At Splice AI, we take your privacy and data security seriously. This Privacy Policy details what data we collect, how it is used, and the rights you have concerning your personal information when using our service.
1. What Data We Collect
To provide you with an automated and seamless AI assistant experience, Splice AI integrates directly with your existing tools. We collect:
- Account Information: Name, email address, and authentication credentials necessary to create and manage your account.
- Integration Data: Data retrieved from third-party services you explicitly authorize — currently Gmail, Google Calendar, WhatsApp Business (Meta), and Slack — via OAuth. This data is only used to execute the specific tasks you command or the automations you configure (e.g., the AI Agent replying to an inbound WhatsApp lead in your team's voice, or booking a meeting on your Google Calendar).
- Usage Metrics: Anonymous telemetry regarding how you interact with Splice AI, such as the frequency of commands executed, to help us improve service performance.
- Agent Memory: Short summaries of your preferences and working context that the AI builds over time to personalise responses. You can view and delete these at any time from your account settings.
2. How We Use It
Your data is used strictly to provide and improve the user-facing features of Splice AI, and for no other purpose. Specifically:
- Executing Commands: Operating the AI engine to draft emails, arrange calendar events, or manage tasks as requested by you.
- Service Maintenance: Monitoring system health, addressing errors, and maintaining operational security.
- Account Communication (your account email only, not Google user data): Sending you service updates, security alerts, and administrative messages to the email address you registered with. We do not use Gmail content or any other Google user data to contact you.
3. How Long We Keep It
We believe in holding onto data only as long as it is actively useful to you:
- Integration Tokens: OAuth tokens are securely encrypted at rest. If an integration is disconnected, the associated tokens are immediately destroyed.
- Task & Conversation History: Retained while your account is active and purged upon account deletion.
- Account Deletion: Upon requesting account deletion, all associated personal data and integration tokens are deleted within 7 business days (and in all cases within 30 days).
How to delete your account and data
You can request deletion of your Splice AI account and all associated data, including Google user data, at any time:
- Sign in to Splice AI at spliceai.co.
- Open Settings from the sidebar.
- Scroll to the Danger Zone section.
- Click Delete account and confirm.
A confirmation email is sent immediately, and all your data — including tasks, meetings, conversations, knowledge base content, and connected integrations (Gmail, WhatsApp, Slack) — is permanently removed within 7 business days. OAuth tokens are destroyed at the same time, which also revokes Splice AI's access to your Google account. You may additionally revoke access directly at myaccount.google.com/permissions. If you cannot access your account, email support@spliceai.co from your registered address and we will process the deletion manually.
4. User Rights
You retain full control over your data. Depending on your jurisdiction, you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Delete: Request immediate deletion of your account and all associated data.
- Export: Download your data in a portable, machine-readable format.
- Revoke: Instantly revoke Splice AI's access to your connected third-party accounts at any time via your dashboard settings or directly through the third-party provider.
5. Third-Party Integrations & OAuth Compliance
Splice AI's core functionality relies on OAuth integrations. Below we describe each provider, what data is accessed, and our compliance commitment.
Google (Gmail)
Splice AI requests the following Google OAuth scopes in a single unified consent flow:
https://www.googleapis.com/auth/gmail.send— to send Agent-generated replies to prospects from your Gmail address, preserving your sender identity and deliverability. We do not read your mailbox with this scope; it is send-only.https://www.googleapis.com/auth/userinfo.email— to identify the connected Google account to you and associate the integration with the correct Splice workspace.
Inbound email is not read via Gmail API. Instead, you set up a Gmail forwarding rule (one-time setup) that forwards prospect emails to a unique Splice-managed address on inbound.spliceai.co. We receive forwarded emails through our Cloudflare Email Worker, not by accessing your mailbox. This means Splice AI never holds read access to your Gmail inbox.
Google API Services User Data Policy — Limited Use: Splice AI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to provide or improve user-facing features of Splice AI that are prominent in the application's user interface (the AI Agent inbox and reply generation).
- We do not transfer Google user data to others except as necessary to provide or improve user-facing features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with user notice.
- We do not use Google user data for serving advertisements, including retargeting, personalised or interest-based advertising.
- We do not allow humans to read Google user data, except: (a) with your affirmative agreement for specific messages; (b) where necessary for security investigations; (c) to comply with applicable law; or (d) where the data has been aggregated and is used for internal operations in compliance with the Google API Services User Data Policy.
- We do not use Google user data to develop, improve, or train generalised AI and/or ML models. Gmail content is sent to LLM providers (Google Vertex AI — Gemini, OpenAI, and Anthropic — see section 7) only at request-time to generate your Agent's reply, under enterprise data terms that prohibit training on customer content.
