SAILZ

Privacy

Sailz LLC · Last updated 5 August 2026

Sailz builds and operates AI agents for businesses. This page explains what data we hold, why, and what we will not do with it. It is written to be read, not to be survived.

Whose data this covers

Our clients, the businesses who pay us, and the people who contact those businesses, whose calls and messages our agents handle on the client's behalf. For that second group, the business is the data controller and Sailz is its processor: we hold their information because our client asked us to, and we act on our client's instructions.

What we collect

What we do with it

Run the service the client bought: answer calls, book appointments, take orders, place consented outbound calls, and produce the reports the client reads. Recordings and transcripts are processed by our AI providers to generate responses and to draft the facts a client's agent proposes to learn.

We do not sell data. We do not share one client's data with another. We do not use client or caller data to train general-purpose AI models.

Who else touches it

Sub-processors, each used only for the function named: Anthropic (language models), Vapi (voice orchestration), ElevenLabs (speech), Deepgram (transcription), Twilio (telephony and SMS), Google (calendar, where a client connects it), Perplexity (public business research), Resend (email), Stripe (payments), Railway (hosting). We will tell clients before adding a sub-processor that handles their data.

Where it lives and how long

Each client has their own isolated deployment and their own database. Data is stored in the United States. Call recordings and transcripts are retained for 12 months unless a client asks for shorter. Contact-form submissions are kept for 24 months. When a client leaves, we export their data to them and delete our copy within 30 days of the request.

Health and financial information

For healthcare clients we operate under a HIPAA posture: minimum necessary data, masking of identifiers in logs and reports, and no clinical advice from any agent. For financial-services clients, agents do not give investment advice and do not discuss the details of anyone's existing plan.

Your rights

If you called one of our clients and want your information corrected or deleted, contact that business. They control it, and we will act on their instruction promptly. If you would rather come to us directly, email privacy@sailz.org and we will route it and follow up. Residents of California, Virginia, Colorado, Connecticut and Utah have statutory rights of access, correction, deletion and opt-out; we honour these for everyone regardless of where they live.

Recording and AI disclosure

Calls handled by our agents may be recorded. Where consent to record is required by law, the agent obtains it at the start of the call. Every agent identifies itself as an AI assistant when asked, and proactively wherever the law requires it.

Security

Encryption in transit, per-client isolation, hashed credentials, signed webhooks, rate limiting, and access logging. If a breach affects your data we will notify affected clients without undue delay and within any deadline the law sets.

Children

Sailz is sold to businesses and is not directed at children under 13. We do not knowingly collect their data.

Changes

If we change this materially, clients get email notice before it takes effect. The current version always lives at this URL.