Honeycomb · Back-office support for salons & studios

Your last client leaves. Your workday should end, too.

Sign in

Privacy Policy

Effective date: August 5, 2026 · Last updated: October 6, 2026

AgentixAI LLC (“AgentixAI,” “we,” “us”) provides a managed back-office service to small businesses. This policy explains what data we handle, why, where it is stored, who can see it, and how to have it deleted.

Contact: info@agentixai.ai · Mailing address: 1617 Adams St, Chattanooga, TN 37408 · Phone: (423) 218-2244

1. Who this policy covers

This policy covers two groups:

  • Our clients — businesses that engage AgentixAI to run administrative and finance operations on their behalf.
  • Our clients’ contacts — the customers, vendors, and staff of those businesses, whose information appears in the documents and messages we process on our client’s instruction. This includes anyone who has written to a client who forwards their business mail to us: if you emailed one of our clients, your message may reach our systems because they asked us to handle their correspondence.

If you are a customer or vendor of one of our clients and want your information removed, contact that business directly, or write to us at info@agentixai.ai and we will route your request.

2. What we collect

Account data. Name, business email address, business name, and phone number for the people authorized to use our service.

Client business data. Only what is needed to perform the services our client has engaged us for:

  • Invoices, bills, receipts, and their line items
  • Customer and vendor records
  • Approval decisions and who made them
  • Documents our client uploads to us

Mail a client forwards to us. Part of this service is an intake mailbox. A client is given an email address that we operate, and forwards business correspondence to it — customer and vendor email, invoices, bills, statements. Where a client uses it, we receive and store that correspondence: the sender’s address, the subject, the date, and the body of the message. We store it because the service is reading a client’s mail on their behalf and turning it into tracked work, and because they need to see afterwards what we did and why. It is held for the life of the engagement and deleted with the rest of that client’s business records, as described in section 7.

Files attached to forwarded mail are retrieved and stored. When a client forwards mail carrying an attachment — an invoice, a receipt, a statement, a photograph of one — we fetch the file and keep it, because it is the record of what the client sent us and in many cases we are their only remaining copy. The message as delivered is also held by our mail provider under its own retention policy (see section 6). Stored files are kept as described in section 7, including the 400-day deletion lock.

Text messages. Part of this service runs over text message. Where a client uses it, we receive and store the messages exchanged with them: the phone number, the time, the text of the message, and any photograph or file sent with it. Messages are carried by the provider named in section 6, which holds them under its own retention policy as well. The text of a message and any attached photograph are stored on our side as described in section 7, including the 400-day deletion lock. We send messages to our client; we do not text a client’s own customers.

How forwarded mail is kept separate. Each client’s intake address contains an identifier unique to that client, and that identifier is what decides whose account a message is filed under. A message that names more than one client’s intake address is refused rather than filed under either, and a message that names none is discarded without being stored. Mail is separated by client and never cross-filed.

That is a statement about where a message lands, not about who is able to send one. An intake address is an ordinary email address: we do not verify that an incoming message came from our client or from someone they do business with, and anyone who learns the address can send to it. Treat it as you would any other business email address. If you believe yours has been circulated, tell us and we will issue you a new one — the old address stops working when we do, and you will need to update your forwarding rule.

Connected-service data. When a client connects a third-party system, we access only the data needed for the specific workflows they have enabled. The table below describes the access we request at the point a client connects a service. No client account is connected today.

ServiceWhat we accessWhy
Google (Gmail) — not available todayRead-only access to email messagesTo triage incoming email, extract action items, and route them for human approval. No Google connection can be made today: this describes access we would request, and the section below is published in advance of Google’s review
Intuit QuickBooks OnlineInvoices, bills, customers, vendors, chart of accountsTo keep records in sync with the client’s book of record

We request the narrowest access a provider offers. We do not request, and will not accept, permissions that allow moving money, initiating payments, or making payroll tax filings. This is enforced rather than promised. Our system holds a list of the specific permissions each provider is allowed to grant us, and refuses anything not on it — so a permission nobody anticipated is refused by default rather than having to be recognized as dangerous. The refusal is enforced in our application, again by our database, and every refusal is recorded. Adding a permission to that list requires a reviewed change to our source code; it cannot be done by changing a setting.

Where a provider offers no read-only permission, we say so rather than imply otherwise. QuickBooks Online is the case in point: Intuit publishes a single accounting permission that covers both reading and writing, with no read-only variant, so that is the permission we hold. Restricting ourselves to reading and drafting is enforced by our own software and by the human-approval step in front of every change we would make in your books — it is not something Intuit’s permission itself constrains. The money-movement refusal above is different, and is enforced twice as described.

