Privacy Policy

Last updated: September 6, 2026

Limited Use Compliance Statement

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

Sonovi uses Google Workspace API data only to provide and operate appointment booking. We do not use this data for advertising, credit or lending decisions, or any purpose other than providing or improving the user-facing booking feature. We do not sell Google user data. We do not transfer Google user data to third parties except as needed to operate that booking feature (for example, secure cloud hosting, or returning a live booking result to the voice feature so that call can be completed) or if required by law.

Google User Data Access

When you connect Google Calendar, Sonovi accesses only the Google user data required to book appointments. We access the following raw data. We do not create aggregated or anonymized datasets from Google user data.

  • Google Account email and public profile:

    We read your primary Google Account email address and basic public profile (name and profile picture) only to identify the connected account, show which Google account is linked, and complete OAuth authentication. This data is not used for advertising or unrelated personalization.

  • Calendar free/busy availability:

    We read busy/free time windows so we can show open appointment slots and avoid double-booking. We do not use this scope to read event titles, descriptions, attendees, or other event details.

  • Calendar events:

    We create, update, or cancel appointment events that were booked through Sonovi. We may list events in a requested time window only to confirm whether that slot is free. We do not read unrelated calendars for marketing, do not share calendars, and do not delete calendars.

Information We Collect from Users

We collect the following information to operate Sonovi accounts, phone intake, and appointment booking:

  • Names
  • Email addresses
  • Phone numbers
  • Call recordings and transcripts
  • Intake and case-related information
  • Website activity
  • IP addresses

How We Collect Information

We collect information through the following methods:

  • Contact forms on our website
  • Phone calls
  • Integrations you connect (including Google Calendar)
  • Cookies (as detailed below)
  • Website analytics on the public marketing site only (not Google Workspace API data)

Why We Collect Information

We collect your information for the following purposes:

  • To create and manage your account
  • To provide AI phone intake, call handling, and scheduling services for law firms

Non-Google product data (for example, account details you type into Sonovi) may be used to operate and maintain those features. Google Workspace API data is never used to improve unrelated products, train models, personalize marketing, or run advertising.

Use of Google Workspace APIs

Data obtained through Google Workspace APIs is used only to check calendar availability and to create, update, or cancel appointment events booked in Sonovi. That is the only user-facing feature that uses this data.

Sonovi does not use raw, aggregated, anonymized, or derived Google Workspace API data to develop, improve, or train generalized AI or ML models. We do not transfer this data to third-party AI services for model training.

Google OAuth tokens and raw Calendar payloads stay on Sonovi servers. Voice or language models used by Sonovi do not receive raw Google Calendar contents. For a live phone or web booking, the voice feature may receive only the result needed to finish that call (for example, that a requested time is available or that the appointment was booked). That result is used only to complete the user-facing booking and is not used to train or improve models.

Data Sharing, Transfer, and Disclosure

We do not sell Google user data or any other personal data. We do not share Google user data with advertisers, data brokers, analytics providers, or marketing platforms.

  • Google user data:

    OAuth tokens and raw Google Calendar payloads stay on Sonovi servers to operate appointment booking. They are not sent to advertisers, data brokers, analytics providers, or marketing platforms. For a live booking call, the voice feature may receive only the booking result (available or booked) so that call can be completed. That result is not used for advertising or model training. Google user data may also be stored on our secure cloud hosting provider solely to run the booking feature. We disclose this data only if legally required.

  • Other Sonovi data (not Google Workspace API data):

    Account, call, and website data that you provide in Sonovi may be processed by service providers we use to deliver the product, such as cloud hosting, telephony, and email delivery. Those providers are not given Google Workspace API data.

  • Legal Requirements:

    We may disclose personal data if required by law or to comply with legal obligations.

How and Where We Store Data

We store user data on secure, encrypted servers managed by trusted third-party service providers. These providers follow industry-standard security practices to keep your information safe. Generally, we do not transfer or store data outside of Canada and the USA.

Data Protection Mechanisms for Sensitive Data

We take the following measures to protect your personal data:

  • Encryption:

    All data is encrypted both in transit (using HTTPS) and at rest to prevent unauthorized access.

  • Access Controls:

    Only authorized personnel with a legitimate need can access personal data.

  • Regular Security Audits:

    We conduct periodic security audits and vulnerability assessments to maintain data safety.

Data Retention and Deletion

We retain personal data only for as long as necessary to provide our services or comply with legal requirements. Specifically, we keep data as long as the account is active and until account deletion. Call recordings are kept under the same "active until deletion" rule as other data.

  • User-Requested Deletion:

    Upon receiving a deletion request, we will delete your data from our systems within 30 days.

  • Google User Data:

    OAuth tokens and Google Workspace API data are kept only while the Google Calendar connection is active and needed to book or manage appointments. When you disconnect Google Calendar or request deletion, we delete stored Google tokens and related Google user data from our systems within 30 days, except where a shorter legal hold is required.

User Rights

Users can access, update, or delete their data. This includes access to their customer's data and their own data, as well as call data, by logging into their account.

Cookies and Tracking Tools

We use cookies for login and authentication. The public marketing website may use Google Analytics and Facebook Pixel to measure site traffic and ads. Those website cookies do not receive Google Workspace API data, Google Calendar contents, OAuth tokens, or any other Google user data obtained through Google sign-in or Calendar access. Google user data is never used for advertising or remarketing.

Children's Privacy

We do not target or knowingly collect information from children under 13 years of age.

Which Privacy Laws We Follow

We comply with applicable privacy laws in Canada and the USA.

Contact Us

If you have any questions or concerns about our privacy practices, please contact us at support@sonovi.co.

Sonovi AI

The intelligent phone system that answers, qualifies, routes, and organizes every new legal inquiry.

TwitterInstagramLinkedInYouTube

Company

Affiliates

© 2026 Sonovi AI. All rights reserved