Privacy Policy
Last updated: 7 September 2026
usepicked (“we”, “us”) operates the website at https://usepicked.com and the usepicked application (together, the “Service”). The Service turns a guided questionnaire about a business into a personalised GoHighLevel configuration, provisions that configuration into a temporary GoHighLevel sub-account, packages it as a snapshot and delivers a share link. This policy explains what personal data we collect to do that, why, who we share it with and what rights you have.
For the personal data of the people who use the Service (account holders and the teammates they invite), we are the data controller. For the data you enter about a business and its customers while creating a Build, you are the controller and we process it on your instructions, as described under “Build data” below.
1. Data we collect
Account data
When you register we collect your name, email address and a password (stored hashed), or the profile details a social login provider such as Google shares with us when you choose that option. If you enable two-factor authentication we store the secret needed to verify your codes. Workspace names, the people you invite and their roles are stored so we can enforce who may view or manage Builds.
Billing data
Subscriptions, Build credit purchases, invoices and the ledger of credits used per Build are stored by us. Card details are never stored by us: payment is handled by our payment processors (Stripe or Paddle), who receive your payment details directly and are independent controllers for that data. We keep the transaction identifiers they return so we can match payments to your account and handle refunds.
Build data
A Build contains everything you tell us about a business: its name, industry, country, time zone, description, services, locations, opening hours, offers, policies and FAQs; the goals, lead sources and automation modules you select; the pipeline; every drafted and approved message; the Voice AI and Conversation AI configuration; the knowledge base articles; and the delivery choice. Some of this may identify people, for example a business owner's name or a staff member's phone number. We also store every version of the compiled Build specification, every revision of generated content and a log of every status change with who made it.
Website analysis data
If you enter a website address on the Business Discovery step, our servers fetch that site and a bounded number of its pages, extract the text and store the extracted proposals until you confirm or discard them. We only fetch addresses you enter, within page-count and size limits, and we do not follow links to other domains. You are responsible for having the right to submit that website for analysis.
GoHighLevel connection data
If you connect your own GoHighLevel agency or sub-account, we store the access token or private integration token you authorise, encrypted at rest, together with the identifiers and names of the locations you choose as delivery targets. Tokens are used only to read the connection's status and to provision the Builds you approve into the target you chose. They are never written to logs. Disconnecting revokes our stored token.
Provisioning and delivery records
For each approved Build we record the temporary GoHighLevel sub-account we created under our own agency, each provisioning step with its outcome and any error, the snapshot identifier and share link, and the time of delivery. These records exist so provisioning can be retried, so operators can package the snapshot and so you can prove what was delivered.
AI generation records
Every request we send to our AI provider is logged with the task, the model used, token counts, the cost, whether the response passed validation, and the resulting draft. We keep these records to enforce the per-Build spending cap, to audit output quality and to investigate problems you report.
Usage data and cookies
Like any web application we receive your IP address, browser type and the pages you request, and we keep application and error logs for a limited period. We set a session cookie so you stay logged in, a cookie to remember your cookie choice, and a security token cookie to protect forms. If we enable web analytics, the script only loads after you accept cookies on the consent bar, and we do not use advertising or remarketing trackers.
2. How we use data
- To run the Service: authenticate you, keep your workspace separate from every other workspace, save your Builds and let you resume them.
- To generate drafts: send the confirmed business profile and, for website analysis, the extracted page text to our AI provider so it can propose pipelines, messages, agent settings and articles for you to review.
- To provision and deliver: create the temporary sub-account, write the approved specification into GoHighLevel, package the snapshot and send you the share link by email.
- To bill you: charge subscriptions and credit packs through our payment processors, deduct and refund Build credits, and issue invoices.
- To support you: answer your emails, investigate failed provisioning runs and share-link errors, and notify you when a Build needs attention.
- To keep the Service secure and improve it: detect abuse, monitor errors, and measure which steps take people the longest.
