1. About this policy
This Privacy Policy explains what information Pursor, LLC ("Pursor") collects, how we use and share it, and the rights you have over it. It applies to our website, dashboard, mobile apps, and AI tools (the "Service").
Pursor handles two distinct types of personal data:
- Your data — the business owner's account, profile, and usage data. We are the controller of this data.
- Your customers' data — names, phone numbers, emails, and message content for the people you communicate with through Pursor. You are the controller, Pursor is the processor.
2. Information we collect
2.1 Information you provide
- Account info: name, business name, email, phone, password
- Billing: payment method (handled by our payment processor, Stripe — we never see full card numbers), billing address
- Business profile: industry, services, pricing, tone preferences, hours of operation
- Communications data: customer contacts, message templates
- Support: any messages you send to support@pursor.co or our chat
2.2 Information collected automatically
- Device & diagnostics: IP address, browser type, and error/crash diagnostics
- Cookies and similar technologies
- Telephony metadata: call timestamps, durations, originating numbers (for missed-call recovery)
2.3 Information from third parties
- Integration data when you connect Google Calendar, email, or CRM tools
- Carrier responses (delivery status, opt-outs)
- Identity verification data from our A2P 10DLC registrar
3. How we use information
We use your information to:
- Operate, maintain, and improve the Service
- Generate AI drafts in your voice and on your behalf
- Process payments and send billing notices
- Authenticate you and protect against fraud or abuse
- Respond to support requests
- Send you product updates, feature releases, and security notices
- Comply with legal obligations including TCPA, A2P 10DLC, and tax law
- Enforce these Terms and our Acceptable Use Policy
We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA.
4. AI processing
When you use AI features, the text and context you provide are sent to our AI model provider(s) — currently Anthropic — to generate drafts. We have contractual protections in place: AI providers do not retain your data for training, and content is not used to train general models.
4.1 Google user data
When you connect your Google account, Pursor requests access to: read your Gmail messages (gmail.readonly); send email on your behalf (gmail.send); and manage events on calendars you own (calendar.events.owned) for scheduling.
How reading works: on a short polling schedule, Pursor checks your inbox for recent unread messages and reads the sender, subject, headers, and the beginning of the message body. Automated and bulk mail (newsletters, notifications, cold campaigns) is filtered out; for messages that look like a real person writing to your business, the message content is sent to our AI provider (Anthropic — see above) to generate a reply draft, which waits for your approval. Sending happens only when you approve a draft. We do not label, modify, archive, or delete your email.
Pursor's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Gmail data to train AI models, for advertising, or for any purpose other than providing the features you enable. The Google access tokens we hold are encrypted at rest with a dedicated key.
You can disconnect Google at any time in Settings → Connections → Disconnect Google. Disconnecting revokes Pursor's access with Google (we call Google's token-revocation endpoint) and deletes the access tokens we stored.
5. How we share information
We share information only as needed to operate the Service:
- Service providers (subprocessors). Hosting (Supabase, Vercel), AI (Anthropic), SMS (Twilio), transactional email (Resend), payments (Stripe), workflow automation (n8n — processes missed-call events to compose recovery texts, and for email drafting reads recent unread Gmail messages using Pursor's Google access and passes their content to our AI provider to generate reply drafts), error tracking (Sentry).
- Mobile carriers. To deliver SMS, we share number, message content, and identity info with carriers and the A2P 10DLC campaign registry.
- Legal compliance. If required by law, subpoena, or to protect rights, safety, or property. We will tell you about the request unless legally prohibited.
- Business transfers. In a merger, acquisition, or sale, your information may be transferred subject to this Policy.
- With your consent. Any other sharing requires your explicit permission.
6. Retention
We keep information only as long as needed for the purposes above:
- Active account: while your subscription is in good standing
- After cancellation: 30 days of full access for export, then 90 additional days in cold storage
- Billing records: 7 years (US tax requirement)
- SMS consent records: 4 years minimum (TCPA), 10 years for Virginia opt-out records
- Security and abuse logs: 1 year
You can request earlier deletion at any time (see Section 7).
7. Your rights (United States)
Depending on your state, you may have the right to:
- Know what personal information we have collected about you
- Access & portability — receive a copy in a portable format
- Correct inaccurate personal information
- Delete your personal information
- Opt out of sale or sharing for targeted advertising (we don't do this, but the right exists)
- Limit use of sensitive personal information
- Non-discrimination — we won't penalize you for exercising these rights
- Appeal a denied request (where state law provides this right)
To exercise any of these rights, email privacy@pursor.co or use the in-app "Privacy" controls in Settings. We respond within 45 days. We will verify your identity before processing the request.
7.1 Authorized agents
You may designate an authorized agent in writing to make a request on your behalf. We will require proof of authorization.
7.2 California Shine the Light
California residents may request a notice describing what personal information we share with third parties for their direct marketing purposes. We do not share personal information for third-party marketing, so the answer is "none."
8. Your rights (EU/UK)
If you are in the European Economic Area or the United Kingdom and you are using Pursor as a business customer, our legal bases for processing are: contract (to provide the Service you signed up for), legitimate interest (security, fraud prevention, product improvement), legal obligation (tax, TCPA-like requirements), and consent (where we ask for it). You have rights under GDPR/UK GDPR to access, rectify, erase, restrict, port, and object to processing. Contact us at privacy@pursor.co.
9. Security
We use commercially reasonable safeguards including encryption in transit (TLS 1.2+) and at rest (AES-256) — sensitive fields such as business EINs and Google OAuth tokens carry an additional layer of application-level AES-256-GCM encryption, each under its own dedicated key — plus least-privilege access controls, MFA for employee accounts, audit logging, and regular security reviews. No system is perfect — we encourage you to use a strong password and enable account security features. If we discover a security incident affecting your information, we will notify you and applicable regulators as required by law.
10. Children's data
The Service is not directed to children under 13 (or 16 in some jurisdictions), and we do not knowingly collect personal information from children. If you believe we have collected information from a child, contact privacy@pursor.co and we will delete it.
11. International transfers
Pursor is operated from the United States. If you access the Service from outside the US, you understand that your information will be processed in the US. For transfers from the EU/UK, we rely on Standard Contractual Clauses where applicable.
12. SMS data & consent
When a business uses Pursor to send text messages, those messages are sent to the business's own customers, who have provided their phone number to that business and agreed to receive texts in connection with a service relationship.
- We do not share, sell, or otherwise provide your mobile phone number, SMS opt-in data, or messaging consent information to any third parties or affiliates for marketing or promotional purposes. Mobile information is not used for any purpose other than delivering the messages the business sends through Pursor.
- Message frequency varies and depends on the recipient's activity with the business — for example, how many appointments are booked or inquiries are made. Pursor is not a high-frequency marketing program.
- Message and data rates may apply. Pursor does not charge recipients; however, standard message and data rates from the recipient's mobile carrier may apply.
- Recipients can opt out at any time by replying STOP to any message, and can request help by replying HELP. After opting out, the recipient will receive one confirmation message and then no further messages from that business unless they later reply START.
- Phone numbers and message content are shared only with mobile carriers and our SMS provider (Twilio) as required to deliver the message, and with the A2P 10DLC campaign registry as required for carrier compliance.
- Consent records (who opted in or out, when, and how) are retained for at least 4 years to comply with the TCPA.
For the full rules that govern messaging through Pursor, including how consent is obtained, see our SMS Consent Flow and Terms of Service.
13. Changes to this policy
We may update this Policy as our practices change. We will update the "Last updated" date at the top and, for material changes, notify you by email or an in-app prompt at least 14 days before they take effect.