Privacy Policy — Episterra LLC
Effective date: July 23, 2026 · Operator: Episterra LLC (United States) · Contact: privacy@episterra.ai
1. Who we are
This policy is issued by Episterra LLC ("we", "us"), the operator of the go-ai platform (the "Service"). It explains what personal and financial information we collect, why, how we protect it, and the choices you have.
2. Information we collect
You provide / your workspace provides:
- Account data: name, email, authentication credentials (managed by our auth provider), and multi-factor authentication enrollment status.
- Workspace & CRM data: company profiles, leads/contacts and their contact details, notes, scheduling events, and other business records you enter.
From connected third-party accounts (only when you connect them):
- Financial data via Plaid: when you link a bank account, we receive — via Plaid — account metadata (institution, account name, type/subtype, last-four "mask", balances) and transaction data (amount, date, merchant/name, category, status). We receive a Plaid access token that we store encrypted; we do not receive or store your online banking username or password.
- Calendar data via Calendly: scheduling links and booked-meeting details for accounts you connect.
- Video conferencing data via Zoom: when you connect a Zoom account, we receive that account's Zoom user id, account id, display name, and email address, so the connection can be labeled and managed. When a booking is made on a Zoom-enabled booking type, we create a meeting on your Zoom account and store the resulting meeting id and join URL so they can be attached to the booking. We receive an OAuth access and refresh token, which we store encrypted; we do not receive or store your Zoom password. We do not access your Zoom recordings, transcripts, chat, contacts, or any meeting we did not create. See Section 6a.
- Communication integrations: data from email/LinkedIn/voice/SMS providers you connect (e.g., message metadata).
Automatically: standard technical data such as log and device/connection information needed to operate and secure the Service.
3. How we use information
- Provide and operate the Service (CRM, scheduling, and financial/budgeting features).
- Display your connected accounts, balances, and transactions, and keep them in sync.
- Secure the Service, prevent abuse, and meet legal obligations.
- Power AI features (writing, scoring, agents). Prompt inputs are sent to our AI gateway to generate responses and are not used by us to train models.
We do not sell personal or financial information.
4. Legal bases
Where data-protection laws such as the GDPR apply, we rely on: performance of a contract (providing the Service), our legitimate interests (securing and improving the Service), legal obligations, and your consent (for example, when you connect a third-party account such as Plaid).
5. How we share information — sub-processors
We share data only with service providers that process it on our behalf under contract. Current sub-processors:
| Sub-processor | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, edge functions, hosting | Account, workspace, financial, and integration data |
| Amazon Web Services (AWS) | Static hosting/CDN (S3, CloudFront), secrets management | Application assets; encrypted secrets |
| Plaid | Bank account linking and transaction retrieval | Financial account & transaction data |
| Calendly | Scheduling integration | Meeting/scheduling data |
| Zoom | Video conferencing integration (creating meetings for bookings) | Connected-account profile (name, email, ids); meetings we create on your behalf |
| Resend | Transactional & outbound email | Email addresses, message content |
| Unipile | LinkedIn/email integration | Communication data for connected accounts |
| Twilio | Voice/SMS | Phone numbers, call/message data |
| Firecrawl | Research/enrichment (web search & scraping) | Query inputs |
| Episterra AI gateway | AI features (routes prompts to underlying model providers) | Prompt inputs |
We rely on each key provider's Data Processing Addendum as incorporated by their terms of service. We may also disclose information if required by law or to protect rights, safety, and the integrity of the Service.
SMS / text messaging consent. You consent to SMS either by opting in through our SMS opt-in page at https://www.go-ai.work/sms-optin, or by texting one of our published customer-care numbers — sending us a message consents to our replying in that conversation. Either way, your mobile phone number and consent are used solely to send the messages you requested, such as customer-support replies and service updates. No mobile information — including your phone number and SMS opt-in/consent data — is shared with third parties or affiliates for marketing or promotional purposes, and it is never sold. Text messaging originator opt-in data and consent are excluded from all of the data sharing described above and will not be shared with any third parties. SMS consent is not a condition of creating or using a go-ai account. You can opt out at any time by replying STOP, or reply HELP for assistance. Message frequency varies; message and data rates may apply.
6. Plaid
Our use of Plaid is also governed by Plaid's end-user privacy policy. By linking an account you authorize Plaid to access information from your financial institution and to share it with us to provide the Service. You can disconnect a linked bank at any time (Section 8), which triggers removal of the connection at Plaid and deletion of the associated stored data.
6a. Zoom
Our use of Zoom is also governed by Zoom's own privacy policy and terms. By connecting a Zoom account you authorize go-ai to identify that account and to create meetings on it on your behalf, using the two OAuth scopes described in our Zoom integration documentation at https://www.go-ai.work/docs/zoom (user:read:user and meeting:write:meeting).
You can revoke that authorization at any time, from either side:
- In go-ai: Schedule → Calendar accounts → Video conferencing → Disconnect. We revoke the OAuth token with Zoom and delete the stored connection.
- In Zoom: Settings → Installed Apps → go-ai → Uninstall. Zoom notifies our deauthorization endpoint, and we delete that account's stored tokens and connection records automatically and confirm the deletion back to Zoom.
Zoom-derived data is deleted on either action; no separate request is needed.
7. Data retention
- We retain workspace and account data for as long as your account/workspace is active and as needed to provide the Service.
- Financial data is retained while the bank connection is active; on disconnect or account deletion it is removed.
- On account or workspace closure, associated personal and financial data is deleted within 30 days, except where we must retain limited records to meet legal obligations.
- Operational logs are retained for 90 days.
This retention and deletion schedule is defined, enforced, and reviewed at least annually (and on material change) by the COO for continued compliance with applicable data-protection laws (including the GDPR and CCPA).
8. Your rights & choices
- Disconnect financial accounts: remove a linked bank in the Finance settings; we call Plaid's item removal and delete the stored connection, accounts, and transactions for that item.
- Disconnect Zoom: remove a connected Zoom account in Schedule → Calendar accounts, or uninstall go-ai from Zoom → Settings → Installed Apps; either deletes the stored tokens and connection (Section 6a).
- Access, correction, deletion, portability: email privacy@episterra.ai and we will respond within 30 days (consistent with GDPR/CCPA where applicable).
- MFA: you can enroll in multi-factor authentication; your workspace may require it.
- Communications: operational/transactional emails are part of the Service; you can opt out of non-essential product updates by contacting us.
- SMS messages: SMS is opt-in only and optional. If you have opted in, reply STOP to any message to unsubscribe, or HELP for assistance.
9. How we protect your information
- Encryption in transit (TLS/HTTPS) for all external communication.
- Encryption at rest: third-party tokens (including the Plaid access token) are application-encrypted with AES-256-GCM; the database is encrypted at rest by our platform provider.
- Strict tenant isolation via row-level security; role-based access control; multi-factor authentication available.
- See our Information Security Policy for the full control set.
10. International transfers
We operate in the United States and our providers may process data in the United States. Where required for transfers of personal data from other regions, we rely on the transfer mechanisms offered by our providers (such as Standard Contractual Clauses).
11. Children's privacy
The Service is a business tool, is not directed to children under 18, and we do not knowingly collect their data.
12. Changes to this policy
We will post updates here and revise the effective date; we will surface material changes in the application.
13. Contact
Episterra LLC · 4791 Roxborough Dr, Littleton, CO 80125 · privacy@episterra.ai
