Privacy Policy
Last updated: July 16, 2026 · Effective: July 16, 2026
EmpirePilot OS ("EmpirePilot", "we", "us") is an AI-native business operating system that helps entrepreneurs run multiple brands from one dashboard — content creation, social publishing, CRM, email inbox, reviews, analytics, and automation. This policy explains what we collect, why, how it is protected, and the choices you have. It applies to empirepilotos.com, our mobile applications, and all EmpirePilot services (together, the "Service").
1. Information we collect
Information you provide
- Account data — name, email address, and password (stored as a hash by our authentication provider). Optional two-factor authentication secrets.
- Business & brand data — brand names, logos, brand voice, knowledge-base entries, uploaded assets, and content you create or schedule.
- CRM data — contacts, leads, deals, and notes you add about your own customers.
- Connected mailboxes — if you connect an email account (IMAP), we fetch and store messages from that mailbox so the AI Inbox can categorize and draft replies. Mailbox credentials are encrypted (see Section 5). We never delete mail from your server.
- Connected integrations — API keys or tokens you connect (e.g., social publishing, Stripe revenue sync, WordPress). Credentials are stored encrypted.
- Payment data — subscription payments are processed by Stripe. We never see or store full card numbers; we store your Stripe customer ID and plan.
Information collected automatically
- Usage data — actions inside the Service (e.g., content generated, posts published) used for features like your activity feed, analytics, and plan limits.
- Device data — browser type, device identifiers for push notifications (if you enable them), and log data (IP address, timestamps) kept for security.
- Cookies — we use strictly necessary cookies for authentication and session management. We do not use advertising cookies or sell data to ad networks.
2. How we use information
- Provide, maintain, and improve the Service.
- Power AI features: your brand voice, knowledge base, and content history are sent to our AI providers (see Section 4) to generate content, replies, articles, and insights on your behalf.
- Publish content you schedule or authorize to your connected social accounts and websites.
- Send transactional messages: push notifications, digests, alerts about errors or milestones, and account emails. You can disable non-essential notifications at any time.
- Process subscription billing and prevent fraud or abuse.
- Comply with legal obligations.
We do not sell your personal information, and we do not use your private business data to train AI models.
3. Your customers' data (processor role)
Data you store about your own customers (CRM contacts, email messages, reviews, social interactions) belongs to you. For that data we act as a processor on your instructions; you are the controller and are responsible for having a lawful basis to store it and for honoring your customers' privacy requests. Deleting a contact, mailbox connection, brand, or your account permanently removes the associated data.
4. Service providers (subprocessors)
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication, and file storage |
| Vercel | Application hosting |
| Anthropic | AI text generation (content, replies, insights) |
| OpenAI | AI image generation |
| Stripe | Subscription payments |
| Ayrshare | Social publishing to your connected accounts |
| Apple / Google / web-push services | Push notification delivery |
Each provider receives only what it needs to perform its function and is bound by its own security and privacy obligations. Data is processed in the United States.
5. Security
- All traffic is encrypted in transit (TLS/HTTPS).
- Connected credentials (mailbox passwords, API keys, push tokens) are encrypted at rest with AES-256-GCM in a dedicated secrets vault.
- Database access is protected by row-level security so each account can only read its own data.
- Optional two-factor authentication (TOTP) is available in Settings → Security.
No method of transmission or storage is 100% secure; if we learn of a breach affecting your data we will notify you as required by law.
6. Data retention & deletion
We keep your data while your account is active. Inside the app you can delete brands (which removes everything belonging to that brand), knowledge entries, automations, and connected mailboxes; disconnecting a mailbox stops all syncing, and messages already imported remain in your workspace until you delete the brand or your account, or ask us to remove them. You can export everything we hold in Settings → Security → Download my data, and permanently delete your entire account and all associated data in Settings → Security → Delete account, or by following the steps at empirepilotos.com/legal/delete-account. Deletion is immediate and irreversible; residual copies in encrypted backups expire within 30 days. Billing records are retained as required by tax law. For removal of specific records we don't yet expose controls for, email privacy@empirepilotos.com — handled within 30 days.
7. Your rights
Depending on where you live (including under GDPR and the CCPA/CPRA), you may have the right to access, correct, export, restrict, or delete your personal information, and the right not to be discriminated against for exercising those rights. Contact us at privacy@empirepilotos.com (or admin@empirepilotos.com) and we will respond within 30 days. We do not sell or share personal information for cross-context behavioral advertising.
8. Push notifications
If you opt in, we send push notifications about your business — new leads, payments, milestones, publishing errors, and daily digests. You can revoke permission at any time in your device or browser settings; expired or revoked tokens are deleted automatically.
9. Children
The Service is for business use and is not directed to anyone under 18. We do not knowingly collect data from children.
10. Changes
We may update this policy as the Service evolves. Material changes will be announced in the app or by email, and the "Last updated" date above will change. Continued use after changes take effect constitutes acceptance.
11. Contact
EmpirePilot OS · privacy@empirepilotos.com · support@empirepilotos.com · empirepilotos.com