Privacy Policy
Last updated: August 17, 2026
MsgHealth (“we”, “us”, or “our”) operates the MsgHealth platform for service businesses. This Privacy Policy explains what information we collect, how we use it, who we share it with, and your rights regarding your data. By using MsgHealth you agree to this policy.
Information We Collect
We collect the following categories of information:
Account Information: Your name, email address, and phone number when you register. Phone numbers are used for OTP login verification.
Business Profile: Business name, branding assets, services, and pricing you configure in your account.
Client Data You Enter: Names, phone numbers, appointment history, health/churn scores, and any notes you add about your clients. You are the data controller for this information.
Booking Submissions: Names and phone numbers submitted by your clients through your public booking page.
Payment Data: Transaction records (amounts, dates, service types). Raw card numbers are never stored — they are tokenized directly by Stripe.
Usage & Analytics: Browser type, IP address, pages visited, feature usage, and error logs collected automatically to operate and improve the service.
Lead Source & Marketing Attribution: When a client is created through your public booking page or a connected social channel, we record UTM source/medium/campaign values and a timestamped touchpoint history against that client record, so you can see which marketing channels drive bookings.
Communications: SMS message logs (outbound and inbound), call logs, and call/video recordings associated with your account, stored in our database.
Voice Data: If you use the AI Voice Assistant's voice cloning feature, we collect a voice sample you provide and send it to our voice-cloning provider (ElevenLabs) to generate a synthetic voice model for your account. Inbound/outbound calls handled by the AI voice assistant may be recorded and transcribed.
Tax & Financial Data: If you use the Accountant module, we collect worker classification data, pay information, and — separately, encrypted — taxpayer identification numbers (TINs/SSNs) for 1099/W-2 filings, plus expense and revenue records you enter.
Connected Third-Party Accounts: If you connect Google Calendar, Google Business Profile, or a social media account (e.g. Meta/Facebook/Instagram) for scheduling or posting features, we store the OAuth access/refresh tokens needed to act on your behalf on that platform.
SMS & Text Messaging
We operate two SMS programs:
OTP Verification (Platform Users): When you sign in with a phone number, we send automated one-time passcodes via SMS for account security only. Frequency: one per login attempt. Provider: Twilio via Supabase Auth.
Business-to-Client Messaging: Your clients may receive SMS messages (appointment reminders, birthday greetings, review requests, and campaigns) sent by you through MsgHealth. These messages originate from your account. You are responsible for client consent. Provider: Twilio.
Message & Data Rates: Standard carrier rates may apply for all SMS messages.
Opt-Out: Any recipient may reply STOP to stop receiving messages. Opt-outs are honored automatically. Contact us to remove your number from our records entirely.
No Marketing to You: We do not send you promotional SMS messages and do not sell or rent your phone number.
How We Use Your Information
We use collected data to:
Authentication: Verify your identity and secure your account.
Service Delivery: Provide dashboard features: client management, SMS automation, booking, payments, AI analytics, and loyalty tools.
AI Features: Generate churn risk predictions and health scores using anonymized client metrics. We send aggregate metrics — not names or phone numbers — to AI provider APIs (Anthropic, OpenAI, xAI Grok) unless you explicitly include personal data in an AI chat message.
Voice Calling & Cloning: Route and record calls handled by the AI voice assistant, transcribe them for quality and response generation, and — if you opt in — generate a cloned voice model from a sample you provide.
Accounting & Tax Filing: Estimate tax set-aside amounts and prepare 1099/W-2 filing data you submit for e-filing through Track1099.
Billing: Process your subscription payments and maintain billing records.
Compliance & Safety: Detect fraud, enforce our Terms, respond to legal requests, and protect user safety.
Service Improvement: Analyze usage patterns to improve features and fix bugs. We do not sell this data.
Third-Party Services & Data Sharing
We share data with the following service providers solely to operate MsgHealth. We do not sell your personal information.
Supabase: Database, authentication, and real-time subscriptions. All data is encrypted at rest and in transit.
