Introduction
Applied AI Partners LLC ("we," "our," or "us") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, and safeguard information when you visit our website at www.appliedaijax.com or use our services.
Information We Collect
Information You Provide
When you use our contact form, schedule a consultation, or communicate with us, we may collect:
- Your name
- Email address
- Phone number
- Message content
- Business/agency information you choose to share
Information Collected Automatically
When you visit our website, we may automatically collect:
- Browser type and version
- Operating system
- Pages visited and time spent
- Referring website
- IP address (anonymized)
How We Use Your Information
We use the information we collect to:
- Respond to your inquiries and contact form submissions
- Provide AI consulting, training, and implementation services
- Improve our website and services
- Send relevant communications (only with your consent)
- Comply with legal obligations
How We Protect Your Information
We implement appropriate technical and organizational measures to protect your personal information, including encrypted data transmission (HTTPS/TLS 1.2+), AES-256 encryption at rest, database-enforced tenant isolation, support for two-factor authentication, secure email handling through Resend, and limited access to personal data. Our full security posture — infrastructure, encryption, access control, subprocessors, and incident response — is documented at appliedaijax.com/security.
Third-Party Services
Our website uses the following third-party services:
- Vercel — website hosting
- Resend — email delivery for contact form submissions
- Google Fonts — typography
These services may collect limited technical data as described in their respective privacy policies.
Calendar Integration (Applied AI products — Google, Microsoft & Apple)
When an insurance agency connects their Google Calendar, Microsoft Outlook Calendar, or Apple iCloud Calendar to one of our calendar-aware products (currently ChatIQ and CalendarIQ), the connecting product accesses the following data on behalf of the connected account:
- Calendar busy/free information — only the start and end times of existing events are read, to compute which time slots are available for new bookings during the agency's configured business hours. Event titles, descriptions, attendees, and attachments are never requested or stored.
- Create new calendar events — when a website visitor (ChatIQ chatbot flow) or a booking-link recipient (CalendarIQ scheduling flow) confirms an appointment, the product creates a single calendar event on the connected account with the booking party as an attendee. The product does not modify or delete any other events.
How data is used: Busy/free times are used exclusively to compute available appointment slots. Newly created events are used exclusively to confirm appointments with the booking party and the agency.
Where data is stored: Google and Microsoft connections use OAuth refresh tokens. Apple iCloud connections use an app-specific password the agency generates at appleid.apple.com — Apple does not offer an OAuth API for iCloud Calendar. Both credential types are stored encrypted at rest in our Supabase (PostgreSQL) database, in the United States, with row-level security policies that restrict access to the owning agency and our service role. Busy/free data is fetched on demand and never persisted. Only the appointment metadata that the agency itself created is retained, for history within the agency dashboard.
Who data is shared with: We do not sell, share, or transfer calendar data to any third party. Calendar data is not used to train AI models, is not used for advertising, and is never accessed by Applied AI staff except as necessary to respond to a support request initiated by the agency.
Retention: Calendar credentials are retained until the agency disconnects the calendar in the product's dashboard. For Google and Microsoft, disconnecting also revokes the OAuth grant on the provider side. For Apple iCloud, Apple does not expose an API to revoke an app-specific password — we delete the credential from our database, and we direct the agency to delete the corresponding app-specific password manually at appleid.apple.com → Sign-In and Security → App-Specific Passwords. Appointment history is retained while the agency's subscription to the product is active.
Revocation: Agencies can disconnect a calendar at any time from their product dashboard. Users can also revoke our products' access directly at myaccount.google.com/permissions (Google), account.microsoft.com/privacy/app-access (Microsoft), or by deleting the app-specific password at appleid.apple.com → Sign-In and Security (Apple).
Compliance: Our products' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Agency Client Data & Connected Mailboxes (AgencyIQ)
AgencyIQ is the agency management system used by an insurance agency's own staff. The agency is the owner and controller of the records it puts into AgencyIQ; Applied AI Partners processes that data on the agency's behalf in order to provide the service. A summary of our full security posture — infrastructure, encryption, tenant isolation, and subprocessors — is published at appliedaijax.com/security.
