SCSAI
WorkPricingContactLog inBook a build call

Privacy Policy

Last updated: 2026-05-30 Operated by: SCS AI LLC, a Wyoming limited liability company (Wyoming SOS Filing ID 2026-001990946 · EIN 42-2683096) 30 N Gould St, Ste R, Sheridan, WY 82801 Contact: marcus@scsai.app

This Privacy Policy describes how SCS AI LLC ("SCS AI," "we," "our") collects, uses, shares, and protects information when you use the SCS AI platform (the "Service") at scsai.app and connected applications.

1. Information we collect

1.1 Account information. Email, name, business name, payment information processed by Stripe (we do not store full card numbers; we store Stripe customer IDs and last-four references).

1.2 Operator-supplied content. Voice corpus samples (text/audio used for the per-tenant voice fingerprint), brand assets, business hours, services, FAQs, and any other content you upload to configure your agents.

1.3 Customer / contact data your business operates with. When you connect external services (Instagram Business, Facebook Pages, your CRM, your booking system, your SMS provider, etc.), the Service processes data those services return — for example: messages sent to your business pages, contact details of people who opted in to your outreach, booking records, comments, reviews.

1.4 Operational telemetry. Action logs (which agent did what, when, for which tenant), error logs, performance metrics, Centurion quality scores, integration audit trails. These are scoped per tenant.

1.5 Cookies and similar. Session cookies for authentication. We do not run third-party advertising cookies on scsai.app.

2. How we use information

  • Operate the Service for you (run your agents, store your data, surface your dashboard).
  • Provide customer support.
  • Send service notices and product updates to the email associated with your account.
  • Improve the Service in aggregate (we do NOT train any general-purpose model on tenant data — see §6).
  • Comply with legal obligations.

3. How we share information

We share information only as follows:

  • Service providers acting on our behalf (Stripe for billing, Anthropic for LLM inference, Netlify for hosting, Resend for transactional email, Twilio for SMS, etc.), under contracts that require them to use the information only for our purposes.
  • At your direction, when you connect an external service (Instagram, Facebook, Gmail, etc.) — the Service then exchanges data with those services per your authorization.
  • Legal compliance, when required by valid legal process.
  • Business transfer, in the event of a merger, acquisition, or sale of substantially all assets, with notice.

We do NOT sell personal information. We do NOT share personal information with advertisers.

4. Meta / Facebook / Instagram data

When you connect a Facebook Page or Instagram Business Account to SCS AI:

  • We request only the permissions necessary to operate the connected agents: instagram_basic (identify the linked Instagram business account), instagram_manage_messages (read and reply to Instagram DMs), instagram_content_publish (publish posts you approve), pages_show_list (find the Facebook Page behind that account), and pages_messaging (read and reply to Messenger conversations). We do not request permissions we do not use.
  • We use Meta-Platform data solely to deliver the Service to you — posting on your behalf with your approval, surfacing comments and DMs in your operator inbox, attributing engagement to your business.
  • We do NOT sell Meta-Platform data, share it with data brokers, or use it for advertising.
  • We delete Meta-Platform data on your request per §8 below, and automatically when you disconnect the integration or close your account.

5. Cross-tenant isolation

The Service is architecturally account-scoped (see ADR-002, "P0 isolation rule"). Each tenant's data is stored under that tenant's account scope, and no agent run, audit log, or stored content from one tenant is accessible to any other tenant. This is enforced at the database, application, and audit-log layers.

6. We do not train general-purpose models on your data

LLM calls made on your behalf (drafts, replies, briefs) are sent to inference providers (e.g., Anthropic) under terms that do not allow your data to be used to train their general models. The per-tenant voice fingerprint and your gold-standard examples improve YOUR experience on the Service — they are not used for any other tenant or any other product.

7. Data retention

  • Account information: kept while your account is active. Deleted within 60 days of account closure per §8.
  • Operator-supplied content (voice corpus, brand assets, configuration): kept while your account is active.
  • Customer / contact data: kept according to your retention configuration (default: until you delete the contact OR until the contact exercises a deletion right under §8).
  • Audit logs: kept for the longer of (a) 2 years or (b) any period we are legally required to retain.
  • Telemetry / aggregate metrics: kept indefinitely in de-identified form.

8. Your rights

You have the right to:

  • Access the personal information we hold about you.
  • Correct inaccurate or incomplete information.
  • Delete your account and personal information (see also our User Data Deletion page).
  • Export your data in a portable format (CSV / JSON).
  • Withdraw consent for processing that is based on consent.

