Privacy Policy

Last updated: 7 September 2026

usepicked (“we”, “us”) operates the website at https://usepicked.com and the usepicked application (together, the “Service”). The Service turns a guided questionnaire about a business into a personalised GoHighLevel configuration, provisions that configuration into a temporary GoHighLevel sub-account, packages it as a snapshot and delivers a share link. This policy explains what personal data we collect to do that, why, who we share it with and what rights you have.

For the personal data of the people who use the Service (account holders and the teammates they invite), we are the data controller. For the data you enter about a business and its customers while creating a Build, you are the controller and we process it on your instructions, as described under “Build data” below.

1. Data we collect

Account data

When you register we collect your name, email address and a password (stored hashed), or the profile details a social login provider such as Google shares with us when you choose that option. If you enable two-factor authentication we store the secret needed to verify your codes. Workspace names, the people you invite and their roles are stored so we can enforce who may view or manage Builds.

Billing data

Subscriptions, Build credit purchases, invoices and the ledger of credits used per Build are stored by us. Card details are never stored by us: payment is handled by our payment processors (Stripe or Paddle), who receive your payment details directly and are independent controllers for that data. We keep the transaction identifiers they return so we can match payments to your account and handle refunds.

Build data

A Build contains everything you tell us about a business: its name, industry, country, time zone, description, services, locations, opening hours, offers, policies and FAQs; the goals, lead sources and automation modules you select; the pipeline; every drafted and approved message; the Voice AI and Conversation AI configuration; the knowledge base articles; and the delivery choice. Some of this may identify people, for example a business owner's name or a staff member's phone number. We also store every version of the compiled Build specification, every revision of generated content and a log of every status change with who made it.

Website analysis data

If you enter a website address on the Business Discovery step, our servers fetch that site and a bounded number of its pages, extract the text and store the extracted proposals until you confirm or discard them. We only fetch addresses you enter, within page-count and size limits, and we do not follow links to other domains. You are responsible for having the right to submit that website for analysis.

GoHighLevel connection data

If you connect your own GoHighLevel agency or sub-account, we store the access token or private integration token you authorise, encrypted at rest, together with the identifiers and names of the locations you choose as delivery targets. Tokens are used only to read the connection's status and to provision the Builds you approve into the target you chose. They are never written to logs. Disconnecting revokes our stored token.

Provisioning and delivery records

For each approved Build we record the temporary GoHighLevel sub-account we created under our own agency, each provisioning step with its outcome and any error, the snapshot identifier and share link, and the time of delivery. These records exist so provisioning can be retried, so operators can package the snapshot and so you can prove what was delivered.

AI generation records

Every request we send to our AI provider is logged with the task, the model used, token counts, the cost, whether the response passed validation, and the resulting draft. We keep these records to enforce the per-Build spending cap, to audit output quality and to investigate problems you report.

Usage data and cookies

Like any web application we receive your IP address, browser type and the pages you request, and we keep application and error logs for a limited period. We set a session cookie so you stay logged in, a cookie to remember your cookie choice, and a security token cookie to protect forms. If we enable web analytics, the script only loads after you accept cookies on the consent bar, and we do not use advertising or remarketing trackers.

2. How we use data

Where the law requires a legal basis, we rely on the contract with you for everything needed to deliver a Build and bill for it, on our legitimate interests for security, support and improvement, and on your consent for optional analytics cookies and for any marketing email, which you can withdraw at any time using the unsubscribe link.

3. Who we share data with

We do not sell personal data. We share it only with the providers we need to run the Service, each bound by contract to use it solely to provide their service to us:

We will also disclose data when the law requires it, to protect the rights or safety of our users or the public, or, with notice to you, if the Service changes hands in a merger or sale.

4. Temporary sub-accounts and snapshots

The temporary sub-account we create for a Build lives in our own GoHighLevel agency and contains only the configuration compiled from that Build: pipeline, custom values, templates, agent settings and knowledge base articles. It holds no contacts, conversations or phone numbers. After the snapshot is delivered the temporary sub-account is scheduled for deletion; the snapshot itself remains available in our agency so the share link keeps working. Snapshots transfer structure, not data or connections, and cannot be used to access your agency.

5. Retention

Account and Build data is kept for as long as your account exists so you can return to any Build and see what was delivered. Invoices and credit ledgers are kept for as long as tax and accounting law requires. Extracted website proposals you discard are removed. Application logs are kept for a limited period and then deleted. When you close your account we delete or anonymise your personal data within 30 days, except records we must keep by law and snapshots already imported into a GoHighLevel agency, which we cannot reach.

6. Security

Every Build, specification, provisioning record and connection is reached only through the workspace it belongs to; a request without a workspace in context is refused rather than answered with someone else's data. GoHighLevel tokens and our own agency credentials are encrypted at rest and stripped from logs. Website fetching runs through checks that block private network addresses and enforce size limits. Passwords are hashed and two-factor authentication is available to every account. No system is perfectly secure; if we learn of a breach affecting your data we will notify you without undue delay.

7. International transfers

Our providers, including GoHighLevel, Anthropic, Stripe and Paddle, may process data in countries other than yours, including the United States. Where a transfer leaves a jurisdiction with data protection law that restricts it, we rely on the safeguards those providers offer, such as standard contractual clauses.

8. Your rights

Depending on where you live you may have the right to access, correct, delete, restrict or export your personal data, to object to certain processing and to withdraw consent. In practice:

If you believe we have not handled your data lawfully you may also complain to the data protection authority where you live.

9. Data you enter about other people

When an agency or consultant creates a Build for a client, the Build may contain the client's personal data. In that case the agency is responsible for having a lawful basis to give it to us, and we process it only to generate, provision and deliver that Build, as set out in this policy and in the Terms of Service. We do not use Build content to train AI models, and our AI provider is contractually bound not to either.

10. Children

The Service is for businesses and is not directed at anyone under 18. We do not knowingly collect data from children, and we will delete it if we learn we have.

11. Changes to this policy

We will post any change on this page and update the date at the top. If a change materially reduces your rights we will email account holders before it takes effect.

12. Contact

Questions and requests about your data go to drserhii@gmail.com.