Privacy stance

What we collect,what we do with it, and who else touches it — in plain language.

This is the working posture, not a generic template. It pairs with the compliance matrix on /compliance — if you want to read the TCPA, AI-disclosure, and FCC stance before reviewing what is collected, start there. The five sections below cover intake, calls, retention, third parties, and your rights, in that order.

1 · What we collect

The intake form, the call, and the SMS confirmations — each piece has a job.

On intake

The intake form is the postmark on every engagement. It collects the full business + contact record the agent will act on — name, email, business name, vertical, the current stack (calendar, CRM, phone system), weekly call volume, and the top pain point the practice is trying to move. Nothing else is pulled in; nothing is inferred from a third-party list.

On the call

When the agent picks up or places a call, it captures the audio and the transcript, the AI-disclosed opening line, and the booking outcome (booked / qualified / not a fit). The transcript is what we tune the agent against between passes — it is the working artifact for the engagement, and it stays tied to the lead record it came from.

On SMS

For the SMS confirmations and follow-ups the agent places, Twilio handles deliverability and TCPA safeguard metadata — opt-in capture, opt-out status, message status callbacks. The thread of SMS messages between the agent and a contact lives in the workspace alongside the call transcript and the booking record.

2 · How we use it

Four jobs: qualify, book, tune, respond — and nothing else.

The data the intake form and the calls collect is used for the jobs the engagement exists to do — and for nothing else. We do not sell it, we do not share it with advertising networks, and we do not repurpose it into a service we have not told you about.

  • To run the engagement.

    Qualify the lead against the criteria your practice sets, book the appointment in the calendar that is already your system of record, hand off to the right person on your side, and send the SMS confirmation that closes the loop.

  • To tune the agent on the practice’s voice.

    The transcript is what we tune against between weekly passes — phrasing, qualification questions, booking handoff. The persona is consistent across the call and the follow-up text because the tuning is anchored to real transcript, not generic script.

  • To confirm scope.

    When you send the rights request described in section 5, the data we hold is what lets us answer it. The intake record, the call transcripts, the booking record, and the SMS thread are exactly the surfaces a rights request reads against.

  • To respond to rights requests.

    When a contact asks to access, correct, delete, or export their data, we run that against the same systems we just named. We do not hold a parallel set of records under a different retention clock.

3 · Retention & deletion

Kept as long as the engagement needs it — deleted when it doesn’t.

Contact-form submissions

Messages sent through /contact and intake submissions are retained for the duration of the engagement, plus a reasonable wind-down window so we can close out scoping, hand back any artifacts, and respond to a late-arriving question. When the engagement ends, the records roll off the active workspace on the same wind-down clock.

Call recordings & transcripts

Call audio and the matching transcript are kept for QA and for the weekly tuning passes that keep the agent on the practice’s voice. A contact who has asked for deletion, or an engagement that has ended, takes the relevant transcripts and recording pointers out of the active queue; a small audit trail of the deletion itself is kept so we can answer the follow-up question.

Deletion on request

If you want something deleted before the engagement ends — a transcript, a contact record, an SMS thread — the channel for that request is the same one as everything else on this page: a real person reads it and runs it through the workflow. We confirm deletion in writing, with what was removed and what remains.

4 · Third parties

Five processors, each scoped to the job it actually does.

The integrations on /integrations are the same five processors who touch data on a live engagement. Each one sees only what its job requires — no advertising-threaded pipeline, no resale, no secondary reuse.

  • Twilio

    SMS deliverability + TCPA safeguard.

    Sends the SMS confirmations and follow-up text the agent places; carries the opt-in / opt-out metadata the consent posture on /compliance is anchored to.

  • HubSpot

    CRM / lead record.

    Stores the lead and contact record the intake form produces — the canonical CRM copy for the engagement, scoped to the fields the practice configured.

  • RingCentral

    Call carrier for office practices.

    Carries the inbound and outbound voice for practices whose phone system is RingCentral. Audio and call metadata live where the practice already expects them.

  • Google Calendar

    Booking system of record.

    Holds the booked slot the agent confirmed on the call — the calendar the practice already lives in is the system of record for the appointment.

  • Jobber

    Dispatch system of record for home services.

    Stores the dispatch record when an HVAC / plumbing / electrical job moves from a booked call to a scheduled dispatch. Same posture as the CRM slot, scoped to the trade.

5 · Your rights & how to reach us

Access, correct, delete, export — answered by a real person.

A contact, a practice, or a regulator can ask for any of the four standard rights against the data described in sections 1–4. We treat each request as a scoped engagement of its own — it is read, owned, and answered by a real person inside our team, not by a queue.

  • Access

    A copy of the data we hold for a contact record, an intake submission, or a call transcript — delivered in a portable format.

  • Correct

    A correction against any field that is wrong, stale, or was supplied at intake and has since changed on the practice side.

  • Delete

    Removal of a specific record (a transcript, an SMS thread, a contact) from the active workspace, with a written confirmation of what was removed.

  • Export

    A pull of the full record set tied to the engagement — transcripts, intake fields, booking record, SMS thread — in the format your team can actually use.

The channel is the same regardless of which right you are exercising: write to threadbay@polsia.app or send a note through /contact. A founder reads every request and comes back within one business day with the concrete next step — what we need from you, the timeline, and the person on our side who owns the answer.

Privacy stance — working, not boilerplate

Have a question we did not cover?

If a data flow, retention window, or processor scope above is not the answer you were looking for, send the question through the contact surface and we’ll write back with where the answer lives — not a link to a template.