Privacy Policy
Last updated: July 2026
This Privacy Policy explains how DeskAI ("we", "us", "our"), operated by Little Stone Haven in Australia, collects, uses, and protects information when you use the DeskAI service.
DeskAI is an AI-powered SMS receptionist service for small businesses. We answer inbound SMS on behalf of business owners, book appointments in their calendar, and hand human takeover back to the business owner when appropriate.
1. Who this policy applies to
This policy applies to two distinct groups:
- Business customers — the businesses that subscribe to DeskAI to answer their SMS on their behalf.
- End users — the members of the public who send SMS to a phone number operated by a DeskAI business customer.
Business customers see the full text of every message their end users send. DeskAI is a tool the business uses to serve its customers; it does not replace the business's own relationship with, or privacy responsibilities to, its customers.
2. Information we collect from business customers
- Account details: name, business name, email address, phone number, and (if provided) industry.
- Configuration data: staff roster, opening hours, pricing, service list, teaching rules the customer authors, and any operational notes needed for the AI to answer correctly.
- Payment details: handled entirely by our payment processor. We do not store card numbers on our servers.
- Integration credentials: OAuth tokens for services the customer connects (e.g. Google Calendar). We store the refresh token so we can continue writing to the customer's calendar without asking them to re-authorise every session. See section 6 for how Google user data specifically is handled.
3. Information we process about end users
When an end user sends an SMS to a DeskAI-operated number, we process:
- The end user's phone number.
- The content of every message the end user sends.
- Any information the end user volunteers in conversation (e.g. name, preferences, booking times).
- Automatically generated conversation metadata: timestamps, AI reply decisions, and — for quality assurance — any operator ratings, corrections, or teaching notes.
We use this information solely to (a) respond to the SMS conversation, (b) book or update appointments on behalf of the business customer, and (c) improve the AI's replies. End-user data is scoped to the business customer whose number the end user contacted; it is not shared across customers.
4. How we use information
- To operate the DeskAI service — replying to SMS, booking appointments, notifying business customers of new bookings.
- To train and improve our AI. Training uses aggregated and de-identified conversation data. Business customers may opt out of contributing their conversations to model training in Settings.
- To detect and prevent spam, fraud, and abuse.
- To comply with applicable laws.
5. Data sharing
We do not sell personal information. We share limited data only with:
- Service providers who help us operate DeskAI: telephony (Twilio), AI model provider (Anthropic), cloud hosting (Amazon Web Services), payment processing. Each is bound by data-processing terms.
- Law enforcement, when lawfully required.
- Successors, in the event of a business transfer.
6. Google user data
When a business customer connects their Google account to DeskAI, we request access to their Google Calendar. We use this access strictly to:
- Read events on the connected calendar so we can quote availability accurately in SMS replies.
- Create, update, and delete events on the connected calendar as bookings are made, moved, or cancelled through DeskAI.
DeskAI's use of information received from Google APIs adheres to Google API Services User Data Policy, including the Limited Use requirements. Specifically, Google user data:
- Is used only to provide or improve user-facing features that are prominent in DeskAI's user interface — namely, availability checks and appointment scheduling.
- Is not transferred to third parties except as necessary to provide those features, in compliance with applicable law, or as part of a merger or acquisition where the acquirer is bound by the same policy.
- Is not used for serving advertisements.
- Is not read by humans, except with the user's explicit consent, for security or debugging by a small number of authorised operators, or as required by law.
Business customers can disconnect their Google account at any time from the DeskAI dashboard, which revokes DeskAI's stored refresh token immediately. For more detail, see our Google User Data Usage disclosure.
7. Data retention
We retain conversation and booking data for as long as a business customer's account is active. When an account is closed, we delete or anonymise that customer's data within 90 days, except where retention is required by law (e.g. tax records).
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal information. Contact us at privacy@deskai.com.au and we will respond within 30 days.
9. Security
We use industry-standard security controls: encryption in transit, encrypted storage of sensitive credentials (OAuth refresh tokens, API keys), and access controls limiting operator access to the minimum needed. No system is perfectly secure; we notify affected users promptly if a breach affecting their data occurs.
10. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify business customers by email and update the "Last updated" date at the top of this page.
Contact
Questions or requests about this policy: privacy@deskai.com.au