Scope
This Privacy Policy describes how Luntive may handle information through the Luntive marketing website and the Luntive tenant application. It covers information processed through active Version 1 features described here. It does not cover features that are not implemented.
Imran Bhuiyan, an individual operator in New York, operates Luntive.
In this policy:
- Customer means the business using Luntive.
- Authorized User means a Customer's staff member who uses the service.
- End Client means the Customer's own client, caller, lead, or appointment participant.
- Account means an individual login used to access Luntive.
- Business workspace means the Customer's tenant or business record in Luntive.
The Customer generally decides what information is entered into its Business workspace and how Luntive is configured. For End Client information handled on the Customer's behalf, the Customer may have the primary relationship with that person.
Information collected or processed
Depending on the features a Customer uses, Luntive may process the following categories:
Account and business information
- Account and authentication information.
- Business identity, contact, service, hours, website, and configuration data.
- Customer-provided prompts, AI instructions, FAQs, policies, and other business knowledge.
Client, lead, appointment, and calendar information
- End Client contact information, including information about clients and leads.
- Optional date of birth and Tax Type fields when a Customer chooses to provide them.
- Appointment and Google Calendar information.
- Caller phone numbers and information used to match a caller to a client or lead.
Calls and voice-related information
Calls may result in call metadata, transcripts, summaries, analysis, raw provider webhook payloads, and recording URLs when supplied by the provider. No local audio-file storage was evidenced. Luntive may store a provider recording URL when supplied.
This policy does not state that every call is recorded or that no calls are recorded. Provider recording behavior, URL expiration, provider retention, and historical provider deletion remain unverified.
Email and communication information
Email workflows may involve recipient addresses, sender information, subject lines, message bodies, provider identifiers, delivery status, and scheduling information. Communication drafts and generated communications may also be processed through the relevant workflow.
Knowledge and AI-assisted information
Luntive may process business knowledge, FAQs, policies, prompts, AI instructions, assistant-chat information, AI conversation records, generated content, and AI-generated summaries. Website import may provide public-page text, source URLs, and extracted or structured business information that is used to help generate business knowledge.
Bookkeeping and operational information
Luntive may process bookkeeping workflow configuration and manually confirmed payment status. It may also process usage, credit, billing-status, Stripe customer, subscription, product, and price identifiers, subscription status, support-session, administrative, and audit data. Stripe Checkout handles payment collection; based on the current product audit, Luntive does not store raw payment-card numbers or CVC/CVV values.
Browser and technical information
Browser and session storage may include authentication/session state, Google OAuth state, signed support-session state, login-lockout information, UI preferences, communication drafts, knowledge-synchronization markers, and sidebar session cache.
Luntive may receive infrastructure or provider request metadata as part of operating the service. Application storage of IP addresses has not been verified. User-agent information may be stored with legal acceptance evidence.
Google API Services and Google User Data
Luntive accesses Google user data only when an Authorized User chooses to connect a Google account or Google Calendar to Luntive. The OAuth scopes currently requested are openid, email, https://www.googleapis.com/auth/calendar.events, and https://www.googleapis.com/auth/calendar.calendarlist.readonly. These permissions provide account identification and email information, access to writable calendars, and the Calendar permissions needed to support appointment synchronization.
For that connection, Luntive may access the Google account subject ID and verified Google account email, available writable calendars and their calendar ID, calendar name or summary, summary override, primary-calendar status, access role, and Google event IDs used for synchronization lookup. Luntive does not read arbitrary full Google Calendar event contents.
Google user data is used only to provide and maintain the user-facing Google Calendar functionality requested by the Authorized User. This includes connecting the authorized account, displaying eligible calendars for selection, creating appointment events, updating appointment events, deleting appointment events, and maintaining synchronization between supported Luntive appointment workflows and the selected Google Calendar. Google user data is not repurposed for unrelated Luntive functionality.
Luntive stores limited Google integration information required to operate the integration, including the Google account ID and email, selected calendar ID and name, Google event IDs, synchronization mappings and status, encrypted refresh-token material, and access-token expiration metadata. Full Google Calendar event payloads are not persisted. Google refresh tokens are encrypted using AES-256-GCM and handled server-side. Google access tokens are used transiently and are not persisted as token values.
Google Calendar-derived API data is not provided to Gemini, Retell, or other AI or model providers for AI processing. Luntive does not use Google user data for advertising, marketing, analytics, profiling, customer scoring, unrelated product development, model training, or generalized AI training.
Limited Google-related information may be processed by Luntive infrastructure or service providers only as necessary to host, secure, transport, or operate the user-requested Google Calendar integration. This does not authorize broad sharing of Google Calendar-derived data with Luntive's AI providers.
