MedspAI, LLC (“MedspAI,” “we,” “us,” or “our”) provides AI receptionist and communication services to medical spas across the United States. This Privacy Policy describes how we collect, use, and protect the personal information of people who visit our website, inquire about our services, book a demo, or receive communications from us — including by SMS/text message or email. If you are a med spa owner, operator, or decision-maker who has interacted with MedspAI in any capacity, this Policy applies to you.
1. Information We Collect
1.1 Information You Provide
When you fill out a form, book a demo, reply to an outreach message, or otherwise contact us, we may collect:
- Your name and job title
- Business name and website
- Email address and phone number
- Location (city, state)
- Any information you share with us in conversations or messages
1.2 Information We Research or Obtain from Third Parties
As part of our outbound sales and marketing process, we may research and collect business contact information from publicly available sources or third-party data providers. This may include:
- Business owner names and contact details found via public directories or business listings
- Business information such as address, website, and social media profiles
- Contact information obtained through lead generation or data enrichment tools
We use this information solely to reach out to med spa owners and operators who may be a good fit for MedspAI’s services.
1.3 Information Collected Automatically
When you visit our website, we may automatically collect:
- IP address and general location
- Browser type and device information
- Pages visited, time on site, and referring URLs
- Cookie and tracking data (see Section 7)
2. How We Use Your Information
We use the information we collect to:
- Contact you about MedspAI’s services via email, phone, or SMS
- Schedule and confirm demo calls or sales meetings
- Send demo appointment reminders and follow-ups
- Share relevant information about MedspAI’s products and updates
- Respond to your inquiries and provide support
- Improve our outreach, messaging, and marketing effectiveness
- Comply with applicable legal obligations
We do not use your information for purposes unrelated to MedspAI’s own business.
3. SMS Messaging — Opt-In and Opt-Out
This section applies to all SMS/text messages sent by MedspAI directly to prospects, leads, and contacts.
3.1 How We Obtain Consent
MedspAI sends SMS messages only to individuals who have provided consent to be contacted. Consent may be obtained when you:
- Submit a form on our website or landing page
- Book a demo or request information from us
- Reply to an outreach message and engage in conversation
By providing your phone number and consenting to be contacted, you agree to receive SMS messages from MedspAI related to our services, demos, and follow-ups. Message frequency will vary. Message and data rates may apply.
3.2 Types of SMS Messages We Send
SMS messages from MedspAI may include:
- Demo confirmations and reminders
- Follow-up messages after demos or inquiries
- Information about MedspAI’s services or updates
- Responses to inbound messages from you
- Opt-out confirmations
3.3 How to Opt Out
You can opt out of SMS messages from MedspAI at any time by replying STOP to any message. After opting out, you will receive a single confirmation message and will not receive further SMS messages from MedspAI unless you provide new consent. For help, reply HELP to any message or contact us at the information in Section 8.
3.4 No Sale of SMS Opt-In Data
We do not sell, rent, share, or transfer your phone number or SMS opt-in information to any third party for their own marketing purposes. Your contact information is used solely by MedspAI to communicate with you about our services. All other use case categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
4. Email Communications
If we have your business email address, we may contact you about MedspAI’s services in compliance with the CAN-SPAM Act. Every marketing email we send will include:
- Clear identification that the message is from MedspAI
- A valid business mailing address
- A clear and easy way to unsubscribe from future emails
To unsubscribe, click the unsubscribe link in any email or contact us at the information in Section 8.
5. How We Share Your Information
We do not sell your personal information. We may share it only in the following limited circumstances:
5.1 With Service Providers
We work with trusted third-party vendors to operate our business — including CRM platforms, email and SMS delivery providers, scheduling tools, and data enrichment services. These providers access your information only as needed to perform services on our behalf and are bound by confidentiality obligations.
5.2 As Required by Law
We may disclose your information when required by law, court order, or governmental authority, or when necessary to protect the rights or safety of MedspAI or any individual.
5.3 Business Transfers
If MedspAI is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will provide notice as required by applicable law.