Usage data. Log records of actions taken in our system — what happened, when, and under whose approval.

We do not collect biometric data, precise location, or data about children.

3. Google user data — Limited Use

AgentixAI’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use Google user data only to provide and improve the user-facing features our client has explicitly enabled.
  • We do not transfer Google user data to third parties except (a) as necessary to provide those features, (b) for security purposes, (c) to comply with applicable law, or (d) as part of a merger or acquisition after obtaining explicit consent.
  • We do not use Google user data for serving advertisements of any kind.
  • We do not sell Google user data.
  • We do not allow humans to read Google user data unless (a) we have the user’s affirmative agreement for specific messages, (b) it is necessary for security purposes such as investigating abuse, (c) it is required to comply with applicable law, or (d) the data has been aggregated and anonymized for internal operations.
  • We do not use Google Workspace API data to develop, improve, or train generalized artificial intelligence or machine learning models.

On our use of AI. We use a third-party large language model provider (Anthropic) to read and classify what our clients send us and to write some of the text we send back. Content may be transmitted to that provider solely to provide our service to that client. Our provider does not train models on data submitted through its API. Where a model is used, and where it is not. For clients we have enabled: mail forwarded to your intake address is classified by a model, which produces a category, a short summary, a suggested owner and any deadline it can find; documents and photographs you send us are read by a model to pull out amounts, dates and payees, which a person at AgentixAI confirms before they are filed (a repeat document from a payee a person has already categorized may be filed without that step, where we have turned that on for you, and the payment due date on a card or loan statement you forward may be added to your deadlines list automatically); and text messages you send us are read by a model together with our recent conversation with you (up to the last two weeks), so that a reply fits what you meant. When you answer a question we asked you, by text or by email — for example the lowest balance you want to keep — a model reads the answer and it may be recorded for you automatically, and we text you back what was recorded. Some replies we text you are partly written by a model: a short sentence saying back what you told us, a short question when your message was unclear, and answers to your questions about your own records. Automated checks stop any such reply that contains a figure, date, link or phone number that is not in your records or in your own message, and a person at AgentixAI is told about every answer a model writes to your questions. Our staff also use a model-backed assistant to look up and summarize your records. If we turn on Veylo for you — the assistant on your dashboard that the business owner and managers can ask about the business — each question you type, together with the earlier messages in that conversation and the records Veylo reads to answer it, is sent to Anthropic and read by a model. Veylo only reads: it cannot send anything, pay anything or change your records. Amounts, dates and names in its reply are checked automatically against the records it read for that question; a reply that fails the check is not shown, and AgentixAI is normally alerted. For each question we keep an audit record of who asked, when, how long the question was, which kinds of records were looked up and what it cost; we do not keep the words of your question or of the reply. You can also save short notes on Veylo’s Memory page — goals, milestones, facts about the business, how you like answers — and Veylo reads them (and sends them to Anthropic) along with your questions. A note the owner marks “Only me” is seen by the owner and AgentixAI staff, not by managers; the owner can see and delete every note, and a manager the ones shared with the team. Deleting takes a note out of our systems. Our audit record keeps that a note was added or deleted, its kind and who could see it, never its words, amount or date. The content involved in each of these is transmitted to Anthropic to produce the output. Not every client is enabled, and we will tell you which applies to your account. Where AgentixAI initiates a message to a customer of yours, explicit human approval is required in every case — a model never decides that something is sent to a customer. Separately from the platform, we also build and operate customer-facing assistants for clients who ask for them. An assistant replies to enquiries a customer has started, uses a third-party model to do so, and answers without a per-message approval — which is what makes it useful to a business that cannot stop to reply. An assistant never initiates contact with a customer, and never moves money or changes a price.

What the model is not allowed to do. Amounts, dates, balances, and aging are computed by our database, never by a model. Where a model produces text for a client, it may only restate figures that already exist in the underlying records or in the client’s own message, and automated checks block the output if a dollar figure, date, invoice number, or name does not match the source record. The model narrates; it does not calculate.

4. Intuit QuickBooks data

We access QuickBooks Online data only for clients who connect their account, and only for the workflows they enable. QuickBooks remains the client’s book of record; we do not replace it. We do not request payment-initiation or bill-pay permissions. No client QuickBooks account is connected today. Access tokens are held in a dedicated encrypted secrets store, with our application database holding only a reference to them — never the token itself.

