1. Scope and who we are
This Privacy Policy applies to Operator AI's websites, applications, AI agents, dashboards, integrations, and related services (the “Service”). “Operator AI,” “we,” “us,” and “our” refer to the provider of the Service. Questions or privacy requests can be sent to contact@operatorai.dev.
2. Information we collect
Account and workspace information
We process identifiers and settings such as your name, email address, organization, workspace membership, authentication details, preferences, agent instructions, approval rules, and support communications.
Connected-service information
When you connect a third-party service, we receive the data and permissions needed to provide the features you request. The exact information depends on the integration and the permissions you grant.
Usage and technical information
We process service activity, agent runs, tool calls, audit events, browser and device information, IP address, error logs, and security signals to operate, secure, troubleshoot, and improve the Service.
3. Google user data
Operator AI may request access to the following Google data after you choose to connect a Google account:
- Google identity: your Google account identifier, name, profile information, and email address for authentication and account linking.
- Gmail: messages, threads, labels, attachments, drafts, and mailbox state needed to search, summarize, organize, draft, or perform user-approved mailbox actions.
- Google Calendar: calendars, events, attendees, availability, and event details needed to review schedules and perform user-approved calendar actions.
- Google Drive: metadata and content for files the Service creates or that you select or open with Operator AI, as permitted by the Google Drive file scope.
- Google Docs: document content and structure needed to read, create, or update documents at your direction.
Operator AI only accesses Google user data after authorization and uses it to provide visible product features, execute your instructions, maintain workspace context, and secure or support the integration.
4. How we use information
- Provide, personalize, and maintain the Service and connected integrations.
- Retrieve context, answer questions, prepare drafts, run approved workflows, and keep user-configured agents operating.
- Authenticate users, protect accounts, detect abuse, investigate failures, and maintain audit records.
- Provide support, communicate service notices, and comply with applicable law.
- Analyze product reliability and improve features using aggregated or de-identified information where practical.
We do not sell Google user data, use it for targeted advertising, or use it to train generalized AI models.
5. AI processing and service providers
To provide AI-assisted features, relevant portions of your instructions and connected data may be sent to contracted infrastructure, hosting, authentication, observability, and AI model providers acting on our behalf. We limit this processing to what is needed to provide and secure the feature you requested and require providers to protect the information under applicable agreements.
Human access is limited to circumstances such as support you request, security and abuse investigation, legal compliance, or situations where you give permission.
6. Google API Services User Data Policy
Operator AI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. How we share information
We may share information with service providers processing data for us; integrations and recipients you direct us to use; your workspace administrators and authorized members; and authorities or other parties when reasonably necessary for legal compliance, safety, fraud prevention, or protection of rights. Information may also transfer as part of a merger, financing, acquisition, or sale of assets, subject to appropriate safeguards.
8. Storage, retention, and deletion
We retain information while your account or integration is active and as needed to provide the Service, meet contractual or legal obligations, resolve disputes, prevent abuse, and maintain security records. OAuth access and refresh credentials are stored in access-controlled application infrastructure while the connection remains active.
You can disconnect Google inside Operator AI and revoke Google access from your Google Account permissions. You may request account or data deletion by emailing contact@operatorai.dev. Deletion from active systems may take time to propagate through limited-duration backups and legally required records.
9. Security
We use administrative, technical, and organizational safeguards designed to protect information, including access controls, environment isolation, secure transport, monitoring, and audit mechanisms. No system is completely secure, and we cannot guarantee absolute security.
10. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information. You may also withdraw consent where processing relies on consent. Contact us to make a request; we may need to verify your identity.
11. International processing and children
Information may be processed in countries other than where you live, subject to applicable transfer safeguards. The Service is intended for business users and is not directed to children under 13 or the minimum age required in their jurisdiction.
12. Changes and contact
We may update this policy as the Service or legal requirements change. We will publish the updated policy here and revise the effective date. Material changes may also be communicated through the Service or by email.
Privacy questions and requests: contact@operatorai.dev.