← Back
Legal

Privacy Policy

Revenue OS is operated by XXIautomate, Australia · privacy questions: xxiautomate@gmail.com

Our two roles

For your account data (your name, email, business details, mailbox connection, billing) we are the data controller. For the lead/contact data you import and work, you are the controller and we are your processor — you confirm you have a lawful basis to contact those leads. A Data Processing Agreement is available on request.

What we collect

Account data (name, email, business, website, mailbox address); connection credentials (mailbox token/password, CRM key — encrypted at rest, AES-256-GCM); lead/contact data (names, emails, phones, notes, message history) that you provide; and usage/billing data (confirmed booked calls, invoices, activity logs).

How we use it

To provide the service: draft and (with your approval + connected mailbox) send messages in your voice, capture replies, book and attribute calls, compute usage-based billing, and show you results. We do not sell personal data and never use one customer’s data to benefit another.

AI processing & sub-processors

To draft and reason over messages, lead context is sent to AI providers via API. We use providers whose terms state they do not train on API data. Our sub-processors: Supabase (database/hosting), Vercel (hosting), Groq, Cerebras, Mistral, Google Gemini, and OpenAI (AI drafting — used in a fallback chain for reliability), our own RunPod GPU (a last-resort AI fallback we operate), Google (Gmail, if you connect it), and PayPal (payments — we never see full card data).

Security

Encrypted in transit (TLS/HTTPS) and at rest. Connection secrets are AES-256-GCM encrypted. Access to production is restricted and logged; each customer’s data is isolated. Opt-outs (“stop”/“unsubscribe”) are honoured automatically and permanently before every send.

Retention & your rights

We keep data while your account is active plus a limited period for legal/accounting purposes. Depending on your jurisdiction (GDPR, CCPA, the Australian Privacy Act) you can access, correct, delete, or export your data, or object to processing. Account deletion hard-deletes your account and all associated personal data. To make a request, email xxiautomate@gmail.com; we respond within the timeframe your law requires.

Breach notification & transfers

If a personal-data breach occurs we notify affected customers and authorities within legally required timeframes (e.g. 72 hours under GDPR; the Australian Notifiable Data Breaches scheme). Data may be processed by sub-processors in other countries under appropriate safeguards.

© 2026 XXIautomate · This policy may be updated; material changes will be communicated.