Scope
This policy explains how AgentBloom handles information when businesses create a workspace, connect communication channels, and use the AI receptionist and staff inbox. A business using AgentBloom controls the customer conversations collected for its workspace. AgentBloom processes those conversations to provide the service.
Information we handle
- Account information such as name, work email, password hash, role, and login-session data.
- Business information such as services, prices, location, hours, policies, phone number, and approved knowledge.
- Information submitted through the free assessment form, such as contact details, business name, industry, website, current inquiry workflow, and the optional marketing-email choice.
- Channel information supplied through authorized Meta, Instagram, or WhatsApp connections, including account identifiers and encrypted access credentials.
- When a workspace owner connects Google Calendar, the calendar identifier, name, time zone, encrypted OAuth credentials, free/busy availability, and details of appointment events created through AgentBloom.
- Customer messages, contact details voluntarily provided in a conversation, appointment interests, staff notes, and conversation status.
- Subscription identifiers and status from PayPal. AgentBloom does not receive or store full payment-card details.
- Technical logs needed for security, webhook delivery, abuse prevention, and troubleshooting.
How information is used
We use information to create and secure workspaces, generate customer replies, route messages to the correct business, display inquiries to authorized staff, maintain subscriptions, prevent abuse, and comply with applicable obligations. Connected Google Calendar data is used only to identify the selected calendar, check availability, and create or cancel appointments requested through the workspace. We do not sell personal information.
Google Workspace API data
The use of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
AgentBloom uses Google Calendar API data only to identify the calendar selected by the workspace owner, check free and busy times, and create, update, or cancel appointments requested by the connected business. Google Workspace API data is not used for advertising, sold, used to build unrelated user profiles, or used to train, fine-tune, or improve any generalized or personalized AI or machine-learning model.
Google Workspace API data is not inserted into AI prompts and is not shared, transferred, or disclosed to Dify, OpenAI, Retell AI, or any other AI or model provider. AgentBloom's AI receptionist receives only business-provided information, approved knowledge, and customer messages. Calendar availability, event contents, calendar identifiers, and Google OAuth credentials remain outside that AI data flow.
Google OAuth credentials are encrypted at rest. A workspace owner can disconnect Google Calendar in AgentBloom at any time, revoke access from their Google Account, or request deletion. Disconnecting removes the stored Google access credentials and stops future calendar access. Appointment records already created in the workspace may be retained for the workspace's normal operational, security, and legal retention periods.
Service providers and data recipients
AgentBloom uses infrastructure and service providers only as needed to deliver enabled features. Our hosting provider stores and processes encrypted platform credentials and operational records on AgentBloom's behalf. Google receives requests required to perform the calendar actions authorized by the workspace owner. Meta platforms process Facebook, Instagram, and WhatsApp messages when those channels are connected. PayPal processes subscription and payment status.
Dify, OpenAI, and Retell AI may process business-provided knowledge and customer conversation content for enabled receptionist or voice features. They do not receive information obtained from Google Workspace APIs. We do not permit any service provider to use Google Workspace API data for advertising or AI or machine-learning model training.
Providers may process permitted information in countries different from the user or business location under their applicable terms, data-processing commitments, and security controls.
Health and sensitive information
AgentBloom is an administrative reception tool, not a medical provider or emergency service. Businesses should configure the system to collect only information necessary for inquiries and booking, and should not use it for diagnosis, treatment decisions, or emergencies.
Security and retention
AgentBloom uses role-based access, password hashing, expiring sessions, audit records, and encrypted storage for platform credentials. No system is completely secure. Information is retained while needed to provide the workspace and for reasonable security, dispute, backup, and legal periods. Businesses may request earlier deletion where applicable.
Your choices
Workspace owners can update business information, remove knowledge, disconnect Google Calendar or other connected channels, and request account or conversation deletion. Google access can also be revoked from the Google Account permissions page. Customers should first contact the business they messaged because that business controls its workspace records.
Marketing permission on the free assessment form is optional. We may still respond directly about an assessment that a person requested. Every permitted AgentBloom marketing email includes a signed unsubscribe link. Using that link immediately places the address on our global marketing suppression list. Necessary account, security, billing, and service messages may still be sent when required.
Contact
Privacy and deletion requests may be sent to xtd508639047@gmail.com. We may ask for verification before changing or deleting account data.