- What is collected: the client and prospect records the agency creates or imports (names, contact details, addresses, households, businesses, policies, carriers, renewal dates, premiums), activity the agency generates in the product (notes, tasks, appointments, opportunities), documents the agency uploads, calls and text messages placed or received through the built-in phone (including call audio, transcripts, and AI summaries), and — only if the agency connects a mailbox — email and calendar data as described below.
- Where it is stored: in our Supabase (PostgreSQL) database and Amazon S3 object storage, both in the United States. Data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Every tenant-scoped table enforces PostgreSQL row-level security, so one agency's records cannot be returned to another agency.
- Who can access it: members of the owning agency, according to the roles that agency assigns. Two-factor authentication is supported and can be required for every member by the agency owner. Applied AI staff do not access agency records except as necessary to respond to a support request the agency initiates.
- AI processing: AgencyIQ uses AI to summarize calls, draft communication, extract policy details from documents, and answer natural-language questions about the agency's own records. Only the specific records needed for a given request are sent for processing. Customer data is never used to train AI models — our AI subprocessors operate under agreements that prohibit training on submitted content. AI-drafted client communication is queued for human approval; nothing AI-generated sends to a client automatically.
- Who data is shared with: we do not sell, rent, or trade agency or client data, and we never share it with advertisers or data brokers. Data reaches a third party only where that provider operates part of the service (see the subprocessor list at appliedaijax.com/security). Syncs to an outside system — Guidewire PolicyCenter, Pipedrive, HubSpot, or a connected mailbox — happen only when the agency itself connects that system.
- Retention and deletion: call recordings are retained one year by default, configurable by the agency from 90 days to two years; call records, transcripts, and summaries are retained seven years in line with insurance recordkeeping practice. An agency can place a one-click legal hold to exempt records from scheduled deletion, and every disposal is written to a tamper-evident log. Agencies can delete individual records, documents, and recordings from the dashboard at any time, or request deletion at info@appliedaijax.com.
Microsoft 365 / Outlook and Google Workspace mailbox connections (AgencyIQ)
An agent may connect their own Microsoft 365 (Outlook) or Google Workspace (Gmail) account to AgencyIQ so client email and calendar activity appears on the client's timeline. Connection uses OAuth 2.0 through the provider's own sign-in page — Applied AI never sees, receives, or stores the account password.
Permissions requested (Microsoft 365): offline_access, openid, email, Mail.ReadWrite, Mail.Send, User.Read, Calendars.ReadWrite, and MailboxSettings.ReadWrite. Every one of these is a delegated permission, meaning AgencyIQ acts solely on behalf of the individual agent who signed in and is bounded by that person's own mailbox and calendar. AgencyIQ requests no application-level or tenant-wide permissions — specifically not Mail.Read.All, Directory.Read.All, Files.Read.All, or Sites.Read.All. There is no configuration in which AgencyIQ can read a mailbox belonging to a user who has not personally connected it.
How the data is used: inbound and sent mail is matched to the corresponding client record and displayed on that client's timeline inside the agency's own workspace, so the agency has a complete history of its own client conversations. Send permission lets the agent send from their own address rather than a no-reply relay. Calendar permission powers two-way sync with the AgencyIQ team calendar. Mailbox-settings permission lets the agent set an out-of-office reply from inside AgencyIQ. Mail and calendar content are never used to train AI models, never sold, and never shared with advertisers or any third party.
Where credentials are stored: the OAuth refresh token is encrypted with AES-256-GCM authenticated encryption under a key held outside the database, in addition to the storage layer's own encryption, and is decrypted server-side only to mint a short-lived access token. Applied AI does not store mailbox passwords.
Revocation: an agent can disconnect the mailbox in AgencyIQ at any time, which deletes the stored credential. A Microsoft 365 administrator can revoke the grant for the entire tenant from the Microsoft Entra admin center; an individual user can revoke it at account.microsoft.com/privacy/app-access. Google users can revoke at myaccount.google.com/permissions. Revocation takes effect immediately and requires no action or approval from Applied AI.
