Skip to content · דלג לתוכן
← Fixer

Privacy Policy

Last updated: August 2026

This Privacy Policy explains how Fixer ("Fixer", "we", "us"), an AI receptionist service operated by Niv Gur, collects, uses, stores and protects personal data, in accordance with Israel's Privacy Protection Law, 5741-1981 and its regulations (including Amendment 13). Contact: office@yourfixerai.com.

Our two roles

  • As a controller - for data about you as an account holder (a business owner who signs up to Fixer).
  • As a processor - for data about your end-customers that the agent handles on your behalf. The business using Fixer is the controller of that data; Fixer processes it only on that business's instructions (see "Data we process for businesses").

What we collect

  • Account data - your name, email, a hashed password, and the business details you enter (business name, description, hours, pricing, and any knowledge you upload).
  • Conversation & customer data - messages exchanged with the agent, including end-customers' names, phone numbers / WhatsApp IDs and message content, and the leads or appointments derived from them.
  • Technical data - log data, IP address, device/browser information and timestamps, used for security and reliability.
  • Cookies - essential cookies only (sign-in session and language). See our Cookie Policy.

How we use it

  • To provide and operate the service - routing messages, generating AI replies grounded in your knowledge, capturing leads, booking, and human hand-off.
  • To secure the service and prevent abuse.
  • To support you and communicate about your account.
  • For billing, if you subscribe to a paid plan.

We do not sell personal data, and we do not use your customers' conversation content to train third-party models for unrelated purposes.

Service providers (sub-processors)

We rely on trusted providers who process data on our behalf: Anthropic (the AI model that generates replies), Voyage AI (makes your knowledge searchable), Meta / WhatsApp Business Platform (message delivery), Google (calendar integration - see "Google user data" below; and Gemini, which transcribes customer voice notes and, only where a business turns it on, describes customer videos), OpenAI (the voice agent that answers phone calls, and the text-to-speech behind voice-note replies where a business turns it on), Telnyx (phone numbers and call handling), LiveKit and Render (the infrastructure the voice agent runs on), Upstash (message queue), Neon (database) and Vercel (hosting). Some process data outside Israel (e.g. the EU or US). We share only what is necessary and rely on these providers' contractual and security safeguards.

Google user data (Google Calendar)

Fixer's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • What we access. If you choose to connect Google Calendar, we ask your permission for two Calendar permissions on the account you select - free/busy information (calendar.freebusy) and events (calendar.events) - plus your email address, used only to show you which account is connected.
  • Why we need it. Free/busy tells the assistant which times are already taken so it never books over an existing commitment. The events permission lets it create the appointment it agreed with your customer, move it if they reschedule, cancel it if they cancel, and read back appointments it created so it notices when you change them yourself. We do not request full calendar access, calendar settings, or sharing permissions.
  • What we store. Your Google access and refresh tokens, encrypted at rest (AES-256-GCM); the email address of the connected account, as a label; and, for appointments the assistant handled, the event identifier, time window, title and description. If you use bookable resources (rooms, stations, equipment) and you create a calendar event yourself whose title names one of those resources, we also store that event's identifier, time window and title for the upcoming booking window (a rolling ~60 days ahead), so availability respects your own holds and your dashboard can show which of your commitments blocked a slot; these records are refreshed on a rolling basis and deleted when you disconnect the calendar. Beyond that, we do not copy, index, or retain your wider calendar - free/busy is read at the moment a customer asks for a time and is not stored.
  • Sharing and Limited Use. We do not sell Google user data, do not use it for advertising or retargeting, do not transfer it to data brokers or information resellers, and do not use it to train any AI model. Calendar content is not sent to our AI providers as training data. We share it with no one except the infrastructure providers listed above, acting on our behalf to run the service.
  • Human access. No person at Fixer reads your Google Calendar data except where you specifically ask us to (for example, to resolve a support issue), where it is necessary for security, or where the law requires it.
  • Revoking and deletion. You can revoke Fixer's access to your Google account at any time at myaccount.google.com/permissions, or by disconnecting the calendar in your Fixer dashboard under Appointments. Disconnecting deletes the stored tokens immediately. Appointment records held in Fixer are deleted when you close your account, or sooner on request to office@yourfixerai.com.

Data we process for businesses

When a business uses Fixer to talk to its customers, that business decides what data is collected and why, and is responsible for having a lawful basis, for informing its customers, and for complying with applicable law. Fixer processes this data only to provide the service and on the business's instructions, and applies reasonable security. A data-processing addendum is available on request.

Retention

We keep personal data while your account is active and as needed to provide the service, then delete or anonymize it within a reasonable period, unless longer retention is required by law. You may request deletion at any time.

Your rights

Under the Privacy Protection Law you may request to review the personal data we hold about you, to correct or update it, and to ask us to delete it. To exercise these rights, contact office@yourfixerai.com. End-customers should contact the business they interacted with; we will assist that business.

Security

We use industry-standard measures - encryption in transit, hashed passwords, access controls and reputable infrastructure. OAuth tokens and integration credentials (including Google Calendar access and refresh tokens) are additionally encrypted at rest with AES-256-GCM, using a random initialization vector per value and an authentication tag, so a database copy on its own does not expose them. No system is perfectly secure, but we work to protect your data and will act promptly on any incident as required by law.

Children

The service is intended for users aged 18+ and is not directed at children.

Changes & contact

We may update this policy; the date above will change and material changes will be communicated where appropriate. Questions or requests: Niv Gur, office@yourfixerai.com.