AI Policy

Last updated: 17 August 2026 · v2026.08

NurtureCRM includes AI-assisted features. This policy states which providers are used, exactly what data reaches them, what they may and may not do with it, where human review sits, and how a Customer turns the features off.

It is written to be checkable. Every commitment below is a statement about how the system is built and contracted, not an aspiration.

1. What the AI features do

Feature What it produces
AI assistant Answers questions about the Customer's own CRM data, drafts messages, summarizes activity
Email drafting and replies Draft text for a message the user is composing, in the user's chosen voice profile
Thread and activity summaries A short summary of a conversation or a contact's recent activity
Insights and scoring Suggested next steps, at-risk deal flags, relationship and pillar scores
Voice profiles Writing-style profiles the Customer configures and the drafting features apply
Transcription and speech Transcription of uploaded audio, and generated speech, where the Customer uses those features

All of these are assistive. None of them sends a message, changes a deal, or takes any other outward action without a user confirming it.

2. Providers

Provider Used for What is sent
OpenAI Text generation, summarization, scoring, audio transcription and generated speech The scoped context for the specific request
Anthropic Text generation and summarization The scoped context for the specific request
AssemblyAI Live speech-to-text during meeting transcription, only where that provider is configured for the deployment Meeting audio streamed while a session is recording, and the resulting transcript

Only OpenAI and Anthropic are on the path that can receive mail content. No speech provider ever receives email.

Which speech provider is used depends on the deployment. Where AssemblyAI is not configured — which is the case for a standard NurtureCRM instance — transcription uses OpenAI instead. Section 5 states what each provider may do with what it receives, and the difference between them matters.

The provider and model used for a given feature may change as we tune quality and cost. The commitments in section 4 apply to every provider on that path; a provider that cannot meet them is not used for that path.

Customer-configured enrichment integrations — Apify and Exa — are a different thing and are not covered by this policy's provider commitments. They run on the Customer's own API credential, are enabled by the Customer, and are listed under Sub-processors § Customer-configured integrations.

3. What data is sent, and what is not

Sent, scoped to the request:

  • the CRM records relevant to what the user asked — for example the contact, deal or thread on screen;
  • message content from a connected mailbox, when the user invokes a feature on that message, such as summarizing a thread or drafting a reply; and
  • the user's own prompt.

Not sent:

  • a Customer's entire database — only the context needed for the request;
  • another Customer's data, ever;
  • data from a mailbox the user has not opened the feature on; and
  • credentials, OAuth tokens or provider secrets.

Fields a Customer excludes from AI processing in its organization settings are not sent.

AI output is written back into the Customer's own tenant database and inherits the same role-based access controls as any other record in it.

4. Commitments

  1. Customer data is not used to train or improve any model — not by us, and not by any AI provider we send it to. This includes CRM records and mail content from connected Microsoft 365 and Gmail mailboxes. The contractual basis for each provider is set out in section 5.
  2. Data is sent only to deliver the specific user-facing feature the user invoked, and only for as long as that request takes.
  3. AI providers act as our sub-processors under contract. They are named at Sub-processors.
  4. AI processing is never used for advertising, and never for cross-customer analysis.
  5. Google user data additionally remains subject to the Limited Use requirements published at Google Limited Use. Where those requirements are narrower than this policy, they govern.

5. Provider retention, and the basis for commitment 1

Commitment 1 rests on each provider's business/API terms, not on a promise we make on their behalf:

Provider Basis Default
OpenAI Data submitted through the OpenAI API is not used to train or improve OpenAI models unless the customer explicitly opts in. We do not opt in. API inputs and outputs may be retained up to 30 days for abuse monitoring, then deleted, except where law requires retention No training
Anthropic Anthropic's Commercial Terms provide that customer inputs and outputs from commercial products, including the API, are not used to train its models by default No training
AssemblyAI AssemblyAI's model-improvement programme is opt-out, not opt-in: by default it may use submitted audio and transcripts to train its models. NurtureCRM therefore will not send audio to AssemblyAI at all unless an operator has confirmed that the opt-out is enabled for that account — this is enforced in code, not by policy, and transcription falls back to OpenAI otherwise Trains unless opted out — so we do not use it until it is

The difference is why section 4's commitment is a statement about contracted and configured behaviour rather than a general assurance: a provider whose default is to train is not used at all until that default has been turned off.

Where a provider cannot offer no-training terms for a given path, that provider is not used for mail content on that path.

We do not enable any provider feature that shares Customer data for model improvement, and we do not submit Customer data to abuse-review or feedback programmes that would.

6. Human review

Consistent with commitment 4 of the Google Limited Use requirements:

  • No one at NurtureCRM reads a Customer's mail content or AI prompts as a matter of routine.
  • A human may access a specific message or request only where:
    • a user or Customer administrator explicitly asks us to investigate it;
    • it is necessary to detect, prevent or respond to a security incident, abuse or fraud; or
    • applicable law requires it.
  • Aggregated, anonymised operational data — request counts, latencies, error rates — is reviewed to run the Service. It does not identify message content.

Access under these exceptions is logged.

7. Limitations, and what users must do

AI output can be wrong. It can invent facts, misread a thread, or produce text that is inappropriate to send.

  • Review every AI-generated message before sending it. Drafts are presented as drafts; nothing is sent automatically.
  • Verify factual claims and any figure an AI feature reports.
  • Do not rely on AI output alone for a decision that matters.
  • AI output is not legal, financial, medical, tax or other professional advice.
  • Report problematic output to support@aicoaches.com.

8. Customer controls

  • Disable AI features. A Customer administrator can turn AI features off for the organization, individually or as a group, in the organization settings. With them off, no Customer data is sent to any AI provider.
  • Scope exclusions. Sensitive fields can be excluded from AI processing in the same settings.
  • Tier availability. Some AI features are available only on certain subscription tiers.
  • Mailbox scope. Disconnecting a mailbox stops any AI feature from reaching that mailbox's content, because ingestion stops.

9. Changes

We will update this policy when the provider set, the data sent, or the commitments change. The version and effective date at the top of the page change with it, and material changes are notified as described in the Terms.

10. Contact

AiCoaches dot com LLC 111 NE 1ST ST, 8TH FLOOR 89145, Miami, Florida, USA 33132 AI and privacy enquiries: support@aicoaches.com