Legal

Privacy Policy

Effective Date: August 18, 2026  ·  Last Updated: August 18, 2026

Shedu is a service operated by Wood Vault Inc. (“Wood Vault,” “we,” “us,” or “our”). References to “Shedu” throughout this policy refer to the Shedu platform operated by Wood Vault Inc.

This Privacy Policy explains how Shedu collects, uses, stores, and shares information when you use our website (shedu.io), our SaaS platform, Nabu and other AI features, the Governed Harness, and related services (together, the “Service”). If you have privacy questions, contact us at support@shedu.io.

1. Overview

Shedu processes four categories of data:

  1. Customer Data (our direct customers and account holders, including free Nabu accounts)
  2. End-User Lead Data (customers of the businesses that use Shedu)
  3. Website Visitor Data (visitors to shedu.io)
  4. AI Feature Content (material you submit to Nabu and other AI features)

Shedu does not sell personal data, and Shedu does not use your content to train general-purpose AI models.

2. Data We Collect

2.1 Data Collected from Customers

When you sign up for Shedu, we collect and store:

Business & Account Information:

  • Business name and owner name
  • Email address and phone number
  • Google Ads Customer ID (10-digit account number), if you connect Google Ads
  • Billing information, processed by Stripe (Shedu does not store full card numbers)

Google Integrations:

  • Google Calendar OAuth tokens (encrypted at rest)
  • Google Ads API OAuth tokens (encrypted at rest)

Operational Configuration Data:

  • Seat information (names, roles, working hours, service areas)
  • Geographic configuration (ZIP codes, service boundaries)
  • Scheduling preferences (booking horizon, ad lead times, quiet hours)
  • Dashboard authentication credentials (email-based sign-in, session cookies)
  • Webhook keys for third-party integrations you configure

This information is necessary to configure and operate your Shedu account.

2.2 Data Collected from Your Customers (End-User Leads)

When a consumer interacts with a Shedu customer’s ad, booking form, or scheduling workflow, Shedu may process:

  • Name, phone number, and email address (if provided)
  • Street address or ZIP code
  • SMS and email conversation history (message logs between the automated assistant and the lead)
  • Appointment details (date, time, assigned seat, status)
  • Job value (when reported by the business)
  • Lead source attribution (Google Ads, referral, etc.)
  • SMS opt-in/opt-out status and consent records

This data is collected and processed on behalf of the business you contacted. That business owns this data; Shedu acts as its service provider.

2.3 Data Collected from Website Visitors (shedu.io)

Analytics Data:

We use Google Analytics to understand how visitors use shedu.io. Google Analytics collects information such as IP address, browser and device information, pages visited, and referral source, using cookies and similar technologies.

Campaign Attribution:

If you arrive from an ad or campaign link, we capture campaign identifiers from the URL (such as UTM parameters, a Shedu campaign ID, and the Google Click ID) in your browser’s session storage, along with the landing page URL. If you later book a demo, these identifiers are submitted with your request so we can measure which campaigns work.

Booking Widget Submissions:

  • Name, email, phone, business type, seat count, ZIP codes

This data is used for demo scheduling and marketing performance tracking.

2.4 Data Collected Through Nabu and AI Features

  • Public demo: chat messages and intention-card content you enter. Demo conversation history is stored in your own browser. The demo uses Cloudflare Turnstile to block automated abuse; Turnstile processes technical data such as your IP address.
  • Free accounts: your email address (used to send one-time login codes via our email provider), signed session cookies, and your saved conversations, intention cards, and rules, stored in private storage keyed to your account.
  • Evidence you attach: files you upload and, if you connect GitHub, repository content you authorize. Submit only material you have the right to share.
  • Feedback: ratings and comments you submit about AI responses.

3. How We Use Data

3.1 Customer Data

We use Customer Data to configure and operate your account, manage Google Ads coverage adjustments, sync Google Calendar availability, route and dispatch work, generate invoices, send automated summaries, provide dashboards, bill subscriptions, and provide support.

3.2 End-User Lead Data

We process lead data on behalf of our customers to send automated messages for scheduling, confirm appointments, send reminders and follow-up messages, send review requests, and record appointment outcomes. We do not use end-user lead data for our own marketing purposes.

3.3 AI Feature Content

We use the content you submit to Nabu and other AI features only to provide, secure, support, and improve the Service — for example, generating responses, saving your conversations and cards to your account, enforcing rate and cost limits, and investigating abuse. We do not use your content to train general-purpose AI models, and we configure our model providers accordingly.

3.4 Website Data

We use website visitor data to improve website performance, track demo conversions, analyze traffic sources, and measure advertising effectiveness.

4. AI Model Providers

Nabu and other AI features generate responses by sending your conversation content to third-party model providers, which may include OpenAI, Google (Gemini), DeepSeek, and xAI. Requests may fail over between providers for reliability. These providers process your content to generate a response and are not permitted to use it to train their general-purpose models under the configurations and terms we use.

Do not submit data to an AI feature unless you are authorized to share it and the feature is appropriate for that data.

