Privacy policy
Pilot review draft: September 26, 2026 · Published by Thorton LLC
The current Day-1 mobile build shows invoice drafts and first-reply drafts stored in an invited workspace for a shop's existing business phone. An authorized owner/admin can also manually add a contact and save owner-written first-reply text for review, edit and save invoice line items, and record approve or reject decisions. The app includes an agent chat. When the owner uses it, OwnerSwitch sends the owner's messages and the workspace details the agent needs to DeepSeek, the agent model provider, and returns proposals the owner reviews. The optional Polish with live AI action sends OpenAI the owner's rough reply (up to 1,000 characters) plus published business-writing and safety instructions. Voice features, where enabled, send the owner's spoken question to OpenAI for transcription and the agent's reply text to OpenAI for speech. The section AI model providers lists exactly what each provider receives. The build does not provision a number, ingest or transmit provider messages, place calls, or send an invoice or payment link; the owner sends outside the app. Sections about message delivery describe a separately approved future pilot, not the current store binary. An internally approved baseline retention schedule exists. This broader page remains a pilot review draft, and live messaging remains disabled until the final notice, pilot agreement, provider terms, current-runtime reconciliation, and implementation proof are complete.
Who's who
Three parties show up in this policy:
- The business - the contractor you hired or contacted (for example, your electrician). During Day 1, they use OwnerSwitch to review and save edits or decisions on invoice and first-reply drafts, then send outside the app from their existing business phone.
- You - either a customer of that business (you text, call, or email them) or a business user (you run the business and use the OwnerSwitch app).
- Us - Thorton LLC, a California limited liability company, which owns and operates the OwnerSwitch product brand on behalf of the business. For customer conversation data, the business decides why it's used; we process it to provide the service.
What we collect
Summary: the Day-1 app may use business, customer, active-work, invoice, draft, account, and basic technical records needed to prepare and review drafts. It does not receive or transmit SMS or calls through OwnerSwitch. Message-channel and consent records below apply only to a separately activated future pilot. No ad trackers, no cookies on this site, no fingerprinting, no buying data about you.
| Category | Examples | Where it comes from |
|---|---|---|
| Business-user account, review, and AI activity | Account name, email, authentication and session identifiers, saved approve or reject decisions, agent chat messages, optional owner-entered rough text submitted to Polish, spoken questions where voice is enabled, and a content-free model-run receipt | The business user and the account-linked review, agent chat, Polish, and voice workflows. The receipt contains bounded hashes, token counts, and provider/model/outcome facts, not the chat text, rough reply, audio, or generated text |
| Contact information | Name, phone number, email, service address | You, when you contact the business or fill a form here |
| Messages and channel events (future pilot only) | Text messages, emails, website leads, call metadata, and content you choose to send through a separately activated pilot channel | Your conversation with the business after that future channel is approved. The Day-1 store binary does not receive or transmit SMS or calls. Voicemail recording and transcription remain off until separate disclosure and retention review is approved |
| Consent records (future pilot only) | Date and time (UTC), the exact consent text version you saw, the page address, your IP address and browser type, your confirmation reply ("YES") or opt-out ("STOP") | The consent, opt-out, and preferences forms on this site, and SMS replies after a future messaging pilot is separately activated |
| Active-work context | Service location, work status, invoice line-item descriptions, quantities, dollar amounts and totals the owner can edit and save, internal notes, and approved conversation history | The business and the customer conversation. The Day-1 app keeps invoices as internal drafts; it does not finalize or send invoices or create pay links |
| Work-item media | Owner-selected job photos, job videos (including audio), voice memos, customer text screenshots read on-device only for first-reply drafting, and existing documents displayed or downloaded with work | The owner explicitly attaches photo, video, or audio evidence, or screenshots / chooses a customer text for drafting. Text is read on the device first; if that fails, the owner's chosen screenshot image is sent to the agent model (DeepSeek) to read the customer message. Existing documents may be received for display or download; the Day-1 app has no document-upload flow |
| Website analytics | Page viewed, a bounded event type (for example "consent form submitted"), and an ephemeral tab session. If you explicitly allow anonymous visitor measurement, we also save one random ID for this browser profile and the disclosure version you accepted. No cookies, fingerprint, raw referrer, or cross-site identifier. | This website and, only for the optional random ID, your saved browser preference |
| Waitlist | Email, business name, trade | The waitlist form |
Anonymous analytics preferences
Basic first-party, cookie-less session measurements help us keep this site working. They disappear from your browser when the tab closes. You can separately allow one random ID to persist in this browser profile so we can count consented browser profiles and understand repeat visits. The ID is not a name, account, device fingerprint, advertising ID, or proof that one person visited; it is not shared across sites and is never used to authorize a text or email.
