Privacy Policy

Last updated: July 16, 2026

This Privacy Policy explains how Edward Karame, a sole proprietor carrying on business as “NeverLose AI” (“NeverLose AI,” “we,” “us,” “our”), located in British Columbia, Canada, collects, uses, discloses, and protects personal information in connection with the NeverLose AI service (the “Service”). We aim to handle personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and British Columbia's Personal Information Protection Act (PIPA). By using the Service, you agree to this Policy.

1. Scope & our role

We provide the Service to businesses (each a “Customer”). A Customer uses the Service to handle calls and bookings with that Customer's own callers and customers (“End Users”). For personal information about End Users, the Customer is responsible for that information and for obtaining any consents required by law (including for call recording and messaging). We process End-User information on the Customer's behalf and at the Customer's direction to provide the Service. If you are an End User, please direct privacy requests to the business you contacted.

2. Information we collect

  • Account information: name, email, phone number, business details, and login credentials.
  • Business content: information a Customer provides to configure the Service (services, prices, hours, policies, staff, greetings, etc.).
  • End-User information (processed on a Customer's behalf): caller phone numbers and names, appointment details, message contents, and call audio and/or transcripts.
  • Payment information: processed by our payment provider (Stripe). We do not store full payment card numbers.
  • Usage & technical data: log data, device/browser information, timestamps, and call metadata (such as time and duration).

3. How we use information

We use personal information to: operate, provide, maintain, and improve the Service; answer calls, share business information, and book and manage appointments; send SMS and notifications; process billing and usage charges; provide support; ensure security and prevent fraud or abuse; and comply with legal obligations.

4. Consent & legal basis

We rely on consent and on the information being necessary to provide the Service requested. Customers are responsible for obtaining any consent required from their End Users (for example, consent to record calls or to receive text messages) under applicable laws such as CASL and, where applicable, the U.S. TCPA.

5. How we share information

We do not sell personal information. We share it only:

  • With service providers that help us operate the Service — including Twilio (telephony), Retell (voice AI), Stripe (payments), calendar providers, and cloud hosting — who are permitted to use it only to provide services to us.
  • To comply with law, legal process, or to protect rights, safety, and the integrity of the Service.
  • In connection with a business transfer (e.g., merger, acquisition, or sale of assets), subject to this Policy.

6. Google Calendar data & Google API Limited Use

When you choose to connect a Google Calendar to NeverLose AI, you authorize us through Google OAuth to access that calendar. We request only the scopes needed to provide the Service: permission to view your calendar events (so the agent can see when staff are busy) and to create, edit, and delete calendar events (so the agent can book, reschedule, and cancel the appointments it makes for you).

We use Google Calendar data solely to: (a) read existing events so the agent books around them and avoids double-booking, and (b) add, change, and remove the appointments that the Service books on your behalf. We store a secure Google authorization token so the Service can continue to read and write your calendar to provide these features; we do not retain a copy of your calendar contents beyond what is needed to operate the Service.

NeverLose AI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google Calendar data for advertising; we do not sell it; we do not use it to train generalized AI/ML models; and we do not transfer it to others except as needed to provide the Service to you, to comply with applicable law, or in connection with a merger or acquisition.

You can disconnect a calendar at any timeinside the app, which immediately stops all further access, or revoke NeverLose AI's access directly from your Google Account at myaccount.google.com/permissions. When you disconnect, we delete the stored Google authorization token. Appointments the Service already added to your calendar remain there unless you remove them.

7. Cookies & analytics

Our app and website use cookies and similar technologies (including browser local storage) to keep you signed in, remember your preferences, operate the Service, and understand how it is used. You can control or clear cookies through your browser settings, though some features may not work properly without them. We may use privacy-respecting analytics to measure and improve performance and reliability.

8. How we improve the Service

We may use your account and call data (de-identified or aggregated where practical) to improve how the agent communicates and to improve the experience for the people who call your business, and to operate, secure, and develop the Service. We do not sell your data, and we do not share your callers' personal information with third parties for their own purposes. Our voice-AI and other providers process call data only to provide the Service to us, subject to their own terms.

9. International processing

Some of our service providers may store or process information in the United States or other countries. By using the Service, you acknowledge that personal information may be processed outside Canada and may be subject to the laws of those jurisdictions.

10. Retention

We retain personal information for as long as needed to provide the Service and for legitimate business and legal purposes, after which we delete or anonymize it. Customers may request deletion of their account information as described below.

11. Security

We use commercially reasonable administrative, technical, and physical safeguards to protect personal information. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security (see our Terms of Service).

12. Your rights

Subject to applicable law, you may request to access or correct your personal information, or request its deletion, by contacting us. We may need to verify your identity and may retain certain information where required by law. End Users should contact the business they interacted with regarding that business's records.

13. U.S. state privacy rights (including California)

If you are a resident of California or another U.S. state with applicable privacy laws, you may have additional rights, including the right to know what personal information we collect and how it is used, the right to request access or deletion, and the right to opt out of the “sale” or “sharing” of personal information. We do not sell personal information. To exercise any of these rights, contact us at neverloseai@gmail.com. We will not discriminate against you for exercising your rights.

14. Data Processing Agreement

Business customers who require a Data Processing Agreement (DPA) to meet their own compliance obligations may request one by contacting us at neverloseai@gmail.com.

15. Children

The Service is intended for businesses and is not directed to children. We do not knowingly collect personal information from children.

16. Changes to this Policy

We may update this Policy from time to time. The “Last updated” date will change, and continued use of the Service after an update constitutes acceptance.

17. Contact

Questions or privacy requests: neverloseai@gmail.com.

© 2026 NeverLose AI — Edward Karame, British Columbia, Canada.