Privacy Policy
Last updated: 5 October 2026
This policy explains what personal information YesBusiness and its assistant GIDEON collect, why, who we share it with, how long we keep it, and the choices and rights you have. It applies to yesbusiness.ai, the app, the phone lines we operate and the emails and messages we send.
The short version
A plain summary. The sections below are the policy.
- XFACTORAI LLC runs YesBusiness. For your account we decide how your information is used. For the content you put through it (your email, files, calls, contacts, books), we act for you.
- We use your information to do the work you ask for, run and secure the Service, bill you and keep you informed.
- To do the work, your content is sent to AI and other providers we list below. We do not sell personal information, and we do not use your content to train our own AI models.
- We hide many personal details from the AI where a tool does not need them, but not everywhere: some tools need the whole document, and calls need names and numbers.
- Our servers are in the United States. If you are elsewhere, your information goes there.
- Analytics on our public pages only load if you accept them.
- You can export or delete your data in the app, or write to it@xfactorai.com.
Contents
- Who we are
- Our two roles
- What we collect and where it comes from
- How we use it and our legal bases
- How the AI handles your information
- Phone calls, recordings and voice
- Google and Microsoft account data
- Who we share it with
- Where it is stored and international transfers
- How long we keep it
- Security
- Cookies, device storage and analytics
- Your rights
- If you are not our user
- Children
- Automated decisions
- Changes to this policy
- Contact and complaints
1. Who we are
YesBusiness is provided by XFACTORAI LLC, a Delaware limited liability company ("XFactorAI", "we", "us"). You can reach us about privacy at it@xfactorai.com. Our Terms of Service use the same words for the Service.
Other Yes apps you open from YesBusiness, and services you connect, have their own privacy policies, which apply to what they do with your information.
2. Our two roles
We are the controller (the party that decides how information is used) for information about our users and site visitors: your account and profile, sign-in and security records, billing and credits, how you use the Service, support conversations, and the analytics on our public pages.
We are a service provider or processor (we act on your instructions) for the content and other people's personal information you put through the Service: the email we read in your connected mailbox, your calendar, files, contacts, staff lists, meeting and call recordings and transcripts (including the voices and words of the people on the call), the callers to your business line, your bank transactions and accounting records, and leads and research about other people and businesses. For that information, you (or your business) are the controller. You are responsible for telling those people about your use of it and for having a lawful basis, as our Terms explain. A data processing addendum is available on request to it@xfactorai.com.
3. What we collect and where it comes from
| What | Examples | Where it comes from |
|---|---|---|
| Account and profile | Name, sign-in email, verified email addresses, the phone numbers you save to your Business profile, which of them you have confirmed by code and which may receive texts, business name, website, location, time zone, what you sell and to whom, settings and preferences | You; Google or Microsoft when you sign in with them; your business website, which we read to fill in your profile |
| Sign-in and security records | When you signed in and how (emailed code or link, Google, Microsoft); sign-up and sign-in attempts with the email and the IP address used; sessions; access keys (stored in a form we cannot read back); a one-way keyed fingerprint of your email address and business domain, kept so free starter credits are given only once; reports of blocked page content sent by browsers (the type and the host only) | Your device and our servers |
| Your requests and conversations | What you type or say to GIDEON in the app, by voice, on a call, by text, WhatsApp or email, and its replies; your tasks, notes, saved work and memory | You |
| Connected mailbox | Email messages, senders and recipients, attachments, and your sent mail, read when a feature you use needs them; our sorting of each email (a tag and a one-line summary); drafts and replies | Google, Microsoft or the mail provider you connect |
| Calendar and contacts | Events, times, attendees and their names and addresses; contacts and business cards you scan | Your connected calendar and contacts; you |
| Files | Documents, photos, spreadsheets, recordings and forms you add, and the text we extract from them; attachments you ask us to read | You; your connected mailbox |
