DavidAgents

Privacy Policy

Privacy

DavidAgents is operated by JDMTECHSOLUTIONS LLC dba DavidAgents. This policy describes how we collect, use, and protect your data across our public site, apps, and services. Last updated August 2026.

What we collect. We collect user data — specifically: contact and account information you provide (name, organization, email, phone); the content of communications you have with us or with our AI agents (messages, emails, call recordings and transcripts where enabled); files and documents you upload or share with the service; usage and device information (pages visited, actions taken, IP address, browser type); and payment records processed by our payment provider (we never store card numbers). We collect it when you submit a form, sign up, communicate with us on any channel, or use the products. We use it to provide and improve the service, follow up on your inquiries, keep consent and compliance records, and meet legal obligations — and for nothing else without asking.

Lead forms collect the information a visitor chooses to submit, such as name, organization, email, phone, preferred contact method, and automation request. Submissions route to governed internal systems for sales follow-up, delivery planning, consent records, and service improvement.

How we use AI. Our products are built on artificial intelligence: AI agents read and write messages, answer and place phone calls, draft documents, and act on your requests. That means data you share with us — messages, call audio and transcripts, documents, account context — is processed by AI systems to produce the service you asked for. Some of that processing happens on AI models hosted by third-party providers under the terms below; some happens on models we run on our own infrastructure. We do not use your data to train AI models, and our providers are chosen so that API content is not used for training by default. Where an AI agent takes an action with real-world effect, it operates inside a policy-and-compliance gate with an auditable record.

Third-party processors. We send data to third-party processors only as needed to run the service: Cloudflare (network delivery, storage), Anthropic and other AI model providers (agent reasoning over the content you send), Telnyx (telephone calls and text messages), Stripe (payments), and ElevenLabs (voice synthesis). Each receives only what its function requires, under its own data-processing terms, and none may use your data for their own marketing. Everything else runs on infrastructure we operate ourselves.

SMS consent is not combined with email or phone-call consent. SMS opt-in is collected only through an explicit checkbox, and SMS sends remain governed by consent, approved-recipient proof rules, 10DLC campaign controls, and STOP/HELP handling. Mobile opt-in data will not be sold, rented, or shared for third-party marketing.

Call recording & transcription. When call recording is enabled for a contact, phone calls between you and DavidAgents (whether placed by a human team member or by one of our AI voice agents) are recorded as mp3 audio files and transcribed to text. The recording and transcript are stored on your record in our CRM and are visible to our team and to AI agents that have been authorized for your account. Recording is used for service quality, training, dispute resolution, and to help our team and AI agents remember the context of prior conversations so you don't have to repeat yourself.

Recording is optional and configurable. We capture your consent at sign-up, on your tokenized preferences page (linked in every email and SMS we send), and verbally when you take an AI-driven call (we disclose at the start of the call when we don't already have your consent on file). You can change your mind at any time by saying so on a call, replying to an SMS or email, or visiting your preferences page. If you decline, calls still happen — we just don't record them. Recordings are retained for as long as the related CRM record is active and are not sold, rented, or shared for third-party marketing.

Cookies & site tracking. Essential cookies (sign-in sessions and security) are always on — the site can't work without them. Everything else asks first. Our own cookieless analytics (Umami, self-hosted, no cookies, no cross-site tracking) counts pageviews in aggregate. If you click Accept on our consent notice, two optional tools also run: Google Analytics (third-party usage measurement) and session replay (OpenReplay, self-hosted on our own servers) which records how the page is used — scrolls, clicks, navigation — so our team can watch a session to improve the site and follow up on inquiries. Session replay never captures what you type: form values, emails, and numbers are masked before anything leaves your browser. If you submit a lead form, your session may be linked to your inquiry so the person following up has context. If you click Decline, neither optional tool runs — only essential cookies and cookieless aggregate counts remain. We honor Global Privacy Control and Do Not Track browser signals automatically as a decline, and you can change your choice any time by clearing this site's browser storage.