An Authorized User may disconnect Google Calendar. When disconnected, Luntive attempts to revoke Google authorization, clears locally stored refresh-token material, and stops future Google Calendar synchronization. Historical Luntive appointment records and synchronization mappings may remain as operational or historical records. Previously created Google Calendar events are not automatically deleted solely because the integration is disconnected.
Luntive's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The Google-specific limitations in this section control over any broader description elsewhere in this policy when Google user data is involved.
How information is obtained
Information may be obtained:
- Directly from Customers and Authorized Users.
- Through CSV import or lead-to-client conversion.
- Through calls handled by Retell.
- Through Google Calendar OAuth and APIs.
- Through website import initiated by the Customer.
- Through AI-assisted and automated workflows.
- Through service operation and provider webhooks.
How information is used
The general uses described in this section apply to Luntive information generally. Google user data obtained through Google APIs is governed by the narrower Google API Services and Google User Data section above. Nothing in these general data-use provisions expands Luntive's permitted use of Google user data.
Luntive may use information to:
- Provide and operate the Luntive service.
- Authenticate Accounts and maintain sessions.
- Configure business context and knowledge.
- Manage clients, leads, appointments, calls, and communications.
- Generate drafts, summaries, and workflow outputs.
- Schedule reminders and proactive events.
- Synchronize Google Calendar.
- Send email through Resend.
- Meter usage and credits.
- Provide support and administration.
- Help with security, fraud prevention, troubleshooting, auditing, service reliability, and duplicate prevention.
- Comply with applicable obligations and enforce applicable agreements, subject to the facts and legal review applicable to the situation.
AI-assisted processing
Luntive uses AI-assisted functionality in areas such as the AI Receptionist, Communication Assistant, Appointment Coordinator, Lead Manager, website import, business knowledge generation, drafting, summaries, and generated communications.
Retell supports the voice-agent platform, and inspected Retell agents use a Retell response engine. OpenAI GPT-4.1 was confirmed only as the inspected model used for post-call analysis in a Retell configuration. Luntive is not representing that it has a confirmed direct OpenAI contractual relationship or that every call or transcript follows the same model route.
Google Gemini is used to provide Luntive Assistant responses, generate user-reviewed email drafts, answer staff questions using approved Luntive business records, and organize crawled website content into reviewable business-information imports. Google Calendar-derived API data is not provided to Gemini. Gemini is not described here as powering the live AI Receptionist voice path.
AI output may be incorrect, incomplete, outdated, or unsuitable for a particular situation. Output depends on the information available to the feature. Customers remain responsible for decisions, important communications, and business actions. The AI Disclosure provides additional context.
Luntive does not make a provider-training or no-training guarantee in this policy.
Calls and voice information
Calls handled through Luntive may result in transcripts, summaries, metadata, analysis, raw webhook payloads, and recording URLs when supplied. No local audio files were evidenced. Retell provider retention, recording behavior, recording-link expiration, and historical provider deletion remain unverified.
This policy does not adopt a definitive call-recording consent or notice position. That position remains subject to legal review and the applicable Customer workflow.
Website import
The Customer supplies a website URL and authorizes the website-import workflow. Public pages may be crawled and processed through Gemini, with source URLs and extracted or structured business information used to help create business knowledge for the Customer's Luntive workflows.
Customers remain responsible for having authority to authorize the processing and for reviewing imported content. Luntive does not claim ownership of all imported content, promise perfect extraction, or promise that imported information stays current. The Website Import Authorization provides additional context.
Automated actions and human review
Some Luntive workflows are automated. The AI Receptionist can handle live calls automatically. Lead and appointment workflows may create, match, reschedule, cancel, or update records automatically. Scheduled reminders and proactive-email workflows may also operate automatically.
Communication Assistant behavior is mixed: some drafts may require review while some scheduled workflows may send automatically. Customers should review important communications and remain responsible for the resulting decisions and actions. Luntive does not claim that all AI actions receive human review.
Sharing and service providers
Luntive may share or make information available to service providers that support the Luntive service, subject to applicable configurations and agreements. Current providers include:
- Supabase: authentication, database, and backend infrastructure.
- Retell: voice-agent and telephony services.
- Google Calendar and Google APIs: calendar connection and event synchronization.
- Google Gemini: Luntive Assistant responses, user-reviewed email drafts, staff assistance using approved Luntive business records, and reviewable website-content imports; not Google Calendar-derived API data.
- Stripe: billing and payment processing, including associated billing identifiers and subscription state.
- OpenAI GPT-4.1: a qualified Retell-dependent post-call-analysis relationship based on an inspected configuration; not a confirmed direct Luntive relationship.
