Privacy policy
Last updated 29 August 2026
This is an English translation. The Portuguese version is at goapexi.com/privacidade. Both say the same thing; if they ever disagree, the Portuguese version is the one that binds us in Portugal.
Who is responsible
ED FLAVIO JOSE DE SOUSA, tax number 310419395, registered at Rua Doutor José Antonio Peixoto Pereira Machado, 339 - Apto.2º Direito · 4750-309 Barcelos · Portugal, trading as GoApexi.
For any question about personal data, including exercising the rights described below: ola@goapexi.com.
This website
This site uses no cookies, has no analytics, and tracks nobody. There are no forms on this page: anyone who wants to talk to us sends an email, and in that case what we know about you is what you wrote to us.
Like any server, the service hosting this site keeps technical request logs (IP address, date, page requested) in order to operate and to resist abuse. Those logs are not used for profiling and are not combined with anything else.
When we work for a business
GoApexi is used by local businesses to respond to the people who contact them. In those cases, the party who decides what the data is for is the business that hired us — we process the data on their behalf, and solely to provide them with the service.
We collect what the person themselves writes in the conversation with the assistant:
- name and phone number;
- what they are looking for — service, timing, and the answers they gave;
- the exact wording of the consent they accepted, and the date and time they did so;
- the address of the page where the conversation started.
We never ask for health data, credit cards or identity documents.
What the business records on your file
Beyond what the person writes themselves, the business may record what it needs in order to serve them better — notes, preferences, and their birthday.
The day and month are used to wish them a happy birthday. The year is optional, is almost never filled in, and has a single purpose: to let automated messages be worded differently depending on age bracket — a suggestion for someone in their twenties is not the same as one for someone in their sixties.
- The year is not used for birthday wishes — people who did not give it receive them all the same.
- It is not used to set prices, nor to exclude anyone from a service.
- It is not shared with anyone outside the business that recorded it.
- You can ask for it to be deleted without deleting the rest of your file.
If you would rather not give it, say so to the business — you lose nothing by it other than messages written to fit you.
Two consents, and they are different
Agreeing that the business may answer your enquiry is not the same as agreeing to receive promotions. They are separate questions, stored separately, and either can be withdrawn without the other.
Only the yes is stored. Anyone who answers no, or does not answer, leaves no record of refusal — there is no list of people who said no.
Automated assistants
When you talk to a GoApexi assistant, it tells you so in its first message. That is not configurable, cannot be switched off, and does not depend on who hired us. It is a legal obligation and it is our own decision.
Google Calendar
A business using GoApexi may connect the Google Calendar it already uses, so that appointments show up on its phone and so that whatever it books by hand stops being offered to people booking online. The business always connects it themselves, with a button, and can disconnect whenever they want.
We request two permissions, and only these two:
- See and edit events (
calendar.events) — to write the appointments booked through GoApexi into their calendar, and to update or remove them when an appointment is moved or cancelled. We only touch events we created ourselves. - Read availability (
calendar.readonly) — to know which hours are already taken.
From their calendar we read only when they are busy, never with what. We use Google's FreeBusy API, which returns start and end intervals with no title, no description and no attendees. The titles of their private appointments never reach our servers.
On the Google side we store this, and only this:
- the email address of the connected Google account, so we can show them which one it is;
- the authorization they granted, so we do not have to ask for it every day;
- the busy intervals (start and end timestamps), so the engine does not offer hours they cannot take.
This data is not sold, is not shared with third parties, is not used for advertising and is not used to train artificial intelligence models. It exists only to make the calendar work.
When they disconnect the integration in the dashboard, the authorization and the copy of the busy intervals are deleted immediately. They can also revoke our access directly from the Google Account permissions page — and GoApexi keeps working, simply without the calendar mirror.
GoApexi's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Artificial intelligence — what we use, and what never goes into it
There are three places where GoApexi uses artificial intelligence models:
- writing text — captions for social posts, articles and page copy, based on what the business itself wrote about itself;
- generating background images for those posts;
- answering written questions from people talking to the assistant.
