How your data is handled
What your assistant collects, who processes it, how long it is kept, and what happens when you disconnect or delete.
Your assistant works from the data you connect. This page is what happens to it.
What is collected
Only what you connect, at the scope you grant. When you link a service, the permissions requested are the ones that connection actually needs — not the widest set the provider would hand over. You can see and change what each connection reaches at any time in Connections.
Beyond connected services, your assistant holds what you give it directly: saved instructions, memories, contacts, files you share with it, and the record of tasks it has carried out.
Your data is not used to train models
Not ours, and not our providers'. This is contractual, not a preference — our AI providers are prohibited from training on customer data.
The operational data that makes the product work — error rates, latency, whether a task succeeded — is used to improve the software, in the way any product uses telemetry. That is a different category from the substance of your messages and files.
Who else processes it
Your data reaches a small number of categories of provider, each under contract:
| Category | Why |
|---|---|
| Cloud infrastructure | Where the product runs and data is stored |
| AI providers | Language understanding, reasoning, generating drafts |
| Communications | Sending email and messages on your behalf |
| Payments | Billing, where applicable |
The specific vendors, and the terms they operate under, are published by whoever provides your assistant — those belong to a company rather than to the product, so they live on that company's trust or privacy pages rather than here.
Separation between customers
Your data is isolated from every other customer's. That boundary is not left to convention — it is enforced on the paths that read data, and verified as ongoing work rather than a one-time check.
The same principle applies inside your own account. When your assistant negotiates a meeting time with someone else's assistant, that exchange works from availability alone — not the titles of your meetings or who is in them.
How long things are kept
| What | How long |
|---|---|
| Administrative audit records | Retained. Kept in versioned, access-restricted storage with no expiry |
| Operational logs and telemetry | Bounded windows, expiring automatically |
| Your content — messages, tasks, files, memories | Kept for the life of your account, subject to deletion below |
Audit records are retained and versioned. That is deliberately not the same claim as tamper-proof, and we would rather say the accurate one.
Disconnecting and deleting
Disconnect a service and your assistant stops using it. Access ends at that point.
Delete your account and a deletion process runs across your data. It is worth knowing precisely what that does, because "everything is erased" would be an overstatement:
| Data | What happens |
|---|---|
| Chats, and memories about you | Deleted |
| Memories you authored about others | Content kept, your authorship removed |
| Contacts | Unlinked from you; contact details preserved |
| Tasks | Closed rather than deleted |
| Task history in shared threads | Anonymised — your identifiers removed, the message body kept |
The reason is that some of this sits in threads other people are still part of. Removing one participant's copy of a shared conversation would take away someone else's record of their own work. That is a considered trade-off rather than an oversight — but it is not deletion, and calling it deletion would be wrong.
Task closure is the guarantee for account deletion as described here. One narrower, legacy account-removal path does not yet carry the same guarantee — we are closing that gap rather than leaving it unstated.
If you need particular content removed rather than an account closed, ask. Your rights over your data, and how to exercise them, are in the privacy policy published by whoever provides your assistant.
Related
- Connections — what each service can reach, and changing it
- Guardrails — the limits that hold regardless of your Autonomy settings
- Security controls — for administrators