Privacy Policy
Privacy Policy
Privacy Policy — Appointwise
Last updated: 13 July 2026
Appointwise ("we," "us," "our") provides tools that help businesses manage, qualify, and book appointments with their leads, including AI-assisted messaging. This Privacy Policy explains what data we collect, how we use it, with whom we share it, how long we keep it, and how you can exercise your rights. It applies to our websites, products, and services (the "Services").
If you are a lead or customer of a business that uses Appointwise (for example, you received text messages from a business using our technology), please see Section 2 ("Our Role: When We Act as a Processor") — the business you communicated with is responsible for your data, and you should direct privacy requests to them. We support them in fulfilling your requests.
If you connect a Google account to Appointwise, this policy also explains our handling of Google user data obtained via Google OAuth. If you connect a Facebook Page or Instagram professional account, this policy also explains our handling of Meta Platform Data obtained via Meta's APIs.
1) Data We Collect
Account & Contact Data. Name, email address, company name, role, and password (hashed).
Usage & Device Data. IP address, browser/OS, pages viewed, app interactions, and diagnostic logs.
Customer Content. Information you upload or generate in the Services (e.g., strategy configuration, prompts and "briefs," knowledge-base documents, workflow settings).
Lead & End-User Data (processed on behalf of our business customers). When a business uses the Services to communicate with its leads and customers, we process those individuals' personal data on the business's behalf. This may include: names, phone numbers, email addresses, the content of conversations (SMS and other channels), appointment details, time zone and general location information, tags and qualification status, and any other information the individual chooses to share in a conversation. Conversation content may incidentally include sensitive information an individual volunteers (for example, health context shared with a healthcare-related business); we process such content only to provide the Services to that business.
CRM & Calendar Integration Data. If a business connects a third-party platform such as GoHighLevel ("GHL"), Google, or Meta (Facebook and Instagram), we access and process the data needed for the enabled features — for example contacts, conversations, calendars and appointments, and the authentication tokens required to act on the business's behalf. Tokens are stored encrypted.
Google User Data (via OAuth). If you authorize Appointwise, we access only the Google data necessary for the features you enable. Examples include:
Basic profile info (e.g., name, email) to identify your account;
Calendar data to create or read events you ask us to manage;
Gmail metadata or content only if you explicitly enable features that require it (e.g., reading specific messages to create appointments);
Contacts data to view or add contacts you direct us to manage.
We do not collect Google user data without your explicit authorization, and we do not use device microphones/cameras unless you opt in for a feature that needs them.
Meta Platform Data (Facebook & Instagram). If a business connects its Facebook Page or Instagram professional account, we access, with the business's explicit authorization via Meta's login flow, only the Meta data needed for the features enabled. This may include:
The list of Pages the business manages and basic Page metadata (name, picture, linked Instagram professional account), used to set up and display the integration;
Page access tokens (stored encrypted), used to act on the business's behalf;
The content of Messenger and Instagram direct-message conversations between the business and its leads, so the AI-assisted features can receive and respond to those messages on the business's behalf;
Lead-form submissions from the business's Facebook Lead Ads, so new leads can be created in the business's account and contacted.
We do not access the personal profiles, friends lists, or feeds of individuals who message the business. We do not collect Meta Platform Data without the business's explicit authorization.
2) Our Role: When We Act as a Processor
For Account & Contact Data and Usage & Device Data, Appointwise is the data controller.
For Lead & End-User Data and Customer Content, Appointwise acts as a data processor (or "service provider" under US state laws) on the documented instructions of the business customer, which is the data controller. The business — not Appointwise — determines the purposes of the processing, is responsible for having a lawful basis to contact its leads (including any required consents for SMS/marketing communications), and is the correct first point of contact for individuals' privacy requests. Where a lead contacts us directly, we will refer the request to the relevant business and provide reasonable assistance. Our Data Processing Agreement is available to business customers on request from hello@appointwise.io.
3) AI-Assisted Features & Automated Processing
The Services use artificial intelligence, including large language models (LLMs), to draft and send conversational replies, qualify leads, propose and book appointment times, and execute related workflow steps that businesses configure.
What the AI processes. To generate responses, relevant conversation history, configuration (e.g., the business's brief and booking rules), and appointment availability are submitted to our AI service providers.
AI service providers. We use vetted third-party AI providers (currently including OpenAI) strictly as processors to provide these features. Under our API terms with these providers, content submitted via their APIs is not used to train their models, and is retained by them only for a limited period for abuse monitoring under their policies.
Automated communications and decisions. AI-generated messages are sent automatically within the rules configured by the business. The Services may automatically update a lead's status (for example, marking a conversation complete, lost, or booked). These automations affect how and whether the business follows up; they are reviewable and reversible by the business, and individuals may request human review or human contact at any time by asking in the conversation or contacting the business directly.
