Legal

Privacy Policy

Effective date: [Requires input: effective date]

This Privacy Policy explains how BusinessOS™ (trybusinessos.app), operated by [Requires input: legal name of the operator] (“we”, “us”), collects, uses, stores, shares and deletes information when you use the BusinessOS web application (the “Service”), including information we receive from Google when you choose to connect your Google account.

1. Information we collect

Account information

When you create an account we collect your name, email address and password (stored only as a secure hash by our authentication provider). If you sign in with Google, we receive your name, email address, profile picture and Google account identifier from Google to create and identify your account. If you sign in with GitHub, we receive the equivalent basic profile information from GitHub.

Workspace content

Content you and your team create in BusinessOS — for example projects, tasks, CRM records, invoices, expenses, knowledge articles, messages and announcements — is stored so the Service can provide it back to you and to the members of your workspace according to their permissions.

Usage and security information

We record activity within your workspace (such as who created, changed or approved a record) to provide activity history and audit logs, and we process technical information such as session cookies needed to keep you signed in securely.

2. Google user data

Connecting Google services is optional. BusinessOS only accesses Google user data after you explicitly authorize it on Google's consent screen, and only for the scopes described below.

Gmail

If you connect a Gmail address, BusinessOS requests:

  • Read-only access to your email (gmail.readonly) — to display the messages and threads of your connected mailbox in the BusinessOS unified inbox.
  • Permission to send email on your behalf (gmail.send) — to send the replies that you write and send from BusinessOS.
  • Your email address (openid, email) — to identify which Gmail address is connected.

Email messages are retrieved from Google on demand when you open your inbox or a message, and are shown to you in your browser. BusinessOS does not copy your mailbox or the full content of your messages into its database. We send email only when you choose to send it.

One limited exception: when a new message arrives while you have the inbox open, BusinessOS creates an in-app notification for you that contains the sender's name or email address and Gmail's short preview snippet of the message. These notifications are stored with your other BusinessOS notifications and are visible only to you.

BusinessOS does not currently request access to Google Calendar or any other Google service beyond those listed in this section.

How Google user data is used

We use Google user data only to provide and improve the user-facing features you have enabled. We do not:

  • sell Google user data;
  • use or transfer Google user data for advertising, including personalized or retargeted advertising;
  • use Google user data to determine creditworthiness or for lending purposes;
  • use Google user data to develop, improve or train generalized or non-personalized artificial intelligence or machine learning models;
  • allow humans to read Google user data, except with your affirmative consent for specific messages, where necessary for security purposes (such as investigating abuse), to comply with applicable law, or where the data has been aggregated and anonymized for internal operations.

We transfer Google user data to others only as necessary to provide or improve the features you use, to comply with applicable law, or as part of a merger, acquisition or sale of assets with notice to you.

Limited Use disclosure

BusinessOS's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

3. How we use information

  • to provide, operate and maintain the Service and your workspace;
  • to authenticate you and keep your account secure;
  • to send transactional emails such as account confirmation, password resets and notifications;
  • to respond to your requests and provide support;
  • to detect, prevent and investigate abuse, fraud and security incidents;
  • to comply with legal obligations.

4. AI features

BusinessOS includes an optional AI assistant, operated by BusinessOS using AI service providers we engage. When a user asks the assistant a question, the question and relevant workspace content may be sent to one of those providers to generate a response. Data received from Google APIs (including Gmail messages) is not sent to AI providers and is never used to train AI models.

5. How we store and protect data

  • Data is transmitted over encrypted HTTPS connections.
  • OAuth access and refresh tokens for connected services are stored encrypted in a dedicated secrets store, are only accessible to the user who connected them, and are never sent to the browser or written to logs.
  • Workspace data is protected by access controls so that users can only access workspaces and records they are permitted to see.

No method of transmission or storage is completely secure, but we work to protect your information.

6. Service providers

We do not sell personal information. We share information only with service providers that process it on our behalf to operate the Service:

  • Supabase — database, authentication and encrypted credential storage;
  • Resend — delivery of transactional email;
  • [Requires input: application hosting provider] — hosting of the web application;
  • AI service providers engaged by BusinessOS (currently Groq) — only when the AI assistant is used, as described in section 4.

We may also disclose information where required by law or to protect the rights and safety of users.

7. Retention and deletion

  • Google user data. The full content of your Gmail messages is not stored in our database. OAuth tokens are kept only while the connection is active; when you disconnect a Gmail address in BusinessOS, its stored tokens are deleted immediately. New-message notifications (sender and preview snippet, described in section 2) are kept with your account's other notifications and follow the account-data retention described below. You can ask us to delete them sooner by contacting us at [Requires input: privacy contact email].
  • Revoking access. You can also revoke BusinessOS's access at any time from your Google Account at myaccount.google.com/permissions.
  • Account and workspace data. We keep your account and workspace content for as long as your account is active. After an account is closed, we retain it for [Requires input: retention period after account closure] and then delete it, unless we are required to keep it longer by law.
  • Deletion requests. You can ask us to delete your account and associated data by contacting us at [Requires input: privacy contact email].

8. Your choices and rights

You can access and update much of your information directly in the Service. Depending on where you live, you may have rights to access, correct, export, delete or restrict the processing of your personal information, or to object to it. To exercise these rights, contact us at [Requires input: privacy contact email].

9. Children

BusinessOS is a business tool and is not directed to children. We do not knowingly collect personal information from children.

10. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the effective date above and, where the changes are material, notify you through the Service or by email.

11. Contact

[Requires input: legal name of the operator]
[Requires input: operator postal address]
Email: [Requires input: privacy contact email]

See also our Terms of Service.