AI Workforce Pro – Privacy Policy

smb d

AI Workforce Pro – Privacy Policy

AI Workforce Pro — Privacy Policy

Last Updated: July 1, 2026

This Privacy Policy explains how The SMB Team, LLC (“SMB Team,” “we,” “us”) collects, uses, stores, and shares information when you use AI Workforce Pro (the “Service”). By using the Service, you consent to the practices described here.

1. Information We Collect

1.1 Account Information. When you create an account, we collect your name, email address, organization (tenant) name, and authentication credentials. If you sign in via a third-party identity provider, we receive the information that provider shares with us (typically email and name).

1.2 User Content. We collect the content you submit to the Service, including:

  • Chat conversations and prompts
  • Files you upload
  • Configuration settings (system prompts, model preferences, integration configurations)
  • Tenant- and group-level settings managed by your Tenant Admin

1.3 Connected Account Data. If you authorize third-party integrations (e.g., Google Workspace, Microsoft 365, Clio), we may access data from those services as scoped by the permissions you grant. We only access what is necessary to provide the integration you’ve authorized.

1.4 Usage Data. We automatically collect technical information about your use of the Service, including IP address, browser type, device information, timestamps, pages accessed, and actions taken. This is used for service operation, security, and improvement.

1.5 Cookies and Tracking. We use cookies and similar technologies to maintain your session, remember your preferences, and analyze usage. You can control cookies through your browser settings; disabling them may affect functionality.

2. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Process AI requests through our model providers
  • Authenticate you and protect your account
  • Communicate with you about the Service (account notices, updates, password resets)
  • Improve the Service (in aggregate / anonymized form)
  • Comply with legal obligations and enforce our Terms
  • Detect and prevent fraud, abuse, or security incidents

We do not sell your personal information or User Content. We do not use your User Content to train AI models, and we contract with our model providers to ensure they do not either. Our agreement with Anthropic (Teams plan) and our use of Zero Data Retention endpoints on OpenRouter (see Section 5) provide contractual no-training and no-storage protections.

3. Data Storage and Security

3.1 Storage location. User Content is stored in our infrastructure on Google Cloud Platform, in the `us-central1` region.

3.2 Encryption. Data is encrypted in transit (TLS) and at rest (provider-managed disk encryption).

3.3 Access controls. Access to production systems is restricted to authorized personnel under role-based controls. We maintain audit logs of administrative access.

3.4 Security measures. We implement industry-standard administrative, technical, and physical safeguards. However, no system is completely secure, and we cannot guarantee absolute security.

3.5 Incident response. In the event of a data breach that affects your personal information, we will notify you in accordance with applicable law.

4. Multi-Tenancy and Data Isolation

The Service uses a multi-tenant architecture in which each organization is a separate “Tenant.” User Content is isolated by Tenant and is not accessible to users outside your Tenant. Tenant Admins can see and manage activity within their Tenant only. Cross-tenant access is not permitted except by SMB Team personnel for support, security, or legal purposes as described below.

5. AI Processing and Model Providers

When you submit a prompt or query, your input (and relevant context) is sent to a third-party AI model provider for processing. The provider returns a response, which we deliver back to you.

Our model providers:

  • Anthropic is our primary model provider. We operate under Anthropic’s Teams plan, which contractually prohibits Anthropic from using customer data to train its models or retaining it beyond what is necessary to provide the service.
  • OpenRouter is used to make additional models available. We restrict OpenRouter integration to Zero Data Retention (“ZDR”) endpoints only — these are paid endpoints whose underlying model providers have contractually agreed not to store or train on customer data. Free-tier OpenRouter endpoints (which may retain data for training) are explicitly disabled.

General practices across providers:

  • Providers do not retain your input or output for training, per our contractual terms and ZDR-only configuration.
  • Providers may retain input/output briefly for abuse detection or service operation, then delete according to their retention policy.
  • We do not control the providers’ internal operations, but we choose providers whose practices align with this policy.

A list of current model providers can be made available on request.

6. Third-Party Integrations and OAuth

When you connect a third-party service (e.g., Google, Microsoft, Clio) to AI Workforce Pro via OAuth:

  • We receive an access token scoped to the permissions you approve
  • We store the token securely and use it only to provide the integration you’ve authorized
  • We do not access data outside the scope you’ve granted
  • You can revoke our access at any time through your account settings or directly with the third-party provider
  • Data flowing through the integration is subject to both this policy and the third party’s terms

7. How We Share Information

We share information only as described:

7.1 Service providers. We share information with vendors that help us operate the Service (e.g., cloud hosting, AI model providers, email delivery, analytics). These vendors are bound by confidentiality and data protection terms.

7.2 Within your Tenant. Information you create as part of group, role, or shared context is visible to other authorized users within your Tenant according to the access controls you and your Tenant Admin configure.

7.3 Legal obligations. We may disclose information if required by law, court order, subpoena, or governmental request, or to protect our legal rights, safety, or property.

7.4 Business transfers. If SMB Team is involved in a merger, acquisition, or asset sale, your information may be transferred as part of that transaction, subject to the new entity honoring this policy.

We do not sell your personal information.

8. Data Retention and Deletion

8.1 Active accounts. We retain User Content and account data for as long as your account is active.

8.2 Closed accounts. Upon account termination, we retain data for up to thirty (30) days to allow export, then delete it from active systems. Backups may persist for up to ninety (90) days, after which they are also deleted, except where retention is required by law.

8.3 Tenant Admin controls. Tenant Admins can request bulk deletion of their Tenant’s data at any time. Users can delete individual conversations through the Service interface.

8.4 Legal retention. Some information may be retained longer where required by law (e.g., billing records, security logs).

9. Your Rights

Depending on where you live, you may have the following rights:

  • Access. Request a copy of the information we hold about you
  • Correction. Request that we correct inaccurate information
  • Deletion. Request that we delete information about you, subject to legal retention requirements
  • Portability. Request your data in a portable format (e.g., JSON export of your account record and conversations)
  • Opt-out. Opt out of marketing communications

To exercise these rights, contact us at support@smbteam.com. We will respond within the timeframe required by applicable law (generally 30 days).

10. International Users

The Service is operated from the United States. If you are accessing it from outside the U.S., your information will be transferred to and processed in the U.S., which may have data protection laws different from your country.

11. Children’s Privacy

The Service is not directed to individuals under 18. We do not knowingly collect information from anyone under 18. If we learn we have collected information from a person under 18, we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the Service or by email. The “Last Updated” date below indicates when this policy was last revised. Continued use after changes take effect constitutes acceptance of the updated policy.

13. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

Email: support@smbteam.com

Mail: The SMB Team, LLC, 3 Bala Plaza Ste 101E, Bala Cynwyd, PA 19004

Last Updated: July 1, 2026

Scroll to Top