polite.aiDocs
REFERENCE

Security, privacy & your data

What polite.ai stores about your calls and your business, how long it's kept, and how you stay in control of all of it.

Everything your agents record, hear and learn belongs to your organisation. You can read it, export it, and delete it — and nothing arrives in it without your say-so.

What we store

For each call: a recording (where you've enabled recording — it's optional, per agent, with a per-number override), stored encrypted; a transcript; and a data feed of what the agent actually did — the tools it called and what came back. Bookings made by your agents live in polite.ai's own booking record, which is what the agent reads back to callers. Knowledge bases hold the text extracted from your crawled pages and uploaded PDFs. Billing keeps a ledger of every wallet movement.

Credentials you store — API keys on an agent, a private site's crawl login — are write-only: saved encrypted, used where you pointed them, and never readable back out of the dashboard.

How long we keep it

Call history follows your plan: 90 days on Starter, 6 months on Pro, 1 year on Scale — see Plans & limits. Knowledge content stays until you delete it: removing a knowledge base purges its pages, documents and stored files permanently.

We only crawl a site when someone authorised ticks I'm authorised to have this site crawled — at signup for your own site, or on Knowledge → Add knowledge base afterwards. Without consent the base shows Consent withheld and is never crawled. Public crawls respect robots.txt.

To revoke, delete the knowledge base — the crawled content is purged and the site isn't crawled again. There's also an org-wide emergency toggle on the Knowledge page that instantly stops every agent using knowledge — see Knowledge bases and Website knowledge.

Connected Google and Microsoft accounts

An admin connects the account once, at organisation level; we store a refresh token so nobody is re-asked. Agents never receive that credential — they get narrow, admin-approved tools, and the AI never browses your calendar or mailbox. A booking agent sees only the offerable slots your policy computes — never your events or free/busy detail — plus a recognised caller's name and its own booking confirmations. Contacts are only ever created, never edited or deleted.

Two further protections: connected-account tools only run on approved AI model providers with clear no-training commitments, and Integrations → Disconnect deletes the stored tokens. polite.ai's use of raw or derived user data received from Workspace APIs adheres to the Google User Data Policy, including the Limited Use requirements.

Getting your data out

You own your agent definitions, prompts, call logs, transcripts and recordings, and can export them from the dashboard and the API:

Questions or requests

For anything this page doesn't answer — deletion requests, closing a workspace, or a security concern — email support@aplisay.com.

Last updated 2026-07-30