Privacy Policy
Effective September 14, 2026
AdvisorPilot provides workflow software for investment advisers and their firms. This policy explains what information we collect, how we use it, who we share it with, and the choices you have. It covers our marketing site at www.advisorpilot.ai and the AdvisorPilot application at app.advisorpilot.ai.
Who controls the information
Advisors and their firms decide what client information to put into AdvisorPilot. For that information, the advisory firm is the controller and AdvisorPilot acts as a service provider processing it on the firm's instructions. For account registration, billing, and our marketing site, AdvisorPilot is the controller.
Information we collect
- Account information. Name, work email address, firm name, and authentication identifiers. Passwords are handled by Google Firebase Authentication and are never stored by us in readable form.
- Client information you provide. Contact details, account statements and other documents you upload, holdings, meeting notes, and material you generate in the product such as reports and client emails.
- Google or Microsoft data you authorize. Described in detail in the next two sections.
- Usage and device information. Log data, IP address, browser and device type, pages viewed, and feature usage, used to operate and secure the service.
- Billing information. Processed by our payment processor. We do not store full payment card numbers.
Google user data we access
Connecting a Google account is optional and is never required to sign in or use AdvisorPilot. If you choose to connect one, we request only these scopes:
gmail.send— permission to send a message from your mailbox. We use it only to deliver emails that you compose or approve in AdvisorPilot, such as a client portfolio snapshot or a scheduled client update, so the message arrives from your own address. This scope does not grant the ability to read, search, download, modify, or delete any message in your mailbox, and we do not do those things.calendar.readonly— read-only access to your calendar events. We use it to show your upcoming client meetings inside the product and to associate a meeting with the right client record. We do not create, modify, or delete calendar events with this scope.
We request these narrow scopes deliberately. Broader Gmail scopes would let us read or modify mail, and AdvisorPilot has no feature that requires it.
We store the OAuth refresh token that lets us send on your behalf without asking you to reauthorize every session. We store calendar event details needed to display your schedule. We do not store the contents of your mailbox. You can disconnect at any time from Settings in the product, or revoke our access directly from your Google Account permissions page. Revoking access stops sending and calendar features immediately.
Limited Use of Google user data
AdvisorPilot's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not use Google user data to serve advertising, we do not sell it, we do not transfer it except as necessary to provide or improve the features you requested, to comply with applicable law, or as part of a merger or acquisition, and we do not allow humans to read it except with your explicit consent for a support request you initiate, where required by law, or for internal security operations and abuse investigation.
We do not use Google user data to develop, train, or improve generalized artificial-intelligence or machine-learning models.
Microsoft data we access
If you connect a Microsoft account, we request Mail.Send and Calendars.Read, which serve the same two purposes described above and carry the same limits. This connection is also optional.
How we use information
- To provide, maintain, and support the service.
- To read uploaded statements and produce drafts, analyses, and client materials you request.
- To send messages you compose or approve, from the mailbox you connected.
- To authenticate you and secure accounts against abuse.
- To bill for the service and to communicate about your account.
- To meet legal, regulatory, and recordkeeping obligations.
We do not sell personal information, and we do not use client information you upload to train generalized AI models.
AI processing and subprocessors
AdvisorPilot uses third-party AI providers to read documents and generate drafts. Depending on your firm's configuration, content you submit for those features may be transmitted to OpenAI, Google, or xAI for processing and returned to the product. We contract for these services on terms that prohibit using your content to train the providers' general models. We also rely on Google Cloud for hosting, databases, and file storage. A current list of subprocessors is available on request.
Storage, security, and location
Data is hosted on Google Cloud infrastructure in the United States. We encrypt data in transit and at rest, restrict internal access to personnel who need it, scope every record to the owning advisor, and log administrative activity. No system is perfectly secure, and we cannot guarantee absolute security.
Retention and deletion
We keep information for as long as your account is active and thereafter as needed to comply with legal, regulatory, and recordkeeping obligations that apply to advisory firms, to resolve disputes, and to enforce our agreements. You may request export or deletion of your firm's data by writing to us at the address below. Disconnecting a mailbox deletes the stored OAuth tokens for that connection.
Sharing
We share information with the subprocessors described above, with professional advisors and authorities where required by law or legal process, and with an acquirer in connection with a merger, acquisition, or sale of assets. We do not sell personal information or share it for cross-context behavioral advertising.
Your choices and rights
You can update your account information in the product, disconnect a mailbox or calendar at any time, and opt out of marketing email. Depending on where you live, you may have rights to access, correct, delete, or port your personal information, or to appeal a decision we make about such a request. Because advisory firms control their client records, we will route requests from an advisor's client to that firm. Contact us using the details below and we will respond as required by applicable law.
Children
AdvisorPilot is a professional tool and is not directed to children under 13, and we do not knowingly collect their personal information.
Changes
We will update this policy as the product changes and will revise the effective date above. Material changes will be communicated in the product or by email.
Contact
Questions, requests, or complaints about this policy can be sent to hello@advisorpilot.ai.
See also our Terms of Service.