No persistent anonymous-measurement preference is assumed.
Turning it off replaces the saved choice and removes the random ID from this browser profile. Earlier append-only events remain subject to the raw-analytics retention limit below; admin reports expose only tenant-scoped aggregate counts, never the ID itself.
What we use it for
- Starting a tenant-scoped internal invoice draft from the owner's own job and displaying stored first-reply drafts for review; allowing an authorized owner to save owner-written first-reply text, invoice line-item edits, and approve or reject decisions. Starting the internal draft does not contact Stripe. The Day-1 app does not send either draft.
- Agent chat, Polish, and voice. The agent answers the owner's questions about their own workspace and proposes drafts, contacts, and invoice changes that the owner reviews. Model output is only a proposal: the agent cannot approve, send, finalize, charge, or record payment. Copy writes the exact draft to the device clipboard; Copy, Polish, and Approve create no SMS, messaging-provider, or customer action. Not right records feedback without an automatic redraft/model call in Day-1 production. See AI model providers.
- Future messaging pilot only: delivering messages, checking consent before each message sent through OwnerSwitch, honoring opt-outs, and flagging emergency language for human follow-up.
- Running and securing the service: authentication, fraud and abuse prevention, debugging, and legally required records.
What we don't do: sell personal information; share it for cross-context behavioral advertising; use one business's customer data for another business's benefit; or use your conversations to train shared AI models. If we ever want to change any of these, we'll ask first, plainly - not with a policy-update email nobody reads.
Your mobile number, specifically
The Day-1 app does not send text messages. If a future messaging pilot is separately activated, carrier rules apply: mobile opt-in data and consent records are not shared with or sold to third parties or affiliates for their marketing or promotional purposes. Text messaging originator opt-in data is used only to run the messaging program the recipient joined.
Who we share with
- The business you're talking to - they see your conversation; it's theirs and yours.
- Day-1 service providers - Clerk provides authentication, and Hetzner Online GmbH / Hetzner Cloud hosts the OwnerSwitch application, database, and stored-file path. DeepSeek is the agent model provider and OpenAI provides Polish and voice (transcription and speech), as described in AI model providers. Their production configuration, narrow authorization receipts, exact data-sharing, retention, and residency settings, contract terms, and exact-build network behavior remain human release gates. The production app includes no Sentry crash-reporting SDK. Messaging and email providers apply only to a separately approved future pilot. A pre-existing hosted invoice link may open directly with its payment processor; OwnerSwitch does not collect card details, create or finalize invoices, or calculate tax.
- Authorities, when legally required - and where the law allows, we'll tell the affected business.
- A future acquirer - if OwnerSwitch is ever acquired, this policy's promises travel with the data, and we'll notify you of any material change.
AI model providers
OwnerSwitch calls AI models only from its own servers, never directly from the app, and only when the owner uses an AI feature. Customer-facing messages are never sent by a model.
| Provider | Feature | What it receives | What it does not receive |
|---|---|---|---|
DeepSeek (model deepseek-flash) | Agent chat, the only agent model | The owner's recent chat messages; business name, owner name, towns served, service radius, services, hours, and business knowledge notes the owner saved (such as pricing notes); job titles and statuses; and, when the agent looks them up, customer display names with the last four digits of a phone number, invoice line items and totals, and attention summaries. Also any customer text the owner pastes or dictates and, if on-device reading fails, a screenshot image the owner chose | Full phone numbers, email addresses, service addresses, device contacts, payment card data, or other workspaces' data |
| OpenAI | Polish with live AI | The owner's rough reply (up to 1,000 characters) plus published business-writing and safety instructions | Customer conversation history, media, invoice/payment data, or device contacts |
| OpenAI | Voice (transcription and speech), where enabled | The owner's spoken question as audio (up to about 1.5 MB), and the agent's reply text (up to 1,000 characters) to read aloud | Workspace records. OwnerSwitch does not keep the audio after the request |
DeepSeek's privacy policy describes processing and storage in China, variable retention, and model training as a processing purpose with an opt-out. The retention, training, and residency terms for the OwnerSwitch DeepSeek account are HUMAN_TBD until Privacy + Security verify them, and live customer data is not sent to DeepSeek until that review is recorded.
OpenAI states that API inputs and outputs are not used to train its models by default unless an organization opts in, and that default abuse-monitoring logs may retain API content for up to 30 days unless approved controls, including eligible Zero Data Retention controls, apply. See OpenAI API data controls and OpenAI business-data commitments. The exact OwnerSwitch project settings and provider-side processing remain HUMAN_TBD until Privacy + Security verifies them.
