Your last client leaves. Your workday should end, too.
Effective date: August 5, 2026 · Last updated: October 6, 2026
AgentixAI LLC (“AgentixAI,” “we,” “us”) provides a managed back-office service to small businesses. This policy explains what data we handle, why, where it is stored, who can see it, and how to have it deleted.
Contact: info@agentixai.ai · Mailing address: 1617 Adams St, Chattanooga, TN 37408 · Phone: (423) 218-2244
This policy covers two groups:
If you are a customer or vendor of one of our clients and want your information removed, contact that business directly, or write to us at info@agentixai.ai and we will route your request.
Account data. Name, business email address, business name, and phone number for the people authorized to use our service.
Client business data. Only what is needed to perform the services our client has engaged us for:
Mail a client forwards to us. Part of this service is an intake mailbox. A client is given an email address that we operate, and forwards business correspondence to it — customer and vendor email, invoices, bills, statements. Where a client uses it, we receive and store that correspondence: the sender’s address, the subject, the date, and the body of the message. We store it because the service is reading a client’s mail on their behalf and turning it into tracked work, and because they need to see afterwards what we did and why. It is held for the life of the engagement and deleted with the rest of that client’s business records, as described in section 7.
Files attached to forwarded mail are retrieved and stored. When a client forwards mail carrying an attachment — an invoice, a receipt, a statement, a photograph of one — we fetch the file and keep it, because it is the record of what the client sent us and in many cases we are their only remaining copy. The message as delivered is also held by our mail provider under its own retention policy (see section 6). Stored files are kept as described in section 7, including the 400-day deletion lock.
Text messages. Part of this service runs over text message. Where a client uses it, we receive and store the messages exchanged with them: the phone number, the time, the text of the message, and any photograph or file sent with it. Messages are carried by the provider named in section 6, which holds them under its own retention policy as well. The text of a message and any attached photograph are stored on our side as described in section 7, including the 400-day deletion lock. We send messages to our client; we do not text a client’s own customers.
How forwarded mail is kept separate. Each client’s intake address contains an identifier unique to that client, and that identifier is what decides whose account a message is filed under. A message that names more than one client’s intake address is refused rather than filed under either, and a message that names none is discarded without being stored. Mail is separated by client and never cross-filed.
That is a statement about where a message lands, not about who is able to send one. An intake address is an ordinary email address: we do not verify that an incoming message came from our client or from someone they do business with, and anyone who learns the address can send to it. Treat it as you would any other business email address. If you believe yours has been circulated, tell us and we will issue you a new one — the old address stops working when we do, and you will need to update your forwarding rule.
Connected-service data. When a client connects a third-party system, we access only the data needed for the specific workflows they have enabled. The table below describes the access we request at the point a client connects a service. No client account is connected today.
| Service | What we access | Why |
|---|---|---|
| Google (Gmail) — not available today | Read-only access to email messages | To triage incoming email, extract action items, and route them for human approval. No Google connection can be made today: this describes access we would request, and the section below is published in advance of Google’s review |
| Intuit QuickBooks Online | Invoices, bills, customers, vendors, chart of accounts | To keep records in sync with the client’s book of record |
We request the narrowest access a provider offers. We do not request, and will not accept, permissions that allow moving money, initiating payments, or making payroll tax filings. This is enforced rather than promised. Our system holds a list of the specific permissions each provider is allowed to grant us, and refuses anything not on it — so a permission nobody anticipated is refused by default rather than having to be recognized as dangerous. The refusal is enforced in our application, again by our database, and every refusal is recorded. Adding a permission to that list requires a reviewed change to our source code; it cannot be done by changing a setting.
Where a provider offers no read-only permission, we say so rather than imply otherwise. QuickBooks Online is the case in point: Intuit publishes a single accounting permission that covers both reading and writing, with no read-only variant, so that is the permission we hold. Restricting ourselves to reading and drafting is enforced by our own software and by the human-approval step in front of every change we would make in your books — it is not something Intuit’s permission itself constrains. The money-movement refusal above is different, and is enforced twice as described.
Usage data. Log records of actions taken in our system — what happened, when, and under whose approval.
We do not collect biometric data, precise location, or data about children.