- Resend: email delivery and newsletter subscriber management.
- Upstash QStash and Upstash Redis: QStash supports job scheduling and message-delivery orchestration; Redis supports rate limiting and related service-integrity functions.
- Geoapify: address search and geolocation support.
- Cloudflare Turnstile: bot detection and abuse prevention during account signup and related security flows.
- Vercel: hosting, application delivery, and edge/runtime infrastructure.
Data retention
Luntive has not adopted fixed retention periods for most information categories. Most local application data currently remains until the applicable Account or eligible Business workspace deletion workflow. No general automatic time-based retention engine exists.
Retention differs by data category and workflow. Provider-side retention and backup behavior remain partly unverified. Luntive does not promise a specific retention period.
Account and business deletion
Eligible account owners may initiate self-service account deletion through the Luntive application. Identity and account ownership are verified before deletion proceeds. Luntive provides an opportunity to export eligible data before deletion is completed.
Deletion is intended to remove eligible tenant and workspace data for the deleted account. Deletion is irreversible after completion. Certain limited records may be retained where required or permitted, including deletion receipts, legal and compliance records, security and audit records, and billing-related records where applicable. Shared user identities may be preserved where they remain associated with another active workspace.
Luntive does not promise immediate or complete deletion from every third-party provider, from backups, or within a fixed period. Provider-side deletion and backup behavior are not fully verified.
Security
Luntive uses high-level safeguards intended to protect information, including Supabase authentication, tenant-scoped Row Level Security for audited core tenant tables, Google OAuth PKCE, encrypted Google refresh tokens, signed and time-limited support sessions, provider and QStash signature verification, idempotency and duplicate-prevention controls, website-import protections for local or private-network destinations, and deletion safeguards.
No system can be guaranteed completely secure. This policy does not claim perfect security, compliance certification, penetration testing, MFA, global rate limiting, or complete backup protection.
Cookies and browser storage
Current browser storage includes necessary authentication and session storage, a Google OAuth state cookie, a signed support-session cookie, login-lockout local storage, UI preferences, communication drafts, knowledge-synchronization markers, and sidebar session cache.
No advertising cookies, marketing pixels, or third-party behavioral analytics were found in the current review. Cloudflare Turnstile processes browser and device information as part of signup security; this is a security measure, not an advertising or tracking use. This policy does not assign expiration periods that have not been verified.
Marketing website forms and email updates
The marketing website currently includes a demo/contact request flow and a separate optional email-updates signup.
The demo/contact request flow collects fields in the browser and may prepare an email in the visitor's own email application. Based on the current marketing-site review, this flow is not described here as a confirmed server-side lead-storage system operated by Luntive.
Visitors may also voluntarily subscribe to future Luntive email updates by providing an email address and giving explicit consent. This signup is separate from demo/contact requests, separate from Luntive customer communications, and separate from client, lead, or appointment workflows inside the service.
The current newsletter signup uses Resend to store subscriber contact information and topic subscription preferences for future update emails. Future marketing emails should use those subscription preferences so that unsubscribed contacts are not sent those updates.
Newsletter broadcast delivery is not otherwise described here as a live reviewed marketing-email program. This policy does not state a fixed retention period for newsletter subscriber records.
Customer responsibilities
Customers control the information they enter and the workflows they configure. Customers are responsible for authority, accuracy, lawful use, and appropriate permissions for information and content they provide or direct Luntive to process.
Customers should avoid providing unnecessary sensitive information, protect Account credentials, review important AI-assisted outputs, and use appropriate internal policies for their staff and End Client relationships.
Children
Luntive is intended for business use and is not intended for use by children. This policy does not establish a specific age threshold or make a jurisdiction-specific conclusion.
Privacy rights and requests
Privacy rights and request procedures may depend on applicable law and the Customer relationship. End Clients generally have their primary relationship with the Customer firm, so requests relating to Customer-controlled data may need to be directed to the relevant Customer. Luntive may assist Customers as appropriate.
Luntive does not claim to provide a completed automated privacy-rights portal or promise a statutory response period in this policy. For legal, privacy, support, security, or abuse questions, contact support@luntive.com.
International and regional processing
Provider regions and processing locations are not yet fully verified. This policy does not make a specific residency, cross-border transfer, GDPR adequacy, or standard contractual clause claim.
Changes to this policy
Luntive may update this policy as the website, service features, provider relationships, and legal review develop. Future versions will identify their publication status, effective date, and last-updated date. This policy does not promise a fixed advance-notice period.
Contact
For legal, privacy, support, security, or abuse questions, contact support@luntive.com.