Switchboard · Legal

Privacy Policy

This explains what Protocol 42 Inc. does with personal information in connection with Switchboard. It is written to Canada’s federal privacy law, the Personal Information Protection and Electronic Documents Act, and we have tried to be specific rather than reassuring.

Version 1.0In force from 18 September 2026Protocol 42 Inc.

01The short version

  • We do not sell your personal information, and we do not use your conversations to train AI models.
  • Your messages are sent to third-party AI companies to be answered, and that usually means they leave Canada. That is how the product works. Every company involved is named on the providers page.
  • Your conversations are stored so you can come back to them, and you can delete them at any time.
  • We keep a record of what each request cost — never of what it said.
  • Voice recordings are passed straight through for transcription and never stored.
  • You can ask us for a copy of what we hold, or to correct it, or to delete it.

02Who is accountable

Protocol 42 Inc., a corporation in Ontario, Canada, decides how personal information is handled in Switchboard and is accountable for it, including for information we pass to the companies that work for us.

The individual accountable for our privacy practices is Adam Berube, Director, reachable at privacy@switchboardai.ca. Any question, request or complaint about privacy goes there and gets a reply.

03What we collect

Because you gave it to us

  • Account information — your email address, and the display name and organisation you choose to add. We use a sign-in link or a one-time code, so we do not hold a password.
  • What you put into the chat — your messages, files, images and project knowledge, and the replies you get back.
  • Voice recordings, when you use dictation. These are passed through for transcription and are never written to our disks or our database. We keep only the text, and only because you chose to put it in the message box.
  • Connected-tool credentials, when you connect one of your own services. These are encrypted, never shown again, and used only to make the requests you ask for.
  • What you write to support, including anything you attach to explain a problem.

Because the service generates it

  • Usage records — for each request, the time, which provider and model handled it, why it was routed there, how many tokens it used, what it cost, how long it took and whether it succeeded. This record does not contain the text of your messages.
  • An audit log — an append-only record that a thing happened: an AI call, a tool run, a routing refusal, a budget change, a deletion. Again, without the content. It cannot be edited or erased, including by us, because a log you can quietly change is not a log.
  • Technical information needed to run and secure the service: IP address, browser and device type, timestamps, error reports, and rate-limiting counters.

From other companies

  • Billing information from Stripe — that a payment succeeded or failed, the last four digits and brand of the card, the billing country, and the subscription state. We never receive or store your full card number.

04Why we collect it

We identify the purpose before we collect, and we use information only for these purposes:

  • to give you the service — answering your messages, keeping your chats, running the tools you connect;
  • to create and secure your account and to sign you in;
  • to take payment, apply your plan, count your allowance and show you where it went;
  • to keep the service up, diagnose faults and improve how it works;
  • to prevent fraud, abuse and attacks, and to enforce the Acceptable Use Policy;
  • to send you service messages — billing, security, changes to these documents, outages;
  • to meet a legal obligation, or to establish or defend a legal claim.

We do not use your personal information to train AI models, and we do not sell, rent or trade it. If we ever wanted to use it for a purpose not listed here, we would come and ask first.

You consent to what is described here by creating an account and using Switchboard. For anything sensitive, or anything beyond running the service, we ask separately and specifically, and we do not bundle it into a single tick-box.

You can withdraw consent at any time by writing to privacy@switchboardai.ca. Some of it we cannot operate without — an email address, for example, or a payment record we are required to keep — and in that case withdrawing means closing your account, which we will help you do.

06Your conversations

Your chats are stored against your account so that you can return to them, search them and export them. They are separated from every other customer’s at the database level, not merely by application code: the database enforces the boundary itself, and the service connects with an account that has only the permissions it needs.

We do not read your conversations. We do not review them for quality, we do not mine them for insight, and no member of staff browses them. There are three narrow exceptions and they are the only ones: you ask us to look at something in support; an automated safety control flags specific content and we have to investigate it; or the law requires it, in which case we will tell you unless we are prohibited from doing so.

You can delete a conversation at any time, and deleting removes its content. The cost and audit record of the requests it contained survives — it has to, for billing and for accountability — but it does not contain what was said.

07Where your information goes

Your messages are processed outside Canada.

To answer you, Switchboard sends your message and its attachments to a third-party AI company. Most of those companies, and the infrastructure we run on, are in the United States. While your information is there it is subject to the laws of that country, which means a court or a government agency there may be able to compel access to it under their own rules, without reference to Canadian law.

We think you should be able to see exactly who that is. The AI providers and sub-processors page lists every company that handles data on our behalf, what it does, where it is, and what it has told us about retention and training. We keep it current and we version it.

What we do to limit the exposure:

  • we turn on every setting a provider offers that prevents retention of, or training on, your content;
  • where we route through an aggregator, we refuse hosts that retain prompts, so requests only reach providers that have agreed not to;
  • we send the model your message and the context it needs — not your name, your email address or your billing details;
  • a project can be restricted to a named set of providers, enforced on our servers, so sensitive work never reaches the others; and
  • outbound traffic from our systems is restricted to an allowlist of provider addresses, so a misconfiguration cannot send your content somewhere unexpected.

