Privacy Policy.
Plain language, no fine-print tricks. This covers what we collect on westhillsai.agency and inside the client portal, why we collect it, who processes it, and the choices you have.
Last updated August 15, 2026
Who we are
West Hills AI (“West Hills AI,” “we,” “us”) provides AI agents, automation, website generation, analytics, and IT support tools through westhillsai.agency and our client portal (together, the “Services”). This policy explains how we handle personal information. If you have questions, email contact@westhillsai.agency.
What we collect
We only collect what the Services actually use:
- Account details — your name, email, a securely hashed password, and your organization name, role, and plan.
- Content you create — agents and their prompts, generated websites and the business descriptions you enter, builder chat messages, saved workflows, uploaded knowledge documents and their embeddings, and agent memory.
- Messages you send us — anything you submit through the contact, custom-build, or newsletter forms (typically name, email, and your message; a phone number if you provide one).
- Billing information — your plan, subscription status, and invoice history. Card payments are handled entirely by Stripe; we never receive or store your full card number.
- Usage records — the AI usage tied to your account, used for metering and billing.
- Support records — support tickets and their message threads, and metadata for any live Zoom or remote troubleshooting sessions you book.
- Optional features — if you use team SMS, the names and phone numbers you add; if you use voice features, usage duration and any pronunciation profiles you create.
- Connected integrations — if you connect Google, Zoom, or Meta, we store the resulting access tokens encrypted at rest so the integration can do what you asked of it. You can disconnect at any time.
- Basic technical data — first-party page analytics that record only the page path, the referring site's hostname, a country code, and any utm_source/medium/campaign tags. We do not log your IP address in analytics and do not set advertising or tracking cookies.
What we don't do
We don't sell or rent your data, we don't run third-party advertising pixels, and we don't set cross-site tracking cookies. We don't use the private content you create to train our own models.
How we use your data
- To provide, secure, and operate the Services and your account.
- To generate the AI outputs, websites, and analytics you request.
- To meter usage, process payments, and manage subscriptions.
- To respond to your messages and provide support.
- To detect, prevent, and investigate abuse, fraud, and security incidents.
- To meet legal, tax, and accounting obligations.
Service providers who process data for us
We rely on a small set of vetted providers, each acting on our instructions to run the Services:
- Supabase — hosts our PostgreSQL database (United States). This is where your account, content, and project data live, encrypted at rest.
- Vercel — hosts and serves the application and its content delivery.
- OpenAI — processes the prompts and content you run through the Builder, Studio, and Website Builder, solely to return your result. Anthropic and NVIDIA may process AI requests where those models are used.
- Stripe — processes card payments for plans and one-time builds.
- Resend — delivers transactional email (for example, password resets).
- Twilio — delivers SMS if you use the team-messaging feature.
- Google, Zoom, and Meta — only if you connect them, and only for the specific integration you enable (calendar access, meetings, or lead sync).
- Duffel and TravelPayouts — only if you use travel booking features, to search and book the travel you request.
Where your data is stored and transferred
Your data is stored in the United States with Supabase and Vercel. If you access the Services from outside the U.S., your information will be transferred to and processed in the U.S. and other countries where our providers operate.
How we protect it
Passwords are hashed with bcrypt and never stored in plain text. Connected-integration tokens are encrypted with AES-256-GCM. Traffic is served over TLS, sessions use short-lived access tokens with rotating refresh tokens, and card data never touches our servers. See our Security page to report a vulnerability.
How long we keep it
We keep your data for as long as your account is active and as needed to provide the Services, then delete or anonymize it on the timelines described in our Data Retention policy.
Your rights and choices
You can access, correct, export, or delete your data. Depending on where you live (for example, the EU/UK under GDPR or California under the CCPA/CPRA), you may have additional rights, including to object to or restrict certain processing. To exercise any of these, email contact@westhillsai.agency — or see Account Deletion for how removal works. We don't discriminate against you for exercising your rights.
Children
The Services are for business use and are not directed to children under 16. We don't knowingly collect data from children; if you believe a child has provided us data, contact us and we'll remove it.
Changes to this policy
We'll update this page when our practices change and revise the “last updated” date. Material changes will be communicated through the Services or by email.
Contact
Questions or requests? Reach us any time at contact@westhillsai.agency.