LithicBack to home

Privacy Policy

Last updated August 1, 2026

Lithic (“Lithic,” “we,” “us”) builds websites, call handling, and an SMS operating layer for small home-service businesses (HVAC and related trades). This policy explains what information we collect through our websites, phone system, and SMS messaging, how we use it, and the choices you have.

Who this applies to

This policy covers two groups of people: the business owners who use Lithic’s products, and the homeowners/customers of those businesses who call, text, or submit a form to a Lithic-powered phone number or website.

Information we collect

  • Contact details you or a business’s customer provides: name, phone number, email, and service address.
  • Call and message content: missed-call recordings/transcripts, SMS conversation history, and service requests, used to route calls, follow up on leads, and keep the business owner informed.
  • Business operational data: appointment schedules, job status, and calendar connections the business owner links to Lithic.
  • Public product-guide questions are answered without an AI model and are not stored; an HMAC of the network address is retained briefly only to enforce abuse limits.

We do not ask for payment card numbers, passwords, login codes, or government ID numbers through SMS or voice. Stripe handles payment-card entry; Lithic stores limited subscription and card-brand/last-four metadata.

How we use it

Information is used only to operate the services a business has enabled, including:

  • Answering and routing missed calls, and following up by text on the business’s behalf.
  • Sending appointment confirmations, reminders, and status updates.
  • With documented consent only, sending a limited number of re-engagement texts to past leads.
  • Giving the business owner a daily summary of activity and flagging items that need their attention.

We do not sell contact information, and we do not use it for advertising unrelated to the business a person already contacted.

How AI is used, and what it doesn’t do

The public product guide on this website uses fixed, curated answers and does not send visitor questions to an AI provider.

Lithic’s SMS admin layer uses AI language models to help business owners get quick, conversational answers about their own business (for example, “what happened today” or “who needs me”). A few safeguards are built into how that works:

  • The AI can propose actions (like a follow-up message or a schedule change), but it can never approve, send, or execute anything consequential on its own — a human owner must confirm with an explicit approval code sent by text.
  • The AI never quotes binding prices, promises a technician’s arrival time, diagnoses or troubleshoots an emergency, or speaks as if it were a person.
  • If a message describes a gas leak, carbon monoxide, fire, or other immediate danger, the system is designed to tell the caller to leave the area and contact emergency services directly rather than attempt to troubleshoot.
  • When a tenant enables an AI feature, real customer data is restricted to the configured paid provider route selected for that purpose. Free/testing-tier models may retain submitted text and are restricted to fictional or non-sensitive internal testing.
  • We keep a record of the owner’s message, the system’s final response, and a redacted trace of what actions were taken — not hidden AI reasoning or full raw model transcripts.

SMS messaging, consent, and opt-out

Text messaging is only enabled for a business after its owner opts in during onboarding. Message frequency varies based on the Lithic services an owner enables and their interactions with the business. Message and data rates may apply. Quiet hours and opt-out handling are described in full in our SMS Terms. In short: no one is enrolled in SMS follow-up without documented consent, replying STOP to any message opts a number out immediately and stops further automated messages, and we never message a number that has previously opted out or replied STOP.

Who we share information with

We use a small set of vetted service providers to operate Lithic, each bound to use data only to provide their service to us:

  • Twilio — phone numbers, call routing, and SMS delivery.
  • Supabase — authentication and our database of record.
  • Stripe — subscription billing and payment-card processing.
  • Postmark — inbound and outbound business email.
  • Vercel and Render — application and agent-runtime hosting.
  • Google — owner-connected Calendar and Business Profile features, plus public listing/site measurements.
  • OpenRouter and the selected model provider — approved AI requests routed without infrastructure credentials.

We do not sell personal information, and we do not share it with data brokers or advertisers.

Mobile information will not be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with third parties except service providers supporting delivery of the Lithic messaging program.

Retention and deletion

We keep information for the enabled service, security, compliance, and contractual purposes described above. Email bodies are scheduled for redaction after 180 days unless an authorized person places a documented hold. Minimized email delivery metadata is generally kept for 30 days, or 7 days when an inbound event cannot be attributed to a customer account. Consent challenges expire and are removed after a short operational buffer. Other channel and account retention periods are finalized with the applicable customer agreement and legal requirements before launch.

A verified access request receives an allowlisted, tenant-scoped export. A verified deletion request removes direct identity and communication content where no continuing basis applies. Lithic may retain minimized consent/opt-out, billing, security, audit, or legal-hold evidence. Opt-out protection is preserved using a tenant-bound one-way digest after the ordinary phone or email field is removed.

Your choices

  • Reply STOP to any Lithic text message at any time to opt out of further messages.
  • Reply YES only to an active, expiring consent-confirmation message for the named business. A standalone keyword does not grant consent.
  • Contact us (below) to ask what information we hold about you or to request deletion. We verify identity and authority before disclosing or changing records.

Contact us

Questions about this policy or a request regarding your information can be sent to kevin@lithicdigital.com.