5. How Data Is Stored and Secured

Infrastructure:

  • Database: PostgreSQL hosted on Neon (encrypted at rest)
  • Application hosting and file storage: Vercel (US-based serverless infrastructure, including private blob storage for Nabu account data)
  • SMS provider: Twilio
  • Email delivery (login codes and notifications): Resend
  • Payments: Stripe
  • Google integrations: Google Ads API, Google Calendar API, and Google Maps Platform (Places and Geocoding)

Encryption:

  • Google OAuth tokens encrypted using AES-256 before storage
  • Data encrypted in transit using HTTPS (TLS)
  • Database encryption at rest via Neon
  • Login and session cookies cryptographically signed

Access Controls:

  • Restricted production access
  • Role-based access internally
  • Unique dashboard authentication tokens per customer

6. SMS Compliance (TCPA)

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes at any time. Mobile numbers and SMS opt-in consent data are used exclusively for service delivery and appointment-related communications.

We do not sell, rent, or share your mobile information with third parties or affiliates for marketing or promotional purposes. Your mobile number and consent data are only used to send you messages related to your service request, such as appointment confirmations, reminders, and follow-ups.

We may share your information with service providers (such as Twilio for SMS delivery) strictly for the purpose of delivering the requested service. These providers are not permitted to use your information for marketing or promotional purposes.

You may opt out of receiving SMS messages at any time by replying STOP. For help, reply HELP.

7. Data Sharing

Shedu does not sell personal data.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes at any time. SMS opt-in data and consent records are never included in webhook exports and are not accessible to customer-configured integrations.

We share data only as necessary to provide the Service:

With Service Providers:

  • Google (Ads API, Calendar API, Analytics)
  • Google Maps Platform (Places and Geocoding APIs — address validation and geocoding of service addresses)
  • AI model providers (see Section 4)
  • Twilio (SMS delivery)
  • Stripe (billing)
  • Resend (email delivery)
  • Cloudflare (Turnstile bot protection on the Nabu demo)
  • Vercel (application hosting and storage)
  • Neon (database hosting)

Shedu’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

With Customer-Specified Integrations:

If a customer configures outbound webhooks, lead and booking data may be sent to Zapier, Make, CRM systems, accounting platforms, or the customer’s custom endpoints. We are not responsible for how customers or third-party tools handle exported data.

We may also disclose information where required by law, to protect the Service and its users, or in connection with a merger or sale of substantially all assets, subject to this policy.

8. Cookies and Local Storage

  • Essential cookies: signed login-code and account session cookies for Nabu accounts, and dashboard session cookies. These are required for sign-in and cannot be disabled while using those features.
  • Preferences: your light/dark theme choice, stored in your browser’s local storage.
  • Attribution: campaign identifiers stored in session storage for the duration of your browser session (see Section 2.3).
  • Analytics: Google Analytics cookies used to measure site usage. You can block these with browser settings or extensions without affecting the Service.

9. Data Ownership

  • Lead and end-user data belongs to the business that collected it; Shedu acts as a data processor/service provider for that data.
  • Content you submit to Nabu and other AI features remains yours, and output generated specifically for you is assigned to you as described in our Terms of Service.
  • Customers may export their data at any time.
  • Upon cancellation, data can be exported and deleted as described in Section 10.

10. Data Retention

  • Active Accounts: Data is retained for the duration of the subscription or account.
  • Canceled Accounts: Data is retained for 30 days after cancellation, then permanently deleted. To receive an export, request it before this window closes.
  • Nabu Account Content: Saved conversations, cards, and rules are retained until you delete them or request account deletion.
  • SMS Logs and Consent Records: Retained for 12 months for compliance and dispute resolution; suppression (opt-out) records are retained as required to honor opt-outs.
  • Event and Audit Logs: Retained for 12 months.
  • Backups: Deletion from active systems may not immediately remove data from encrypted backups, which age out on the applicable backup cycle.

11. Your Rights and Requests

Customers and account holders may request export of their account data, request deletion of their account, update account information, and disable integrations. End-user leads may opt out of SMS by replying STOP, or request deletion of their data by contacting the business they hired or Shedu at support@shedu.io; we will coordinate with that business to fulfill deletion requests. Submit any request to support@shedu.io.

12. California Privacy Rights (CCPA)

If you are a California resident, you may request disclosure of the data we collect, request correction or deletion of your data, and opt out of the sale or sharing of personal data. Shedu does not sell personal data and does not share it for cross-context behavioral advertising. We will not discriminate against you for exercising these rights. Submit requests to: support@shedu.io

13. International Users (GDPR)

Shedu is based in the United States and designed primarily for North American businesses. If you are located in the European Union or are subject to the General Data Protection Regulation (GDPR), please contact us at support@shedu.io before using the Service to ensure appropriate data processing agreements are in place. We follow data minimization and security best practices and will update this policy if GDPR obligations become applicable.

14. SOC 2 Status

Shedu is an early-stage company and is not currently SOC 2 certified. We implement reasonable administrative, technical, and physical safeguards appropriate to our size and stage, and we do not represent that any independent audit or attestation has occurred.

15. Children’s Privacy

The Service, including the Game, is not intended for individuals under 18. We do not knowingly collect data from children. If we learn that we have collected personal data from a child, we will delete it.

16. Changes to This Privacy Policy

We may update this Privacy Policy periodically. Material updates will be communicated via email notice (if applicable) or website notification, and will not retroactively expand our use of previously collected data in a materially different way without any notice or consent required by law. Continued use of the Service after updates constitutes acceptance.

17. Contact Information

Wood Vault Inc. dba Shedu

Website: shedu.io

Email: support@shedu.io

Jurisdiction: North Carolina, United States

By using Shedu, you acknowledge that you have read and understood this Privacy Policy.