We remain accountable for your information while it is with a company working for us, and we require comparable protection by contract. We cannot audit another company’s data centre, and we will not claim to.

We do not otherwise disclose personal information, except to a buyer of the business as part of a sale (on notice to you, and subject to this policy), or where the law requires it. We resist requests that are overbroad or improperly made.

08How long we keep it

  • Conversations, files and project knowledge — until you delete them or close your account.
  • Voice recordings — never stored. The audio is streamed to the transcription provider and discarded.
  • Account information — while your account is open, then deleted within 30 days of closure.
  • Usage and cost records, and the audit log — kept for seven years, because tax and accounting law requires a business record of what was sold, and because an audit trail with gaps is worse than none. Neither contains the content of your messages.
  • Billing records — as required by Canadian tax law, currently seven years.
  • Security and abuse records — up to two years, or longer where an investigation or a legal claim is live.
  • Support correspondence — three years.

09How we protect it

Protection is proportionate to sensitivity, and a chat history is sensitive. Concretely: everything travels over encrypted connections and is encrypted at rest; each customer’s data is isolated by database-enforced row-level security rather than by application code alone; the service connects to the database with a least-privilege account; connected-tool credentials are encrypted and never shown again; uploads are checked by content rather than by filename and executables are rejected; the audit log cannot be altered or deleted; outbound traffic is restricted to an allowlist; and dependencies and code are scanned automatically for vulnerabilities.

No system is perfectly secure, and anyone who tells you theirs is, is selling something. What we can promise is that we treat a breach as an emergency and that we will tell you about one — see the next section.

10Your rights

You can ask us to:

  • tell you what we hold about you, where it came from, what it has been used for and who it has been disclosed to;
  • give you a copy of your account information and your own chats, in a machine-readable format — you can also export any chat yourself, at any time, without asking;
  • correct anything inaccurate or incomplete;
  • delete your content and your account, subject only to records we are legally required to keep;
  • withdraw consent, as described above; and
  • explain a decision made about you by an automated system, and have a person review it.

Write to privacy@switchboardai.ca. We reply within 30 days, free of charge. We may need to confirm who you are first — we will ask for the least that does the job, and we will not use what you send us for anything else. If we have to refuse part of a request, we will say which part, and why, and tell you how to challenge it.

11If something goes wrong

If personal information in our care is lost or accessed by someone who should not have it, and there is a real risk of significant harm to you, we will:

  • report it to the Office of the Privacy Commissioner of Canada as soon as feasible;
  • notify you directly and conspicuously, telling you what happened, when, what information was involved, what we have done, what you can do, and who to speak to; and
  • notify anyone else — a payment processor, an identity provider, law enforcement — who can help reduce the harm.

The legal standard is “as soon as feasible”, and that is the commitment we are making, because promising a fixed number of hours we might not meet would be worse than useless to you. We keep a record of every security incident, not only the reportable ones, for at least 24 months.

12Children

Switchboard is for adults. We do not offer it to anyone under 18 and we do not knowingly collect personal information from a child. If you believe a child has created an account, tell us at privacy@switchboardai.ca and we will close it and delete the information.

13Cookies and analytics

We use the minimum: storage in your browser to keep you signed in and to remember interface preferences such as which tab you were on. That information stays in your browser and is not used to build a profile of you.

We do not use advertising cookies, we do not run third-party trackers, and we do not take part in cross-site behavioural advertising. Nothing we do requires a cookie consent banner, which is why you have not seen one.

14Email from us

Service email — receipts, renewal and price notices, security alerts, changes to these documents — comes with your account and is not marketing. You cannot unsubscribe from it while you have an account, because some of it we are legally required to send you.

Marketing email is opt-in and separate. We will not add you to a mailing list because you bought something. If we do send marketing, every message will identify us, give a working postal or electronic address, and carry an unsubscribe link that works in one click and takes effect immediately, as Canada’s anti-spam law requires.

15Automated decisions

Some controls operate without a person: rate limits, allowance ceilings, upload screening, fraud and abuse signals, and automatic suspension in the most serious cases.

If one of them makes a decision about you and you want to challenge it, write to support@switchboardai.ca. We will tell you what information the decision used and the main factors behind it, and a person with authority to change it will review it. The exception is section 3 of the Acceptable Use Policy, which concerns child safety.

Which AI model answers a given message is also decided automatically. That is a routing decision about a request, not a decision about you, and it has no consequences for your rights.

16Changes to this policy

We will update this policy as the product changes. Each version is numbered and dated. For a change that materially affects how your personal information is handled, we will email you at least 30 days before it takes effect. Adding a provider to the providers list is published there as it happens.

17How to complain

Come to us first: privacy@switchboardai.ca. We will acknowledge within five business days, investigate, and tell you what we found and what we are doing. If we got it wrong we will say so and fix it.

If you are not satisfied, you can complain to the Office of the Privacy Commissioner of Canada, or to the privacy regulator where you live. You do not need our permission and we will not treat it as a reason to close your account.

How to reach us

Protocol 42 Inc. is a corporation incorporated in Ontario, Canada, and operates Switchboard at https://www.switchboardai.ca.

All legal documentsHome