| Calls and voice | Recordings and transcripts of calls GIDEON makes for you, calls you make to GIDEON, and calls Jasmine answers on your business line; caller numbers; messages taken; your spoken requests in voice mode | You and the people on the calls; our telephone and voice providers |
| Texts and WhatsApp | Messages between you and GIDEON, delivery status, and opt-out (STOP) records | You; our messaging provider |
| Money | Bank accounts (with numbers masked), balances and transactions; invoices, bills, contacts and profit and loss from your accounting package; bills and invoices you add | Basiq or Plaid and your bank; Xero or QuickBooks; you |
| Other people and businesses | Leads, business details and contacts found for you; signals about companies you deal with; staff names on your policy register and when they acknowledged a policy; people your work is handed to or approved by | Lead and business data providers, public web pages and search results, you |
| Payments and credits | Credit purchases, the payment reference, credits used and by which feature, refunds and disputes. We do not receive or store your full card number. | Stripe; our records |
| Usage and technical | Which features you use and when, what each piece of work cost to run, errors, device and browser type, push notification subscriptions for your devices, and, for some features, the words of a request; a copy of each email we send from our own address, including its content and recipient | Your device and our servers |
| Site visitors | Pages viewed, clicks and session replays on our public pages, only if you accept analytics | Google Analytics and Microsoft Clarity |
4. How we use it and our legal bases
If the EU or UK General Data Protection Regulation applies, we rely on these legal bases for the information we control:
| Purpose | Legal basis |
|---|---|
| Provide the Service: do the work you ask for, run your account, send the emails, texts and calls you instruct or approve | Performance of our contract with you |
| Bill you, keep the credits ledger and accounting records | Contract; legal obligation |
| Keep the Service secure, prevent fraud and abuse (for example free-credit abuse), enforce our Terms | Legitimate interests in protecting the Service, our users and others |
| Measure cost and reliability, fix faults and improve the Service | Legitimate interests in running a reliable, affordable service |
| Tell you about your account, changes and new features | Contract; legitimate interests (you can opt out of non-essential messages) |
| Analytics on our public pages | Consent, which you can withdraw at any time |
| Comply with law, respond to lawful requests and defend claims | Legal obligation; legitimate interests |
For content we process for you as a processor, we use it only to provide the Service to you and as you instruct, and to keep the Service secure.
5. How the AI handles your information
Sent to AI providers to do the work. To answer, draft, research, read files and run calls, the relevant parts of your request, profile and content are sent to the AI model provider (Anthropic) and, for voice and speech, to ElevenLabs and, as a fallback for speech to text, OpenAI. Research features send search queries to the web search the model provider runs, which may contain words from your request.
Training. We do not use your content to train our own AI models. We use these providers under their business or API terms, which, as we understand them on the date of this policy, do not allow them to use that content to train their models.
Hiding personal details. In many places, including reading and sorting your email, drafting replies and summarising your files, GIDEON replaces detectable personal details (such as email addresses, phone numbers, card and bank numbers, tax numbers and names it recognises) with placeholders before the AI reads the text, and puts them back in your own view. This is not applied everywhere and does not catch everything. It is not applied where a tool needs the whole document to work, including the financial analysis, document checks, travel bookings, forms, bank and accounting data, and phone calls, where the voice must hear and say names and numbers.
What the AI gets wrong. AI output can be inaccurate. See section 5 of our Terms.
6. Phone calls, recordings and voice
- Every call GIDEON places, and every call Jasmine answers for a business, says it is an AI assistant and that the call is recorded. Calls are carried by Twilio, the voice is provided by ElevenLabs, and the call is recorded and transcribed.
- When you call GIDEON from a number on your Business profile, the call is treated as you, and the assistant can read your connected email, calendar and files during the call unless you turn phone access off.
- Recordings of calls Jasmine answers on your business line are kept for the period you choose (30 days, 90 days, or until you delete them). Other recordings are kept until you delete the call or your account. Transcripts are kept with the call in your account. Our voice provider also keeps conversation records under its own retention settings.
- For people on these calls who are not our users, see section 14.