Disconnecting, stated precisely. Disconnecting from within your AgentixAI dashboard, or asking us to disconnect, destroys the stored credential and asks Intuit to revoke the grant. If Intuit cannot be reached, we destroy the credential anyway and record that the revocation did not complete — so we can no longer reach your account either way. Disconnecting from inside QuickBooks instead is a signal we cannot authenticate, so we record it and act on it deliberately rather than treating an unverified request as an instruction — we do not tear down a connection on the strength of a message anyone could have sent. Intuit stops honoring our access at their end when you revoke it there. If you want our stored credential destroyed at the same moment, use the dashboard or email us.

5. How we store and protect data

  • Where. Our production database is hosted on Supabase (Amazon Web Services, United States). The files a client sends us are stored in a Cloudflare bucket we operate (United States). The web application is hosted on Vercel (United States). Background processing runs on Railway (United States). Bank and card connections a client chooses to make are held through Plaid (United States), read-only. Mail a client forwards to us is received through Resend (United States), which is also the path we will use to send messages a client has approved — no message has been sent on any client’s behalf to date. Text messages to and from a client are carried by Quo (United States).
  • Isolation. Every record carries an organization identifier, and database-level row security prevents any client from reading another client’s data. This is enforced by the database itself, not only by application code. One honest limit: the stored files in our storage bucket are reached by the Service using a single account credential, so for the file contents the per-client boundary is enforced by our own code checking that the file belongs to the organization asking — backed by, but not the same thing as, the database row check that decides whether the file may be seen at all.
  • Credentials. One client has connected one account to date. Tokens are held in a dedicated encrypted secrets store, separate from our application database, which holds only a reference to them. No code path in our system writes a token to the application database; if the secrets store cannot be reached, a connection fails rather than falling back to storing the token somewhere else.
  • Access. Access is limited to AgentixAI personnel who need it to deliver the service, under written confidentiality obligations.
  • Audit trail. Every automated action taken inside a client’s account is logged with what happened, when, and under whose approval — including actions our own safety checks refused to take, so a blocked action is visible rather than merely absent. Audit records cannot be edited or deleted, and that is enforced by two independent locks in the database rather than by our application choosing not to — the Service cannot edit or delete an entry, and a correction is recorded as a new entry. One case sits outside this by construction: a message that cannot be attributed to any client is refused before it becomes anyone’s data, so there is no client record to log it against — it is refused at the door and never stored.
  • Transport and storage. Data is encrypted in transit (TLS) and at rest.

No system is perfectly secure. We will notify affected clients without undue delay if we become aware of a breach affecting their data.

6. Sub-processors

ProviderPurposeLocation
SupabaseDatabase, authentication, and file storage for documents received before 20 September 2026United States
CloudflareStorage of the files a client sends us — in use since 20 September 2026 and now the store for every such file. The bucket carries a 400-day deletion lock that Cloudflare enforces and we cannot lift; see section 7United States
PlaidBank and card account connections a client chooses to make, so balances and transaction lines can reach us daily without a statement being forwarded. Read-only: we request the ability to read balances and transactions and nothing that can move money. Plaid receives a non-personal account identifier for the person connecting. The client can disconnect at their bank at any time; when a client leaves us the connection is removed at Plaid as part of offboardingUnited States
VercelWeb application hostingUnited States
RailwayBackground workersUnited States
Resend (Plus Five Five, Inc.)Receiving mail forwarded to a client’s intake address — in use. Sending our own email to a client, such as the daily briefing — in use. Sending messages a client has approved to that client’s customers — configured; no client’s customer has been sent anything as of the date above. Resend holds the message as delivered, attachments included, under its own retention policy, which we do not controlUnited States
Quo (Quo, Inc.)Carrying text messages to and from a client — in use. Quo holds the phone number, the message text and any photograph or file sent with it, under its own retention policy, which we do not controlUnited States
TypeSafe (Typesafe AI, Inc.)Reading a client’s text messages to tell what is being asked, for clients we have enabled — in use; the message text is sent. Suggesting how a client’s bank charges should be sorted — being tested; only the payee name as printed by the bank and the client’s own category names are sent. Suggesting why a bank charge or deposit is not a cost or not income — configured; no client is switched on as of the date above; the name on the bank line is sent. TypeSafe states it does not train its models on what we sendUnited States
AnthropicClassification of forwarded mail, for clients we have enabled — in use. Reading the text out of a photograph or a scanned document a client sends, for clients we have enabled — in use; the file’s own contents are sent. Reading a client’s text messages with the recent conversation, and writing part of our replies to the client, for clients we have enabled — in use. Our staff’s assistant over a client’s records — in use. Veylo, the assistant a client’s owner and managers can ask about their own records, for clients we have enabled — in use. Suggesting how a client’s bank charges should be sorted, for clients we have enabled — in use; only the payee name as printed by the bank and the client’s own category names are sent, and a person approves every suggestion before it is recordedUnited States

We will update this list before adding a sub-processor that handles client data.

