Legal
Privacy Policy
Effective September 24, 2026
This policy explains what Ask Garrett (the web chat at garrettsmith.com, [email protected], and the Slack app) collects, why, who we share it with, and how long we keep it. It’s provided by [Company legal name]. The short version: we use what you send us to answer you, we don’t sell it, and we keep as little as we can.
What we collect
When you use the web chat
- Your questions and the answers. The conversation is kept in your browser tab (session storage) and sent to our server with each new question so the AI has context. We don’t store web conversations on our servers. Closing the tab clears them.
- Your IP address, to count free questions and prevent abuse. The counter expires after 30 days.
- Messages turned away. An automated check screens each message for topic. If it declines one (for example, off-topic or trying to get around the rules), we keep that single message, not the conversation, to review how the check is working. We keep the most recent 500.
When you become a member
- Your email address and plan, and the Stripe customer and subscription IDs that link them. Stripe handles your card; we never see or store card numbers.
- Notes about your business that the AI saves so it remembers you: things like business names, locations, competitors, and goals (up to 40 short notes). The same notes are used on the web, by email, and in Slack for your account.
- A sign-in cookie (“ag_member”) that keeps you signed in for up to 60 days. It’s the only cookie we set, and it’s required for the Service to work. We don’t use advertising or tracking cookies.
When you email [email protected]
- The email: sender, subject, and message. We keep the last 12 messages of each thread for 60 days so replies have context. Attachments aren’t read.
- Email authentication results (SPF, DKIM, DMARC), so we only reply to real senders.
- If you aren’t a member, we keep your address for 30 days so we only send you one reply.
When your team uses the Slack app
- Messages in threads where Garrett is mentioned, and direct messages to Garrett, read at the time to answer. We don’t store Slack conversations; we store the workspace’s saved notes and the Slack access token, which is deleted when the app is uninstalled.
- Slack user IDs, so the AI can tell teammates apart within a thread.
When you use the contact form
- Your email, topic, and note, so Garrett can reply. We keep the most recent 1,000 requests.
How we use it
- To answer your questions, including looking up live search data about the businesses you ask about.
- To run your account: billing, sign-in, the free-question limit, and fair use.
- To send emails you’d expect: answers, sign-in links, receipts, and important account notices.
- To keep the Service secure and fix problems.
We don’t sell or rent personal information, don’t use it for advertising, and don’t use your conversations to train AI models.
Who we share it with
Only the providers that run the Service, and only what each one needs:
- Anthropic (the AI model): your questions, conversation context, and saved notes, to generate answers. Anthropic’s commercial terms don’t allow it to train its models on this data.
- Local SEO Data (a related service Garrett operates): the business names, keywords, locations, and URLs being looked up.
- Stripe (payments): your email and payment details.
- Resend (email): emails to and from [email protected].
- Upstash (database) and Railway (hosting): where the data described above is stored and processed.
- Slack, if your team installs the app.
We may also share information if the law requires it, to protect someone’s safety, or as part of a sale or merger of the business (in which case this policy would still apply to your data).
These providers may process data in the United States and other countries. Where required, we rely on their standard contractual protections for international transfers.
How long we keep it
- Web conversations: only in your browser tab.
- Email threads: 60 days after the last message.
- Free-question and rate-limit counters: 30 days.
- Messages turned away by the topic check: the most recent 500, then deleted.
- Saved business notes: until you ask us to delete them.
- Account and billing records: while you’re a member, and afterwards as long as needed for taxes, disputes, and the law.
- Server logs from our hosting provider: kept briefly for debugging, under the provider’s retention.
Your choices and rights
You can ask us to show you, correct, export, or delete your personal information, including your saved notes, by emailing [email protected] from the address on your account. We’ll respond within 30 days. Depending on where you live (for example California, the EU, or the UK), you may have additional rights, including the right to complain to a data protection authority. We won’t treat you differently for using them.
Security
Connections are encrypted, webhooks from Stripe, Resend, and Slack are signature-checked, sign-in uses expiring signed links, and access to production data is limited to the people who run the Service. No system is perfectly secure; if a breach affects your data, we’ll tell you as the law requires.
Children
The Service is for businesses and isn’t directed at anyone under 18. We don’t knowingly collect their data.
Changes
If we change this policy in a way that matters, we’ll email members before it takes effect and update the date above. See also our Terms of Service.
Contact
Privacy questions or requests: [email protected].