7. Google and Microsoft account data
When you connect a Google account we ask only for the access the features you choose need, such as reading or sending Gmail, your calendar events or your contacts. Changing your mailbox (archiving, marking read) needs a separate permission that we ask for only if you press the button for it.
YesBusiness's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we use Google user data only to provide and improve the features you use in YesBusiness; we transfer it to others only as needed to provide those features (such as the AI provider that reads an email you asked about), to comply with law, or as part of a merger or acquisition; we do not use it for advertising; we do not use it to train generalised AI or machine learning models; and our people do not read it unless you give us permission, it is needed for security or to investigate abuse, the law requires it, or it has been aggregated and anonymised for internal operations.
How we access, use, store and share Google user data.
- Access and use. We read your Gmail only to run the features you use: My email (showing and sorting your inbox, opening a message when you open it, drafting a reply you ask for, reading an attachment you ask about), and the daily briefing and news, which read the sender, subject and opening lines of your recent emails to tell you what needs you. We send Gmail only when you ask, approve or set up a send. We read your calendar to brief you on meetings and add events you ask for, and your contacts when you choose to bring them in.
- Storage. The access and refresh tokens Google gives us are stored encrypted (AES-256-GCM). We do not keep a copy of your mailbox. We keep our sorting of each email (a tag and a one-line summary), the drafts and replies you work on, and the text of an attachment you asked us to read or saved, in your account on our servers, until you delete them or your account (section 10).
- Sharing. The parts of an email or event a feature needs are sent to our AI provider (Anthropic) to do that work, with detectable personal details replaced first where section 5 says so. We do not sell Google user data, use it for advertising, or give it to data brokers, and we use our AI providers under terms that do not let them train their models on it (section 5).
- Ending access. Disconnecting a Google account in the app deletes the stored token and asks Google to revoke it. You can also remove our access at myaccount.google.com/permissions.
We apply the same commitments to data from your Microsoft account (Outlook mail, calendar and contacts) and to any other mailbox you connect.
You can disconnect an account at any time in the app, and you can remove our access from your Google or Microsoft account settings.
8. Who we share it with
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We share it only as follows.
Service providers who process it for us
| Provider | What for | When |
|---|---|---|
| Fly.io | Hosting the app and its stored files | Always |
| Supabase | Database of accounts (account records are encrypted before they are stored) | Always |
| Anthropic | AI models and web search | When you ask for AI work |
| ElevenLabs | Voice for calls, spoken replies and audio briefings; speech to text | When you use calls or voice |
| OpenAI | Speech to text when our main provider is not available | When you use voice or add a recording |
| Twilio | Phone calls, call recordings, phone numbers, texts and WhatsApp messages | When you use calls, texts or business-phone answering |
| Resend | Sending the emails we send (sign-in codes, notices, reports, approval requests) and receiving email sent to GIDEON | Always |
| Stripe | Payments | When you buy credits |
| Cloudflare | Receiving and routing email sent to GIDEON's address | When you email GIDEON |
| Our lead and business data service, using Explorium, Apollo, Hunter, Google Places and GLEIF | Finding leads, business details and company records | When you use lead, local business or company look-ups |
| OpenStreetMap (Nominatim and map tiles) | Turning an address into a place on a map. Only the address text is sent for a lookup; showing a map loads map images from OpenStreetMap in your browser. | When you open a map |
| Our video studio, using Google (Vertex AI) and ElevenLabs | Making videos from your brief, photos and clips | When you make a video |
| Apple, Google and Mozilla push services | Delivering notifications to your devices | When you turn on notifications |
| Google Analytics and Microsoft Clarity | Measuring and recording visits to our public pages | Only if you accept analytics |
| Google Fonts and public script libraries (jsDelivr, cdnjs) | Fonts and page code loaded by your browser, which receives your IP address | When you load our pages |
Services you connect or choose
When you connect or use them, information passes between us and: Google and Microsoft (sign-in, mail, calendar, contacts, analytics reports); any other mail provider you connect by IMAP and SMTP; Basiq or Plaid and your bank (bank feed); Xero or Intuit QuickBooks (accounting); LinkedIn or Facebook if you connect them to post; booking and other websites GIDEON opens for you, including in a remote browser where offered; other Yes apps you open from YesBusiness or let use your credits; and the AI apps you connect GIDEON to with an access key. Each handles your information under its own terms.