There are two providers, and these are they:
- Cloudflare Workers AI — open-weights models running on Cloudflare's own infrastructure. Cloudflare states that it does not use customer content to train models.
- KIE.ai — a single gateway that routes the request to the third-party models we use: Claude, by Anthropic, for text, and the nano-banana models for images.
No data received from Google APIs enters any of these services — not raw, not aggregated, not anonymized, not derived. And that is not a promise: it is how the system is built.
- The Google Calendar integration is handled exclusively by deterministic code. The busy intervals we read feed an availability engine that adds and subtracts hours — never a model request.
- The assistant receives a closed list: the facts the business wrote, its own catalogue, and its opening hours. That list has no calendar field — it is not a rule that has to be obeyed, it is a field that does not exist.
Google user data is never used to create, train or improve artificial intelligence models, ours or anyone else's.
Data received from Google APIs is never transmitted to any third-party AI or ML service, and is never used — raw, aggregated, anonymized, or derived — to develop, train, or improve any generalized or foundational AI/ML model. The Google Calendar integration is handled exclusively by deterministic code; no Google user data is included in any prompt or model request.
Who it is shared with
Nobody, except the services needed to make the system work. We do not sell data, do not trade it, and it does not go into third-party advertising.
- Supabase — database and authentication
- Cloudflare — hosting and page delivery
- Resend — sending email notifications
- Cloudflare Workers AI and KIE.ai — the models that write text and generate images. Neither of these two ever receives data coming from Google. See the artificial intelligence section above.
- Google — only when the business connects its own Google Calendar. In that case the name and the service of whoever booked are written into that business's calendar, which is the business that asked to see them there. See the section above.
Each of these services processes data only on our instructions, under a data processing agreement. Where any of them processes data outside the European Economic Area, it does so under the standard contractual clauses approved by the European Commission.
How the data is protected
These are the measures in force today, not a list of intentions.
- Encrypted in transit. Everything that moves between the browser, our servers, the database and Google's APIs travels over TLS (HTTPS). There is no plaintext endpoint.
- Encrypted at rest. The database runs on Supabase, whose disks are encrypted with AES-256, with per-project keys.
- Each business sees only its own. Every table carries the account identifier, and it is the database itself that refuses any read outside it. This is not a check written in the application, which can be forgotten — it is a database rule, and it covers every entry point at once.
- The Google authorization is out of the dashboard's reach. The table holding the calendar access authorization has no read policy and no grant to authenticated users: that authorization is never sent to anybody's browser — not even the business owner's own. Only the server touches it, and only to call Google.
- The authorization flow is signed. The request coming back from Google carries an HMAC-SHA-256 signature with an expiry, verified in constant time. Without it, somebody could link their calendar to another tenant's account.
- Only «when», never «what». From the calendar we read Google's FreeBusy API, which returns intervals with no titles. Titles, descriptions and attendees never reach our servers — there is no field in which to store them.
- Keys do not live in the code. Secrets and credentials live in the platform secret store, never in project files.
- Minimal human access. Administrative access to the database is restricted to whoever operates GoApexi. There are no shared or generic accounts.
- Deleting means deleting. When the business disconnects Google Calendar, the authorization and the cached busy intervals are deleted in the same operation. Nothing is kept «in case they come back».
In the event of a security incident affecting personal data, those affected are notified and the supervisory authority is informed within the legal deadlines.
For how long
Contacts and conversations are kept for as long as the business is a GoApexi customer and needs them to serve those people. When a business stops being a customer, its data is deleted on request, and in any case within 90 days of the end of the service.
Consent records are kept for as long as the consent is valid — because they are what proves it was given.
Your rights
You have the right to know what data exists about you, to correct it, to erase it, to restrict what is done with it, to object to the processing, and to take it with you. If you gave consent, you can withdraw it at any time — and that does not make what was done before unlawful.
Write to ola@goapexi.com. If the request concerns data we hold on behalf of a business, we forward it to that business and help them answer it.
You also have the right to lodge a complaint with the Portuguese Data Protection Authority (CNPD).
Changes
If this policy changes, the date at the top changes with it. Changes affecting what is done with data already collected are communicated to those affected.