polite.aiDocs
REFERENCE

Security, privacy & your data

What polite.ai stores about calls and the organisation, how long it is kept, and how it all stays under the organisation's control.

Everything the agents record, hear and learn belongs to the organisation. It can be read, exported and deleted — and nothing arrives in it without consent.

What is stored

For each call: a recording (where recording is enabled — optional, per agent), stored encrypted; a transcript; and a data feed of what the agent actually did. Recording can use the organisation's own encryption key, set in the agent editor's Operations section — with a customer-supplied key the platform cannot decrypt the recordings itself. Bookings made by agents live in polite.ai's own booking record. Knowledge bases hold the text extracted from crawled pages and uploaded PDFs. Billing keeps a ledger of every wallet movement.

Stored credentials — API keys on an agent, a private site's crawl login — are write-only: saved encrypted, used where they were pointed, and never readable back out of the dashboard.

How long it is kept

Call history follows the plan: 90 days on Starter, 6 months on Pro, 1 year on Scale — see Plans & limits. Knowledge content stays until it is deleted: removing a knowledge base purges its pages, documents and stored files permanently.

A site is only crawled after someone authorised ticks I'm authorised to have this site crawled — at signup for the organisation's own site, or on Knowledge → Add knowledge afterwards. Public crawls respect robots.txt. Deleting the knowledge base revokes consent — the crawled content is purged and the site isn't crawled again. An org-wide emergency toggle on the Knowledge page instantly stops every agent using knowledge — see Knowledge bases.

Connected Google and Microsoft accounts

An admin connects the account once, at organisation level. Agents never receive the credential — they get narrow, admin-approved tools, and the AI never browses a calendar or mailbox. A booking agent sees only the offerable slots the booking policy computes, a recognised caller's name, and its own booking confirmations. Contacts are only ever created, never edited or deleted.

Two further protections: connected-account tools only run on approved AI model providers with clear no-training commitments, and Integrations → Disconnect deletes the stored tokens. polite.ai's use of raw or derived user data received from Workspace APIs adheres to the Google User Data Policy, including the Limited Use requirements.

Getting data out

Agent definitions, prompts, call logs, transcripts and recordings belong to the organisation and export from the dashboard and the API:

  • Calls → Export CSV — call history for any range; transcripts and recordings are read per-call in the call drawer.
  • Usage → Export — raw metered usage as CSV (Usage analytics).
  • Download config on any team or agent — the full configuration as JSON (Open source & no lock-in).

Questions or requests

For anything this page doesn't answer — deletion requests, closing a workspace, or a security concern — email support@aplisay.com.

Last updated 2026-08-18