← Rozon AI

Privacy Policy

Effective date: July 29, 2026

Rozon AI (“Rozon AI,” “we,” “us”) is operated by Rozon LLC. This Privacy Policy explains what information we collect through our platform, how we use it, and the choices you have. It applies to the businesses that use Rozon AI (“tenants”) and to the customers, leads, and contacts that interact with a tenant through the platform.

1. Information we collect

Account and business information. When a business signs up, we collect account details (name, email, authentication credentials handled by our authentication provider) and business configuration (business type, services offered, service areas, business hours, pricing, and similar details the tenant provides to configure their AI team).

Lead and customer information. On behalf of our tenants, the platform captures information submitted by their leads and customers — for example name, contact details, and message content submitted through web forms, chat widgets, email, SMS, or connected social/ad channels. This information is owned and controlled by the tenant; we process it on their behalf.

Usage data. We collect standard technical data (IP address, browser type, pages visited, timestamps) to operate and secure the platform.

Connected advertising accounts (including Meta). If a tenant chooses to connect a Meta Ads or Google Ads account through that platform’s own login screen, we receive and store, strictly within the scope the tenant authorizes: an encrypted access token; the connected ad account’s ID and name; and, for campaigns the tenant creates through Rozon AI, the campaign name, objective, budget, status, and performance data (such as delivery status and spend). See Section 5 for how this data is used.

2. How we use information

  • To operate the platform: routing leads, scheduling, drafting responses, and generating the recommendations shown to tenant staff.
  • To power the AI features (see Section 3) that respond to leads, draft content, and draft ad campaigns for staff review.
  • To send transactional email and SMS on a tenant’s behalf (e.g. appointment confirmations, follow-ups).
  • To maintain security, prevent abuse, and enforce tenant data isolation.
  • To improve the platform’s reliability and features.

We do not sell personal information, and we do not use one tenant’s data to train models or features for another tenant.

3. AI processing

Rozon AI uses a third-party large language model provider (Anthropic) to draft responses, content, and ad copy. Relevant business context and message content is sent to that provider to generate a draft. Some actions — publishing an ad or changing an ad budget — require an explicit, logged approval from a human staff member before anything goes live; no ad publishes or spends money automatically.

Rozon AI uses these providers only to generate output in response to a request. No data Rozon AI sends to an AI provider is used by that provider to train, fine-tune, or improve its models, and Rozon AI does not train or fine-tune models of its own on tenant, customer, or Google user data. Section 5 covers how this applies to Google Workspace data specifically.

4. Third-party service providers

We use the following categories of subprocessors to operate the platform. Each only receives the data necessary to perform its function:

  • Authentication: Clerk — account and organization management.
  • Database hosting: Neon (PostgreSQL) — stores tenant and lead data.
  • AI processing: Anthropic — generates AI-drafted responses and content.
  • Email delivery: Postmark — transactional email.
  • SMS delivery: Twilio — transactional SMS and two-way messaging.
  • Image generation: fal.ai — AI-generated marketing images.
  • Voice: ElevenLabs — AI-generated voiceover audio, and the conversational agent that answers a tenant’s phone calls.
  • Media storage: Vercel Blob — stores generated and uploaded media.
  • Hosting: Vercel — application hosting and infrastructure.
  • Advertising platforms: Meta and Google — only when a tenant explicitly connects their own ad account, to create and manage the campaigns that tenant authorizes.

5. Google Workspace data and the Limited Use policy

Rozon AI’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Rozon AI never uses, transfers, or sells Google user data — raw, aggregated, anonymized, or derived — to create, train, improve, or fine-tune any foundational or generalized artificial-intelligence or machine-learning model, whether our own or a third party’s.

The only Google Workspace data Rozon AI reads is free/busy time from Google Calendar, through the calendar.freebusy scope. That endpoint returns nothing but the start and end times of periods a tenant is already occupied — no event titles, descriptions, guests, locations, or attachments. Rozon AI uses those intervals for exactly one purpose: to remove times a tenant is already busy from the appointment slots it would otherwise offer a customer.

That filtering happens in Rozon AI’s own scheduling engine before any AI model is involved. The AI assistants that write messages to customers receive only the resulting list of available times, computed by Rozon AI — they are never given Google Calendar data, and no Google Workspace data is included in any prompt, request, or payload sent to a third-party AI provider.