Transparency. Appointwise agents are designed not to deny being automated: if an individual asks whether they are talking to an AI, the agent is instructed to confirm it.
Human oversight. Businesses can review every AI conversation, take over conversations manually, and disable the AI per lead or per account at any time. We log AI actions to support audit and review.
4) How We Use Data
We use data to:
Provide, operate, secure, and troubleshoot the Services, including the AI-assisted features described in Section 3;
Authenticate you and manage your account and connections (e.g., Google OAuth, GHL, Meta);
Perform actions you request (e.g., read a calendar, create an event, send a message to a lead, add a contact);
Improve the Services (analytics, testing, research) — using aggregated or de-identified data where feasible;
Communicate with you (support, product updates, security notices);
Comply with law and enforce our terms.
Google user data is used only to provide the features you've enabled and for no other purpose. We do not use Google user data for advertising, profiling unrelated to the requested features, or building unrelated datasets. Meta Platform Data is likewise used only to provide the features the business has enabled and for no other purpose.
5) With Whom We Share, Transfer, or Disclose Data
We do not sell your personal information, Lead & End-User Data, Google user data, or Meta Platform Data.
We disclose data only in these situations:
Service Providers (Processors / Sub-processors). We use vetted third parties under written contracts to process data for us and only as needed to deliver the Services. Categories include: cloud hosting and storage (e.g., Amazon Web Services), AI/LLM providers (e.g., OpenAI), databases and backups, analytics, error monitoring, logging, email delivery, and customer support tooling.
Platforms You Connect. When a business connects a platform such as GHL, Google, or Meta and directs us to act (e.g., send an SMS via GHL, book a calendar slot, reply to an Instagram message), we transmit the data needed to perform that action to that platform. Those platforms process data under their own terms and policies.
Your Direction. We disclose data when you instruct or consent.
Legal, Safety, and Rights. If required by law or in good-faith belief disclosure is necessary to protect you, us, users, or the public (e.g., court order, detecting abuse, preventing fraud).
Business Transfers. If we undergo a merger, acquisition, or asset sale, your data may transfer as part of the transaction, subject to this Policy.
Human Access to Google User Data. Human access is limited and permitted only: (a) with your explicit consent; (b) to comply with applicable law; or (c) for security and abuse investigations, troubleshooting, or debugging. Access is logged and restricted. The same restrictions apply to human access to Meta Platform Data.
6) Google OAuth & "Limited Use" Commitments
For Google user data obtained via OAuth:
We only request the minimal scopes needed for the features you use.
We do not sell Google user data.
We do not share Google user data with third parties except as needed to provide the Services (processors) or as required by law.
We do not use Google user data for serving ads.
We do not allow unauthorized human reading of Google user data.
Google user data is not shared with AI/LLM providers except where strictly necessary for a feature you have explicitly enabled.
You can review or revoke Appointwise's access at any time in your Google Account: https://myaccount.google.com/permissions.
7) Meta Platform Data Commitments
For data obtained via Meta's APIs (Facebook and Instagram):
We request only the permissions needed for the features the business uses, and we use Meta Platform Data solely to provide those features on the business's behalf.
We do not sell Meta Platform Data, use it for advertising, or use it to build profiles unrelated to the requested features.
We share Meta Platform Data only with service providers acting as our processors (for example, cloud hosting, and the AI providers described in Section 3, strictly to generate responses in the business's own conversations) or as required by law.
We do not allow unauthorized human access to Meta Platform Data; human access is limited, logged, and restricted as described in Section 5.
We process Meta Platform Data in accordance with Meta's Platform Terms and Developer Policies.
You can disconnect the Meta integration at any time in Appointwise (Settings → Integrations → Disconnect). You can also remove Appointwise's access from your Facebook settings under Settings → Business Integrations at https://www.facebook.com/settings.
8) Cookies & Similar Technologies
We use cookies and similar technologies to keep you signed in, remember preferences, measure usage, and improve performance. You can control cookies in your browser settings; some features may not function without them.
9) Data Retention & Deletion
General retention.
Account data: kept while your account is active. If you delete your account, we delete or anonymize account data within 30 days.
Customer content and Lead & End-User Data: retained while the business's account is active and as instructed by the business; deleted or anonymized within 30 days after account deletion or upon the business's verified deletion instruction.
AI provider retention: content submitted to AI providers to generate responses is retained by those providers only per their API data policies (typically up to 30 days for abuse monitoring) and is not used to train their models.
Google user data.
OAuth tokens: stored while your Google account is connected; deleted within 7 days after you disconnect or delete your Appointwise account.
Synchronized items (e.g., created events/contacts): we keep only what is necessary to display history in the app. If you delete your account or disconnect Google, related cached Google data is deleted within 30 days.
Indexed/search caches: refreshed frequently and purged within 30 days after disconnection.