To exercise any of these rights, email marcus@scsai.app with the subject line "Privacy request — [your request]." We respond within 30 days.

If you are a California resident, you have additional rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of "sharing" (we do not sell or share for cross-context behavioral advertising). Submit CCPA/CPRA requests to the same address.

9. Security

We use industry-standard administrative, technical, and physical safeguards to protect personal information, including encryption at rest, encryption in transit (TLS), per-tenant access controls, secret-management via Bitwarden, and audit logging on every state-changing action. No system is perfectly secure; we will notify affected users of any material security incident within the timeframes required by applicable law.

10. Children

The Service is intended for businesses and is not directed to children under 13. The Service's NIL Athletes tier is intended for high-school athletes (14-18) and operates under COPPA-compliant guards; data of athletes under 13 is not knowingly collected.

11. International users

The Service is operated from the United States. By using the Service, you consent to the transfer of your information to the United States.

12. Changes

We may update this Policy. Material changes will be announced via email and posted at scsai.app/privacy with a revised "Last updated" date.

13. Google user data (Google Sign-In and Gmail)

When you connect a Google account to SCS AI:

  • Scopes we request. Google Sign-In (openid, email, profile) to identify you, and Gmail access (https://www.googleapis.com/auth/gmail.modify) when you connect your inbox so your SCS AI operator can read and triage your email, draft replies, and — with your approval — send those replies from your own mailbox (in the original thread, so your customer sees a reply from the address they wrote to). We request gmail.modify (read, draft/compose, and send); we do not permanently delete your email and do not change your Gmail account settings. This is the minimum access for an assistant that both triages and responds on your behalf, and every send is consent- and approval-gated — nothing leaves your mailbox without your sign-off.
  • Limited Use disclosure. SCS AI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we use Google user data only to provide and improve the user-facing features that are prominent in the Service (inbox triage, reply drafting, and approval-gated sending from your mailbox). We do not transfer or sell this data to third parties except as necessary to provide the Service or as required by law; we do not use it for advertising or to serve ads; we do not use it to train generalized or AI/ML models; and we do not allow humans to read it except (a) with your affirmative agreement for specific messages, (b) as necessary for security purposes (e.g., investigating abuse), (c) to comply with applicable law, or (d) where the data is aggregated and anonymized.
  • Storage and encryption. Google access/refresh tokens are stored encrypted with AES-256-GCM in a per-tenant credential vault, isolated to your tenant (§5). Email content the operator processes is handled in-tenant, is never used to train any model (§6), and is never accessible to any other tenant (§5).
  • Deletion and revocation. Disconnecting your Google account in the Service immediately revokes the token and deletes the stored credential; processed Gmail data is deleted per the retention schedule (§7) or sooner on request (§8). You can also revoke SCS AI's access anytime at myaccount.google.com/permissions.

14. SMS and text messaging

When you provide your mobile number to SCS AI or to a business operating on the Service, and that business sends you text messages through SCS AI:

  • Consent. You will only receive text messages after you opt in — for example, by checking a consent box (not pre-checked) on a web form, by texting the business, or by giving consent at the time of booking. Consent to receive text messages is never a condition of any purchase.
  • Message types and frequency. Messages may include appointment confirmations, booking reminders, follow-ups, and replies to your inquiries. Message frequency varies based on your interactions with the business.
  • Rates. Message and data rates may apply, depending on your mobile carrier and plan.
  • Help and opt-out. Reply HELP for help, or STOP at any time to stop receiving messages. After you reply STOP you will receive one confirmation message and no further messages unless you opt in again.
  • No sharing of mobile information. Mobile phone numbers and SMS consent are never sold and are never shared with third parties or affiliates for their own marketing or promotional purposes. Phone numbers are used solely to deliver the messaging described above and are shared only with the SMS provider (e.g., Twilio) acting on our behalf to transmit the messages you requested. No mobile information is shared with third parties for marketing purposes.

15. Contact

Privacy questions: marcus@scsai.app SCS AI LLC · 30 N Gould St, Ste R, Sheridan, WY 82801

SCSAI

Websites that work like an employee. Run the business, not the busywork.

(310) 997-4158
  • Instagram
  • TikTok
  • X
  • LinkedIn
  • Facebook

One email when we ship something real. No cadence, no filler.

What we build

  • Websites we've built
  • What it costs
  • See the AI employee
  • Portfolios

Company

  • Pricing
  • Get started
  • Contact
  • Client log in
  • Book a call
© 2026 SCS AI LLC
PrivacyTermsData deletionAccessibility