we make material changes, we will update the date above and, for clients, notify by email.
9. Contact
Questions about this policy or about your data: hello@caplexer.com.