AI Paragon Consulting Group ("AI Paragon," "we," "us," or "our") operates the website aiparagonconsulting.com and the Spectrum Care Advisory OS care dashboard (the "dashboard"). We respect your privacy and are committed to protecting the information entrusted to us.
This Privacy Policy explains how AI Paragon collects, uses, stores, shares, and protects information when you visit our website, contact us, or use the dashboard and other applications we provide.
It also explains how we handle information we receive from Google when you choose to connect a Google account to the dashboard.
1.Information We Collect
Information you give us. Your name, email address, organization, job title, phone number, and anything you submit through our contact or consultation forms.
Account information. When you use the dashboard, we process the details needed to create and secure your account, such as your name, email address, role, and the organization you belong to.
Information you enter into the dashboard. The records your organization manages in the dashboard, such as appointments, tasks, staff records, documents, and messages.
Google Calendar data. If you connect a Google account, we access Google Calendar event information as described in sections 2 to 5.
Technical information. Limited technical information needed to run, secure, and troubleshoot our website and applications.
When the dashboard sends email, such as staff invitations, reminders, or task digests, it sends it from an AI Paragon email account. The dashboard does not access your Gmail account.
2.Google Account Access
You can connect a Google account to the dashboard so your appointments and Google Calendar stay in sync. You connect through Google's own sign-in and consent screen, and you decide whether to grant access. We never see or receive your Google password.
The dashboard requests the Google Calendar permission necessary to view, create, update, and delete calendar events so that dashboard appointments can be displayed and synchronized with your Google Calendar:
https://www.googleapis.com/auth/
This is the only Google permission the dashboard requests.
We do not request access to Gmail, Google Drive, Google Contacts, or any other Google service.
3.Google Calendar Integration
With your permission, the dashboard uses the Google Calendar API to:
- Show your Google Calendar events alongside your dashboard appointments;
- Create a Google Calendar event when you create an appointment in the dashboard;
- Update, cancel, or delete that Google Calendar event when you change the appointment in the dashboard;
- Add the attendees you choose to an appointment, which lets Google send them an invitation; and
- Check your calendar for changes made in Google to events the dashboard created (new date, time, length, location, or cancellation) and apply those changes to the matching dashboard appointment.
Calendar events not created through the dashboard. Other events on your connected Google Calendar may be retrieved and displayed temporarily in the dashboard so you can view your schedule. These events are not copied into or persistently stored in our dashboard database.
Calendar events created through the dashboard. When an appointment is created through the dashboard, we store the corresponding appointment information and Google Calendar event ID so the two records can remain synchronized.
Events the dashboard creates identify clients by initials and a client ID number only, not by full name.
4.How We Use Google User Data
We use Google user data only to provide the calendar features described above, to keep them working and secure, and to answer your questions through the dashboard's AI assistant when you ask one (see section 6).
We do not sell Google user data. We do not use it for advertising, retargeting, or marketing profiles. We do not use it to develop, improve, or train artificial intelligence or machine-learning models.
AI Paragon's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5.Where Google User Data Is Stored
Dashboard database. For appointments created in the dashboard, we store the appointment details (title, date, time, length, location, attendees, and status) together with the matching Google Calendar event ID. Our database is hosted by Supabase.
Your browser. When you connect Google Calendar in the dashboard, Google gives your browser a short-lived access token. It is held in memory for your current session and is not saved by us.
Calendar sync service. Keeping your organization's calendar in sync runs on our automation platform (a self-hosted n8n instance). It holds an authorized Google Calendar connection for your organization, stored encrypted, and uses it only for syncing. Every 10 minutes it reads events in a window from 30 days in the past to 180 days ahead to find changes to dashboard-created events. The platform keeps a log of each run, which can include the event details it read. These logs are deleted automatically after about 14 days.
6.AI Assistant
The dashboard includes an optional AI assistant that answers questions about information currently available in your organization's dashboard. When you choose to use the assistant, your question is sent to Anthropic's Claude API together with a snapshot of the dashboard information the assistant uses to answer it. This information may include appointments and connected Google Calendar event information displayed in the dashboard.
Google user data is transferred to Anthropic only when you affirmatively use the AI assistant, and only for the purpose of generating the response you requested. We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine-learning models.
Clients appear in the snapshot by initials and client ID number only. We keep a record of each question and answer in your organization's dashboard database.
8.Human Access to Google User Data
AI Paragon staff do not read your Google user data except when:
- You give us permission or ask us for help that requires it;
- It is necessary for security, such as investigating abuse or a security incident;
- It is required by law; or
- It is otherwise permitted under Google's API Services User Data Policy.
Any access is limited to what is needed for that purpose.
9.Analytics and Advertising
Our website and the dashboard do not currently use Google Analytics, Meta Pixel, LinkedIn Insight Tag, Google Ads tracking, or similar advertising trackers.
We use only the technical mechanisms needed to keep our website and applications working and secure. If this changes, we will update this Privacy Policy.
10.Data Security
We use reasonable administrative, technical, and organizational safeguards to protect information, including encrypted connections (HTTPS), encrypted storage of service credentials, account sign-in, and database access rules that limit each organization to its own records.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
11.Data Retention
- Dashboard appointments and event IDs: kept until you or your organization delete them, or until your organization's account is closed.
- Calendar sync logs: deleted automatically after about 14 days.
- Google access in your browser: ends when your session ends or the token expires.
- Your organization's Google Calendar connection: kept until it is disconnected or access is revoked.
- AI assistant questions and answers: kept in your organization's dashboard until deleted or the account is closed.
- Other information you give us: kept as long as reasonably needed to provide our services, keep business records, meet legal requirements, resolve disputes, or enforce agreements.
12.Your Choices, Revocation, and Deletion
Connecting a Google account is optional. You can remove the dashboard's access at any time from your Google Account permissions page. After you revoke access, the dashboard can no longer read or change your Google Calendar, and calendar sync stops.
To ask us to delete Google user data or other personal information we hold, including stored appointment records and event IDs, email us. We will delete it unless we are legally required to keep it.
13.Third-Party Services
Google, Supabase, Anthropic, and our hosting providers have their own privacy policies and terms. This Privacy Policy covers how AI Paragon handles information and does not replace theirs.
14.Children's Privacy
Our website and applications are business tools and are not directed to children under 13. We do not knowingly collect personal information from children under 13 through them. If we learn that we have, we will delete it.
15.Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes to our applications, integrations, practices, or legal requirements. When we do, we will update the "Last updated" date at the top of this page. Where required by law, we will give additional notice or ask for consent before materially changing how we use information we have already collected.
