Legal
Privacy Policy
Last updated: June 27, 2026 · Effective immediately for all users.
1. What we collect
We collect business information you provide (name, email, phone, business type, vertical) and operational data generated by the AI agents we deploy for you (call recordings, transcripts, SMS message logs, appointment bookings, CRM updates, lead source attribution, IP address, browser metadata, and UTM parameters when you arrive from a marketing campaign). All data is encrypted at rest with AES-256 and in transit with TLS 1.2+.
2. AI-handled communication — disclosure
Calls and messages handled by NeverMissAgain AI are conducted by artificial intelligence agents (the ‘AI workforce’: Aria, Mira, Rex, Wendy, Quincy, Cal, Cole, Dex, Ace, Reya, Sue, Ozzie, Connie). Every voice call opens with an explicit AI disclosure (“This is an AI assistant”). Every outbound SMS contains an opt-out instruction (“Reply STOP to opt out”), and WhatsApp outreach uses the applicable customer-service-window or approved-template rule. If you are in California, Colorado, Florida, Illinois, Nevada, Oregon, Utah, or another jurisdiction with mandatory AI-disclosure laws, our agents comply with the strictest applicable rule by default. You can request a human at any time and the agent will transfer or escalate.
3. Call recording & transcription
Calls handled by our voice agents are recorded for quality assurance, training, and product improvement. Recordings are retained for a maximum of 7 days and are then permanently and irrecoverably deleted by an automated daily process. Transcripts (text representations of calls) are retained for up to 90 days for operational analytics, then permanently deleted unless you are an active customer and we are processing them as part of your service. You may request immediate deletion of any specific call at any time by emailing privacy@nevermissagainai.com.
4. TCPA & A2P 10DLC compliance (US SMS & voice)
Outbound SMS and AI-initiated voice calls are sent only to recipients who have opted in via affirmative consent (form checkbox, in-conversation reply, or written client agreement). Every outbound message routes through our Compliance Gate, which checks for active consent, Do-Not-Call list status, recipient-local quiet hours (8a–9p), and applies the required opt-out and AI-disclosure language. STOP, UNSUBSCRIBE, QUIT, CANCEL, END, and QUIT are all honored instantly and logged. A2P 10DLC brand and campaign registration is completed before any tenant goes live.
5. How we use data
Your data powers your AI agent stack. We use call transcripts, SMS logs, and CRM events to tune and improve your specific agents. We do not sell customer data. We do not use customer data to train general-purpose AI models without explicit written consent. Subprocessors that process data on our behalf (Vapi for voice infrastructure, Twilio for telephony, Supabase for database hosting, Anthropic for the language model, n8n self-hosted for orchestration) are bound by data-processing agreements (DPAs).
6. Data ownership & portability
You own your tenant data. On written request we export everything (calls, recordings within retention window, messages, leads, conversations, audit logs, contracts) in machine-readable formats (JSON, CSV) within 30 days, and delete our copies within 30 days of export, subject to legal retention obligations.
7. Data retention summary
Call recordings: 7 days, then permanent deletion (automated daily cron). Call transcripts: 90 days. SMS message logs: 90 days. Structured event logs and lead records: 24 months. Contracts and signed agreements: 7 years (legal obligation). Demo-page lead records (people who try our marketing demo): 12 months unless converted to paid customer. CRM-synced data follows the connected platform’s retention. You may request shorter retention in your contract.
8. Your rights (GDPR / UK GDPR / CCPA / CPRA)
Depending on your jurisdiction you have the right to: (a) access the personal data we hold about you, (b) request correction of inaccurate data, (c) request deletion (‘right to be forgotten’), (d) request portability in a machine-readable format, (e) object to processing or restrict it, (f) withdraw consent at any time, and under CCPA (g) opt out of any sale or sharing of personal information (we do neither). To exercise any right, email privacy@nevermissagainai.com from the email address on file. We respond within 30 days (or sooner where required).
9. Cookies & tracking
Our marketing site (nevermissagainai.com) uses essential cookies only — no advertising or analytics trackers are loaded without consent. UTM and referrer parameters are captured at the point of form submission (not as a tracking cookie). The operator dashboard (command center) uses a single HttpOnly session cookie for authentication and does not load any third-party scripts.
10. Children
Our services are not directed to anyone under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, email privacy@nevermissagainai.com and we will delete it.
11. Security incidents
In the event of a security incident affecting your data, we will notify you within 72 hours of confirmation, in writing, with the nature of the incident, the data potentially affected, the steps we have taken, and the steps you should consider. We maintain an incident response runbook and conduct annual tabletop reviews.
12. Changes to this policy
We will email customers about material changes at least 30 days before they take effect. The current version date is shown at the top of this page.
13. Contact
Privacy inquiries: privacy@nevermissagainai.com. Data subject requests: privacy@nevermissagainai.com. Security: security@nevermissagainai.com. General: kasi@nevermissagainai.com.