Forwarded email content is retained only as long as needed to power ongoing Agent conversations and audit trails for your workspace, and is encrypted at rest. We delete Google user data within 30 days of account deletion or when you disconnect the Google integration. OAuth tokens are encrypted at rest, never exposed to third parties or LLM providers, and immediately destroyed on disconnection.
Google Calendar
If you connect Google Calendar, Splice AI requests the https://www.googleapis.com/auth/calendar.events scope. This scope is used only to: create a calendar event (with a Google Meet link) on your primary calendar when a meeting is booked from the AI Agent inbox or by your Agent on a call; update or cancel that event if the meeting time changes or is cancelled; and read existing events on your primary calendar to check free/busy availability before proposing a meeting time. We do not access any calendar other than your primary calendar, and we do not read or modify calendar settings, sharing permissions, or other users' calendars.
Calendar event data (titles, times, locations, and attendee emails you or your Agent add) is encrypted at rest and used only to power the meeting-scheduling feature described above. We delete Google Calendar data within 30 days of account deletion or when you disconnect the Google Calendar integration. As with Gmail, our use of this scope adheres to the Google API Services User Data Policy Limited Use requirements: we do not use Calendar data for advertising, do not allow humans to read it except under the same narrow exceptions described above, and do not use it to develop, improve, or train generalised AI/ML models.
WhatsApp Business (Meta)
Splice AI connects to your WhatsApp Business Account via the WhatsApp Business Cloud API provided by Meta. When you authorise the integration, we request the whatsapp_business_messaging and whatsapp_business_management permissions to send and receive messages on your behalf and to read basic account configuration (phone number ID, display name, business profile).
We receive and store: inbound and outbound message content (text, media references, interactive message payloads), sender and recipient phone numbers, timestamps, delivery and read receipts, and message metadata. This data is used to power the AI Agent (generating context-aware replies trained on your team's own past conversations), maintain conversation continuity across sessions, schedule meetings, escalate to a human when the Agent is under its confidence threshold, and provide audit logs to your team.
WhatsApp message content and access tokens are encrypted at rest. We retain messages for the lifetime of your account and delete them within 30 days of account deletion or when you disconnect the WhatsApp integration. We do not use your WhatsApp data to train general-purpose AI models, do not sell or share it with advertising networks, and do not share it with other Splice AI customers. The only external processors that handle WhatsApp content are the LLM providers strictly required to generate your Agent's replies (Google Vertex AI — Gemini, OpenAI, and Anthropic — see section 7), under enterprise data terms that prohibit training on customer content.
Our use of the WhatsApp Business Platform complies with the WhatsApp Business Solution Terms, the WhatsApp Business Messaging Policy, and the Meta Platform Terms. You may revoke Splice AI's access at any time from your Splice dashboard or directly in the Meta Business Suite.
Instagram (Meta)
Splice AI connects to your Instagram professional account through Instagram Login, using the Instagram API with Instagram Login. When you authorise the integration, we request two permissions:
instagram_business_basic— to read the account ID and username of the Instagram professional account you connect. The username is shown in your dashboard so you can confirm which account is linked; the account ID lets us route incoming messages to the right workspace. We do not request your profile picture, follower count, media count, or any other profile field, and we never read the profile of any account other than the one that authorised Splice AI.instagram_business_manage_messages— to receive Instagram Direct messages sent to your account and to send replies on your behalf.
We receive and store: inbound and outbound direct message content, the sender's Instagram-scoped user ID, their username or display name where Instagram provides it, message IDs, and timestamps. This data is used to power the AI Agent (generating context-aware replies from your own knowledge base and past conversations), maintain conversation continuity, escalate to a human when the Agent is below its confidence threshold, and provide audit logs to your team. We do not access your posts, stories, comments, insights, media, or follower list.
Instagram message content and access tokens are encrypted at rest. We retain messages for the lifetime of your account and delete them within 30 days of account deletion or when you disconnect the Instagram integration. We do not use your Instagram data to train general-purpose AI models, do not sell or share it with advertising networks, and do not share it with other Splice AI customers. The only external processors that handle Instagram message content are the LLM providers strictly required to generate your Agent's replies (Google Vertex AI — Gemini, OpenAI, and Anthropic — see section 7), under enterprise data terms that prohibit training on customer content.
Instagram permits businesses to send free-form replies only within 24 hours of a customer's last message; outside that window Splice AI sends a reply only when a human on your team writes it, using Meta's Human Agent tag, and never for an automated reply. Our use of the platform complies with the Meta Platform Terms and the Messenger Platform Policy. You may revoke Splice AI's access at any time from your Splice dashboard, or from Instagram under Settings → Website permissions → Apps and websites. Revoking access from Instagram notifies us automatically and we delete the stored token and connection.