How long we keep things
An internally approved baseline retention schedule exists. That baseline is not proof that current collection, deletion execution, processor follow-up, legal-hold handling, or backup expiry has been reconciled and implemented. Functional draft-review decisions and content-free agent chat, Polish, and voice model-run receipts are retained with the approval/audit records; the exact model-receipt period remains HUMAN_TBD. OpenAI's default provider-side abuse-monitoring retention may be up to 30 days unless approved project controls change it; DeepSeek's retention is variable under its public policy. Exact provider retention and residency for both remain HUMAN_TBD. Mobile screen-view/tap analytics and Sentry crash collection are disabled in Day-1 production. For any separately activated future messaging pilot, consent and opt-out evidence is proposed to be kept for at least 5 years from the last message that relied on it, subject to applicable law and the final signed pilot process. Other pilot periods must still match the signed pilot agreement, data-processing terms, and implemented backup and deletion controls.
Raw website analytics, including any consented random browser-profile ID, have a maximum operating limit of 13 months. The final approved schedule may be shorter but must not silently extend that limit.
Deleting your account and data
Approved deletion-policy component: account-deletion policy version 2026-08-29-review-draft-v1 received recorded human legal/privacy approval on August 29, 2026. That bounded approval does not make this broader privacy notice effective, approve the Terms of Service, prove production fulfillment, or authorize deployment. Every account holder, whether owner, admin, operator, or viewer, can initiate personal-account deletion inside the app. A workspace member uses More → Setup → Account & privacy → Delete my account. A signed-in person with no workspace uses the blank slate's direct Account & privacy → Delete my account path. The same request can be started without reinstalling the app from /account/delete/.
Personal-account deletion removes the authentication account and personal profile, disables access in every workspace, deletes private preferences and usage identifiers, and de-identifies attribution that a business must retain in shared records. Workspace deletion is separate and owner-only. A sole owner's personal deletion waits for an approved ownership transfer or completion of the workspace-deletion plan.
Under the approved deletion policy, active account data is targeted for verified deletion within 30 days. Legal holds, required fraud/security records, business-owned shared records, and unavailable processor deletion may change what can be erased. Any retained category and reason must appear in the final notice. A submitted request, including intake confirmation, is not proof of deletion or completion. A request remains pending until active deletion is verified; backup expiry is independently verified after 35 elapsed days (840 hours) from verified active-system deletion; Clerk/authentication deletion is verified; the final notice is successfully issued; and a policy-bound, bounded completion receipt binds all evidence.
Your rights
Depending on where you live, which law applies, and OwnerSwitch's role for the data, you may have rights to know, access, correct, delete, or limit certain processing. We do not claim that every privacy law applies to every pilot record. The request channel is available regardless, and the business may be the party responsible for deciding a customer-record request:
- Email privacy@ownerswitch.com to make a request. We verify authority and respond within the timeframe required by the applicable law and approved pilot process.
- If the data belongs to your conversation with a business, we may route the request to that business. Consent and opt-out evidence may be retained where needed to honor suppression and meet approved legal-record requirements.
- If a future messaging pilot is activated, you will never need an account or login to opt out: opt-out form, STOP reply, or unsubscribe link.
Security
OwnerSwitch first-party endpoints require TLS in transit, role-limited tenant access, redacted operational logs, and append-only records for approvals and consent changes. Exact signed-binary, active-SDK, and provider-path verification remains pending, so this draft does not claim that every collected-data path has been proved encrypted for the Google Play answer. Encryption at rest, off-box backup protection, restore evidence, access review, and incident notification must be verified in the final data-governance pack before live customer data is enabled. No system is unhackable.
Children
OwnerSwitch is for business communication and isn't directed at children under 13. If you believe a child's information reached us, email privacy@ownerswitch.com and we'll delete it.
Changes
We'll post changes here with a new effective date. For material changes affecting message recipients, we'll notify the businesses (who can notify you) and, where required, notify you directly. The prior version stays available on request.
Contact
Thorton LLC
2108 N St Ste N, Sacramento, CA 95816
Privacy: privacy@ownerswitch.com · Support: support@ownerswitch.com
Registered agent for service of process: Northwest Registered Agent, Inc. (California 1505 registered corporate agent).
This policy is a working draft for counsel and operator review, not a claim that the live-data gate is cleared. Final language and the signed pilot agreement must match the verified runtime before any live customer data is enabled.