7. How long we keep data

DataRetention
Client business recordsFor the life of the engagement, then 30 days, then deleted from our systems. One limit we cannot waive: the stored copy of a file you sent us sits in our storage provider’s bucket under a 400-day deletion lock, counted from the day it arrived. See “How deletion actually happens” below.
Mail forwarded to a client’s intake addressFor the life of the engagement, then 30 days, then deleted — together with the summary, any task raised from it, and the copy of the message text held in the internal processing record of the job that handled it. The message text and any attachment are also kept as stored files, and those carry the same 400-day deletion lock described below
Audit and approval records7 years — retained to support our clients’ recordkeeping obligations
Google user data — none held todayDeleted within 30 days of disconnection or account closure
QuickBooks dataDeleted within 30 days of disconnection or account closure
Account and contact dataUntil account closure, then 30 days

Disconnecting a service through your dashboard, or asking us to disconnect it, destroys the stored credential immediately and asks the provider to revoke the grant; if the provider cannot be reached, the credential is destroyed anyway, so we can no longer reach your account. See section 4 for what happens when you disconnect from inside the provider instead. Asking us to stop receiving forwarded mail takes effect immediately; mail already received is deleted on the schedule above. We can remove our records of it sooner on request, but the stored copy is subject to the deletion lock described below.

How deletion actually happens. Deletion at the end of an engagement is carried out by our team, on request or at offboarding, and recorded — it is not yet run automatically by a timer. If you want your data removed on a specific date, tell us and we will do it then. Two things about it are worth stating plainly rather than leaving you to discover them.

We will not destroy raw files of yours that you have never been given back. While we are still holding files you sent us that have not been handed back to you, the system refuses to run the deletion at all — a refusal, not a delay, and nothing is removed in the meantime, our index included. Clearing it is a step our team carries out; ask us and we will tell you where your request stands. We would rather be slow than destroy the only copy of something of yours.

Removing the records and destroying the stored file are two different steps. Once the deletion runs it removes our database records and our index of your files, so nothing in the Service can find or serve them. The stored file itself sits under a 400-day lock, counted from the day it arrived, which our storage provider enforces and which we cannot lift or shorten — it exists so that nothing, including a mistake of ours, can destroy your records early. A file past that window is destroyed with the rest. A file still inside it is destroyed once the window expires, in a step our team runs rather than a timer. We can tell you which of your files are in that state.

8. Your rights and how to exercise them

You may request access to the data we hold about you, correction of it, deletion of it, or an export of it. Write to info@agentixai.ai. We respond within 30 days.

One deliberate exception: audit and approval records. What action was taken, when, and under whose approval is retained for 7 years and is not deleted on request. These records exist to give you and your accountant a reliable history of financial actions taken in your name, and that history is only worth something if it cannot be removed after the fact. They describe actions and approvals; they are not a copy of your business records, which are deleted as described above.

Deletion reaches uploaded documents in file storage as well as database records, and we capture a record of what was removed so the deletion itself can be evidenced — subject to the 400-day storage lock described in section 7, which we cannot waive. It reaches a forwarded message, its summary, the work raised from it, and the copy of the message text held inside the internal processing record of the job that handled it — that last one is the copy most easily overlooked, and it is cleared with the rest.

Deleting Google data specifically. A client may revoke our access at any time at myaccount.google.com/permissions, or by emailing us. On revocation we stop accessing the account immediately and delete previously retrieved Google user data within 30 days, except where retention is required by law.

Depending on where you live, you may have additional rights under laws such as the California Consumer Privacy Act or the GDPR. We do not sell personal information, and we do not share it for cross-context behavioral advertising.

9. Children

Our service is for businesses. We do not knowingly collect data from anyone under 16.

10. Changes

We will post any change here and update the “last updated” date. For material changes affecting how we handle client or Google user data, we will notify clients directly before the change takes effect.

11. Contact

AgentixAI LLC · 1617 Adams St, Chattanooga, TN 37408 · info@agentixai.ai · (423) 218-2244

This document is provided for transparency and platform-review purposes and is not a substitute for legal advice specific to your business.

Prepares work for a human bookkeeper or CPA. Does not provide tax, audit, legal or investment advice, and never moves money.

Privacy PolicyTerms of Service

Privacy Policy — AgentixAI Managed Back Office