Legal
Privacy Policy
Last updated August 10, 2026
Pombi provides an AI assistant that helps local businesses answer calls, book jobs, take orders, and follow up with their customers. This policy explains what information we collect, how we use it, and the choices you have.
01Who we are
“Pombi,” “we,” “us,” and “our” refer to Pombi LLC, 35 Burnham Hl, Westport, CT 06880-6607, the operator of the Pombi service (the “Service”). This policy applies to the Pombi website, dashboard, and the voice and messaging assistant we provide to businesses (“Customers”).
Two kinds of people appear in this policy: the business owner and staff who sign up for and use Pombi, and the end customers of those businesses (the people who call, text, book, or order). We handle the second group’s information on the business’s behalf, as described below.
02Information we collect
Account information you give us when you sign up: your name, business name, email address, phone number, business address, hours, services, and pricing.
Business content you configure or generate in the Service: menus and service lists, booking rules, message templates, and the knowledge you teach the assistant about your business.
End-customer information that flows through the Service as we operate it for you, which may include:
- Caller and customer names, phone numbers, and email addresses
- Call audio, transcripts, and text-message content
- Bookings, orders, quotes, and payment status
- Reviews and the replies drafted in response
Payment information. Subscription payments and any payments your customers make are processed by Stripe. Pombi does not store full card numbers; we receive limited details such as the last four digits, brand, and payment status.
Technical information collected automatically: log data, device and browser information, IP address, and usage of the dashboard, used to operate and secure the Service.
03How we use information
- Operate the Service — answer calls and messages, book jobs, take orders, send reminders and follow-ups, and surface everything in your dashboard.
- Generate drafts and suggestions using AI, which you review and approve before they are sent or acted on.
- Process payments and, where you enable it, route your customers' payments to your own connected account.
- Communicate with you about your account, security, and product updates.
- Maintain, secure, debug, and improve the Service.
- Comply with law and enforce our Terms.
We do not sell personal information, and we do not use the content of your calls, messages, or customer records to train third-party foundation models.
04AI, calls, and message processing
The assistant transcribes calls, understands requests, and drafts responses using AI. To do this, relevant content is processed by our AI and voice providers (for example, speech-to-text, text-to-speech, and large-language-model services) solely to deliver the Service to you. Recording and transcription may be subject to consent requirements — see our Terms of Service for your responsibilities around notifying and obtaining consent from callers.
05Google user data and Limited Use
If you connect your Google account, Pombi requests access only to the Google data needed for the features you turn on:
- Google Calendar (calendar events) — to create, read, and update bookings on your calendar so appointments the assistant takes appear on your schedule.
- Google Business Profile (only if you grant it) — to read your listing and, where supported and approved, help manage reviews.
- Gmail — send access (
gmail.send, only if you connect Gmail) — to send the replies you write in Pombi from your own address, so your customer hears from you, not from a platform sender. - Your Google account email address (basic profile only, when you connect Gmail) — to label the connection and set the address your replies send from.
What Pombi reads from your mailbox: nothing. The Gmail permission Pombi asks for is send-only. It cannot open, list, or search your mail — incoming email stays in Gmail, and Pombi only ever transmits the specific replies you write or approve, from your own address. Pombi never sends an automatic AI reply on your email threads — the assistant may draft, but nothing leaves your address unless you send it. (Accounts connected under Pombi’s earlier two-way sync permission — currently limited to internal test accounts — additionally sync customer threads into the inbox, under strict rules: only messages from an already-known customer or an already-tracked thread; drafts, spam, trash, and self-mail are skipped; mailbox history is never backfilled.)
What we store, and where. For email that enters the product this way — replies you send, and synced threads on the earlier-permission accounts described above — we store the sender and recipient names and addresses, the subject, the timestamp, the plain-text body, and Google’s thread and message identifiers, in the same conversation record used by every other channel. It is held in our hosted Postgres database, separated per business by database-enforced access rules. Your Google access and refresh tokens are encrypted at rest with AES-256-GCM and are never shown back to you or to anyone else.
How long we keep it, and how to get it deleted. The text of synced email is retained for 365 days by default, after which it is automatically purged — the words are deleted and only metadata (timestamps, channel, and outcome) remains. You can disconnect Google at any time from your dashboard: that revokes Pombi’s access at Google and deletes the stored tokens immediately. Disconnecting does not by itself erase email already synced into your inbox — that email remains visible to you until it ages out under the 365-day limit, or until you ask us to delete it. To have it deleted sooner, or to have all Google-derived data removed, email us at pombihq@gmail.com and we will delete it.