Slack (optional)
If you connect Slack, Splice AI uses the official Slack OAuth flow to post escalation notifications to a channel you designate — for example, when the Agent's confidence drops below 95% on a prospect question and it needs human input. We request the minimum scopes needed to post into the channel you authorise. We do not read messages in other channels, do not access your Slack workspace's member list beyond what is necessary to post, and do not use Slack data to train AI models. Our integration complies with the Slack API Terms of Service.
6. Data Protection & Security
Splice AI uses industry-standard safeguards to protect personal data and integration data, including data classified as sensitive (such as email content received via Gmail, Google Calendar event details, WhatsApp Business message bodies, and OAuth tokens). The following technical and organisational mechanisms are in place:
- Encryption in transit: All traffic between your browser, our servers, and third-party APIs is encrypted using TLS 1.2 or higher. Our origin is fronted by Cloudflare with HSTS enforced; HTTP requests are upgraded to HTTPS automatically.
- Encryption at rest: All persistent data stores (PostgreSQL on Amazon RDS, Redis on ElastiCache, object storage on Amazon S3) use AES-256 encryption at rest, managed via AWS KMS. OAuth tokens and other secrets are additionally encrypted at the application layer before being written to disk.
- Access controls: Production database access is restricted to a private subnet reachable only from our application servers. No Splice AI employee has direct read access to customer Gmail content, WhatsApp message bodies, or other sensitive integration data in the normal course of operations. Privileged access for security investigations is logged, time-bound, and requires explicit justification.
- Authentication & session security: Account access is gated by OAuth (Google, Microsoft) or email plus a one-time password. Session tokens are HTTP-only, Secure, and SameSite=Lax. Session tokens are hashed before storage so even a database compromise does not yield usable credentials.
- Network isolation: Application servers, databases, and worker queues run in a private VPC. Public ingress is restricted to the ports and paths necessary for the user-facing application; no database or Redis port is publicly reachable.
- Backups & deletion: Automated daily encrypted backups of the primary database are retained for 14 days, then permanently destroyed. On account deletion, customer data is purged from primary stores within 7 business days and from all backups within the standard 14-day backup window.
- Subprocessors: A current list of subprocessors that may process customer data is available on request to support@spliceai.co. Each subprocessor is bound by data-processing terms that prohibit using customer content to train AI models or for any purpose outside delivering their service to us.
- Incident response: In the event of a data breach affecting your personal data, we will notify you and the relevant supervisory authorities without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
7. AI / ML Disclosure
Splice AI does not train, develop, or operate its own foundation models. All AI inference (generating Agent replies, classifying messages, extracting structured data) is performed by the following third-party AI providers, each of which is bound by data-processing terms that prohibit training on customer content:
- Google Cloud — Vertex AI (Gemini models). Customer content sent to Vertex AI is processed under Google's Cloud Data Processing Addendum and the Vertex AI Generative AI data governance terms, which prohibit Google from using customer prompts or responses to train Google's foundation models.
- OpenAI — API (ChatGPT / GPT models). Customer content sent to the OpenAI API is processed under OpenAI's Business Terms and Enterprise Privacy commitments. Per OpenAI's default API policy in effect since March 1, 2023, data submitted to the API is not used to train or improve OpenAI's models.
- Anthropic — API (Claude models). Customer content sent to the Anthropic API is processed under Anthropic's Commercial Terms of Service and the Anthropic data-training policy, under which inputs and outputs submitted via the commercial API are not used to train Anthropic's models.
Routing of a given request to one of the providers above is determined by feature suitability and cost. In every case the request is made over TLS, contains only the minimum content needed to produce the response, and discards the response on our side as soon as the user-facing feature has consumed it.
We affirm explicitly, in compliance with the Google API Services User Data Policy and the Workspace API user data and developer policy: we do not use Google Workspace API data (including Gmail message content received via forwarding, Gmail addresses, Google Calendar event details, or any field accessed via Google OAuth scopes) to develop, improve, train, or fine-tune generalised AI/ML models — whether our own, any of the AI providers listed above, or any other third party. Workspace data sent to any provider above is used only at request-time to generate the specific user-facing output (e.g. one outbound reply) and is not retained by the provider for training.
Any future addition or change of AI subprocessor will be subject to equivalent contractual prohibitions on training on customer content, and this policy will be updated to reflect the change before the new subprocessor begins processing customer data.
8. GDPR & CCPA Compliance
For EU Users (GDPR): Splice AI acts as a Data Controller for your account information and a Data Processor for the content fetched from your integrations. We rely on your explicit consent and the necessity to fulfill our contract with you as lawful basis for processing.
For California Residents (CCPA): We do not "sell" your personal information, nor do we "share" it for cross-context behavioral advertising. You have the right to request disclosure of our data collection practices and request deletion of your data.
9. Contact Us
If you have questions about this Privacy Policy or wish to exercise any of your data rights, please contact our privacy team at: