Skip to content
Back to home

Privacy Policy

Last updated: August 1, 2026

1. Who We Are and What This Policy Covers

ProFront ("we," "us") provides an AI-powered front office for businesses. This policy explains what personal information we collect, how we use it, and the choices available. It covers our websites, dashboard, and the AI communication services we operate for our business customers.

Two roles matter throughout:

  • For our customers (the businesses that sign up), we are the "business"/controller for their account information.
  • For their customers and callers (the people who talk to a business's AI assistant), we act as a service provider/processor on the business's behalf. The business is responsible for its own privacy notices to its customers. Section 7 covers this in detail.

2. Information We Collect

  • Account data: name, business name, email, phone, password credentials, team member details, plan and settings.
  • Business knowledge: content you upload or configure for your assistant (FAQs, documents, business details, staff and contact directories).
  • Conversation records: for calls, texts, and chats handled by the Service — transcripts; call recordings when the business enables recording; message content; caller/contact identifiers such as phone numbers, names, and emails; and structured records of the actions the assistant took during a conversation (for example, a booking created or a message sent), together with snapshots of the configuration in effect.
  • Appointments and contacts: records the Service creates or manages for the business.
  • Billing data: subscription and usage records; payment card details are collected by our payment processor (Stripe), not stored by us.
  • Usage and device data: log, device, and interaction data for the dashboard and websites. We use cookieless analytics and only strictly necessary cookies (sign-in, security, payment). No advertising trackers.
  • Demo data: if you request a demo, the business details and contact info you provide, used to generate and deliver the demo.

3. How We Use Information

We use the information above to:

  1. Provide the Service — answer and conduct conversations, take messages, book appointments, send communications the business has configured or requested, and maintain the dashboard.
  2. Operate automated quality and safety review. We run automated checks on every conversation record (deterministic rules) and AI-assisted review on flagged or sampled conversations, to detect safety issues, abuse, malfunction, quality drift, and compliance risks.
  3. Take bounded protective actions when review detects likely harm — for example reverting a recent configuration change or holding a capability — surfaced to the affected business in its dashboard.
  4. Validate improvements ("replay"). We may re-run past conversations against updated software or configuration in a sandboxed environment that never contacts a real person.
  5. Improve the platform using de-identified and aggregated patterns across customers (Section 12). We do not use your customers' personal information to train third-party foundation models.
  6. Bill, secure, and support — process payments, prevent fraud and abuse, provide support, meet legal obligations.
  7. Communicate with our customers — service notices, and marketing to business contacts with unsubscribe honored.

4. AI Processing

Conversations handled by the Service are processed by AI systems, including third-party large-language-model and voice providers acting as our subprocessors. Model providers are contractually restricted to processing conversation content to provide the Service; they do not use it to train their models, and any retention on their side is limited to transient operational purposes such as response caching and abuse prevention under their agreements with us.

5. Third-Party Service Providers

We share personal information only with service providers that help us run the Service (hosting, telephony, AI inference, voice synthesis, payments, email), under contracts restricting their use of it. The current list is published at /legal/subprocessors and is incorporated here. We update that page when providers change; material changes follow the notice mechanism in Section 16. We do not sell personal information and do not share it for cross-context behavioral advertising.

5a. Business Transfers

If ProFront is involved in a reorganization, incorporation, merger, acquisition, financing, or sale of all or part of its business, personal information may be transferred to the successor or acquirer as part of that transaction, subject to this policy's commitments. We will provide notice of any transfer that results in your information becoming subject to a materially different privacy policy.

6. Data Retention

  • Account, business knowledge, appointments, contacts: retained while the account is active.
  • Conversation records: transcripts and messages are retained while the account is active, unless the business configures a shorter retention window in its settings. Call transcripts and summaries are retained by ProFront for 12 months by default; a business can configure this in its settings. Call audio is stored by our voice provider, not by ProFront, and is subject to that provider's own retention window, which is shorter than the period above — ProFront does not keep a separate copy of call audio. Conversation-activity records used by our quality and safety systems are automatically deleted after 90 days.
  • Billing and consent records: retained as required for legal, tax, and audit purposes, including records proving acceptance of terms and opt-out requests.
  • On account deletion: permanent deletion within 30 days per the Terms of Service, except the legal/tax/consent records above, de-identified or aggregated data (Section 12), and backup copies that age out on the backup cycle.

7. Your Customers' Data (When We Act as Processor)

If you are a customer or caller of a business that uses ProFront, that business controls your information; contact the business for its privacy practices, including access and deletion requests, which we support the business in honoring.

For our business customers: we process your customers' personal information on your documented instructions (your configuration and requests in the Service) for these processing modes:

  • Handling inbound conversations on your behalf across voice, SMS, and chat;
  • Placing outbound calls and messages you configure or request (for example appointment reminders and callbacks), with platform-enforced opt-out handling, contact-time limits, and identification;
  • Passing information between your assistants (for example your customer assistant consulting your business assistant) within your account;
  • Recording calls where you enable it, with disclosure played;
  • The automated review, protective-action, and replay processing in Section 3;
  • Creating and maintaining records (contacts, appointments, messages) in your dashboard.

The Data Processing Addendum (available at /legal/dpa and incorporated into our Terms) states these commitments contractually, including confidentiality, subprocessor flow-down, security, breach notice, and deletion.

8. Security

We maintain administrative, technical, and organizational safeguards appropriate to the data we process, including encryption in transit, access controls with row-level security, service-role isolation for sensitive stores, redaction of certain sensitive values in conversation-activity records, and audit trails. No system is perfectly secure; we notify affected parties of breaches as required by law.

9. AI Accuracy

AI-generated content can be inaccurate. Businesses are responsible for reviewing AI output they rely on. See the Terms of Service for the full disclaimer.

10. Cookies

We use only strictly necessary cookies (authentication, session security, payment) and cookieless analytics. Because we do not use advertising or cross-site tracking cookies, we do not show a cookie consent banner. If that changes, this policy and the site will be updated first.

11. California and US State Privacy Rights

Where state privacy law applies to personal information we hold as a business/controller, you have rights to know/access, delete, correct, and to opt out of sale or sharing (we do not sell or share personal information for advertising), without discrimination. Business customers can exercise access and deletion self-serve in Settings → Data & Privacy (full export and account deletion). Others may contact us per Section 17; where we act as processor we will route the request to the controlling business and assist. We honor these requests as required by law and verify identity before acting.

12. De-identified and Aggregated Data

We derive de-identified, aggregated patterns from usage of the Service (for example, categories of failure modes across many conversations) to improve safety and quality. This data no longer identifies a person or a specific business, we commit to not re-identifying it, and it may be retained after deletion requests. Records that still identify you are handled per Sections 6 and 11.

13. International

The Service is operated from the United States and offered to US businesses. If you access it from elsewhere, your information is processed in the US.

14. Data Processing Addendum

Our DPA is published at /legal/dpa and applies to all business customers as part of the Terms of Service. Signed copies are available on request for customers whose procurement requires an executed counterpart.

15. Children

The Service is not directed to children under 13 and we do not knowingly collect their information. Businesses must not configure the Service for child-directed use.

16. Changes to This Policy

We will post updates here and give at least 14 days' notice of material changes via the dashboard and/or email before they take effect.

17. Contact

Privacy requests and questions: privacy@profront.ai