6. Data Retention
We retain your contact and communication information for as long as necessary to manage our sales and marketing activities, maintain business records, or comply with applicable legal obligations. If you opt out or request deletion of your information, we will honor that request subject to any legal retention requirements.
7. Cookies and Tracking
Our website uses cookies and similar tracking technologies to understand how visitors use our site, improve our content, and support our marketing efforts. You can manage cookie preferences through your browser settings. Disabling cookies may affect certain website functionality.
8. Google User Data and Limited Use
When you connect your Google account to MedspAI, we request access to your Google Calendar in order to provide our appointment scheduling features. Specifically, MedspAI’s AI receptionist reads your calendar availability and creates, updates, or cancels calendar events on your behalf when your customers book, reschedule, or cancel appointments.
MedspAI’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only access the Google Calendar data necessary to provide our scheduling functionality.
- We do not use Google user data for advertising, and we do not sell Google user data.
- We do not transfer Google user data to third parties except as necessary to provide or improve the scheduling features, to comply with applicable law, or as part of a merger or acquisition.
- We do not use Google user data for any purpose other than providing the services you have requested.
- We do not allow humans to read your Google Calendar data unless we have your explicit consent to do so, it is necessary for security purposes (such as investigating abuse), to comply with applicable law, or the data is aggregated and anonymized.
You may revoke MedspAI’s access to your Google account at any time through your Google account settings.
9. How We Protect Google User Data
We access sensitive Google user data through the Google Calendar API (the calendar.freebusy, calendar.events, and calendar.readonly scopes). We treat this Google Calendar data as sensitive and protect it with the following safeguards:
- Google Calendar data is encrypted in transit using TLS/HTTPS on all connections.
- Google Calendar availability is read in real time to answer each request and is not stored on our servers. Any Google Calendar data we do retain, such as appointment records and the associated Google event identifier, is encrypted at rest in our database (Supabase/PostgreSQL).
- The Google OAuth tokens that authorize access to this sensitive data are stored in encrypted form using AES-256-GCM encryption and are never exposed to end users or third parties.
- Access to Google Calendar data is restricted to the account that granted it and to the specific application functions that require it.
- We request only the minimum Google scopes necessary for the feature in use.
- Google Calendar data is retained only as long as needed to provide the service. The OAuth tokens are removed from our database when a customer disconnects the calendar integration, and all stored Google integration credentials and appointment records are deleted when a customer’s account is deleted. You can also revoke MedspAI’s access to your Google account at any time through your Google Account settings.
10. AI Processing and Google User Data
Some MedspAI features are powered by artificial intelligence. We use a third-party AI service (OpenAI) and a self-hosted embedding model that we run ourselves. Our handling of Google user data in connection with these features is as follows:
- Google Workspace user data is never used to train, improve, or develop any artificial intelligence or machine learning model, consistent with Google’s Limited Use requirements.
- Data sent to OpenAI is processed through the OpenAI API, which does not use data submitted through the API to train its models.
- Our knowledge-base embedding model runs entirely within our own infrastructure. It processes only business knowledge-base content and never receives Google user data. Text it processes is handled locally and is never transmitted to any external model provider for training or any other purpose.
- Our AI receptionist connects to your Google Calendar to manage appointments. To offer open times and avoid double-booking, the AI processes appointment availability and existing appointment times from your calendar. The information sent to OpenAI is limited to times (open slots and existing appointment times). Event titles, descriptions, attendee names, email addresses, and phone numbers are never sent to any AI service. When an appointment is booked, the details are written directly to your Google Calendar.
11. Contact Us
If you have questions about this Privacy Policy, want to opt out of communications, or want to request deletion of your information, please contact us:
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will post the revised version on our website with an updated effective date. Your continued engagement with MedspAI after any update constitutes acceptance of the revised Policy.
This Privacy Policy is designed to comply with the TCPA, CAN-SPAM Act, and A2P 10DLC carrier requirements. To opt out of SMS from MedspAI, reply STOP at any time. For help, reply HELP or email team@medspai.com.