Beta open3 Foundation spots left at $999 build.Free blueprint →
Trust & data handling

How we handle
your data.

Plain language. Your business data is yours. We use it to run your account and to make LeadLockr smarter for every contractor on the platform — anonymized, aggregated, never resold.

Last updated July 20, 20266 sectionsPlain language
01

Your data is yours.

02

AI is opt-in and supervised.

03

Security is built in, not bolted on.

01 · Contractor data

Your business data is yours.

You're the customer. Your business data is the most sensitive thing on the platform. Here's how we handle it.

What we store: your business profile, your Twilio credentials (encrypted with AES-256 at rest), conversation history (SMS and voice transcripts between you and your customers), lead events, job records, photo uploads, and your password (bcrypt-hashed, never plaintext).

Each contractor's data is isolated from every other contractor on the platform. Multi-tenant by design, single-tenant by access. We don't sell it, rent it, or hand it to third parties to train their AI models.

Where we do use your data: we use the anonymized signal across all contractors on LeadLockr — which platforms move the needle for which trades, which review request copy converts highest in which regions, which job patterns correlate with growth — to make Lockr smarter for everyone on the platform. Your individual data stays yours. The patterns across thousands of contractors become the moat that makes Lockr better than any single-account tool can be.

Read the full Privacy Policy
02 · Your customers

Your customers matter too.

When a homeowner texts you through LeadLockr, their conversation is stored so you can serve them. We don't share their personal information with third parties. We don't use their phone number for any LeadLockr marketing. The conversation patterns help Lockr respond better across the platform — fully anonymized, with PII stripped before any aggregation.

STOP works. Every SMS conversation respects opt-out, immediately.

03 · AI use

AI is a co-worker, not a black box.

Lockr handles routine customer messages on your behalf. You control whether AI is on, and you can take over any conversation at any time.

We use Claude (by Anthropic) for AI reasoning. Per Anthropic's commercial terms, your conversation data is not used to train their models. Every AI response is logged so you (and we) can audit what was said.

When voice calls go unanswered, Lockr may answer, take a message, qualify the lead, and escalate to you via SMS. Voice calls are recorded and transcribed. We disclose this on every call.

04 · Platform security

Security is a product feature, not a slogan.

We built the platform so a misconfiguration crashes the service rather than silently weakening security. Specifically:

  • Verified webhooks. Every webhook from Twilio is cryptographically verified before it can change anything on the platform.
  • Rate-limited surfaces. Every public form, agreement intake, and chat widget on client sites is rate-limited to prevent abuse.
  • Encrypted at rest. Sensitive data, including business and Twilio credentials, is encrypted at rest, and third-party service credentials are kept separate from one another.
  • Revocable share links. Receipt and share links use HMAC-signed tokens that you can revoke at any time.
  • Immutable audit log. All admin destructive actions write to an audit log that can't be silently edited.
SOC 2 status: we're building toward it. We're not certified yet. We'll say so when we are. Same for any other compliance certification. No vague “bank-grade” claims here.
05 · Connected accounts

When you connect Google, you keep the keys.

Connecting your Google Business Profile is optional, and the platform works without it. When you do connect it, you're handing us a specific, narrow, revocable permission — not your Google account. Here's exactly what that means.

  • One permission, not your whole account. We ask Google for a single scope: manage business listings. No Gmail, no Drive, no contacts, no calendar. Google's own consent screen shows you the one thing we asked for.
  • The token is encrypted with its own key. The credential that keeps the connection alive is encrypted at rest using a key dedicated to third-party logins, separate from every other secret on the platform. If that stored data is ever tampered with, decryption fails shut and the connection asks you to reconnect. It never quietly falls back to something weaker.
  • It can't reach further than you can. Connecting delegates the access your Google account already has. If you don't manage a profile on Google, neither do we. You pick which specific location we watch, from a list — we never guess on your behalf.
  • AI drafts, code posts. When Presence suggests a reply to a review, the review text goes to Claude to write a draft. The model never holds your Google credentials and never talks to Google directly. Nothing is published until you approve it, or until a review clears the safety rules for automatic replies that you turned on yourself.
  • Disconnect in one click, any time. Disconnecting revokes our access with Google and deletes the stored credential. You can also cut us off from your Google Account permissions page without touching LeadLockr at all.
What we never do with Google data: we don't sell it, advertise against it, use it to train AI models, or fold it into the anonymized cross-contractor patterns described above. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
06 · Your rights

Your rights, plainly.

Four things you can do at any time. No phone tree, no support ticket queue.

  • Access

    Email support@leadlockr.ai and we'll send you what we have on you within 30 days.

  • Delete

    Email support@leadlockr.ai and we'll delete it within 30 days unless we're legally required to retain it. Some logs (security audit, financial records) are retained per legal requirements.

  • Opt out · SMS

    Reply STOP to any text. Works immediately.

  • Security report

    Email security@leadlockr.ai. We'll respond within one business day.

Specific question?

We'll answer plainly.

hello@leadlockr.ai

Question about how we handle a specific piece of data, or how an agent works on your account? Email us. Lockr drafts, Garrett reviews, we reply within a business day.