Privacy Policy
This Privacy Policy explains how Pipworks, Inc. ("Pipworks", "we", "us") collects, uses, and shares information in connection with the Pipbit voice-first platform, including the Pipbit developer website and portal, the Pipbit APIs and SDKs, and the cellular-connected Pipbit hardware device (collectively, the "Service"). Pipworks is the controller of personal information collected through the Service, except where a developer operates an independent agent as described below.
Our address is 98 San Jacinto Blvd, Suite 400, Austin, TX 78701, United States. You can reach us at privacy@pipworks.ai.
1. Who this policy applies to
This policy covers two audiences:
- Developers who register for a developer account to build agents on the Pipbit platform.
- End users who interact with a Pipbit Device by voice and whose speech is routed through our platform to one or more developer-operated agents ("Agents").
When an end user speaks to an Agent built by a third-party developer, that developer is an independent controller (or business) of the data their Agent receives and generates. That developer's own privacy policy governs their handling of the end user's data.
2. Information we collect
2.1 Information developers provide
- Account information: name, email address, password hash, and organization name.
- Agent configuration: agent name, description, webhook URL, voice identity settings, skills/tags, and related metadata you submit to the developer portal.
- Billing information (if and when paid plans are offered): handled by our payment processor; we do not store full payment card numbers.
- Communications: support emails and other correspondence you send us.
2.2 Information from Pipbit Devices and end users
- Voice audio: audio captured by the device's microphone when the user interacts with the device, transmitted over cellular and processed by our speech-to-text provider.
- Transcripts and conversation context: text transcripts of user utterances and of synthesized responses, together with routing metadata needed to deliver a reply.
- Device telemetry: device identifier, firmware version, cellular connectivity status, battery level, diagnostic logs, and similar operational signals.
- Per-user agent preferences: agents the user has connected with, nicknames the user has assigned to agents, and recent conversation state needed for continuity.
2.3 Information collected automatically on the website
- Log data: IP address, user-agent, pages requested, timestamps, and referrer. We use short-lived HTTP-only session cookies to authenticate signed-in developers; we do not use third-party advertising cookies.
3. How we use information
We use the information described above to:
- Provide, operate, and maintain the Service, including routing end-user speech to the correct developer Agent and returning synthesized responses.
- Authenticate developers, secure the platform, and detect and prevent abuse, fraud, and unauthorized access.
- Troubleshoot issues, monitor performance, and improve reliability, speech recognition quality, and voice synthesis.
- Communicate with developers about their account, the Service, and security or policy updates.
- Comply with legal obligations and enforce our Terms of Service.
We do not sell personal information, and we do not use end-user voice audio or transcripts to train third-party advertising models.
4. How we share information
- With developer Agents you choose to talk to. When an end user invokes an Agent, Pipworks delivers the user's utterance (and limited routing context) to that Agent's webhook. What the developer does with that data is governed by the developer's own terms and privacy policy.
- With service providers (sub-processors). We rely on third parties to operate the Service, including cellular connectivity and messaging providers (e.g., Twilio), cloud hosting, speech-to-text and text-to-speech providers, large-language-model providers, error monitoring, and email delivery. These providers act on our behalf under contractual confidentiality and security obligations.
- For legal reasons. We may disclose information to comply with applicable law, lawful requests from public authorities, court orders, or to protect the rights, property, or safety of Pipworks, our users, or others.
- In a business transaction. In connection with a merger, acquisition, financing, or sale of assets, information may be transferred subject to customary confidentiality protections.
5. Voice data handling
Voice-first products raise distinct expectations, so we want to be specific:
- The device transmits audio to Pipworks only when a conversation is active. The device indicates activity to the user.
- Audio is converted to text by a speech-to-text provider. Raw audio may be retained for a short, bounded period to support quality assurance and debugging, and is deleted under our retention schedule.
- Transcripts and conversation state are retained for as long as needed to provide conversational continuity and to satisfy operational, security, and legal requirements.
- End users can request deletion of their conversation history as described in Section 7.
6. Data retention
We retain personal information only for as long as necessary to provide the Service, to comply with legal obligations, to resolve disputes, and to enforce our agreements. When information is no longer needed, we delete or de-identify it. Specific retention windows for audio, transcripts, and logs are set internally and may change as the Service evolves; you can request current details by contacting us.
7. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. Developers can update most account information directly in the developer portal.
To exercise rights or ask a question about this policy, email privacy@pipworks.ai. We will verify your request before acting on it. If an end user contacts us about data held by a third-party developer's Agent, we will route the request to that developer, who is the controller of that data.
California, Virginia, Colorado, Texas, and similar state laws provide additional rights to residents of those states, including the right not to receive discriminatory treatment for exercising those rights. Because we do not sell personal information and do not engage in "cross-context behavioral advertising," there is nothing to opt out of in that regard.
8. Security
We use administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit, least-privilege access controls, and secure credential handling. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. If you believe your account has been compromised, contact us immediately.
9. International users
The Service is operated from the United States. If you access the Service from outside the United States, you understand that information will be transferred to, stored in, and processed in the United States and other countries where our service providers operate. Where required by law, we use appropriate safeguards for international data transfers.
10. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us personal information, please contact us and we will take appropriate steps to delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time. If we make a material change, we will provide reasonable notice, for example by posting the updated policy on the developer portal and updating the "Last updated" date. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
12. Contact us
Pipworks, Inc.Attn: Privacy
98 San Jacinto Blvd, Suite 400
Austin, TX 78701, United States
privacy@pipworks.ai