Where the law requires a legal basis, we rely on the contract with you for everything needed to deliver a Build and bill for it, on our legitimate interests for security, support and improvement, and on your consent for optional analytics cookies and for any marketing email, which you can withdraw at any time using the unsubscribe link.
3. Who we share data with
We do not sell personal data. We share it only with the providers we need to run the Service, each bound by contract to use it solely to provide their service to us:
- GoHighLevel (HighLevel Inc.) — receives the approved Build specification when we provision it into the temporary sub-account under our agency, or into the sub-account you connected. Once you import a snapshot into your own agency, that copy is governed by your agreement with GoHighLevel, not by this policy.
- Anthropic — our AI provider. It receives the confirmed business profile, the extracted website text and your editing instructions in order to generate drafts. It never receives your GoHighLevel credentials or payment details.
- Stripe and Paddle — payment processing and invoicing.
- Email delivery providers — to send verification, delivery, invoice and notification email.
- Hosting and infrastructure providers — where the application, database, queues and backups run.
- Social login providers — only if you choose to sign in with them.
We will also disclose data when the law requires it, to protect the rights or safety of our users or the public, or, with notice to you, if the Service changes hands in a merger or sale.
4. Temporary sub-accounts and snapshots
The temporary sub-account we create for a Build lives in our own GoHighLevel agency and contains only the configuration compiled from that Build: pipeline, custom values, templates, agent settings and knowledge base articles. It holds no contacts, conversations or phone numbers. After the snapshot is delivered the temporary sub-account is scheduled for deletion; the snapshot itself remains available in our agency so the share link keeps working. Snapshots transfer structure, not data or connections, and cannot be used to access your agency.
5. Retention
Account and Build data is kept for as long as your account exists so you can return to any Build and see what was delivered. Invoices and credit ledgers are kept for as long as tax and accounting law requires. Extracted website proposals you discard are removed. Application logs are kept for a limited period and then deleted. When you close your account we delete or anonymise your personal data within 30 days, except records we must keep by law and snapshots already imported into a GoHighLevel agency, which we cannot reach.
6. Security
Every Build, specification, provisioning record and connection is reached only through the workspace it belongs to; a request without a workspace in context is refused rather than answered with someone else's data. GoHighLevel tokens and our own agency credentials are encrypted at rest and stripped from logs. Website fetching runs through checks that block private network addresses and enforce size limits. Passwords are hashed and two-factor authentication is available to every account. No system is perfectly secure; if we learn of a breach affecting your data we will notify you without undue delay.
7. International transfers
Our providers, including GoHighLevel, Anthropic, Stripe and Paddle, may process data in countries other than yours, including the United States. Where a transfer leaves a jurisdiction with data protection law that restricts it, we rely on the safeguards those providers offer, such as standard contractual clauses.
8. Your rights
Depending on where you live you may have the right to access, correct, delete, restrict or export your personal data, to object to certain processing and to withdraw consent. In practice:
- You can update your name, email and password in your account settings.
- You can edit any Build that has not been approved, and disconnect a GoHighLevel connection at any time.
- Every approved Build shows exactly what was delivered in its workspace, and we will export it on request.
- For anything else, including closing your account, email us and we will respond within 30 days. We may ask you to verify your identity first.
If you believe we have not handled your data lawfully you may also complain to the data protection authority where you live.
9. Data you enter about other people
When an agency or consultant creates a Build for a client, the Build may contain the client's personal data. In that case the agency is responsible for having a lawful basis to give it to us, and we process it only to generate, provision and deliver that Build, as set out in this policy and in the Terms of Service. We do not use Build content to train AI models, and our AI provider is contractually bound not to either.
10. Children
The Service is for businesses and is not directed at anyone under 18. We do not knowingly collect data from children, and we will delete it if we learn we have.
11. Changes to this policy
We will post any change on this page and update the date at the top. If a change materially reduces your rights we will email account holders before it takes effect.
12. Contact
Questions and requests about your data go to drserhii@gmail.com.