Meta Platform Data.
Page access tokens: stored encrypted while the Meta integration is connected; deleted within 7 days after you disconnect Meta or delete your Appointwise account.
Page metadata, Messenger/Instagram conversation content, and lead-form data: retained while the business's account is active; deleted or anonymized within 30 days after disconnection, account deletion, or a verified deletion instruction.
To request deletion of data obtained from Meta, disconnect the integration in-app (Settings → Integrations), or email hello@appointwise.io from your registered address; we will confirm completion by email. Leads and end users who messaged a business on Facebook or Instagram should contact that business, and we will assist it in fulfilling verified requests.
System logs containing incidental identifiers may persist for up to 90 days for security and audit, then are deleted or anonymized. Encrypted backups roll off within 35 days under standard backup rotation.
Inactivity. We may deactivate and delete accounts with no sign-ins or activity for 18 months, after notice to the registered email.
How to delete data.
Delete your account in-app (Settings → Account → Delete) or email hello@appointwise.io from your registered address.
Disconnect Google at any time in Appointwise (Settings → Integrations) and/or via Google at https://myaccount.google.com/permissions.
Disconnect Meta at any time in Appointwise (Settings → Integrations) and/or via Facebook under Settings → Business Integrations.
If you are a lead/end user, contact the business you communicated with; we will assist them in fulfilling verified requests.
We will confirm completion of deletion requests to your registered email.
10) Your Rights & Choices
Access, correct, or delete your information;
Export your data where technically feasible;
Opt out of non-essential emails;
Withdraw Google permissions at any time (https://myaccount.google.com/permissions);
Withdraw Meta permissions at any time (in-app or via Facebook Settings → Business Integrations);
Object to or request human review of automated processing as described in Section 3.
Leads/end users: because the business you interacted with is the controller of your data, please direct requests to that business. You can also opt out of further messages at any time, including by replying STOP where supported.
To exercise rights, use the in-app controls or contact hello@appointwise.io. We may verify your identity before fulfilling requests.
11) Security
We use industry-standard security measures, including encryption in transit and at rest (including encryption of stored phone numbers and integration tokens), least-privilege access, and continuous monitoring. No method is 100% secure; we will notify you of significant incidents as required by law.
12) International Data Transfers
If we transfer data across borders (including to AI and cloud providers in the United States), we use appropriate safeguards (e.g., standard contractual clauses) as required by applicable law.
13) Age Requirements & Children's Privacy
Account holders. The Services are business tools. You must be at least 18 years old (or the age of majority in your jurisdiction) to create an account or use the Services.
Leads and end users. The Services — including AI-assisted messaging — are not directed to, and must not be used to communicate with, children under 13 (or under the higher age defined by local law, e.g., 16 in parts of the EU). Businesses using the Services are responsible for ensuring their contact lists and campaigns are not directed at children.
We do not knowingly collect or process children's data. If we become aware that a lead is a child, we will stop processing and delete the related data, and notify the responsible business. If you believe a child has provided data, contact us at hello@appointwise.io and we will delete it.
14) Changes to This Policy
We may update this Policy from time to time. Material changes will be notified by email and/or in-app. The "Last updated" date reflects the latest revision.
15) Contact Us
Questions or requests about privacy?
Email: hello@appointwise.io
Privacy Policy — Appointwise
Last updated: 13 July 2026
Appointwise ("we," "us," "our") provides tools that help businesses manage, qualify, and book appointments with their leads, including AI-assisted messaging. This Privacy Policy explains what data we collect, how we use it, with whom we share it, how long we keep it, and how you can exercise your rights. It applies to our websites, products, and services (the "Services").
If you are a lead or customer of a business that uses Appointwise (for example, you received text messages from a business using our technology), please see Section 2 ("Our Role: When We Act as a Processor") — the business you communicated with is responsible for your data, and you should direct privacy requests to them. We support them in fulfilling your requests.
If you connect a Google account to Appointwise, this policy also explains our handling of Google user data obtained via Google OAuth. If you connect a Facebook Page or Instagram professional account, this policy also explains our handling of Meta Platform Data obtained via Meta's APIs.
1) Data We Collect
Account & Contact Data. Name, email address, company name, role, and password (hashed).
Usage & Device Data. IP address, browser/OS, pages viewed, app interactions, and diagnostic logs.
Customer Content. Information you upload or generate in the Services (e.g., strategy configuration, prompts and "briefs," knowledge-base documents, workflow settings).
Lead & End-User Data (processed on behalf of our business customers). When a business uses the Services to communicate with its leads and customers, we process those individuals' personal data on the business's behalf. This may include: names, phone numbers, email addresses, the content of conversations (SMS and other channels), appointment details, time zone and general location information, tags and qualification status, and any other information the individual chooses to share in a conversation. Conversation content may incidentally include sensitive information an individual volunteers (for example, health context shared with a healthcare-related business); we process such content only to provide the Services to that business.
