1. Introduction
Kulltivate.ai ("Company," "we," "us," or "our"), operated by Drew Kull in Canton, Massachusetts, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website (kulltivate.ai), client portal, and services.
2. Information We Collect
2.1 Information You Provide
- Account information: Name, email, phone number, business name, address
- Business content: Logos, photos, descriptions, and other materials you provide for your website or social media
- Communications: Messages sent through the portal, email, or chatbot
- Payment information: Processed securely by Stripe — we never store credit card numbers
2.2 Information Collected Automatically
- Usage data: Pages visited, features used, time spent on site (via Google Analytics)
- Device information: Browser type, operating system, IP address
- Chatbot conversations: Messages exchanged with our AI chatbot for service improvement
- Cookies: Session cookies for authentication; analytics cookies (Google Analytics)
2.3 Information from Third Parties
- Social media platforms: When you connect your social accounts for our management services
- Stripe: Payment status and subscription information
3. How We Use Your Information
- To provide, maintain, and improve our services
- To build and maintain your website, social media content, and chatbot
- To communicate with you about your services, updates, and support requests
- To process payments and send invoices
- To train and improve our AI systems (using anonymized/aggregated data only)
- To monitor service health and detect issues proactively
- To comply with legal obligations
We do NOT:
- Sell your personal information to third parties
- Use your business data to benefit competing businesses
- Share your data with other clients — your data is isolated at the database level
3A. SMS & Text Messaging
Kulltivate.ai sends operational SMS notifications to business clients who subscribe to our SaaS platform as part of our Kulltivate.ai Client Notifications program. By providing your phone number and opting in, you agree to the following:
What Phone Numbers We Collect
We collect your mobile phone number when you provide it during account setup, subscription purchase, or portal login. Your phone number is stored securely in our database and is associated with your client account.
What Messages We Send
We use SMS for operational purposes only. No marketing or promotional messages are sent. Message types include:
- Portal login verification codes: One-time security codes to verify your identity when signing in to your client portal
- AI chatbot handoff alerts: Notifications when your AI chatbot detects a customer who needs human assistance
- Appointment booking confirmations and reminders: Confirmations for new bookings and reminders before upcoming appointments
How You Opt In
You provide consent to receive SMS messages when you:
Consent is not a condition of purchase. Full SMS consent details are available at kulltivate.ai/sms.
Message Frequency & Costs
You may receive up to 10 messages per month. Message and data rates may apply. Check with your wireless carrier for details.
How to Opt Out
You can stop receiving SMS messages at any time by:
After opting out, you will receive a one-time confirmation message. No further messages will be sent. You can opt back in at any time by texting START or contacting us.
Help
For help with SMS messages, reply HELP to any message or contact help@kulltivate.ai.
Phone Number Sharing
We do not sell, rent, or share your phone number with third parties for marketing purposes. Your phone number is used solely to deliver Kulltivate.ai operational messages as described above. Phone numbers are shared only with our SMS delivery provider (Twilio) for the sole purpose of transmitting messages.
Carrier Disclaimer
Carriers are not liable for delayed or undelivered messages. Message and data rates may apply for any messages sent to or from you.
4. Data Isolation & Security
We use a multi-tenant architecture with row-level security (RLS). This means:
- Your data is stored in the same secure database but is logically isolated by your unique tenant ID
- Database policies enforce that no client can query, view, or access another client's data
- Admin access (Drew and our AI assistant Konsult) can view all data for service delivery purposes
- All data is encrypted in transit (TLS/HTTPS) and at rest
- Our database is hosted on Supabase (AWS infrastructure) with automated backups
5. AI & Automated Processing
We use artificial intelligence to deliver several of our services. Specifically:
- Chatbot (Kulltibot): Processes visitor messages to provide helpful responses about your business. Conversations are stored to improve response quality.
- Social media content: AI generates draft posts based on your brand guidelines. All content requires your approval before publishing.
- Konsult (AI assistant): Our operational AI that manages service delivery, communication, and reporting. Konsult is transparent about being an AI.
AI models are provided by Anthropic (Claude) and OpenAI. Your data sent to these providers is subject to their data processing agreements, which prohibit using your data to train their models.
6. Third-Party Services
We use the following third-party services to operate:
| Service | Purpose | Data Shared |
|---|
| Supabase | Database & auth | All service data |
| Vercel | Website hosting | Website content, logs |
| Stripe | Payments | Name, email, payment info |
| Gmail API | Email delivery | Email addresses, content |
| Anthropic/OpenAI | AI processing | Message content (not stored) |
| Buffer | Social publishing | Social post content |
| Google Analytics | Website analytics | Anonymous usage data |
7. Data Retention
- Active clients: Data retained for the duration of service
- After cancellation: Data retained for 90 days, then deleted (unless legally required to keep longer)
- Chatbot conversations: Retained for 12 months for service improvement, then anonymized
- Analytics data: Retained per Google Analytics default (26 months)
- Invoices/payment records: Retained for 7 years per tax requirements
8. Your Rights
You have the right to:
- Access: Request a copy of all data we hold about you
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your data (subject to legal retention requirements)
- Export: Receive your data in a portable format (JSON or CSV)
- Opt-out: Opt out of marketing communications at any time
- Restrict AI processing: Request that your data not be used for AI training
To exercise any of these rights, contact us at drew@kulltivate.ai. We will respond within 30 days.
9. Cookies
We use the following cookies:
- Essential cookies: Authentication session tokens (required for portal access)
- Analytics cookies: Google Analytics (can be opted out via browser settings or Google's opt-out tool)
We do not use advertising or tracking cookies.
10. Children's Privacy
Our services are designed for businesses and are not directed to individuals under 18. We do not knowingly collect information from children.
11. Massachusetts Privacy Rights
Under Massachusetts law (201 CMR 17.00), we implement reasonable security measures to protect personal information of Massachusetts residents. This includes encryption, access controls, and employee training.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email at least 30 days before taking effect. The "Last updated" date at the top reflects the most recent revision.
13. Contact
For privacy questions or data requests:
- Email: drew@kulltivate.ai
- Address: Canton, MA 02021
- Website: kulltivate.ai