Privacy Policy

Effective date: August 5, 2026

Repsmith ("Repsmith," "we," "us") is an AI sales-coaching service operated by CoPilot AI [legal entity name and address — confirm with counsel], based in Vancouver, British Columbia, Canada. Repsmith reads the text transcripts of a customer's sales calls and sends each sales representative a short, private coaching message. This policy explains what data we handle, why, and the choices available to you.

1. The two roles we play

For Customer Content, we are a processor. When a business ("Customer") connects its calendar, meeting, and messaging tools to Repsmith, we process meeting metadata, call transcripts, and coaching outputs on that Customer's behalf and under its instructions. The Customer is the controller of this data. If you are a sales representative whose calls are analyzed by Repsmith, your organization chose to use Repsmith and controls that data; questions and rights requests about it are best directed to your organization, and we will support them in responding.

For account, billing, and website data, we are the controller. This covers information about the people who sign up for and administer Repsmith, payment records, support conversations, and visits to our website.

2. Data we process

CategoryExamplesSource
Account dataName, work email, role, workspace settingsProvided by Customer admins and users
Connection dataOAuth tokens for Zoom, Google, Microsoft, and Slack (encrypted at rest); connection health statusAuthorized by Customer admins
Meeting metadataCalendar event titles, times, attendee emailsCustomer's calendar provider
Call transcriptsText transcripts of the Customer's recorded sales meetings, with speaker attribution. Text only — we never access or store audio or video.Customer's meeting provider (Zoom, Microsoft Teams, or Google Meet)
Coaching outputsTracker scores, evidence quotes, coaching messages, progress historyGenerated by the service
Billing dataCompany details, subscription records. Card details are collected and stored by Stripe — they never touch our systems.Provided at purchase
Usage & log dataFeature usage, diagnostic logs, IP address, browser typeCollected automatically

3. How we use data

What we never do: we do not sell personal information; we do not use Customer Content for advertising; and we do not use Customer Content to train artificial-intelligence models — ours or anyone else's. Large-language-model processing of transcripts is performed through providers under zero-data-retention terms: the provider does not retain the content after processing and does not use it for training.

4. Google API Services — Limited Use disclosure

Repsmith's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we only use Google Calendar and Google Meet data to provide user-facing coaching features; we do not transfer it except as necessary to provide those features, to comply with law, or as part of a merger or acquisition with notice; we do not use it for advertising; and no humans read it except with the Customer's affirmative agreement, for security purposes, to comply with law, or when aggregated for internal operations.

5. Subprocessors and service providers

ProviderPurposeLocation
SupabaseDatabase and application hosting (tenant-isolated with row-level security)United States [confirm region]
[LLM provider — to be confirmed]Transcript analysis and message generation under zero-data-retention termsUnited States
StripePayment processingUnited States
ResendTransactional and coaching email deliveryUnited States
CloudflareDNS, network security, website hostingGlobal

The tools a Customer connects (Zoom, Google, Microsoft, Slack) act as independent services under their own terms; we access them only with the Customer's authorization and only to the extent needed to provide Repsmith.

6. Retention and deletion

7. Security

Data is encrypted in transit (TLS) and at rest. OAuth tokens are stored in an encrypted vault. Every tenant's data is isolated by database row-level security. Access by our staff is limited, logged, and — for transcript content — requires an elevated, recorded access grant used only for support with Customer permission, security, or legal compliance. No system is perfectly secure; we notify affected Customers of incidents as required by law.

8. Your rights

Depending on where you live (including under Canada's PIPEDA, the EU/UK GDPR, and US state privacy laws), you may have rights to access, correct, delete, or export personal information, to object to or restrict certain processing, and to complain to a supervisory authority. For Customer Content, submit requests through your organization; for data we control, contact us at privacy@repsmith.ai [set up this address] and we will respond within the time required by law. We do not discriminate against anyone for exercising privacy rights.

9. International transfers

We are a Canadian company and our infrastructure providers are primarily located in the United States. Where data is transferred across borders, we rely on appropriate safeguards such as standard contractual clauses. A Data Processing Addendum (including subprocessor commitments) is available to Customers on request at support@repsmith.ai.

10. Cookies and website data

Our website uses only the cookies necessary to operate and to remember sign-in state, plus privacy-respecting analytics [confirm analytics choice]. We do not use advertising cookies or cross-site tracking.

11. Children

Repsmith is a workplace tool for business use and is not directed to anyone under 18. We do not knowingly collect data from children.

12. Changes and contact

We will post any changes to this policy here and, for material changes, notify Customer admins. Questions: privacy@repsmith.ai or Repsmith Privacy, CoPilot AI, [street address], Vancouver, BC, Canada.