CRM & Calendar Integration Data. If a business connects a third-party platform such as GoHighLevel ("GHL"), Google, or Meta (Facebook and Instagram), we access and process the data needed for the enabled features — for example contacts, conversations, calendars and appointments, and the authentication tokens required to act on the business's behalf. Tokens are stored encrypted.
Google User Data (via OAuth). If you authorize Appointwise, we access only the Google data necessary for the features you enable. Examples include:
Basic profile info (e.g., name, email) to identify your account;
Calendar data to create or read events you ask us to manage;
Gmail metadata or content only if you explicitly enable features that require it (e.g., reading specific messages to create appointments);
Contacts data to view or add contacts you direct us to manage.
We do not collect Google user data without your explicit authorization, and we do not use device microphones/cameras unless you opt in for a feature that needs them.
Meta Platform Data (Facebook & Instagram). If a business connects its Facebook Page or Instagram professional account, we access, with the business's explicit authorization via Meta's login flow, only the Meta data needed for the features enabled. This may include:
The list of Pages the business manages and basic Page metadata (name, picture, linked Instagram professional account), used to set up and display the integration;
Page access tokens (stored encrypted), used to act on the business's behalf;
The content of Messenger and Instagram direct-message conversations between the business and its leads, so the AI-assisted features can receive and respond to those messages on the business's behalf;
Lead-form submissions from the business's Facebook Lead Ads, so new leads can be created in the business's account and contacted.
We do not access the personal profiles, friends lists, or feeds of individuals who message the business. We do not collect Meta Platform Data without the business's explicit authorization.
2) Our Role: When We Act as a Processor
For Account & Contact Data and Usage & Device Data, Appointwise is the data controller.
For Lead & End-User Data and Customer Content, Appointwise acts as a data processor (or "service provider" under US state laws) on the documented instructions of the business customer, which is the data controller. The business — not Appointwise — determines the purposes of the processing, is responsible for having a lawful basis to contact its leads (including any required consents for SMS/marketing communications), and is the correct first point of contact for individuals' privacy requests. Where a lead contacts us directly, we will refer the request to the relevant business and provide reasonable assistance. Our Data Processing Agreement is available to business customers on request from hello@appointwise.io.
3) AI-Assisted Features & Automated Processing
The Services use artificial intelligence, including large language models (LLMs), to draft and send conversational replies, qualify leads, propose and book appointment times, and execute related workflow steps that businesses configure.
What the AI processes. To generate responses, relevant conversation history, configuration (e.g., the business's brief and booking rules), and appointment availability are submitted to our AI service providers.
AI service providers. We use vetted third-party AI providers (currently including OpenAI) strictly as processors to provide these features. Under our API terms with these providers, content submitted via their APIs is not used to train their models, and is retained by them only for a limited period for abuse monitoring under their policies.
Automated communications and decisions. AI-generated messages are sent automatically within the rules configured by the business. The Services may automatically update a lead's status (for example, marking a conversation complete, lost, or booked). These automations affect how and whether the business follows up; they are reviewable and reversible by the business, and individuals may request human review or human contact at any time by asking in the conversation or contacting the business directly.
Transparency. Appointwise agents are designed not to deny being automated: if an individual asks whether they are talking to an AI, the agent is instructed to confirm it.
Human oversight. Businesses can review every AI conversation, take over conversations manually, and disable the AI per lead or per account at any time. We log AI actions to support audit and review.
4) How We Use Data
We use data to:
Provide, operate, secure, and troubleshoot the Services, including the AI-assisted features described in Section 3;
Authenticate you and manage your account and connections (e.g., Google OAuth, GHL, Meta);
Perform actions you request (e.g., read a calendar, create an event, send a message to a lead, add a contact);
Improve the Services (analytics, testing, research) — using aggregated or de-identified data where feasible;
Communicate with you (support, product updates, security notices);
Comply with law and enforce our terms.
Google user data is used only to provide the features you've enabled and for no other purpose. We do not use Google user data for advertising, profiling unrelated to the requested features, or building unrelated datasets. Meta Platform Data is likewise used only to provide the features the business has enabled and for no other purpose.
5) With Whom We Share, Transfer, or Disclose Data
We do not sell your personal information, Lead & End-User Data, Google user data, or Meta Platform Data.
We disclose data only in these situations:
Service Providers (Processors / Sub-processors). We use vetted third parties under written contracts to process data for us and only as needed to deliver the Services. Categories include: cloud hosting and storage (e.g., Amazon Web Services), AI/LLM providers (e.g., OpenAI), databases and backups, analytics, error monitoring, logging, email delivery, and customer support tooling.
