Privacy Policy
Last updated: August 25, 2026
Who this policy covers
TuchPilot is operated by Nehemiah Armstrong ("TuchPilot," "we," "us"). TuchPilot is not currently operated through a separate registered legal entity. TuchPilot provides automation software ("Pilots") that small businesses connect to their own phone, payment, and social media accounts. This policy describes what data TuchPilot processes, why, and how it's handled — for both the business customers who sign up for TuchPilot and the individuals (their customers, or Facebook/Instagram users) whose data passes through a connected Pilot on a customer's behalf.
Business and account data we process
When you create a TuchPilot account, we process your name, email address, password (stored hashed, never in plain text), business name, industry, and timezone. If you invite teammates, we process their email address and role within your organization. We also keep a record of who did what within your account (an audit log) for security and support purposes.
Documents you upload
Some Pilots (like Quote & Reservations) ask you to upload a document — a price list as a PDF, image, or spreadsheet. We store the original file in a private cloud storage bucket that only your account and TuchPilot's backend can access; it is never publicly reachable. We use AI to read structured data (item names, prices, units) out of the document, and we keep both the AI's raw output and your confirmed corrections, so there's always a record of what was extracted versus what you approved. Nothing extracted from a document is used anywhere in the product until you explicitly confirm it.
Twilio (phone and text messages)
If you connect a Twilio phone number, we process call metadata (who called, when, whether it was answered) and the content of the automated text messages TuchPilot sends on your behalf, along with any replies your customers send back. This is the data the Missed-Call Text-Back Pilot needs to function. We do not record or process call audio.
If a recipient replies STOP to one of these texts, we record that phone number on a suppression list for the sending business and stop sending it further automated texts immediately; replying HELP returns a short informational message. We keep suppression-list entries so opt-outs are honored reliably going forward (see "Data retention" below).
SMS / text messaging program (Missed-Call Text-Back)
This section describes TuchPilot's current text-messaging use specifically: a low-volume, non-marketing customer-care program. When a business connects a Twilio phone number to the Missed-Call Text-Back Pilot, a caller to that number first hears a complete automated disclosure in full, and only afterward is asked to press 1 for permission to receive a text if the call goes unanswered; a key pressed during the first, complete disclosure is not collected and cannot count as a response. The call is forwarded to the business either way. Only if that caller presses 1 to agree, and the forwarded call then goes unanswered, does TuchPilot send that caller one automated text on the business's behalf, continuing the conversation only if the caller replies. Calling the number, by itself, is never treated as consent to receive a text — see "Consent" in our Terms of Service for exactly how consent is captured. TuchPilot does not use this number, or any phone number collected this way, to send marketing or promotional messages, and does not add numbers to any list used for a different business or a different purpose. We do not record or store the audio of the call itself — only the caller's phone number, whether they pressed 1, and which version of the disclosure they heard (see "Twilio (phone and text messages)" above for related call metadata).
- Your mobile information — the phone number and message content described above — is not shared with third parties or affiliates for marketing or promotional purposes.
- Text opt-in status and consent records are not shared with anyone except the service providers necessary to deliver the message itself (Twilio, as the carrier gateway — see "Service providers we use" below). We do not sell this data.
- Message frequency varies based on your own activity (how many times you call or text the business, and how the conversation goes) — there is no fixed number of messages per period.
- Message and data rates may apply, charged by your mobile carrier, not by TuchPilot.
- Reply STOP at any time to stop receiving automated texts from that business number; reply HELP for help. See the "Twilio (phone and text messages)" section above for exactly what happens when you do.
Written with reference to Twilio's A2P 10DLC messaging-policy documentation (twilio.com/docs/messaging/compliance) and the CTIA Messaging Principles and Best Practices (ctia.org). Describing our practice this way is not a legal guarantee of compliance with every applicable law or carrier requirement.
Square (payments)
If you connect a Square account, we store an encrypted access token so TuchPilot can create Square-hosted payment links on your behalf, along with the resulting payment's status, amount, and currency. TuchPilot never receives, processes, or stores raw card numbers or other card details — Square's own hosted checkout page is the only place a customer ever enters payment details, and TuchPilot only ever sees Square's confirmation of the result.
Meta (Facebook and Instagram)
If you connect a Facebook Page (and its linked Instagram Professional account) to the Social Media Pilot, we store an encrypted access token, the Page/Instagram account identifiers, and the content you upload or approve for posting (images, captions, and scheduling information). We use this only to draft, schedule, and publish posts you've reviewed — never to post without your review unless you've explicitly turned on Auto-Publish mode for that Pilot. If a person who authorized TuchPilot through Facebook Login requests deletion of their data, we honor that request — see "Your right to deletion" below.
AI processing
TuchPilot uses OpenAI's API, under a TuchPilot-owned API key (you never need your own), to read uploaded documents, draft recovery text messages, and generate social media captions. Content sent to OpenAI for these purposes is processed under OpenAI's standard API terms, which — as of this policy's publication — do not use API content to train OpenAI's models. AI output is always treated as a draft: pricing data requires your explicit confirmation before it's used, and social media posts require your review unless you've turned on Auto-Publish.
Service providers we use
TuchPilot is built on top of a small number of infrastructure and API providers, each of whom processes a slice of the data described above solely to provide their service to us:
- Supabase — database, authentication, and private file storage
- Railway — application hosting
- Twilio — phone calls and SMS
- OpenAI — AI text and document processing
- Square — payment processing
- Meta (Facebook/Instagram) — social media publishing
- Stripe — TuchPilot's own subscription billing, for organizations where it's enabled
Stripe billing isn't yet enabled for every organization; where it isn't, we arrange payment directly with you and no billing data is sent to Stripe.
We do not sell your personal data to anyone, and we don't share it with third parties for their own marketing purposes.
Data retention
We retain account and Pilot data for as long as your account is active, plus a limited period afterward to support account recovery and to meet legitimate legal, security, and financial record-keeping obligations (for example, audit logs and payment records are retained longer than other data even after an account closes, since deleting them immediately could itself create a compliance problem). When you delete a specific document, quote, or draft, we remove it from active use immediately; some records may persist in backups for a limited time before being purged.
Records of whether a caller pressed 1 to consent to a text (see "SMS / text messaging program" above) are automatically deleted no more than two years after they're created, by an automated process that runs continuously — not only when someone remembers to trigger it. We keep them for that period, rather than deleting them immediately, so a consent decision can still be checked if it's later questioned, before they're removed. Two years is TuchPilot's own chosen retention period for this data, set as an engineering policy — it is not a legal opinion or guarantee that this period satisfies every law that could apply to a given business or caller, and has not been reviewed by an attorney.
Your right to deletion
You can request deletion of your account and its data at any time by contacting us (see "Contact" below). If you authorized TuchPilot through Facebook Login and want your data deleted, you can do this directly from Facebook's "Apps and Websites" settings, which sends TuchPilot an automated deletion request — you can check the status of that request at the URL Facebook shows you, or at /data-deletion-status/[confirmation code] on this site. As noted above, some records (e.g. payment and audit records) may be retained longer where TuchPilot has a legal or security obligation to do so, even after a deletion request.
Contact
TuchPilot is currently operated as an early-stage service by Nehemiah Armstrong, without a separate registered legal entity. For any privacy question, data access request, or deletion request, contact:
Changes to this policy
If this policy changes in a way that materially affects how your data is handled, we'll update the "Last updated" date above and, where required, notify account owners directly.