Allura Privacy

Allura Privacy Policy

Last updated: August 30, 2026. This policy describes how Allura processes information through its apps, connected workflows, and supporting services.

This policy applies to Allura, the AI receptionist control application used by authorized med spa business users. It covers information processed through the native app and connected receptionist, messaging, calendar, AI, and hosting services.

About Allura

Allura is an AI receptionist control application for med spas. It helps authorized business users manage client conversations, client records, consultation and appointment workflows, staff review, and receptionist operations across iPhone, iPad, and Mac.

Information Allura Processes

Depending on the features and integrations used by a workspace, Allura may process names, phone numbers, email addresses, WhatsApp profile or display names, conversation content, appointment requests and booking details, client records, conversation summaries, staff notes, receptionist actions, and workspace settings.

Conversation content may include photos, videos, documents, incoming and outgoing voice or audio messages, captions, and related attachment information such as file type, size, delivery state, and message association. Where an authorized AI workflow supports it, Allura may also create and process audio transcripts, image descriptions or visible text, and content extracted from documents. Video messages are supported for messaging and staff review, but Allura does not send video content to AI for video analysis.

Allura may also process limited technical and operational information needed to operate, secure, and troubleshoot the connected workspace, such as connection and delivery status, timestamps, workspace preferences, and security or operational audit records. This information is used for service operation and security, not advertising or tracking.

How Information Is Collected and Used

Clients communicate with a med spa through its connected WhatsApp number. Meta and WhatsApp provide the message content and delivery information needed to show and manage those conversations in Allura. Authorized staff may also choose photos, videos, or documents to send, use the camera on iPhone or iPad to capture a photo or video, or intentionally record and send a voice reply. Allura receives only the items staff choose, capture, or record for that action; selecting an attachment does not give Allura blanket access to a photo library or filesystem.

Allura uses this information to deliver and organize messages, maintain client records, answer business questions, assist consultation scheduling and follow-ups, manage bookings and calendars, show conversation history, support staff review and Human Takeover, provide notifications, and operate and secure the med spa's connected Allura service.

Device Permissions

On iPhone, iPad, and Mac, microphone access is requested only when an authorized staff member deliberately starts a voice recording or performs another action that requires microphone access. On iPhone and iPad, camera access is requested only when an authorized staff member chooses the Camera action; capturing video with audio may also require microphone access. Allura does not continuously listen, record in the background, or access the microphone without a direct user action.

Photos and videos are chosen through the operating system's photo picker. iPhone and iPad may ask for photo-library permission and support limited access; on Mac, the picker grants access to the selected items. Documents are chosen through the system file picker, which provides access to the selected file rather than the whole filesystem.

Users can decline or later manage applicable camera, microphone, photo, and notification permissions in device settings. Denying microphone permission prevents the related recording action but does not affect unrelated Allura functionality. Operating-system permissions do not change the separate workspace authorization for AI Processing.

AI Processing and Authorization

Allura uses third-party AI services, including OpenAI, to provide AI receptionist features. Before automated AI handling can operate, an authorized workspace user must review and accept the AI Processing disclosure in Allura Settings. The authorization can be reviewed or disabled later. Disabling AI Processing stops automated AI handling for the workspace; manual staff workflows and existing records remain available.

When AI Processing is authorized, relevant conversation history and related client, appointment, summary, staff-note, and workflow context may be processed to answer business questions, understand and follow up on inquiries, assist consultation booking, summarize conversations, and support receptionist efficiency. Supported customer images may be described and checked for visible text, customer documents may have relevant content extracted, and incoming client voice or audio messages may be transcribed. Captions and related consecutive messages may be processed as conversation context. Video files are not provided to the AI for video analysis, although a video caption may be used as text context. This AI processing description does not state that outgoing staff voice replies are analyzed by AI.

OpenAI does not use API inputs and outputs to train its models by default unless the account opts in. OpenAI may process or retain data according to its API data controls, service terms, endpoint behavior, and account settings; not being used for training does not mean that data has zero retention. AI processing is used to provide Allura functionality, not advertising.

Third-Party Services

Allura relies on OpenAI for the authorized AI features described above; Meta and WhatsApp for message and attachment delivery; Google Calendar for calendar synchronization when a workspace enables it; Apple for push-notification delivery to registered devices; and hosting, storage, and infrastructure providers for application operation, storage, security, and processing.

Each provider processes the information needed for its role under its own service terms, policies, and retention practices. Calendar synchronization and AI Processing are controlled separately within the workspace where available.

Retention, Archiving, and Deletion

Conversation, client, appointment, staff-note, and operational data may be retained according to workspace configuration, legitimate business requirements, security needs, and applicable obligations. Allura may keep recent incoming voice messages, media, and documents in a device cache for up to 30 days, subject to the workspace's media-download settings and the device's storage behavior.

Archiving a conversation removes it from the active workflow but retains its history and attachments. Deleting a conversation removes its message history, photos, videos, documents, voice recordings, captions, reply context, generated transcripts, extracted document content, media descriptions and other media-derived content, and conversation summary. Those conversation attachments are not transferred to or preserved in a separate client-record media or document collection. Deleting the conversation does not automatically delete an existing client record, past or upcoming appointment history, or staff notes retained with the client record.

Deletion from Allura does not promise immediate deletion from every message recipient, device backup, or third-party service. Those systems may retain information under their own policies or legal requirements. No single retention period applies to every category of information.

Access, Correction, and Deletion Requests

Authorized workspace users can review and update client information, manage workspace settings, enable or disable AI receptionist functionality, archive or delete conversations when permitted, and contact support about access, correction, or deletion requests.

A client seeking access to, correction of, or deletion of information held by a med spa should normally contact that med spa first. Farbod Dev can assist an authorized med spa user and can respond to privacy questions sent to the address below. A request may require verification and may be limited by legitimate retention or legal requirements.

Responsibilities, Sensitive Content, and Security

Farbod Dev is responsible for operating Allura and applying appropriate privacy and security controls to the services it provides. Med spa businesses using Allura remain responsible for their own customer relationships, instructions, notices, permissions, access decisions, and legal obligations. Allura's software does not replace a med spa's privacy responsibilities.

Clients or staff may voluntarily include treatment goals, allergies, sensitivities, preparation, aftercare, complaints, or other health-related context in a conversation or note. Allura may process that content as part of the relevant workflow. Allura does not provide medical advice, and this policy does not claim HIPAA certification or guarantee that a workspace's use complies with every law.

Farbod Dev uses safeguards intended to protect information and support secure service operation, but no internet, device, or storage system can be guaranteed absolutely secure. Allura does not sell personal information and does not use it for advertising or cross-app or cross-service tracking.

Contact

For privacy questions, email connect@farbod-dev.com with the subject line Allura Privacy.