Platforms You Connect. When a business connects a platform such as GHL, Google, or Meta and directs us to act (e.g., send an SMS via GHL, book a calendar slot, reply to an Instagram message), we transmit the data needed to perform that action to that platform. Those platforms process data under their own terms and policies.
Your Direction. We disclose data when you instruct or consent.
Legal, Safety, and Rights. If required by law or in good-faith belief disclosure is necessary to protect you, us, users, or the public (e.g., court order, detecting abuse, preventing fraud).
Business Transfers. If we undergo a merger, acquisition, or asset sale, your data may transfer as part of the transaction, subject to this Policy.
Human Access to Google User Data. Human access is limited and permitted only: (a) with your explicit consent; (b) to comply with applicable law; or (c) for security and abuse investigations, troubleshooting, or debugging. Access is logged and restricted. The same restrictions apply to human access to Meta Platform Data.
6) Google OAuth & "Limited Use" Commitments
For Google user data obtained via OAuth:
We only request the minimal scopes needed for the features you use.
We do not sell Google user data.
We do not share Google user data with third parties except as needed to provide the Services (processors) or as required by law.
We do not use Google user data for serving ads.
We do not allow unauthorized human reading of Google user data.
Google user data is not shared with AI/LLM providers except where strictly necessary for a feature you have explicitly enabled.
You can review or revoke Appointwise's access at any time in your Google Account: https://myaccount.google.com/permissions.
7) Meta Platform Data Commitments
For data obtained via Meta's APIs (Facebook and Instagram):
We request only the permissions needed for the features the business uses, and we use Meta Platform Data solely to provide those features on the business's behalf.
We do not sell Meta Platform Data, use it for advertising, or use it to build profiles unrelated to the requested features.
We share Meta Platform Data only with service providers acting as our processors (for example, cloud hosting, and the AI providers described in Section 3, strictly to generate responses in the business's own conversations) or as required by law.
We do not allow unauthorized human access to Meta Platform Data; human access is limited, logged, and restricted as described in Section 5.
We process Meta Platform Data in accordance with Meta's Platform Terms and Developer Policies.
You can disconnect the Meta integration at any time in Appointwise (Settings → Integrations → Disconnect). You can also remove Appointwise's access from your Facebook settings under Settings → Business Integrations at https://www.facebook.com/settings.
8) Cookies & Similar Technologies
We use cookies and similar technologies to keep you signed in, remember preferences, measure usage, and improve performance. You can control cookies in your browser settings; some features may not function without them.
9) Data Retention & Deletion
General retention.
Account data: kept while your account is active. If you delete your account, we delete or anonymize account data within 30 days.
Customer content and Lead & End-User Data: retained while the business's account is active and as instructed by the business; deleted or anonymized within 30 days after account deletion or upon the business's verified deletion instruction.
AI provider retention: content submitted to AI providers to generate responses is retained by those providers only per their API data policies (typically up to 30 days for abuse monitoring) and is not used to train their models.
Google user data.
OAuth tokens: stored while your Google account is connected; deleted within 7 days after you disconnect or delete your Appointwise account.
Synchronized items (e.g., created events/contacts): we keep only what is necessary to display history in the app. If you delete your account or disconnect Google, related cached Google data is deleted within 30 days.
Indexed/search caches: refreshed frequently and purged within 30 days after disconnection.
Meta Platform Data.
Page access tokens: stored encrypted while the Meta integration is connected; deleted within 7 days after you disconnect Meta or delete your Appointwise account.
Page metadata, Messenger/Instagram conversation content, and lead-form data: retained while the business's account is active; deleted or anonymized within 30 days after disconnection, account deletion, or a verified deletion instruction.
To request deletion of data obtained from Meta, disconnect the integration in-app (Settings → Integrations), or email hello@appointwise.io from your registered address; we will confirm completion by email. Leads and end users who messaged a business on Facebook or Instagram should contact that business, and we will assist it in fulfilling verified requests.
System logs containing incidental identifiers may persist for up to 90 days for security and audit, then are deleted or anonymized. Encrypted backups roll off within 35 days under standard backup rotation.
Inactivity. We may deactivate and delete accounts with no sign-ins or activity for 18 months, after notice to the registered email.
How to delete data.
Delete your account in-app (Settings → Account → Delete) or email hello@appointwise.io from your registered address.
Disconnect Google at any time in Appointwise (Settings → Integrations) and/or via Google at https://myaccount.google.com/permissions.
Disconnect Meta at any time in Appointwise (Settings → Integrations) and/or via Facebook under Settings → Business Integrations.
If you are a lead/end user, contact the business you communicated with; we will assist them in fulfilling verified requests.
We will confirm completion of deletion requests to your registered email.
10) Your Rights & Choices
Access, correct, or delete your information;
Export your data where technically feasible;
Opt out of non-essential emails;
Withdraw Google permissions at any time (https://myaccount.google.com/permissions);
Withdraw Meta permissions at any time (in-app or via Facebook Settings → Business Integrations);
Object to or request human review of automated processing as described in Section 3.