Pombi’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we use Google user data only to provide and improve the features you enable, we do not transfer or sell it to third parties except as needed to operate the Service or as required by law, we do not use it for advertising, and we do not allow humans to read it except with your consent, for security, to comply with law, or where the data is aggregated and anonymized. You can disconnect Google at any time from your dashboard, which revokes our access.
06Facebook and Instagram data
Pombi does not have a live Facebook or Instagram integration today. This section describes what happens when you connect one, so it is disclosed before it is used rather than after.
What we would collect. If you connect your Facebook or Instagram account through Facebook Login, we receive only what you grant: the list of Pages and Instagram professional accounts you manage, the name and identifier of the account you choose to connect, an access token, and — for the account you connect — the direct messages sent to it and the identifiers and display names of the people who send them. We do not request your friends, your posts, your ad accounts, your email address, or your personal profile.
What we do with it. Exactly one thing: bring those messages into your Pombi inbox alongside your calls, texts, and email, and send the replies you or the assistant compose back in the same conversation. Replies that the assistant writes are marked as automated to the person receiving them. We do not use this data for advertising, we do not sell it, and we do not use the contents of your messages to train third-party foundation models.
How long we keep it, and how to have it deleted. Message content follows the same 365-day limit as every other channel; access tokens are encrypted at rest and are deleted immediately when you disconnect. You can disconnect at any time from the Connections page in your dashboard, or remove Pombi from your Facebook app settings. Removing Pombi there sends us a deletion request automatically; we answer it at /api/meta/data-deletion and hand back a confirmation code you can check any time at pombi.app/data-deletion. You can also start a deletion yourself from that page, or by emailing pombihq@gmail.com.
Our use of information received from Meta’s platforms follows Meta’s Platform Terms and Developer Policies, including the requirement that automated messages identify themselves as automated.
07Service providers we share with
We share information with vendors who process it on our behalf, under contracts that limit their use to operating the Service. These include, by function:
- Hosting and database (application hosting; Supabase)
- Telephony and messaging (Twilio)
- Speech and voice (speech-to-text and text-to-speech providers)
- AI language models (Anthropic)
- Payments (Stripe, including Stripe Connect)
- Point of sale and orders (Square, where you connect it)
- Calendar and business listings (Google)
- Email delivery (Resend)
We may also disclose information to comply with law, to protect rights and safety, or in connection with a merger or acquisition (with notice where required).
08Text messaging (SMS) and mobile information
Businesses using Pombi may send text messages to their customers — such as booking confirmations, appointment reminders, order updates, and follow-ups — only to customers who have provided their phone number and consented to receive them.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing with subcontractors in support services, such as customer service and message delivery (for example, our messaging provider Twilio), is permitted solely to deliver the Service. All other use categories exclude text messaging originator opt-in data and consent; this information will not be shared with, or sold to, any third parties.
You can opt out of text messages at any time by replying STOP to any message. Reply HELP for help, or contact us at pombihq@gmail.com. Message and data rates may apply, and message frequency varies. See our Terms of Service for the full SMS messaging terms.
09Data retention
We keep information for as long as your account is active and as needed to provide the Service, then for a reasonable period afterward to meet legal, accounting, and security obligations. You can ask us to delete your account data, subject to records we must retain by law.
Conversation content has a fixed limit. The words of a conversation — call transcripts, text messages, web chats, and synced email — are automatically purged 365 days after the conversation, on every channel. What remains afterward is the metadata: when it happened, which channel, and how it ended. This runs automatically; you do not have to ask for it.
10Security
We use administrative and technical safeguards to protect information, including encryption of sensitive credentials at rest and access controls. No method of transmission or storage is perfectly secure, but we work to protect your information and to notify you of material incidents as required by law.
11Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal information, and to object to or restrict certain processing. Business owners can manage most data directly in the dashboard, disconnect integrations, and cancel at any time. To make a request, contact us at pombihq@gmail.com.
End customers of a business using Pombi should contact that business directly; we will support the business in responding to your request.
Deletion has its own page: pombi.app/data-deletion explains how to have your data removed and where a request stands.
12Children
The Service is for businesses and is not directed to children under 13, and we do not knowingly collect their personal information.
13Changes to this policy
We may update this policy from time to time. When we do, we will change the “Last updated” date above and, for material changes, provide additional notice.
14Contact us
Questions about this policy or your data? Email pombihq@gmail.com.