Infinite State Machines LLC
Privacy Policy

Privacy Policy

This Privacy Policy describes how Infinite State Machines LLC collects, uses, discloses, and retains personal information collected through dfsm.ai, BOS applications and MCP services, connected third-party providers, classes pages, public lead forms, and lead-generation campaigns.

Effective date: August 25, 2026 Operator: Infinite State Machines LLC Contact: cody.marcel@dfsm.ai
Summary: we process account, business-workflow, and connected-provider information to authenticate users, operate requested BOS workflows and integrations, respond to inquiries, secure our systems, and support customers. We do not sell personal information or connected Google user data, and we do not use connected Google user data for advertising.

1. Scope

This Privacy Policy applies to information we collect online from visitors, prospects, customers, and other users through:

This policy does not apply to third-party websites, applications, or services that we do not control, even if they link to us or integrate with our campaigns.

2. Categories of personal information we collect

The categories of personal information we collect depend on how you interact with us. In the preceding 12 months, we have collected or may collect the following categories:

Category Examples Why we collect it
Identifiers and contact information Name, email address, phone number, and similar lead-form fields. To respond to inquiries, send requested follow-up, schedule demos or classes, and maintain lead records.
Inquiry and lead details Product or class interest, use case, requested tier, answers submitted in a form, campaign or landing-page source. To route leads, understand what you asked for, personalize follow-up, and measure campaign effectiveness.
Internet or network activity information IP address, browser type, device details, timestamps, referring page, and server request logs. To operate, secure, troubleshoot, and improve our websites and forms, and to prevent abuse or fraud.
Professional or commercial information Company, role, business context, or operational needs if you provide them. To understand the context of your request and determine whether our offerings are a fit.
BOS account and authorization information Verified email, user identifier, organization and application membership, role, installation scope, OAuth grant metadata, and provider-connection status. To authenticate you, enforce tenant and role boundaries, maintain authorized connections, and audit access.
Connected-provider data Data you authorize BOS to access from Google or another provider, which may include calendar events, email messages or metadata, files, spreadsheets, contacts, advertising data, and associated account identifiers, depending on the scopes you approve. To perform the specific BOS workflow or integration you request and to return the requested result.
Business workflow and MCP activity Prompts or commands sent to BOS, tool calls, workflow inputs and outputs, approvals, operational records, status, errors, and audit events. To execute, secure, troubleshoot, document, and improve authorized BOS operations.
Education or child-related information you choose to submit Child name or age, class preference, or family context, if a form specifically requests it and you provide it. To process class-related inquiries and respond to the request you submitted.

3. Sources of personal information

We collect personal information from the following sources:

4. How we use personal information

We may use personal information for the following business and commercial purposes:

5. Google user data and connected providers

BOS accesses Google user data only after you grant permission through Google's OAuth process. The exact data available to BOS depends on the scopes displayed during consent and the BOS integration you choose to connect. BOS uses that data only to provide or support the user-facing workflow you request, maintain the authorized connection, protect the service, and comply with law.

We do not sell Google user data, use it for advertising, or allow humans to read it except when you direct us to do so, when limited access is necessary for security or support with your permission, when required by law, or when the data has been aggregated and anonymized for internal operations. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

OAuth tokens and provider credentials are stored in managed credential storage and are used only for the connected provider and authorized BOS scope. You can revoke Google's access at Google Account third-party connections. You may also disconnect a provider through the applicable BOS connection settings or email cody.marcel@dfsm.ai with the subject Disconnect Provider.

6. Meta or Facebook lead ads

If you submit a lead form through Meta or Facebook, Meta may collect information in accordance with its own terms, policies, and settings before transmitting lead information to us. Once we receive that information, we process it under this Privacy Policy. We use those leads to respond to the request reflected in the ad or form, record the lead in our intake systems, and evaluate campaign performance.

7. Cookies, server logs, and similar technologies

Our websites and infrastructure may automatically record technical information such as IP address, browser type, device information, timestamps, and requested URLs in server logs. We use this information for site operation, security, troubleshooting, and basic performance monitoring.

If we later deploy analytics, advertising, or similar tracking technologies that materially change our data practices, we will update this Privacy Policy and any related disclosures as required by applicable law.

8. How we disclose personal information

We may disclose personal information to the following categories of recipients:

We do not sell personal information for monetary consideration. We also do not disclose personal information to unrelated third parties for their own direct marketing.

9. Retention

We retain personal information for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, including lead management, follow-up, recordkeeping, security, dispute resolution, and legal compliance. Retention periods may vary depending on the type of information and the nature of the relationship or inquiry.

Connected-provider data is retained only for as long as reasonably necessary to operate the requested integration, maintain required business or audit records, resolve disputes, protect the service, and comply with law. Provider credentials are retained while the connection remains active and are deleted or disabled when the connection is disconnected or a verified deletion request is fulfilled, subject to legal and security retention requirements.

10. Data security

We use reasonable administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. No method of transmission over the internet or method of electronic storage is completely secure, so we cannot guarantee absolute security.

11. Your privacy rights, deletion, and revocation

Depending on where you live and subject to applicable law, you may have the right to request access to personal information we maintain about you, request correction, request deletion, or appeal a decision about a privacy request. Some laws also provide the right to request information about categories of data collected, sources, purposes of use, and categories of disclosures.

To submit a privacy request, email cody.marcel@dfsm.ai with the subject line Privacy Request. We may need to verify your identity before fulfilling a request. Rights are not absolute and may be limited by applicable law.

To request deletion of BOS-hosted personal information or connected-provider data, use the same email address with the subject Delete My Data and identify the relevant BOS account or organization. To stop future Google access immediately, revoke the BOS connection through Google Account third-party connections. Revocation stops future authorized access but does not itself delete information that BOS must retain for security, legal, or legitimate business recordkeeping; submit a deletion request for that review.

12. Do Not Track

Some browsers offer a “Do Not Track” setting. Because there is not a universally accepted standard for responding to these signals across all websites and services, we do not currently respond to browser-based Do Not Track signals in a uniform way.

13. Children’s privacy

Our websites and services are generally directed to adults, parents, operators, and business users. We do not knowingly sell the personal information of minors under 16. If you believe a child has provided personal information to us in a way that is inconsistent with applicable law, contact us and we will investigate and take appropriate action.

14. International transfers

Our business is based in the United States, and information we collect may be stored or processed in the United States or other jurisdictions where our service providers operate. By using our websites or submitting information to us, you understand that your information may be transferred to and processed in the United States.

15. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will revise the effective date at the top of the page. Your continued use of our websites or submission of information after an updated policy becomes effective means the updated policy will apply from that point forward.

16. Contact information

If you have questions about this Privacy Policy or our privacy practices, contact:

Infinite State Machines LLC
Email: cody.marcel@dfsm.ai
Website: https://dfsm.ai

This page is the privacy-policy URL for BOS applications and MCP services, connected-provider integrations, public pages, classes pages, lead forms, and campaigns operated by Infinite State Machines LLC.