Privacy policy

Plain language, because a policy nobody understands protects nobody. Working name deployment; the product's final name will replace it here.

What we store

Your account email and password hash. The OAuth refresh tokens or API keys for accounts you connect (Google, Slack, HubSpot, Stripe), encrypted at rest with keys bound to your organization. A log of every call made with your API keys that records the shape of each request — which service, which endpoint, status, duration — and never its contents.

What we never do

We never sell or share your data. We never read your connected accounts except when your own API key asks a tool to. One organization's credentials and data are never reachable from another organization's requests: the database enforces this with row-level security, and each connected platform enforces it again because the credential is yours, not ours.

Google user data

This application's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google data is read only when a tool call you authorized requests it, is never used for advertising, and is never transferred except to serve that tool call back to you.

Deletion

Disconnecting a service deletes its stored credential immediately. Revoking an API key stops it immediately. To delete your account and everything it stored, email the address below and it happens within 30 days.

Contact

eugeniu.ghelbur@singlegrain.com · policy last updated 2026-07-30