Privacy Policy
Last updated July 24, 2026
Staffed ("Staffed," "we," "us") is an AI chatbot service operated by The AI Handyman LLC. This policy explains what information we collect, how we use it, and the choices you have. It covers the Staffed portal at staffed.theaihandyman.ai, the chat widget you embed on your website, and the optional Instagram messaging connection described in section 5.
1. Information we collect
- Account & business information. Your name, email address, and the business details you choose to provide: your business name plus any profile you add (owner and team names, business description, hours, location, and time zone). We use these to create and secure your account and to power your chatbot's answers.
- Documents you upload. The files you add to build your chatbot (PDF, Word, or text), and the text we extract and index from them.
- Website chat usage data (not message content). When a visitor chats with your chatbot on your website, we process their message to generate a reply but we do not store the message text or the reply. What we keep is anonymous usage data only: a per-conversation identifier (not tied to a person), token counts, and response latency, used to power your analytics and our billing. The message itself is sent to our AI providers (Anthropic and Google Vertex AI) to produce the answer, under their no-training commercial terms, and is not retained by us. Instagram conversations work slightly differently; see section 5.
- Payment information. Handled by Stripe. We do not store full card numbers; we keep a customer/subscription reference and your plan status.
- Technical data. Standard logs (e.g. IP address, request metadata) used for security, abuse prevention, and reliability.
2. How we use information
- To build and operate your chatbot and answer your customers.
- To show you analytics about your chatbot's usage.
- To process payments and manage your subscription.
- To provide support and communicate with you about the service.
- To protect the service: rate-limiting, abuse and fraud prevention, and enforcing our fair-use limits.
3. Tenant isolation & security
Each business's data is isolated to its own account. Access is scoped per business at the database layer (row-level security and per-business scoping on backend paths), and your chat widget is domain-locked, so it only loads and answers on the website domains you approve. Data is encrypted in transit. Our team may access your account data only as needed to operate the service, provide support you request, and protect its security, never to share it or use it for unrelated purposes.
4. AI processing and "no training"
Your chatbot is powered by Anthropic's Claude for chat and Google Cloud's Vertex AI for indexing your documents. Both are used under their commercial API terms, which do not use your content to train their models. Your documents and chats are used to answer your customers, not to train anyone's AI.
5. Instagram messaging (Meta platform data)
If you connect your Instagram professional account, your Staffed chatbot answers direct messages sent to that account. This section explains how we handle Instagram data for that feature. Our Meta app uses Instagram access only; we do not request or receive Facebook profile data.
- What we access. With your authorization through Instagram login, we receive your Instagram account ID, username, and an access token that lets us reply on your behalf. When someone messages your connected account, Meta sends us the message text and the sender's Instagram-scoped ID so the chatbot can respond.
- How we use it. Solely to generate and send automated replies for your business. Message text is processed by our AI provider (Anthropic, under no-training commercial terms) to compose the answer. We do not use Instagram data for advertising, we do not sell it, and we do not share it with third parties beyond the service providers that run Staffed (section 6).
- What we store and for how long. We keep your access token while the connection is active, and the most recent messages of each conversation (a short rolling window) so the chatbot has context for follow-up questions. Conversation context is deleted automatically 90 days after a conversation's last message, and older messages roll off continuously before that. We also keep the same anonymous usage counts described in section 1 (no message text). Business owners see their Instagram conversations in their own Instagram inbox; Staffed's dashboard shows aggregate counts, not transcripts.
- Disconnecting and deletion. You can disconnect at any time by removing the app in your Instagram settings (Apps and Websites) or by asking us. To request deletion of Instagram data we hold (your token and stored conversation context), email support@theaihandyman.ai and we will delete it promptly. This is also our data deletion process for Meta platform data.
6. Service providers (sub-processors)
We rely on a small set of trusted vendors to run the service, described by role below. A current list of the specific providers is available on request at support@theaihandyman.ai.
- AI providers: Anthropic (Claude) generates the chat replies and Google Cloud (Vertex AI) creates the document embeddings used for retrieval, both under no-training commercial terms.
- Cloud hosting & compute: serving the portal and chat widget and running document processing.
- Database, authentication & document storage.
- Payment processing.
- DNS.
- Transactional email, where enabled.
- Website-preview images: generating the optional preview backdrop shown when you preview your chatbot (only the site URL you enter is sent).
7. Data retention & deletion
We retain your documents, anonymous chat usage data, and account data while your account is active (we do not store website chat message content; Instagram conversation context is the exception described in section 5). You can ask us to delete your data, and we delete it when you close your account, subject to limited records we must keep for legal, tax, or security reasons. To request deletion, email support@theaihandyman.ai.
8. Your responsibilities as a business
You decide what you upload, and the chat runs on your website, so the documents and the visitor messages flowing through Staffed are your data, not ours. You are responsible for having the right to use what you upload, for telling your visitors that the chat collects their messages (your own privacy notice, where required), and for not uploading sensitive personal information you don't have a basis to process. To help with that, the chat widget shows a short note to your visitors by default ("Messages are processed to answer your questions and are never sold or shared."); you can turn it off in your dashboard if you post your own notice. Please don't put secrets (passwords, card numbers) into documents or the chat.
9. Children
Staffed is a business tool and is not directed to children under 13, and we don't knowingly collect their information.
10. International users
We operate in the United States, and your information is processed there. By using Staffed you understand your information may be processed in the U.S.
11. Changes & contact
We may update this policy and will revise the date above when we do. Questions or requests: support@theaihandyman.ai.