Effective: [TO BE FILLED IN BEFORE PUBLISH] · Last updated: [TO BE FILLED IN]
ReviewPilot ("ReviewPilot," "we," "us") is operated by AI Automated Inc. ("Company"). This Privacy Policy explains what information we collect, how we use it, and the choices you have.
ReviewPilot is a SaaS tool that helps US-based medical spas respond to Google reviews and request post-visit Google reviews via SMS. Contact: support@togtuun.com.
Account info (name, email, phone, business name, address, EIN), billing info (handled by Stripe), and content you upload (client first name + phone for SMS review requests).
When you connect your Google Business Profile via OAuth: profile email and name, locations, reviews (text, rating, reviewer name, timestamp), and replies you have posted. We use this only to provide the service.
Log data (IP, user agent, timestamps) and aggregate analytics (Plausible, no cookies).
ReviewPilot's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements:
To operate the service (read reviews, draft replies, post your approved replies, send SMS), to bill you, to email you about service updates and support, and to comply with law.
| Vendor | Purpose | Data shared |
|---|---|---|
| Supabase | Database hosting | All app data |
| Anthropic | LLM (Claude) for reply drafting | Review text + your past replies |
| Twilio | SMS delivery | Recipient first name, phone, business name |
| Stripe | Payment processing | Email, billing info |
| Cloudflare | CDN, DNS, edge | Request metadata |
| Plausible | Site analytics | Aggregated, no personal data |
| Google Workspace | Internal email | Inbound/outbound emails to you |
We do not sell personal information. We do not share for cross-context behavioral advertising.
TLS in transit, AES-256 at rest. OAuth tokens encrypted in DB. Secrets stored in encrypted env vars. Access logging on all admin actions.
Access, correction, deletion, portability. California (CCPA/CPRA), Colorado, Connecticut, Virginia, Utah residents have additional rights. To exercise any right, email privacy@togtuun.com.
You can revoke ReviewPilot's access to your Google account anytime at myaccount.google.com/permissions. We will retain copies of replies already drafted for 30 days then delete.
SMS goes only to numbers you provide for the service you signed up for. Recipients can reply STOP to opt out, HELP for help. STOP/HELP are honored automatically and the recipient is suppressed within minutes.
ReviewPilot is not directed to anyone under 18.
Our infrastructure is in the US. If you're accessing from outside the US, your data is processed in the US.
We notify you of material changes by email at least 30 days before they take effect.
General: support@togtuun.com · Privacy: privacy@togtuun.com