AgentixAI’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
On our use of AI. We use a third-party large language model provider (Anthropic) to read and classify what our clients send us and to write some of the text we send back. Content may be transmitted to that provider solely to provide our service to that client. Our provider does not train models on data submitted through its API. Where a model is used, and where it is not. For clients we have enabled: mail forwarded to your intake address is classified by a model, which produces a category, a short summary, a suggested owner and any deadline it can find; documents and photographs you send us are read by a model to pull out amounts, dates and payees, which a person at AgentixAI confirms before they are filed (a repeat document from a payee a person has already categorized may be filed without that step, where we have turned that on for you, and the payment due date on a card or loan statement you forward may be added to your deadlines list automatically); and text messages you send us are read by a model together with our recent conversation with you (up to the last two weeks), so that a reply fits what you meant. When you answer a question we asked you, by text or by email — for example the lowest balance you want to keep — a model reads the answer and it may be recorded for you automatically, and we text you back what was recorded. Some replies we text you are partly written by a model: a short sentence saying back what you told us, a short question when your message was unclear, and answers to your questions about your own records. Automated checks stop any such reply that contains a figure, date, link or phone number that is not in your records or in your own message, and a person at AgentixAI is told about every answer a model writes to your questions. Our staff also use a model-backed assistant to look up and summarize your records. If we turn on Veylo for you — the assistant on your dashboard that the business owner and managers can ask about the business — each question you type, together with the earlier messages in that conversation and the records Veylo reads to answer it, is sent to Anthropic and read by a model. Veylo only reads: it cannot send anything, pay anything or change your records. Amounts, dates and names in its reply are checked automatically against the records it read for that question; a reply that fails the check is not shown, and AgentixAI is normally alerted. For each question we keep an audit record of who asked, when, how long the question was, which kinds of records were looked up and what it cost; we do not keep the words of your question or of the reply. You can also save short notes on Veylo’s Memory page — goals, milestones, facts about the business, how you like answers — and Veylo reads them (and sends them to Anthropic) along with your questions. A note the owner marks “Only me” is seen by the owner and AgentixAI staff, not by managers; the owner can see and delete every note, and a manager the ones shared with the team. Deleting takes a note out of our systems. Our audit record keeps that a note was added or deleted, its kind and who could see it, never its words, amount or date. The content involved in each of these is transmitted to Anthropic to produce the output. Not every client is enabled, and we will tell you which applies to your account. Where AgentixAI initiates a message to a customer of yours, explicit human approval is required in every case — a model never decides that something is sent to a customer. Separately from the platform, we also build and operate customer-facing assistants for clients who ask for them. An assistant replies to enquiries a customer has started, uses a third-party model to do so, and answers without a per-message approval — which is what makes it useful to a business that cannot stop to reply. An assistant never initiates contact with a customer, and never moves money or changes a price.
What the model is not allowed to do. Amounts, dates, balances, and aging are computed by our database, never by a model. Where a model produces text for a client, it may only restate figures that already exist in the underlying records or in the client’s own message, and automated checks block the output if a dollar figure, date, invoice number, or name does not match the source record. The model narrates; it does not calculate.
We access QuickBooks Online data only for clients who connect their account, and only for the workflows they enable. QuickBooks remains the client’s book of record; we do not replace it. We do not request payment-initiation or bill-pay permissions. No client QuickBooks account is connected today. Access tokens are held in a dedicated encrypted secrets store, with our application database holding only a reference to them — never the token itself.
Disconnecting, stated precisely. Disconnecting from within your AgentixAI dashboard, or asking us to disconnect, destroys the stored credential and asks Intuit to revoke the grant. If Intuit cannot be reached, we destroy the credential anyway and record that the revocation did not complete — so we can no longer reach your account either way. Disconnecting from inside QuickBooks instead is a signal we cannot authenticate, so we record it and act on it deliberately rather than treating an unverified request as an instruction — we do not tear down a connection on the strength of a message anyone could have sent. Intuit stops honoring our access at their end when you revoke it there. If you want our stored credential destroyed at the same moment, use the dashboard or email us.
No system is perfectly secure. We will notify affected clients without undue delay if we become aware of a breach affecting their data.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, and file storage for documents received before 20 September 2026 | United States |
| Cloudflare | Storage of the files a client sends us — in use since 20 September 2026 and now the store for every such file. The bucket carries a 400-day deletion lock that Cloudflare enforces and we cannot lift; see section 7 | United States |
| Plaid | Bank and card account connections a client chooses to make, so balances and transaction lines can reach us daily without a statement being forwarded. Read-only: we request the ability to read balances and transactions and nothing that can move money. Plaid receives a non-personal account identifier for the person connecting. The client can disconnect at their bank at any time; when a client leaves us the connection is removed at Plaid as part of offboarding | United States |
| Vercel | Web application hosting | United States |
| Railway | Background workers | United States |
| Resend (Plus Five Five, Inc.) | Receiving mail forwarded to a client’s intake address — in use. Sending our own email to a client, such as the daily briefing — in use. Sending messages a client has approved to that client’s customers — configured; no client’s customer has been sent anything as of the date above. Resend holds the message as delivered, attachments included, under its own retention policy, which we do not control | United States |
| Quo (Quo, Inc.) | Carrying text messages to and from a client — in use. Quo holds the phone number, the message text and any photograph or file sent with it, under its own retention policy, which we do not control | United States |
| TypeSafe (Typesafe AI, Inc.) | Reading a client’s text messages to tell what is being asked, for clients we have enabled — in use; the message text is sent. Suggesting how a client’s bank charges should be sorted — being tested; only the payee name as printed by the bank and the client’s own category names are sent. Suggesting why a bank charge or deposit is not a cost or not income — configured; no client is switched on as of the date above; the name on the bank line is sent. TypeSafe states it does not train its models on what we send | United States |
| Anthropic | Classification of forwarded mail, for clients we have enabled — in use. Reading the text out of a photograph or a scanned document a client sends, for clients we have enabled — in use; the file’s own contents are sent. Reading a client’s text messages with the recent conversation, and writing part of our replies to the client, for clients we have enabled — in use. Our staff’s assistant over a client’s records — in use. Veylo, the assistant a client’s owner and managers can ask about their own records, for clients we have enabled — in use. Suggesting how a client’s bank charges should be sorted, for clients we have enabled — in use; only the payee name as printed by the bank and the client’s own category names are sent, and a person approves every suggestion before it is recorded | United States |
We will update this list before adding a sub-processor that handles client data.
