← Back to LFSA Digital

Privacy Policy

Last updated: August 25, 2026

1. SMS & Phone Number Data

When you opt in to our SMS program ("LFSA Digital Client Communications"), we collect:

How you opt in: You opt in to receive SMS messages by submitting the SMS sign-up form on our website at lfsadigital.com/sms, where you enter your name and phone number and tick one or both of two separate, unchecked consent boxes: one for appointment and service texts, one for promotional texts. We will always obtain your express written consent before sending any SMS messages. This is the only way to opt in to our SMS program.

How we use this data:

Two separate SMS consents. Our opt-in form at lfsadigital.com/sms collects two independent consents, each with its own unchecked checkbox: one for appointment and service messages (up to 10/month), and a separate one for promotional and marketing messages (up to 4/month). You may accept either, both, or neither. Declining promotional texts does not affect appointment texts, and declining both does not affect your ability to work with LFSA Digital.

SMS consent is never required. Neither checkbox is pre-ticked, neither is bundled with our Terms of Service, and neither is a condition of creating an account, purchasing anything, or receiving any LFSA Digital service. The opt-in page also offers a skip link.

Message frequency: message frequency varies; you may receive up to 10 messages per month. Message and data rates may apply. Reply STOP to opt out at any time, or HELP for assistance.

We do not sell, rent, or share your phone number or SMS opt-in data with third parties for their marketing purposes. No mobile information collected as part of this SMS program will be shared with third parties or affiliates for marketing or promotional purposes at any time. Your phone number is shared only with our SMS service provider (Twilio) as necessary to deliver messages on our behalf.

You may opt out at any time by replying STOP. After opting out, your phone number will be retained in our opt-out list solely to honor your request. All other data will be deleted within 30 days.

For full SMS program terms including carrier information and support options, see our Terms of Service.

2. Website Data

We do not track you on this website. It runs no analytics, advertising, or tracking scripts, sets no cookies, and stores nothing in your browser. We do not collect page views, referring URLs, device information, or any other record of your visit.

Forms. The SMS opt-in form described in section 1 is the only form on this site. There is no contact or lead-capture form, and we collect no email addresses through the website.

Hosting. The site is served by GitHub Pages. Like any web host, GitHub processes technical request data such as your IP address in order to deliver the pages to you. That processing is governed by GitHub's privacy statement. We have no access to those logs.

Content loaded from other services. Some page assets are fetched directly by your browser from third parties: typefaces from Google Fonts, icons from Cloudflare, and video thumbnails from YouTube. Those requests happen between your browser and those companies, and they may see your IP address as a result. We receive nothing from them.

Links that leave this site. Our booking buttons open Cal.com and our contact button opens WhatsApp. Anything you enter on those services is collected by them under their own privacy policies, not this one.

3. Content Manager Data (LFSA Content Manager)

When you connect your TikTok account to LFSA Content Manager, we collect and store:

4. Google User Data (LFSA AI Employee)

LFSA Digital builds and operates "AI employees" — software agents that carry out a defined business role for a client. When a client chooses to connect a Google account to one of these agents, the agent accesses that account's Gmail data through Google's APIs.

What we request, and nothing more. The agent requests exactly two OAuth scopes:

The agent cannot send email. This is not a policy we ask you to trust; it is a technical limit. The credential we hold carries no send permission, so a request to send is refused by Google. Every message the agent writes is a draft that a person at your company opens, reads, and sends. We do not request gmail.send, gmail.modify, gmail.compose, or full-mailbox access, and we cannot delete your mail.

Why narrower scopes are not sufficient. The role we are automating requires reading the substance of messages, not only their headers or labels. Google offers no read scope below gmail.readonly that exposes message bodies, so it is the minimum scope that lets the agent do the work it was hired for.

How we use it. Google user data is used solely to operate the agent for the client who connected the account — reading the messages relevant to that role and drafting replies. We do not use it for advertising, we do not sell or rent it, and we do not use it to create, train, or improve any generalized or foundational machine-learning or artificial intelligence model.

LFSA Digital's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. AI Services and Your Google Data

The agent's reasoning is performed by a third-party large language model: Grok, provided by SpaceXAI LLC (formerly xAI) through its API. To answer a question or draft a reply, the contents of the specific messages the agent is working on are sent to that API. We do not send your mailbox wholesale to any AI provider.

Under SpaceXAI's Terms of Service — Enterprise, which govern API use, SpaceXAI does not use API inputs or outputs to train its models or to develop new products or services. SpaceXAI's own documentation states that it "never trains on your API inputs or outputs without your explicit permission." We have not granted, and will not grant, such permission.

No retention at the model provider. LFSA Digital operates its SpaceXAI account with Zero Data Retention enabled. Message content exists on SpaceXAI's systems only for as long as it takes to generate the response, and is deleted on delivery of that response. No logs, backups, or persistent copies are kept, and SpaceXAI derives no de-identified or aggregated data from our usage. SpaceXAI's default 30-day audit retention does not apply to our account.

6. Storage, Security, and Human Access

OAuth access and refresh tokens for a client's Google account are stored on a server that LFSA Digital controls, in files with restrictive permissions. The agent's tooling necessarily uses the Gmail token to do its work, so the safeguard we rely on is not secrecy but scope: the token carries read and draft permissions only, and a send attempt is refused by Google no matter who holds it. Keys for our messaging and AI-model providers are kept outside the agent's execution sandbox entirely.

Human access. LFSA Digital personnel do not read a client's Google user data in the ordinary course of business. A person may access it only when the client asks us to, for example to diagnose a problem they have reported; when necessary to investigate a security incident or suspected abuse; or when required by law. We do not use human review of Google user data to develop or improve our products.

7. Retention and Revocation of Google Data

We do not keep copies of your email. The agent reads messages through Google's API at the moment it needs them; it does not maintain a mirror or an archive of your mailbox.

You may disconnect at any time by asking us to revoke the connection, which deletes the stored token immediately, or by removing access yourself from your Google Account permissions page. Once the token is revoked the agent loses all access to your Google account. On termination of a client engagement, all stored Google credentials are revoked and deleted.

8. How We Use Your Data

Your data is used exclusively for:

9. Data Sharing

We do not sell, rent, or share your personal data with any third parties for their marketing purposes. Your data is shared only with service providers as required to deliver our services: Twilio for SMS, the TikTok API for content management, and SpaceXAI LLC (Grok) for the language model that powers our AI employees, as described in section 5.

10. Data Storage & Security

Your data is stored on secured servers. OAuth tokens and sensitive credentials are stored encrypted. We implement reasonable technical and organizational measures to protect your data from unauthorized access, loss, or misuse.

11. Data Retention

We retain your data only for as long as necessary to provide our services. When you opt out of SMS, disconnect your accounts, or request deletion, we remove all associated data within 30 days (except opt-out records maintained to honor your preference).

12. Your Rights

You may at any time:

13. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

To exercise any of these rights, contact us at luiz@lfsadigital.com. We will respond to verifiable requests within 45 days.

14. Children's Privacy

Our services are not intended for use by individuals under the age of 18. We do not knowingly collect data from minors.

15. Changes to This Policy

We may update this Privacy Policy from time to time. Continued use of our services after changes constitutes acceptance.

16. Contact

For privacy-related questions or data requests, contact us at luiz@lfsadigital.com.

© 2026 LFSA Digital. All rights reserved.