Compliance: our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Meeting Audio & Recordings (MeetingIQ — web and mobile apps)
MeetingIQ records meetings so they can be transcribed and summarized for the account holder's insurance agency. This applies to the MeetingIQ web app and the native MeetingIQ mobile app for iPhone and iPad.
- What is collected: meeting audio you choose to record, the transcript and summary generated from it, the meeting details you enter (client name, meeting title, agenda), your account email address, and your account user ID. Recording only happens when you start it; the microphone is used only while a recording is active.
- How it is processed: audio is transcribed by AssemblyAI and summarized by Anthropic's Claude models under agreements that prohibit those providers from using your content to train their models. Summaries and action items can optionally sync to the agency's own CRM (Pipedrive or HubSpot) when the agency connects one.
- Where it is stored: audio files are stored encrypted (AES-256, server-side KMS encryption) on AWS S3 in the United States with UUID-only filenames that contain no personal information. Transcripts and summaries are stored in our Supabase (PostgreSQL) database in the United States with row-level security restricting access to the owning account and agency. In the mobile app, your recordings are also saved locally on your device — that on-device copy is fully under your control and can be deleted in the app at any time.
- Who can access it: the account holder and, where team features are enabled, members of the same agency. We do not sell or share meeting content with any third party. Applied AI staff do not access meeting content except as necessary to respond to a support request initiated by the agency. Meeting content is never used for advertising and never used to train AI models.
- Consent: the person operating MeetingIQ is responsible for complying with applicable recording-consent laws in their state and obtaining any required consent from meeting participants before recording.
- Retention and deletion: meeting recordings, transcripts, and summaries are retained while the agency's MeetingIQ subscription is active. Agencies can delete individual meetings at any time from the dashboard, which permanently removes the audio, transcript, and summary; deletion requests can also be sent to info@appliedaijax.com.
SMS / Text Messages
If you provide your mobile phone number through one of our website forms (the contact form at /contact-applied-ai, the SMS sign-up form at /sms-signup) or during signup for one of our software products, and you explicitly check the SMS consent checkbox, we use your phone number to send you SMS text messages as described below.
Types of messages:
- Transactional account notifications — meeting and appointment booking confirmations, calendar reminders, reschedule and cancellation notices, meeting recording-ready alerts (MeetingIQ), and account security notifications such as password changes or logins from new devices.
- Product updates — occasional informational messages when we release a new product, ship a major feature, or publish a guide built for insurance agencies. You only receive these if you opted in via the SMS sign-up form.
Message frequency: Message frequency varies based on your account activity and the product flows you trigger. We do not send recurring scheduled marketing blasts. Most users receive fewer than four messages per month; up to eight messages per recipient per month for higher-activity accounts.
Message and data rates may apply. Carrier charges from your wireless provider apply per message received; Applied AI Partners does not charge you to receive messages.
How we share mobile information: No mobile information — including phone numbers, opt-in status, or any data collected through SMS opt-in — is shared, sold, rented, or transferred to any third party or affiliate for their own marketing or promotional purposes. This restriction applies regardless of any other consent or opt-out preferences you have set. Mobile information is shared only with subprocessors that operate the underlying SMS delivery infrastructure (e.g., Twilio Inc., our SMS provider) solely for the purpose of delivering the messages you opted in to receive. We do not sell or share mobile information with advertising networks, data brokers, or third-party marketers.
Opt-out: You may stop receiving SMS messages at any time by replying STOP to any message. We will immediately and permanently remove your number from the sending program. You may also reply HELP for support information, or contact us at info@appliedaijax.com or (904) 830-9969.
Storage and retention: Phone numbers are stored encrypted at rest in our Supabase (PostgreSQL) database in the United States, with row-level security policies that restrict access to authorized service accounts. If you opt out via STOP, your number is moved to a suppression list to prevent further messages and retained for a minimum of three years to comply with TCPA record-keeping requirements; after that retention period, the number is deleted from our systems.
Your Rights
You have the right to:
- Request access to your personal data
- Request correction or deletion of your data
- Opt out of marketing communications
- Request information about how your data is used
Contact Us
If you have questions about this Privacy Policy or your personal data, contact us at:
- Email: info@appliedaijax.com
- Phone: (904) 830-9969
Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date.