Skip to content
GateKeeperAI homeby VerdictIQ

GateKeeperAI · Legal

Privacy Policy

Effective September 25, 2026

GateKeeperAI is operated by VerdictIQ. This policy covers gatekeeperai.org and the GateKeeperAI app at gatekeeperai.verdictiq.org.

GateKeeperAI is a CRM with an optional AI receptionist for small businesses. It captures leads from calls, web forms, website chat and Facebook Lead Ads, books appointments, and helps manage Google review replies. The AI answers phone calls only on the AI Receptionist plan; on the Capture and Operate CRM plans, calls ring through to the business and the AI does not answer them. It is operated by VerdictIQ. This policy explains what data we collect, how we use and protect it, how we handle Google user data and Meta Platform Data, and the strict limits we place on the AI services we rely on.

1. Who this policy covers

This policy applies to the GateKeeperAI product, presented at gatekeeperai.org and verdictiq.org/gatekeeperai and delivered through the application at gatekeeperai.verdictiq.org. “You” means the business that uses GateKeeperAI. “Callers” means the people who contact your business through the receptionist.

2. Information we collect

  • Account data. Your name, email, and password (stored hashed).
  • Business data. Your business name, phone numbers, hours, services, and intake questions.
  • Caller and lead data. Information callers provide (name, phone, email, request details), plus call recordings and transcripts used to produce your lead summary.
  • Google user data. When you connect Google Calendar, the availability and event data described in Section 4. When you connect Google Business Profile, your business locations and the public Google reviews described in Section 4.
  • Meta Platform Data. When you connect a Facebook Page, the Page and lead data described in Section 5. We refer to data GateKeeperAI receives from Meta’s APIs as “Platform Data”.
  • Usage data. Standard log and diagnostic data (IP address, timestamps, error logs) used to operate and secure the service.
  • Website analytics. On gatekeeperai.org we use Google Analytics, loaded through Google Tag Manager, to understand how visitors find and use the site. It sets cookies and records information such as the pages you view, the links you click, the site that referred you, your device and browser type, and your approximate location. When you start a free trial, the Google Analytics identifier for that visit is passed to the GateKeeperAI app with the signup link, and when the trial begins we report that it began, and which plan was chosen, to Google Analytics under the same identifier, so we can tell which parts of the site lead to trials. The app itself runs no analytics scripts and sets no analytics cookies, and we never send your name, email, payment details, or any lead or caller data to Google Analytics. You can opt out by blocking cookies or with Google’s Analytics opt out browser add on.

3. How we use information

  • To operate the AI receptionist on the AI Receptionist plan: answer calls and chats, collect what a caller provides, and produce a lead summary for you. On the Capture and Operate plans, to record and transcribe calls that ring through to you and produce the same lead summary.
  • To check your availability and to book, reschedule, or cancel appointments on your connected calendar.
  • To monitor your Google reviews and, if you enable it, draft and publish replies to those reviews on your behalf.
  • To deliver the leads from any Facebook Page you connect into your lead inbox, label them with the Page and ad that produced them, and notify you about them.
  • To send you lead notifications, summaries, and account communications.
  • To secure, maintain, debug, and improve the reliability of the service.

4. Google user data and permissions

GateKeeperAI offers three optional Google integrations, each requesting only the permissions it needs. When you connect Google Calendar, it requests the scopes needed to schedule appointments on your behalf. When you connect Google Business Profile, it requests the single scope Google provides for review management. When you connect Gmail, it requests only the permission to send email as you:

