Privacy Policy
Last updated: February 22, 2026
1. Introduction
Afterhours AI ("we," "us," or "our") operates the Afterhours AI platform at getafterhours.ai (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our Service.
By accessing or using our Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this Privacy Policy, please do not access the Service.
2. Information We Collect
2.1 Account Information
When you create an account, we collect your name, email address, phone number, company or brokerage name, and billing information. If you sign up using Google OAuth, we receive your name and email address from Google.
2.2 Call Data
Our Service processes voice calls on your behalf. We collect and store call recordings, AI-generated transcripts, call duration, caller phone numbers, call outcomes, and qualification data. Call recordings are stored securely in Google Cloud Storage and are accessible only by authorized users within your organization.
2.3 CRM Data
When you connect a CRM integration (Follow Up Boss, HubSpot, kvCORE, or Salesforce), we access contact information, lead status, and activity data necessary to sync call outcomes. CRM credentials are encrypted using AES-256 encryption before storage.
2.4 Usage Data
We automatically collect information about how you interact with the Service, including pages visited, features used, browser type, IP address, and device information. We use analytics tools including PostHog to understand usage patterns.
2.5 Billing Information
Payment processing is handled by Stripe. We do not store your full credit card number. Stripe collects and processes your payment information in accordance with their own privacy policy.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service
- Process voice calls, generate transcripts, and qualify leads
- Sync data with your connected CRM systems
- Process payments and manage your subscription
- Send transactional communications such as call notifications, billing receipts, and service updates
- Improve and optimize the Service
- Detect and prevent fraud or abuse
- Comply with legal obligations
4. How We Share Your Information
We do not sell your personal information. We share data only in the following circumstances:
- Service providers: We use third-party services to operate the platform, including Twilio (telephony), Anthropic (AI language model), Deepgram (speech-to-text), Cartesia (text-to-speech), Google Cloud (storage and infrastructure), Stripe (payments), and SendGrid (email).
- CRM integrations: When you connect a CRM, we transmit call data and lead information to your CRM as directed by you.
- Legal requirements: We may disclose your information if required to do so by law, court order, or government regulation.
- Business transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
5. Data Storage and Security
Your data is stored on infrastructure hosted by Google Cloud Platform in the United States. We implement industry-standard security measures including:
- AES-256 encryption for CRM credentials at rest
- TLS 1.2+ encryption for all data in transit
- Signed URLs with 15-minute expiry for call recording access
- Role-based access controls and multi-tenant data isolation
- Regular security audits and monitoring
While we strive to protect your information, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
6. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. Specific retention periods:
- Call recordings: Retained according to your account settings. Default retention is 90 days.
- Call transcripts: Retained for the duration of your subscription.
- Account data: Retained for 90 days after account deletion.
- Billing records: Retained for 7 years as required by tax law.
- Consent logs: Retained indefinitely for compliance purposes.
7. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate personal data.
- Deletion: Request deletion of your personal data, subject to legal retention requirements.
- Portability: Request your data in a machine-readable format.
- Opt-out: Opt out of marketing communications at any time.
To exercise any of these rights, please contact us at privacy@getafterhours.ai.
8. Cookies and Tracking
We use cookies and similar technologies to maintain your session, remember your preferences, and analyze usage patterns. Essential cookies are required for the Service to function. Analytics cookies (PostHog) help us understand how users interact with the Service and can be disabled in your browser settings.
9. Children's Privacy
Our Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected information from a child under 18, we will delete that information promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.
11. Contact Us
If you have any questions about this Privacy Policy, please contact us:
- Email: privacy@getafterhours.ai
- Website: getafterhours.ai