How we protect your data. We apply layered safeguards to all personal data, and additional care to sensitive data — including authentication credentials, OAuth tokens and API keys, call recordings and transcripts, message content, and any personal data we receive from platforms such as Google or Meta. In transit: all data moving between you, our services, and third-party APIs is encrypted with TLS (HTTPS); internal service-to-service traffic runs over private, access-controlled networks. At rest: data is stored on infrastructure we operate ourselves; secrets — credentials, OAuth tokens, API keys, and signing keys — are held in a dedicated encrypted secrets vault, never in plaintext configuration or source code, and are decrypted only in memory at the moment of use. Access controls: access to systems and data requires authenticated identity through our single-sign-on provider and is granted on a least-privilege basis; each customer's data is isolated so one customer can never read another's; automated agents operate under scoped, per-agent credentials that limit what each can reach. Operational safeguards: outbound actions and messages pass a policy-and-compliance gate before they execute, sensitive values are redacted from logs and agent outputs, and access is auditable. Retention & deletion: we keep personal and sensitive data only as long as needed to provide the service or meet a legal or billing obligation, and delete it on request as described under Data deletion. No method of transmission or storage is perfectly secure, but these measures are designed to protect your data against unauthorized access, disclosure, alteration, and loss.

Google user data (YouTube connections). If you connect a YouTube channel to our social publishing tools, we request only the narrow Google permissions needed to operate the feature: your basic profile and email address (to identify the connecting account), read-only access to your channel and video metadata (to show your channel name, picture, and the status of posts we published), permission to upload videos and set thumbnails (to publish the content you schedule), and read-only YouTube Analytics (to show you how your own posts performed). Access: we access your channel identity, the metadata of videos we publish for you, and per-video/per-channel analytics metrics. Use: this data is used solely to provide the publishing and reporting features you see in the product — connecting your channel, publishing the posts you schedule, and displaying your own post performance back to you. Transfer: we do not sell, rent, or share Google user data with any third party; it is processed and stored on our own self-hosted infrastructure and sent only to Google's own APIs to perform the actions you request. Protection: OAuth tokens are stored encrypted on access-controlled servers we operate, transmitted only over TLS, and are never exposed to other customers. Retention & deletion: tokens and cached channel data are kept only while your channel remains connected; disconnecting the channel in the product, requesting deletion (see below), or revoking access in your Google security settings removes our access, and we delete stored tokens and cached Google data within 30 days. AI/ML: we do not use Google user data to develop, improve, or train AI or machine-learning models, and we do not transfer it to any third-party AI service. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Government & public authority data requests. Requests from government or public authorities for personal data — including data we receive from platforms such as Meta or Google — are governed by our Government Data Request Policy: every request undergoes a required legality review before any response; we narrow or challenge requests that are unlawful or overbroad; when disclosure is lawfully compelled we disclose only the minimum data necessary; and we document every request, our legal reasoning, and our response. Where lawful, we notify affected users before disclosure. To date we have received zero such requests, including national security requests.

Data deletion. You can request deletion of your personal data at any time — including data collected through our website, lead forms, calls, SMS, or social platform integrations (such as Facebook or Instagram lead forms and logins). To request deletion, email [email protected] from the address on file, reply DELETE to any SMS from us, or say so on any call — an agent or team member will confirm and process it. We delete your CRM record, associated recordings, transcripts, and consent records within 30 days, except where a legal or billing obligation requires longer retention (we tell you if so). Facebook/Instagram users: this page is our data deletion instructions URL — the request routes are the same.

Current status: controlled launch scaffold. Public site deployment, standard Google Analytics 4 aggregate measurement, email proof, Telnyx voice, and approved SMS proof paths are active for launch-readiness review. Live CRM write, public outreach, ads, and paid analytics upgrades remain gated until final approval.