Others
- The people you contact. Emails, texts, calls, reports and approval requests you instruct go to the people you choose, and contain what you approve. Work you hand to another YesBusiness account is copied into that account.
- Legal and safety. When we believe in good faith it is needed to comply with law or a lawful request, to enforce our Terms, or to protect anyone's rights, safety or property, including telephone carriers and platforms investigating abuse.
- Business transfers. As part of a merger, acquisition, financing or sale of assets, under this policy.
- With your permission for any other purpose.
9. Where it is stored and international transfers
Our application servers and their stored files are in the United States (Fly.io, Ashburn, Virginia). Most of the providers in section 8 are based in, or process data in, the United States. If you are outside the United States, including in Australia, New Zealand, the United Kingdom, the European Union or Canada, your information is transferred to and processed in the United States and possibly other countries where our providers operate.
Where the EU or UK GDPR applies, we rely on the European Commission's Standard Contractual Clauses (and the UK addendum) or another lawful mechanism for these transfers. For Australian users: we disclose personal information to recipients in the United States, and in other countries where the providers listed in section 8 operate. By using the Service you consent to that disclosure, and you acknowledge that Australian Privacy Principle 8.1 will not apply to it, so we will not be accountable under the Privacy Act 1988 for how an overseas recipient handles it and you may not be able to seek redress under that Act.
10. How long we keep it
| Information | How long |
|---|---|
| Your account, profile, conversations, files, saved work, tasks and settings | While your account is open. Deleted from our live systems when you delete your account, together with call recordings held by our telephone provider, a phone number we bought for your business (which is given up unless you asked us to transfer it to you first), and pending approvals and hand-overs. |
| Your sorting of email, text copies of attachments you asked about, synced accounting records and bank transactions | While your account is open, within limits (for example, bank transactions for about 400 days); deleted with your account or when you disconnect the account they came from |
| Call recordings | Business line: the period you choose. Others: until you delete the call or your account, when the recording held by our telephone provider is also deleted. Conversation records kept by our voice provider need a separate request (see below). |
| Your photos and clips sent to the video studio | Deleted 30 days after the video project's last activity |
| Saved website sign-ins in the remote browser (only if you tick to keep them) | Dropped after 30 days unused, or when you remove them |
| Work handed to someone without an account | Up to 30 days while the invitation is open |
| Copies of emails we send from our own address (reports, notices, approval requests), kept so we can check what was sent and investigate problems | Kept after your account is closed for a limited period |
| Credits ledger and payment records | As long as needed for accounting, tax and legal purposes, after your account is closed |
| Activity, cost and sign-up logs (which can include your account id, email and, for sign-ups, IP address, but not the content of your work) | Kept after your account is closed for security, fraud prevention and accounting, for a limited period |
| The fingerprint used to give starter credits only once | Kept after your account is closed, so the same address or business does not receive them twice |
| Text message opt-outs (STOP) | Kept so we keep honouring them, even after an account is closed |
| Backups (encrypted backups we make, and those kept by our hosting and database providers) | Overwritten or expired on their normal cycle |
Some records are not removed when you delete your account: the credits ledger and payment records, the security, usage and sign-up logs, copies of emails we sent, the starter-credit fingerprint, text opt-outs, backups until their cycle ends, and conversation records held by our voice provider. The app tells you what is kept before you delete. If you want those removed, write to it@xfactorai.com and we will act on the request as the law requires.