Leads/end users: because the business you interacted with is the controller of your data, please direct requests to that business. You can also opt out of further messages at any time, including by replying STOP where supported.
To exercise rights, use the in-app controls or contact hello@appointwise.io. We may verify your identity before fulfilling requests.
11) Security
We use industry-standard security measures, including encryption in transit and at rest (including encryption of stored phone numbers and integration tokens), least-privilege access, and continuous monitoring. No method is 100% secure; we will notify you of significant incidents as required by law.
12) International Data Transfers
If we transfer data across borders (including to AI and cloud providers in the United States), we use appropriate safeguards (e.g., standard contractual clauses) as required by applicable law.
13) Age Requirements & Children's Privacy
Account holders. The Services are business tools. You must be at least 18 years old (or the age of majority in your jurisdiction) to create an account or use the Services.
Leads and end users. The Services — including AI-assisted messaging — are not directed to, and must not be used to communicate with, children under 13 (or under the higher age defined by local law, e.g., 16 in parts of the EU). Businesses using the Services are responsible for ensuring their contact lists and campaigns are not directed at children.
We do not knowingly collect or process children's data. If we become aware that a lead is a child, we will stop processing and delete the related data, and notify the responsible business. If you believe a child has provided data, contact us at hello@appointwise.io and we will delete it.
14) Changes to This Policy
We may update this Policy from time to time. Material changes will be notified by email and/or in-app. The "Last updated" date reflects the latest revision.
15) Contact Us
Questions or requests about privacy?
Email: hello@appointwise.io
Privacy Policy — Appointwise
Last updated: 13 July 2026
Appointwise ("we," "us," "our") provides tools that help businesses manage, qualify, and book appointments with their leads, including AI-assisted messaging. This Privacy Policy explains what data we collect, how we use it, with whom we share it, how long we keep it, and how you can exercise your rights. It applies to our websites, products, and services (the "Services").
If you are a lead or customer of a business that uses Appointwise (for example, you received text messages from a business using our technology), please see Section 2 ("Our Role: When We Act as a Processor") — the business you communicated with is responsible for your data, and you should direct privacy requests to them. We support them in fulfilling your requests.
If you connect a Google account to Appointwise, this policy also explains our handling of Google user data obtained via Google OAuth. If you connect a Facebook Page or Instagram professional account, this policy also explains our handling of Meta Platform Data obtained via Meta's APIs.
1) Data We Collect
Account & Contact Data. Name, email address, company name, role, and password (hashed).
Usage & Device Data. IP address, browser/OS, pages viewed, app interactions, and diagnostic logs.
Customer Content. Information you upload or generate in the Services (e.g., strategy configuration, prompts and "briefs," knowledge-base documents, workflow settings).
Lead & End-User Data (processed on behalf of our business customers). When a business uses the Services to communicate with its leads and customers, we process those individuals' personal data on the business's behalf. This may include: names, phone numbers, email addresses, the content of conversations (SMS and other channels), appointment details, time zone and general location information, tags and qualification status, and any other information the individual chooses to share in a conversation. Conversation content may incidentally include sensitive information an individual volunteers (for example, health context shared with a healthcare-related business); we process such content only to provide the Services to that business.
CRM & Calendar Integration Data. If a business connects a third-party platform such as GoHighLevel ("GHL"), Google, or Meta (Facebook and Instagram), we access and process the data needed for the enabled features — for example contacts, conversations, calendars and appointments, and the authentication tokens required to act on the business's behalf. Tokens are stored encrypted.
Google User Data (via OAuth). If you authorize Appointwise, we access only the Google data necessary for the features you enable. Examples include:
Basic profile info (e.g., name, email) to identify your account;
Calendar data to create or read events you ask us to manage;
Gmail metadata or content only if you explicitly enable features that require it (e.g., reading specific messages to create appointments);
Contacts data to view or add contacts you direct us to manage.
We do not collect Google user data without your explicit authorization, and we do not use device microphones/cameras unless you opt in for a feature that needs them.
Meta Platform Data (Facebook & Instagram). If a business connects its Facebook Page or Instagram professional account, we access, with the business's explicit authorization via Meta's login flow, only the Meta data needed for the features enabled. This may include:
The list of Pages the business manages and basic Page metadata (name, picture, linked Instagram professional account), used to set up and display the integration;
Page access tokens (stored encrypted), used to act on the business's behalf;
The content of Messenger and Instagram direct-message conversations between the business and its leads, so the AI-assisted features can receive and respond to those messages on the business's behalf;
Lead-form submissions from the business's Facebook Lead Ads, so new leads can be created in the business's account and contacted.
We do not access the personal profiles, friends lists, or feeds of individuals who message the business. We do not collect Meta Platform Data without the business's explicit authorization.