Twilio: SMS delivery for OTP verification and business-to-client messaging. Phone numbers are shared with Twilio to route messages.
SignalWire: Voice calling and the AI voice assistant. Call audio, recordings, and phone numbers are shared with SignalWire to route and process calls.
Telnyx: Ringless voicemail delivery. Recipient phone numbers and voicemail audio are shared with Telnyx to deliver drops.
ElevenLabs: AI voice cloning for the Voice Assistant. Voice samples you provide are sent to ElevenLabs to generate a synthetic voice model.
Stripe: Payment processing, Terminal hardware, subscription billing, and SMS-overage metered billing. Stripe receives transaction data and card details directly. Subject to Stripe's Privacy Policy.
Track1099 (Avalara): 1099-NEC/1099-MISC/W-2 e-filing. Payee names, addresses, TINs/SSNs, and payment amounts you confirm are submitted to Track1099 to prepare filings.
Anthropic (Claude): AI-powered churn prediction, chat assistant, and Accountant explanations. Anonymized client metrics and user chat inputs are sent to Anthropic's API.
OpenAI: Alternative AI chat assistant (user-selectable). Chat inputs may be sent to OpenAI's API.
xAI (Grok): ML-based business forecasting. Aggregated metrics only.
Google (Calendar, Business Profile, Reviews): If you connect these integrations, we exchange booking/review data with Google APIs on your behalf using the OAuth tokens described in Section 1.
Meta / Social Platforms: If you connect a social media account for the Social Planner, post content and scheduling data are sent to that platform's API using your connected account's OAuth token.
Resend: Transactional and marketing email delivery (booking confirmations, reports, campaigns).
Apple & Google Wallet: If you generate a digital business card wallet pass, the pass content is signed and delivered through Apple Wallet / Google Wallet infrastructure.
Upstash Redis: Rate limiting. IP addresses are used ephemerally for rate-limit counters and are not stored long-term.
Cloudflare: Application hosting and edge network. Subject to Cloudflare's Privacy Policy.
Cookies & Local Storage
MsgHealth uses browser localStorage to persist your session, theme preference, and pinned dashboard widgets. We do not use third-party advertising cookies. We may use first-party cookies for session management via Supabase Auth.
Data Retention
Active Accounts: Data is retained for the duration of your account, including SMS/call logs, recordings, and payment transaction records entered in the app. You can export your client data at any time from the dashboard.
Account Deletion: Deleting your account is immediate and permanent: your client records, bookings, campaigns, and related account data (including in-app payment transaction records) are deleted at the time of the request and cannot be recovered afterward. Export any data you need before deleting your account. Records held directly by Stripe, Track1099, or other third-party processors are retained separately under their own policies, which may include longer regulatory retention periods for payment and tax records that MsgHealth does not control.
Voice Samples & Cloned Voices: Voice samples and cloned voice models are stored with ElevenLabs and are deleted when you remove the associated voice assistant or on request.
Security & Sensitive Data
We implement industry-standard safeguards: TLS encryption in transit, encryption at rest for stored data (via Supabase), row-level security policies so each user can only access their own data, HMAC-authenticated cron and webhook endpoints, and dedicated AES-256-GCM field-level encryption for taxpayer identification numbers (TINs/SSNs) collected in the Accountant module. However, no method of transmission or storage over the internet is 100% secure, and we cannot guarantee absolute security. Voice recordings, call transcripts, and cloned voice models are sensitive data; access is restricted to your account and processed only to deliver the features you enable.
Your Rights
Depending on your jurisdiction, you may have the right to:
Access: Request a copy of the personal data we hold about you.
Correction: Request correction of inaccurate or incomplete data.
Deletion: Request deletion of your personal data (subject to legal retention requirements).
Portability: Export your client data in a machine-readable format from the dashboard at any time.
Opt-Out of SMS: Reply STOP to any SMS message or contact us to opt out of all SMS communications.
Children's Privacy
MsgHealth is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will promptly delete it.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or in-app notification at least 14 days before the change takes effect. The updated policy will be posted here with a revised effective date.
Questions? Contact us at support@msghealth.net