Rozon AI also writes appointments it books into a tenant’s Google Calendar using the calendar.events scope. That is Rozon AI’s own booking data being sent to Google, not Google user data being read out.

6. Meta and Google advertising data

When a tenant connects a Meta Ads account, Rozon AI requests the ads_management and ads_read permissions through Meta’s own login and consent screen. We only receive the ad account(s) and data the tenant explicitly authorizes on that screen, and we use it solely to:

  • Show the tenant which of their ad accounts is connected.
  • Create a draft ad campaign as a paused campaign, only after a staff member has reviewed and approved it — Rozon AI never publishes an ad or spends money without that explicit, logged approval.
  • Let a staff member change an existing campaign’s budget, again only after explicit approval.
  • Display campaign status and spend back to the tenant, by periodically reading it from Meta’s Marketing API.

We do not use Meta Platform Data for any purpose beyond providing this feature to the connected tenant, we do not share it with any party except the subprocessors listed in Section 4 that are necessary to run the platform, and we do not use it to serve ads to anyone outside of the campaigns the tenant configures and approves. A tenant can disconnect their Meta Ads account at any time from Settings; doing so immediately stops all further access and triggers deletion of the stored token as described in Section 9.

We process this data in compliance with Meta’s Platform Terms and Developer Policies. The same principles — access limited to what the tenant authorizes, used only to provide the connected feature, deletable on request — apply identically to Google Ads data when a tenant connects a Google Ads account.

This Privacy Policy describes Rozon AI’s own collection and use of information. It does not describe, and is not a substitute for, Meta’s own privacy policy governing Meta’s collection and use of information, available at facebook.com/privacy/policy.

7. Data isolation and security

Every tenant-owned record is scoped to that tenant, and all queries are tenant-scoped — one tenant cannot access another’s data through the platform. All traffic to and from the platform is encrypted in transit (HTTPS/TLS). Sensitive credentials, including connected advertising-account access tokens, are encrypted at rest using AES-256-GCM before they are ever written to our database — we do not store third-party access tokens in plain text. Access to tenant data within our own team is limited to what is necessary to operate and support the platform, and we do not sell User Data under any circumstances, including where a disclosure of intent to sell might otherwise appear in a policy like this one.

8. Data retention

We retain account and lead data for as long as an account is active, and for a reasonable period afterward to comply with legal obligations, resolve disputes, and enforce agreements. Connected advertising-account access tokens are retained only for as long as the connection stays active — disconnecting an account (Section 5) deletes the stored token immediately, not at the end of a retention window. A tenant or contact may request deletion at any time as described in Section 9.

9. Cookies

We use cookies and similar technologies that are strictly necessary for authentication and session management. We do not use third-party advertising or tracking cookies on the Rozon AI platform itself.

10. How to delete your data

Disconnecting a connected ad account. A tenant can disconnect their Meta Ads or Google Ads account at any time from Settings → Ad account integrations. This immediately revokes Rozon AI’s access and permanently deletes the stored access token; any campaigns already created remain in the tenant’s own Meta or Google account, unaffected, since we never take ownership of them.

Deleting your account or data. To request deletion of a tenant account, or any personal information we hold about you as a lead, customer, or tenant user, email hello@rozon.ai with the subject line “Data deletion request” and the account or email address in question. We will verify the request, delete the corresponding data from our production systems within 30 days, and confirm by email once complete. Deletion also removes any Meta or Google access tokens associated with the account.

11. Your rights and choices

Depending on your location, applicable law (for example the EU/UK GDPR or the California Consumer Privacy Act) may give you some or all of the following rights over your personal information: to know what we collect and how we use it; to access a copy of it; to correct inaccurate information; to request deletion (Section 9); to receive it in a portable format; and to not be discriminated against for exercising these rights. If you are a lead or customer of a Rozon AI tenant, the tenant business controls that data and we recommend contacting them directly; we will still assist with any request routed to us. If you are a tenant, or have another privacy request, contact us at the email in Section 14.

12. International data transfers

Rozon AI is operated from the United States, and our hosting and database subprocessors (Section 4) store and process data in the United States. If you access the platform from outside the United States, your information will be transferred to, stored, and processed in the United States.

13. Children’s privacy

Rozon AI is a business-to-business platform and is not directed at, or knowingly used to collect information from, children under 13.

14. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the effective date above.

15. Contact us

Questions about this policy, or a privacy or data deletion request, can be sent to hello@rozon.ai.