Google scopes GateKeeperAI requests and why
ScopeWhy we request it
calendar.readonlyTwo uses: (a) checking your free/busy times (via Google’s freeBusy endpoint, which returns only busy time intervals) so the receptionist can offer open slots; and (b) displaying your calendar inside your GateKeeperAI dashboard, an owner-only view that reads event details. Event details are shown only to you and are never sent to any AI provider (see Section 6).
calendar.eventsCreating the appointment a caller books, and rescheduling or cancelling it. This scope can technically access all events, but GateKeeperAI only creates, updates, or deletes the appointments it books.
userinfo.emailIdentifying which Google account is connected, and for Gmail, which address your email is sent from.
business.manageReading your business locations and the public Google reviews left on them (reviewer display name, star rating, review text), and publishing the replies you approve or enable to those reviews. This is the only scope Google offers for review management; GateKeeperAI uses it solely to read locations and reviews and to post review replies, and it never edits your business information, posts, photos, or any other part of your profile.
gmail.sendSending the emails you write, approve, or set a rule to send to your own leads and contacts, from your own Gmail or Google Workspace address, so replies come back to your own inbox. This is a send only permission: GateKeeperAI cannot read, search, label, or delete any message in your mailbox, and it requests no Gmail read access. We store only the connected address and an encrypted access token, plus a record of each email GateKeeperAI sent for you so you can see it on the lead.

We request the narrowest scopes that support checking availability, creating, rescheduling, and cancelling appointments, and sending the email you ask GateKeeperAI to send. If your email is on Outlook or Microsoft 365, GateKeeperAI instead requests Microsoft’s delegated Mail.Send, User.Read, and offline_access permissions on the same send only terms: it cannot read your mailbox. You can revoke GateKeeperAI’s access at any time from your Google Account permissions or by disconnecting the integration in your GateKeeperAI settings.

5. Meta (Facebook) data and permissions

GateKeeperAI offers an optional Facebook integration that delivers your Facebook Lead Ads leads into your GateKeeperAI inbox. You connect it through Facebook Login for Business and choose exactly which Pages to connect. We call the data GateKeeperAI receives from Meta’s APIs Platform Data. We request the following permissions:

Meta permissions GateKeeperAI requests and why
PermissionWhy we request it
pages_show_listShowing you the list of Facebook Pages you manage so you can choose which ones to connect. We do not connect a Page until you select it.
pages_read_engagementReading the name and basic metadata of a connected Page, so leads are labelled with the Page that produced them.
pages_manage_metadataSubscribing a connected Page to the leadgen webhook, so Meta can notify us the moment a lead form is submitted, and unsubscribing it when you disconnect.
leads_retrievalRetrieving the answers a person submitted to your lead ad form (typically name, phone, email, and the questions you configured) so the lead appears in your GateKeeperAI inbox. This is the core of the integration.
business_managementReading the Pages your Business portfolio owns. Pages granted through a Business portfolio are not returned by the personal Pages endpoint, so without this permission your Page list can come back empty.
ads_read, ads_management, pages_manage_adsReading ad campaign, ad set, and insights data for the ad accounts you connect, so leads can be attributed to the campaign and ad that produced them and reported back to you. GateKeeperAI does not create, edit, pause, or spend against your ads.

Lead data is used only to deliver, display, and notify you about your own leads, and to report on the ads that produced them. We never use Meta Platform Data for advertising, never sell it, never combine it with data from other businesses, and never send it to a third party except the subprocessors in Section 8 that operate GateKeeperAI on our behalf. You can disconnect a Page at any time in your GateKeeperAI settings, or revoke access entirely from your Facebook Business Integrations settings. See Section 9 for how we delete it.

6. AI services and Limited Use

GateKeeperAI uses third-party AI services to power the voice and chat receptionist and to draft review replies. The only Google Calendar-derived data ever sent to an AI service is the computed set of free appointment times the receptionist may offer a caller (for example, “Tuesday at 2:00 PM”). Event titles, descriptions, and attendee details are never sent to any AI service. If you enable review replies, the content of a public Google review (reviewer display name, star rating, and review text) is sent to the AI provider solely to draft a reply for that review; drafts for critical reviews are held for your approval before anything is posted.

