Your data, in plain English.
No dark patterns, no data broking. This tool runs in your browser and keeps your work there. This page lists every way data leaves your browser, where it goes, and why.
To open the app you fill in a short contact form, once, at the door. It asks for your name, work email, phone, company and which PSA you run, and optionally your MSP size and your role. We receive it, with the time you sent it, the campaign link you arrived through, the page that referred you and your browser's user-agent string. We use it to understand who is using the reference, and we only email you further if you tick the optional box.
Your work in the app is stored in your browser, not on our servers. Your assessment answers, MSP profile, roster, the tickets you create and the numbers you type into the calculators live in your browser's local storage.
Some of it leaves your browser only when you use a feature that needs it: the AI Concierge (your conversation, and whatever it reads from your profile, assessments or roster to answer you, goes to an AI model provider); an emailed result, if you ask for one; and StackJack, if you connect it. We never sell your data, and never share it with data brokers or advertisers. The detail is below.
The contact form at the door
The app opens behind a short contact form; until you submit it, the app doesn't load. It collects your first and last name, work email, phone, company name and the PSA you use (required), your MSP size and your role (optional), and an unticked opt-in box for occasional emails. Alongside it we record the time you submitted it, which form it came from, which campaign link you arrived through, your referrer and your browser's user-agent string, the ordinary web context that tells us where to improve.
Your browser sends the form to a Google Apps Script web app that adds it as a row in a Google Sheet we control. A copy stays in your browser's local storage so the app knows you've been through the door; clearing your browser data removes that copy and brings the form back. The form is a courtesy gate, not a security control.
We use it to understand who is using the reference and to send you anything you go on to ask for. We email you further only if you tick the opt-in box. Leave it unchecked and you won't hear from us: no cold outreach, no newsletter you didn't ask for. If you subscribe to the newsletter from the app's header instead, we receive your email address (and your first name, if you give it) the same way, with the same time, referrer and user-agent details.
What stays in your browser
The reference and its four assessments run in your browser. Your assessment ratings, your MSP profile (size, offerings, verticals, geography, packages, tool stack, team), the figures you enter in the valuation calculator, your My Org roster (technician names, tiers, skills), the tickets you create, your AI chat history and any AI provider key you add are all stored in your browser's local storage, on your own machine. We don't receive any of it unless you use one of the features below. Clear it any time from Settings → Clear all local data, or by clearing your browser storage.
The AI Concierge
The in-app AI Concierge is optional; the app sends nothing to a model provider until you chat with it. When you do, the app sends your message, the conversation so far, the Concierge's instructions and the results of the tools it uses to answer you to an AI model provider. Its instructions tell it to read the app's current state before it answers, so in practice every conversation sends the view you're on, your PSA and the PSA lens you've selected, your MSP size filter, your service offerings and a summary of your MSP profile (how complete it is, its size and geography, and how many products, roles, verticals and packages it lists). Depending on what you ask, other tool results can include your MSP profile (size, service offerings, geography and the gaps the app derives from them), your self-assessment ratings (for maturity coaching), your My Org roster (technician names, tiers and skills) and the labels from a PSA configuration you pasted into the app.
By default the request goes through our server function to Anthropic, under our API key; our function forwards it and returns the answer, and our code doesn't store or log the conversation. If you bring your own API key (Anthropic or OpenAI), the request goes directly from your browser to that provider under your own account, and your key stays in your browser's local storage. Either way, the provider processes the request under its own terms.
Two smaller routes: if your browser offers its own AI assistant through the WebMCP interface, the app lets that assistant call some of the Concierge's tools. Most of them read: app state, the diagnostic, gap analysis, workflow lookups, documentation coverage for the sample clients, and technician recommendations drawn from your My Org roster. The others change what the app shows: switching the view, setting the MSP size filter, setting the viewer lens, and opening a record's detail (which also returns its summary). What the assistant does with the results is up to your browser. And the other in-app agents and automatic ticket triage are wired to a development-only service that isn't deployed on this site, so their requests reach our host and are refused.
An emailed result
If the app offers to email you an assessment result and you accept, we receive your email address, your first name if you give it, which assessment it was, and the result, with the time you asked, the page that referred you and your browser's user-agent string. For the maturity assessments that's your overall level and the level of your lowest-rated area. For Financial & Valuation it's your estimated valuation range, your EBITDA margin and the name of the driver pulling the estimate down. The individual ratings and the revenue and cost figures you typed aren't sent. (Today that offer only appears to visitors who haven't filled in the form at the door, so in normal use you won't see it.)
Connecting StackJack
If you connect StackJack from Settings, the app registers itself with StackJack, opens StackJack's own sign-in in a popup (whatever you type there goes to StackJack, not to us) and keeps the resulting access tokens in your browser's local storage. It then asks StackJack for its list of available tools. It doesn't send your profile, assessments or other app data to StackJack. If you type your email into the box on that screen and press Save, it is kept in your browser only; it isn't sent to us.
Analytics and fonts
We use Vercel Web Analytics and Speed Insights, which are cookieless. They count page views (including the address you land on, such as a campaign link), three named clicks (a report download, a share, interest in AI Autopilot) and page-load performance. They build no advertising profile and never see your assessment answers, your MSP profile or your numbers. The pages load their fonts from Google Fonts, so your browser fetches them from Google like any other web request.
Who handles data for us
Google (the contact-form sheet, and font delivery), Vercel (hosting, the Concierge's server function, analytics), Anthropic (Concierge conversations on the default route; Anthropic or OpenAI if you use your own key) and StackJack (only if you connect it).
What we don't do
We do not sell your data, and we do not share it with data brokers or advertisers. The contact details you give us are used by AI Autopilot, the team behind this reference, and held for us by the services above.
Who is responsible for your data
The controller of the personal data this page describes, the company that decides why and how it is used, is AI Autopilot Inc., a Delaware corporation. You can reach us about it at support@aiautopilot.ai.
How long we keep it
Our retention period is 90 days from receipt for contact-form submissions without marketing opt-in and emailed-result requests, or 365 days from an explicit marketing opt-in. These are deletion eligibility thresholds; our policy calls for a weekly review to remove eligible records from the active contact sheet. Sending an email does not restart the period. Earlier deletion or unsubscribe requests take priority. A documented legal obligation may require a limited hold.
Implementation status: the deletion procedure is prepared, but deployment and the first cleanup of our external Google Sheet have not yet been confirmed. We cannot yet claim that every older record has been removed. Deleting an active row does not erase Google Sheets revision history, exported copies or messages already delivered to a mailbox; those require separate review. You can ask us to delete your details now using the contact below. Data in your browser stays until you clear it; service providers process their copies under their own terms and account settings.
Your rights, and how to use them
You can ask us for access (to tell you what personal data we hold about you and send you a copy), for correction (to fix anything we hold about you that is wrong or out of date) and for deletion (to delete the personal data we hold about you).
How to ask: email support@aiautopilot.ai, say which of these you want, and tell us the email address you gave us so we can find your details. We may ask you to confirm the request from that address before we act on it. Depending on where you live, privacy laws such as GDPR, UK GDPR or CCPA/CPRA may give you further rights, and you can ask us about those at the same address. The data on your own machine is yours to clear any time, from Settings or by clearing your browser storage.
This page is written to be read, not to bury you in boilerplate: an honest description of how the tool actually works, not certified legal text. Questions about how it applies to you under a specific privacy law (GDPR, UK GDPR, CCPA/CPRA)? Email support@aiautopilot.ai.