11. Security
We use measures designed to protect your information, including: encryption in transit (HTTPS); stored credentials for connected accounts, and account records in our database, encrypted with AES-256-GCM; separation of each account's data; signed, expiring links for anything shared outside the app; sign-in codes and session limits; no third-party session recording inside the signed-in app; and limited internal access. No system is completely secure, and we cannot guarantee the security of information. If we become aware of a breach affecting you, we will tell you and the authorities as the law requires.
12. Cookies, device storage and analytics
Necessary storage. The app stores your sign-in token and some preferences (for example, recent searches, voice and sound settings, and whether you dismissed a message) in your browser's local storage. These are needed for the Service to work or remember your choices, and are not used for advertising.
Analytics, only with your consent. On our public pages, and only for visitors who are not signed in, we use Google Analytics (to count visits and see which pages are used) and Microsoft Clarity (which records how a visitor moves around a page, including clicks and scrolling, to help us improve it). They set their own cookies. They do not load until you press Accept on the banner. If you press Decline, or your browser sends a Global Privacy Control signal, they do not load. You can change your choice at any time with "Cookie choices" at the foot of our home page. They never load inside the signed-in app.
We do not use advertising cookies, and we do not respond to "Do Not Track" signals, which have no agreed standard; we do honour Global Privacy Control as described above.
13. Your rights
In the app. You can view and edit your profile and what GIDEON remembers, delete files, calls and saved work, disconnect accounts, export your data (Settings, Export my data) and delete your account (Settings, Delete my account).
By email. For anything else, write to it@xfactorai.com from your account's email address. We may need to verify your identity, and we will answer within the time the law requires. You may use an authorised agent where the law allows; we may ask for proof of their authority. We will not treat you differently for exercising your rights.
EU and UK
You have the right to access, correct and erase your personal information, to restrict or object to our processing of it, to data portability, to withdraw consent at any time, and to complain to your data protection authority (in the UK, the Information Commissioner's Office).
California and other US states
California residents have the right to know the categories and specific pieces of personal information we collect, the sources, purposes and recipients (set out in sections 3, 4 and 8); to access, correct and delete it; and to opt out of the sale or sharing of personal information and to limit the use of sensitive personal information. We do not sell or share personal information as those terms are defined, and we use sensitive personal information (such as account sign-in details) only to provide the Service. Residents of other US states with privacy laws have similar rights, including to appeal a decision on a request by replying to our answer.
Australia and New Zealand
You may ask to access and correct the personal information we hold about you. If you have a complaint about how we handle it, write to us first and we will respond within 30 days. If you are not satisfied, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au) or, in New Zealand, the Office of the Privacy Commissioner (privacy.org.nz).
Canada
You may ask to access and correct your personal information and withdraw consent, and complain to the Office of the Privacy Commissioner of Canada.
14. If you are not our user
We may hold information about you because a YesBusiness user put it through the Service: for example if you were emailed, called or texted by GIDEON for them, called a business line Jasmine answers, appear in their mailbox, contacts, files, meeting or staff register, or were found as a lead or a company contact. That business decides how your information is used, and you should contact them first to exercise your rights.
You can also write to it@xfactorai.com. Tell us which business contacted you, or the number or address involved. We will pass your request to the business, help them respond, and act on it ourselves where we hold your information for our own purposes or the law requires us to. To stop texts from GIDEON, reply STOP.
15. Children
The Service is not for anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has given us personal information, write to it@xfactorai.com and we will delete it.
16. Automated decisions
GIDEON uses automated processing to sort email, rank tasks, read documents and suggest actions for you. We do not make decisions about you that produce legal or similarly significant effects based solely on automated processing.
17. Changes to this policy
We will post any change here with a new date. If a change is material, we will tell you in the app or by email before it takes effect.
18. Contact and complaints
Privacy questions, requests and complaints, and any other question: it@xfactorai.com.
By post: XFACTORAI LLC, 7345 W Sand Lake Rd, Ste 210 - Office 4812, Orlando, Florida 32819, United States.
XFACTORAI LLC is a Delaware limited liability company.
© 2026 XFACTORAI LLC