GateKeeperAI never reads your Gmail, so no Gmail message content is ever sent to any AI service. The gmail.send permission is used only to deliver an email you wrote, approved, or set a rule to send, and never to send anything else.

If you enable AI reply drafts for leads, the content of a lead, including a lead that reached you through a Facebook lead ad, is sent to the AI provider solely to draft a reply to that lead. A draft is stored for your review and is never sent to anyone until you send it. Meta Platform Data is never used to train any AI model, and the providers below exclude API data from training.

AI providers GateKeeperAI uses and whether they train on its data
ProviderTierTrains on our data?
OpenAIBusiness API (pay-as-you-go)No. API data is excluded from training by default.
Anthropic (Claude)Commercial APINo. API data is excluded from training by default.
NVIDIABusiness APINo. Never receives any Google user data.

These are hosted commercial APIs whose terms exclude API inputs and outputs from model training by default. GateKeeperAI does not operate self-hosted AI models. We do not use, transfer, or sell Google user data to train or improve any generalized or foundational machine-learning or AI model. We do not use Google user data for advertising, and we do not sell it or share it with data brokers.

Limited Use. GateKeeperAI’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

7. How we protect your data

  • Encryption in transit. All data is transmitted over TLS/HTTPS.
  • Encryption at rest. Data is stored in a managed Postgres database with encryption at rest; OAuth tokens are stored encrypted.
  • Access controls. Production data is restricted to authorized personnel and enforced by per-tenant isolation so one business can never see another’s data. Our staff do not access the contents of your calendar except where strictly necessary for security or debugging, on a need-to-know basis.
  • Least privilege. We request the minimum Google scopes required, and AI services receive only the minimum data needed to complete a task.
  • Provider retention limits. Our AI providers delete API inputs and outputs from their systems within 30 days by default.

8. Data sharing and subprocessors

We do not sell your data or callers’ data. We share data only with the service providers that operate GateKeeperAI on our behalf, under contract: cloud hosting and database, telephony (Twilio), email delivery, website analytics (Google Analytics, see Section 2), and the AI providers listed in Section 6. We may disclose data if required by law.

9. Data retention and deletion

We retain account, business, and lead data for as long as your account is active. Call recordings and transcripts are kept for as long as your account is active unless you ask us to delete them sooner. We do not delete them on a fixed schedule, because the right retention period depends on your business and the record keeping rules that apply to it (for example, rules for law, medical, or tax practices), so you decide how long to keep them. You can ask us to delete specific recordings, or all of them, at any time, and we will do so within 30 days of your request. Recordings are deleted when your account is deleted. A caller who wants a recording deleted should contact the business they called, which controls those records. You may request deletion of your data, or delete your account, by contacting us at the address below; we will delete your data except where retention is required by law. Disconnecting Google Calendar or Google Business Profile immediately stops all access under that integration and revokes our stored tokens. Disconnecting Gmail in your GateKeeperAI settings immediately stops GateKeeperAI from sending as you and deletes the stored token and connected address; you can also remove GateKeeperAI from your Google Account permissions at any time. Disconnecting a Facebook Page immediately stops all access under that integration, unsubscribes the Page from our lead webhook, and deletes the Page access token we stored for it. Meta Platform Data is deleted when you delete the lead it belongs to, when you disconnect the Page, or when you delete your account, whichever comes first. To request deletion of all Meta Platform Data we hold for your business, email us at the address below and we will delete it within 30 days.

10. Your rights

You may access, correct, request a copy of, or delete your personal data, and revoke Google or Meta access at any time. Meta access can also be revoked directly from your Facebook Business Integrations settings. To exercise any of these rights, contact us at hello@verdictiq.org.

11. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the effective date above and, where appropriate, communicated to you directly.

12. Contact us

Questions about this policy or your data? Email hello@verdictiq.org.

See GateKeeperAI plans and pricingAbout VerdictIQ, the company behind GateKeeperAI