2) Our Role: When We Act as a Processor
For Account & Contact Data and Usage & Device Data, Appointwise is the data controller.
For Lead & End-User Data and Customer Content, Appointwise acts as a data processor (or "service provider" under US state laws) on the documented instructions of the business customer, which is the data controller. The business — not Appointwise — determines the purposes of the processing, is responsible for having a lawful basis to contact its leads (including any required consents for SMS/marketing communications), and is the correct first point of contact for individuals' privacy requests. Where a lead contacts us directly, we will refer the request to the relevant business and provide reasonable assistance. Our Data Processing Agreement is available to business customers on request from hello@appointwise.io.
3) AI-Assisted Features & Automated Processing
The Services use artificial intelligence, including large language models (LLMs), to draft and send conversational replies, qualify leads, propose and book appointment times, and execute related workflow steps that businesses configure.
What the AI processes. To generate responses, relevant conversation history, configuration (e.g., the business's brief and booking rules), and appointment availability are submitted to our AI service providers.
AI service providers. We use vetted third-party AI providers (currently including OpenAI) strictly as processors to provide these features. Under our API terms with these providers, content submitted via their APIs is not used to train their models, and is retained by them only for a limited period for abuse monitoring under their policies.
Automated communications and decisions. AI-generated messages are sent automatically within the rules configured by the business. The Services may automatically update a lead's status (for example, marking a conversation complete, lost, or booked). These automations affect how and whether the business follows up; they are reviewable and reversible by the business, and individuals may request human review or human contact at any time by asking in the conversation or contacting the business directly.
Transparency. Appointwise agents are designed not to deny being automated: if an individual asks whether they are talking to an AI, the agent is instructed to confirm it.
Human oversight. Businesses can review every AI conversation, take over conversations manually, and disable the AI per lead or per account at any time. We log AI actions to support audit and review.
4) How We Use Data
We use data to:
Provide, operate, secure, and troubleshoot the Services, including the AI-assisted features described in Section 3;
Authenticate you and manage your account and connections (e.g., Google OAuth, GHL, Meta);
Perform actions you request (e.g., read a calendar, create an event, send a message to a lead, add a contact);
Improve the Services (analytics, testing, research) — using aggregated or de-identified data where feasible;
Communicate with you (support, product updates, security notices);
Comply with law and enforce our terms.
Google user data is used only to provide the features you've enabled and for no other purpose. We do not use Google user data for advertising, profiling unrelated to the requested features, or building unrelated datasets. Meta Platform Data is likewise used only to provide the features the business has enabled and for no other purpose.
5) With Whom We Share, Transfer, or Disclose Data
We do not sell your personal information, Lead & End-User Data, Google user data, or Meta Platform Data.
We disclose data only in these situations:
Service Providers (Processors / Sub-processors). We use vetted third parties under written contracts to process data for us and only as needed to deliver the Services. Categories include: cloud hosting and storage (e.g., Amazon Web Services), AI/LLM providers (e.g., OpenAI), databases and backups, analytics, error monitoring, logging, email delivery, and customer support tooling.
Platforms You Connect. When a business connects a platform such as GHL, Google, or Meta and directs us to act (e.g., send an SMS via GHL, book a calendar slot, reply to an Instagram message), we transmit the data needed to perform that action to that platform. Those platforms process data under their own terms and policies.
Your Direction. We disclose data when you instruct or consent.
Legal, Safety, and Rights. If required by law or in good-faith belief disclosure is necessary to protect you, us, users, or the public (e.g., court order, detecting abuse, preventing fraud).
Business Transfers. If we undergo a merger, acquisition, or asset sale, your data may transfer as part of the transaction, subject to this Policy.
Human Access to Google User Data. Human access is limited and permitted only: (a) with your explicit consent; (b) to comply with applicable law; or (c) for security and abuse investigations, troubleshooting, or debugging. Access is logged and restricted. The same restrictions apply to human access to Meta Platform Data.
6) Google OAuth & "Limited Use" Commitments
For Google user data obtained via OAuth:
We only request the minimal scopes needed for the features you use.
We do not sell Google user data.
We do not share Google user data with third parties except as needed to provide the Services (processors) or as required by law.
We do not use Google user data for serving ads.
We do not allow unauthorized human reading of Google user data.
Google user data is not shared with AI/LLM providers except where strictly necessary for a feature you have explicitly enabled.
You can review or revoke Appointwise's access at any time in your Google Account: https://myaccount.google.com/permissions.
7) Meta Platform Data Commitments
For data obtained via Meta's APIs (Facebook and Instagram):
We request only the permissions needed for the features the business uses, and we use Meta Platform Data solely to provide those features on the business's behalf.
We do not sell Meta Platform Data, use it for advertising, or use it to build profiles unrelated to the requested features.