| Data | Retention |
|---|---|
| Client business records | For the life of the engagement, then 30 days, then deleted from our systems. One limit we cannot waive: the stored copy of a file you sent us sits in our storage provider’s bucket under a 400-day deletion lock, counted from the day it arrived. See “How deletion actually happens” below. |
| Mail forwarded to a client’s intake address | For the life of the engagement, then 30 days, then deleted — together with the summary, any task raised from it, and the copy of the message text held in the internal processing record of the job that handled it. The message text and any attachment are also kept as stored files, and those carry the same 400-day deletion lock described below |
| Audit and approval records | 7 years — retained to support our clients’ recordkeeping obligations |
| Google user data — none held today | Deleted within 30 days of disconnection or account closure |
| QuickBooks data | Deleted within 30 days of disconnection or account closure |
| Account and contact data | Until account closure, then 30 days |
Disconnecting a service through your dashboard, or asking us to disconnect it, destroys the stored credential immediately and asks the provider to revoke the grant; if the provider cannot be reached, the credential is destroyed anyway, so we can no longer reach your account. See section 4 for what happens when you disconnect from inside the provider instead. Asking us to stop receiving forwarded mail takes effect immediately; mail already received is deleted on the schedule above. We can remove our records of it sooner on request, but the stored copy is subject to the deletion lock described below.
How deletion actually happens. Deletion at the end of an engagement is carried out by our team, on request or at offboarding, and recorded — it is not yet run automatically by a timer. If you want your data removed on a specific date, tell us and we will do it then. Two things about it are worth stating plainly rather than leaving you to discover them.
We will not destroy raw files of yours that you have never been given back. While we are still holding files you sent us that have not been handed back to you, the system refuses to run the deletion at all — a refusal, not a delay, and nothing is removed in the meantime, our index included. Clearing it is a step our team carries out; ask us and we will tell you where your request stands. We would rather be slow than destroy the only copy of something of yours.
Removing the records and destroying the stored file are two different steps. Once the deletion runs it removes our database records and our index of your files, so nothing in the Service can find or serve them. The stored file itself sits under a 400-day lock, counted from the day it arrived, which our storage provider enforces and which we cannot lift or shorten — it exists so that nothing, including a mistake of ours, can destroy your records early. A file past that window is destroyed with the rest. A file still inside it is destroyed once the window expires, in a step our team runs rather than a timer. We can tell you which of your files are in that state.
You may request access to the data we hold about you, correction of it, deletion of it, or an export of it. Write to info@agentixai.ai. We respond within 30 days.
One deliberate exception: audit and approval records. What action was taken, when, and under whose approval is retained for 7 years and is not deleted on request. These records exist to give you and your accountant a reliable history of financial actions taken in your name, and that history is only worth something if it cannot be removed after the fact. They describe actions and approvals; they are not a copy of your business records, which are deleted as described above.
Deletion reaches uploaded documents in file storage as well as database records, and we capture a record of what was removed so the deletion itself can be evidenced — subject to the 400-day storage lock described in section 7, which we cannot waive. It reaches a forwarded message, its summary, the work raised from it, and the copy of the message text held inside the internal processing record of the job that handled it — that last one is the copy most easily overlooked, and it is cleared with the rest.
Deleting Google data specifically. A client may revoke our access at any time at myaccount.google.com/permissions, or by emailing us. On revocation we stop accessing the account immediately and delete previously retrieved Google user data within 30 days, except where retention is required by law.
Depending on where you live, you may have additional rights under laws such as the California Consumer Privacy Act or the GDPR. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
Our service is for businesses. We do not knowingly collect data from anyone under 16.
We will post any change here and update the “last updated” date. For material changes affecting how we handle client or Google user data, we will notify clients directly before the change takes effect.
AgentixAI LLC · 1617 Adams St, Chattanooga, TN 37408 · info@agentixai.ai · (423) 218-2244
This document is provided for transparency and platform-review purposes and is not a substitute for legal advice specific to your business.
Prepares work for a human bookkeeper or CPA. Does not provide tax, audit, legal or investment advice, and never moves money.