Privacy Policy
Effective October 5, 2026
1. Who we are and what this covers
ClientFlow AI (“we”, “us”) is software that helps service businesses keep track of clients and leads, and send reminders, win-back messages, review requests, and follow-ups by text (SMS) and email. We are based in Tennessee, USA. This Privacy Policy explains what information we collect, how we use and share it, and the choices you have. It forms part of our Terms of Service.
It covers two groups of people: (a) the businesses that sign up for an account (“our customers”), and (b) the clients, leads, and other people whose details our customers put into, or collect through, the Service. If you are in the second group, see section 3.
2. Information we collect from our customers
Account information: your business name, email address, and password (stored only as a salted, one-way hash, never in readable form), plus a record of which version of our Terms and Privacy Policy you accepted and when.
Business data you add: clients and leads (names, phone numbers, email addresses, visit dates, service types, consent status, referral relationships), appointments, packages, the messages you generate and send, replies you receive, and settings such as your tone of voice, email sign-off, and business mailing address.
Online bookings: if you use the booking page, we store what a client enters (name, phone number, email address), the service and time they chose, and a private link used to cancel. If they tick the text-message checkbox, we also record the wording shown, when they agreed, their IP address, and their browser type, as proof of consent.
Missed calls: if you use missed-call text-back, we record the phone number of each caller whose call went unanswered, when they called, whether we texted them, and the reason if we didn't. We do not record or store the audio of calls.
Connected-account credentials: if you connect Twilio, an email service (an API key for Resend or SendGrid, or SMTP server details including a username and password), or Square, we store the keys, tokens, or login details you provide so the Service can act on your behalf. They are kept in your business's own database, are not shown back to you after saving, and are never sent to your browser.
Connected booking systems: if you connect a calendar feed, we store its link (which can act like a password) and regularly download the feed, keeping the appointment details it contains, such as client names, email addresses or phone numbers, times, and service names. Events without a client's contact details are kept only as blocked time. If you create a webhook address, we store its secret and keep the appointment details your systems send to it. The feed link is not shown back to you in full after saving.
Review links: if you use review requests, we record when a client taps the review link in the message (the time and which client). We do not see whether they then post a review.
Technical information: a login cookie (see section 7), and ordinary server logs kept by our hosting provider, which can include IP address, browser type, and the pages or API endpoints requested. We use these to run, secure, and troubleshoot the Service.
3. Information about our customers' clients and leads
Our customers use the Service to manage their own clients and leads. That information is collected when a business uploads a list, when appointments sync from Square, a calendar feed, or a webhook the business has connected, or when someone fills in a business's lead form, consent page, or referral link. It can include name, phone number, email address, visit and service history, the messages sent to and received from them, whether they have agreed to receive texts or emails, and who referred them.
For this information we act as a service provider on the business's behalf. The business decides who is contacted and what is said, and is responsible for having permission to contact you. We process the information only to provide the Service to that business. If you are a client or lead of one of our customers and want to see, correct, or delete your information, or stop messages, contact that business directly. You can also reply STOP to any text, or use the unsubscribe link in any email, and we will help the business honor your request.
4. How we use information
We use information to operate the Service and send messages at our customers' direction; to draft messages with AI; to keep accounts and data secure and prevent abuse; to provide support; to send account emails such as password resets; to comply with legal obligations; and to improve the Service using anonymous, combined statistics.
We do not sell personal information. We do not show advertising, and we do not use your data or your clients' data to build advertising profiles.
5. AI-drafted messages
When the Service drafts a message, we send an AI provider, Anthropic, the details needed to write it: the client's name, their last visit date and how long ago it was, the service type if you entered one, your business name, and your tone and sign-off instructions. We do not send phone numbers or email addresses for this purpose. According to Anthropic's published commercial terms, information sent through its API is not used to train its models by default.
Please do not put health information, financial account numbers, or other sensitive details into client records or tone instructions.
6. Who we share information with
We share information only with service providers that help us run the Service, and only as needed: our hosting provider (Railway) to store and serve the Service and its data in the United States; Twilio, to deliver text messages from your connected account; the email service you connect (such as Resend, SendGrid, or another SMTP provider), to deliver your business's email; Resend, to deliver our own account emails such as password resets; Square, if you connect it, to read appointments; and Anthropic, for AI drafting as described above.
We may also disclose information if required by law or legal process, to protect the rights, safety, or security of our users or the Service, or in connection with a merger, acquisition, or sale of the business (we would tell you and the new owner would be bound by this policy).
We do not share mobile phone numbers or text-message consent information with third parties for their own marketing or promotional purposes. Phone numbers are shared only with our messaging providers so that messages can be delivered.
7. Cookies
We use one essential cookie, which keeps you logged in (up to 30 days, or until you log out). We do not use advertising or third-party analytics cookies or trackers.
8. How long we keep information
We keep an account's information while the account is active. You can ask us to delete your account and the business data in it at any time by contacting us. Password-reset links expire after one hour and are stored only as hashes. Server logs are kept by our hosting provider under its own retention schedule. The Service is early-stage and we do not maintain backups, so deletion is generally prompt, and you should keep your own copy of any records you rely on.
9. Security
Each business's data is stored in its own separate database. Passwords are stored as salted hashes, connections to the Service use HTTPS, password-reset tokens are stored hashed and work once, and saved provider credentials are never sent back to the browser. No system is perfectly secure, so we cannot guarantee absolute security. If we learn of a security incident that affects your information, we will notify you as required by law.
10. Your choices and rights
Account holders can access, correct, or delete their information, or close their account, by emailing us. Depending on where you live (for example California and several other states), you may have additional rights over your personal information, such as to access, correct, delete, or opt out of certain uses. For information we hold as a service provider for one of our customers, please direct requests to that customer; we will assist them in responding. We will not treat you differently for exercising your rights.
11. Health information
The Service is not designed for protected health information and is not HIPAA-compliant. Customers in any industry must not enter medical or other health information into it. See section 6 of our Terms of Service for details.
12. Children
The Service is for businesses and is not directed to anyone under 18. We do not knowingly collect personal information from children.
13. Changes to this policy
We may update this policy. If we make a significant change, we will update the date above and may notify you by email or in the Service. Continuing to use the Service after a change means you accept the updated policy.
Questions? Contact us at nolan@drclientflow.com. See also our Terms of Service.