Plain-language policy
Privacy
Early-access policy · July 15, 2026
The public website
We do not add advertising trackers, behavioral analytics, marketing cookies, account registration, or an embedded contact form. Our hosting provider may process standard request data such as IP address, user agent, and security logs to deliver and protect the site. If you email us, your email provider and ours process that message under their own policies.
The free 30-day scan
When you connect HighLevel, HighLevel sends ActuallyBooked a short-lived OAuth token. The hosted Worker keeps it in an encrypted, HTTP-only browser cookie only while it performs the scan. The authorization screen requests read-only access to Voice AI logs and calendar events, together with HighLevel’s app-install token scopes needed to select a location and issue its scan token. ActuallyBooked does not request permission to create, move, cancel, or edit appointments.
What is processed
The Worker reads Voice AI call-log data, including returned transcript text, booking actions, timestamps, and linking identifiers. Transcript text is processed transiently by deterministic rules to look for explicit agent confirmation language; it is not sent to an external AI or model provider. The Worker also reads current calendar-event metadata needed to compare booking actions with records in the scan window.
What is stored
ActuallyBooked does not write raw HighLevel responses, transcript text, summaries, recordings, contact names, phone numbers, calendar events, access tokens, or raw identifiers to a database, object store, analytics system, or customer report. Raw data is held only in memory during processing. The scan token is discarded when the result is ready.
The result contains aggregate counts and a capped set of pseudonymous case references, timestamps, finding categories, and short reasons. It is sealed in an encrypted, HTTP-only browser cookie for up to 24 hours, then expires. Because exact timestamps can still be identifying in context, the result should be treated as operational data rather than anonymous statistics.
Agency sub-account selection
If you connect at agency level, HighLevel temporarily returns the names and identifiers of sub-accounts where the app is installed so you can choose one. The list is rendered for the picker and is not written to a database or retained after selection.
What we may receive directly
- Your email address and message when you contact us or request monitoring updates.
- A pseudonymous case reference you choose to discuss with us.
Do not email recordings, transcripts, names, phone numbers, raw exports, or other sensitive content.
Disconnecting
ActuallyBooked discards its scan token after producing the result. The Marketplace app may remain installed in HighLevel until you uninstall it there. Uninstall the app in HighLevel to revoke its authorization at the source.
Excluded accounts
ActuallyBooked is not accepting healthcare, dental, financial, or legal accounts while its privacy, security, and compliance program is still being built. Do not connect an excluded account or send patient, client, payment-card, or similarly sensitive content.
Contact
Questions or deletion requests: trillionleonardo@gmail.com.
← Return to ActuallyBooked