Privacy Policy
This Privacy Policy explains how GroundCrew Labs ("GroundCrew Labs", "we", "us") handles personal information when you use our website and our service — the control panel at admin.groundcrewlabs.ai and the artificial-intelligence agents we operate for our clients (together, the "Service"). It is written to be read, not to hide behind.
If you have a question, or want to exercise a right described below, email privacy@groundcrewlabs.ai.
1. Who this covers
The Service is provided to businesses and to the people they invite to use it. Where a client connects the Service to its own systems and accounts, that client is the controller of the information processed on its behalf and we act as its processor; this policy describes what we do with that information as well. If you are an individual whose information reached us through a client's use of the Service, your first point of contact is that client.
2. Information we collect
Information you give us
- Account details — your name, email address and password, and the organisation, role and contact details used to set up and administer your access. Authentication is handled through our authentication provider; we do not store passwords in readable form.
- Support and correspondence — the content of messages you send us.
Information from the systems you connect
The agents we operate can be connected, at your direction, to outside services — for example a Google account, a messaging account, a code repository or a document store. When you connect one, you authorise the agent to read and act on the data that service exposes within the permissions you grant. That can include the content of email and messages, calendar events, files and their contents, contact records, and the metadata that accompanies them. We process exactly the data the granted permissions allow and nothing more.
Google user data
This section describes our handling of data obtained through Google APIs (programming interfaces). It applies when you or your organisation connect a Google account to an agent.
We request only the Google scopes (permissions) needed for the features your agent has been granted:
| Scope | What it allows |
|---|---|
gmail.readonly | Read Gmail messages and metadata. |
gmail.modify | Read, compose, and manage Gmail messages. |
gmail.send | Send email from the connected mailbox. |
calendar.readonly | Read calendars and events. |
calendar | Read and edit calendars and events. |
drive.readonly | Read files in Google Drive. |
drive | Read, create and edit files in Google Drive. |
spreadsheets.readonly | Read spreadsheets. |
documents | Read, create and edit Google Docs. |
spreadsheets | Read, create and edit Google Sheets. |
contacts | Read and manage contacts. |
userinfo.email |
See the connected account's email address, so we can show you which account is connected. |
- How we use it. Solely to provide the features you or your organisation asked for through the agent — for example summarising or answering mail, scheduling and updating events, reading or producing documents and spreadsheets, or looking up a contact.
- How we store it. An OAuth refresh token (a standing permission to act on the account) is kept encrypted in our secrets store and never leaves our control plane; a short-lived access token is issued to the agent only when it needs to call Google. Where the agent needs to work on the content of a message or file, it is processed to produce the result and is not kept longer than that requires, except where you ask us to keep a derived result (for example a meeting summary in your own document store).
- Who can see it. Access is limited to the systems and staff that operate and support the Service, on a need-to-know basis, and is logged. See section 6.
- How to remove it. Disconnect the account in the Service, or revoke our access from your Google Account permissions page (myaccount.google.com/permissions). We then delete the stored token and stop processing the account's data.
Limited Use disclosure. GroundCrew Labs' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, we do not use it for advertising, and we do not use it to train or improve generalised artificial-intelligence or machine-learning models.
Usage and technical information
- Service usage — records of actions, feature use, and the cost of any model or vendor calls, so we can operate, meter and bill the Service.
- Device and log information — IP address, approximate location derived from it, browser and device type, timestamps, and security events, kept to run and protect the Service.
Cookies and similar technologies
We use the cookies strictly necessary to sign you in and keep your session secure; without them the dashboard cannot work. We do not use advertising cookies, and we do not sell information gathered from cookies.
3. How we use information
- To provide, operate, maintain and improve the Service.
- To carry out the tasks you and your organisation ask the agents to perform.
- To authenticate you and keep the Service secure, including detecting and preventing abuse.
- To measure usage, cost and performance.
- To provide support and communicate with you about the Service.
- To comply with law and enforce our agreements.
4. Artificial intelligence and model providers
Agents use large-language models, some run on our own infrastructure and some provided by third parties, to understand requests and produce results. Content an agent needs to work on is sent to the model provider that serves the agent. We configure and contract so that this content is processed to answer the request, is not used to train the provider's models, and is not used for advertising. Model output can be wrong; it is a draft, not a decision, and you should review it before relying on it.
5. How we share information
We do not sell personal information. We share it only as described here:
- Service providers (subprocessors) — companies that host or run the Service for us, bound by contract to use the information only to provide their service to us. They include cloud hosting, storage and secrets management (Amazon Web Services); database and authentication (Supabase); model providers (including OpenRouter, Anthropic, OpenAI and Google); the outside services you connect (for example Google, Meta, Telegram, Slack, Notion, GitHub, and self-hosted services such as Nextcloud and Forgejo); and contact data sources used for research. A current list is available on request.
- Your organisation — if you use the Service through a client, that client and its administrators.
- Legal and safety — where required by law, to respond to valid legal requests, to protect the rights, property or safety of anyone, or to investigate abuse.
- Business transfers — in connection with a merger, acquisition or sale of assets, subject to this policy.
6. Who can access your data
Our staff can access the Service and the data in it only as needed to run, support, secure and develop it, under access controls and logging. We do not let staff read the content of your email, messages, files or documents except where necessary to provide support you asked for, to investigate a security or abuse issue, or to comply with law.
7. Data retention
We keep personal information for as long as needed to provide the Service and for the purposes described in this policy, then delete or de-identify it. A Google account's stored token is kept until you disconnect the account or ask us to delete it. Closing your organisation's account, or asking us, removes the data we hold for it, except what we must keep for legal, security or accounting reasons. Some information survives in backups for a limited period before it is overwritten.
8. Security
We use administrative, technical and physical measures designed to protect personal information against unauthorised access, loss or alteration — including encryption in transit and at rest, scoped access, secrets held outside the machines that use them, and activity logging. No method of transmission or storage is perfectly secure, so we cannot promise absolute security.
9. International transfers
We and our service providers may process information in countries other than the one you are in. Where required, we put contractual safeguards in place for those transfers.
10. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent. To exercise a right, email privacy@groundcrewlabs.ai. If your information reached us through a client, we will refer your request to that client and help them respond. You can also disconnect any connected service at any time, and revoke a Google account's access at myaccount.google.com/permissions.
We do not sell personal information and we do not share it for cross-context behavioural advertising, so no "opt out of sale" is needed.
11. Children
The Service is for businesses and is not directed to children. We do not knowingly collect personal information from children.
12. Changes to this policy
We may update this policy from time to time. When we do, we change the "last updated" date above, and for a material change we will take reasonable steps to let you know. Continuing to use the Service after an update means you accept the revised policy.
13. Contact us
GroundCrew Labs — privacy@groundcrewlabs.ai.