We share Meta Platform Data only with service providers acting as our processors (for example, cloud hosting, and the AI providers described in Section 3, strictly to generate responses in the business's own conversations) or as required by law.
We do not allow unauthorized human access to Meta Platform Data; human access is limited, logged, and restricted as described in Section 5.
We process Meta Platform Data in accordance with Meta's Platform Terms and Developer Policies.
You can disconnect the Meta integration at any time in Appointwise (Settings → Integrations → Disconnect). You can also remove Appointwise's access from your Facebook settings under Settings → Business Integrations at https://www.facebook.com/settings.
8) Cookies & Similar Technologies
We use cookies and similar technologies to keep you signed in, remember preferences, measure usage, and improve performance. You can control cookies in your browser settings; some features may not function without them.
9) Data Retention & Deletion
General retention.
Account data: kept while your account is active. If you delete your account, we delete or anonymize account data within 30 days.
Customer content and Lead & End-User Data: retained while the business's account is active and as instructed by the business; deleted or anonymized within 30 days after account deletion or upon the business's verified deletion instruction.
AI provider retention: content submitted to AI providers to generate responses is retained by those providers only per their API data policies (typically up to 30 days for abuse monitoring) and is not used to train their models.
Google user data.
OAuth tokens: stored while your Google account is connected; deleted within 7 days after you disconnect or delete your Appointwise account.
Synchronized items (e.g., created events/contacts): we keep only what is necessary to display history in the app. If you delete your account or disconnect Google, related cached Google data is deleted within 30 days.
Indexed/search caches: refreshed frequently and purged within 30 days after disconnection.
Meta Platform Data.
Page access tokens: stored encrypted while the Meta integration is connected; deleted within 7 days after you disconnect Meta or delete your Appointwise account.
Page metadata, Messenger/Instagram conversation content, and lead-form data: retained while the business's account is active; deleted or anonymized within 30 days after disconnection, account deletion, or a verified deletion instruction.
To request deletion of data obtained from Meta, disconnect the integration in-app (Settings → Integrations), or email hello@appointwise.io from your registered address; we will confirm completion by email. Leads and end users who messaged a business on Facebook or Instagram should contact that business, and we will assist it in fulfilling verified requests.
System logs containing incidental identifiers may persist for up to 90 days for security and audit, then are deleted or anonymized. Encrypted backups roll off within 35 days under standard backup rotation.
Inactivity. We may deactivate and delete accounts with no sign-ins or activity for 18 months, after notice to the registered email.
How to delete data.
Delete your account in-app (Settings → Account → Delete) or email hello@appointwise.io from your registered address.
Disconnect Google at any time in Appointwise (Settings → Integrations) and/or via Google at https://myaccount.google.com/permissions.
Disconnect Meta at any time in Appointwise (Settings → Integrations) and/or via Facebook under Settings → Business Integrations.
If you are a lead/end user, contact the business you communicated with; we will assist them in fulfilling verified requests.
We will confirm completion of deletion requests to your registered email.
10) Your Rights & Choices
Access, correct, or delete your information;
Export your data where technically feasible;
Opt out of non-essential emails;
Withdraw Google permissions at any time (https://myaccount.google.com/permissions);
Withdraw Meta permissions at any time (in-app or via Facebook Settings → Business Integrations);
Object to or request human review of automated processing as described in Section 3.
Leads/end users: because the business you interacted with is the controller of your data, please direct requests to that business. You can also opt out of further messages at any time, including by replying STOP where supported.
To exercise rights, use the in-app controls or contact hello@appointwise.io. We may verify your identity before fulfilling requests.
11) Security
We use industry-standard security measures, including encryption in transit and at rest (including encryption of stored phone numbers and integration tokens), least-privilege access, and continuous monitoring. No method is 100% secure; we will notify you of significant incidents as required by law.
12) International Data Transfers
If we transfer data across borders (including to AI and cloud providers in the United States), we use appropriate safeguards (e.g., standard contractual clauses) as required by applicable law.
13) Age Requirements & Children's Privacy
Account holders. The Services are business tools. You must be at least 18 years old (or the age of majority in your jurisdiction) to create an account or use the Services.
Leads and end users. The Services — including AI-assisted messaging — are not directed to, and must not be used to communicate with, children under 13 (or under the higher age defined by local law, e.g., 16 in parts of the EU). Businesses using the Services are responsible for ensuring their contact lists and campaigns are not directed at children.
We do not knowingly collect or process children's data. If we become aware that a lead is a child, we will stop processing and delete the related data, and notify the responsible business. If you believe a child has provided data, contact us at hello@appointwise.io and we will delete it.
14) Changes to This Policy
We may update this Policy from time to time. Material changes will be notified by email and/or in-app. The "Last updated" date reflects the latest revision.
15) Contact Us
Questions or requests about privacy?
Email: hello@appointwise.io