1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Your name and email address
- Organization name and billing information
- User preferences and settings
1.2 Gmail Integration Data
To provide the Service, we access your Gmail account through Google OAuth and collect:
- Email metadata (sender, recipient, subject, date)
- Email content for AI processing and categorization
- Email attachments (PDF, Word documents, images)
- OAuth access tokens (encrypted and securely stored)
1.3 Usage Information
We automatically collect information about how you use the Service:
- Number of emails processed
- Attachment processing counts
- Feature usage patterns
- Login activity and session data
- Browser type, device information, and IP address
1.4 Payment Information
Payment processing is handled by Stripe. We do not store your full credit card information. Stripe collects and processes payment information according to their privacy policy at https://stripe.com/privacy.
2. How We Use Your Information
We use the collected information to:
- Provide and operate the Service: Process and categorize your emails using artificial intelligence
- Generate AI-powered email drafts: Create suggested responses based on email content
- Process attachments: Extract text from PDFs, Word documents, and images (OCR)
- Manage your account: Handle authentication, billing, and subscription management
- Monitor usage: Track usage against your subscription tier limits
- Improve the Service: Analyze usage patterns to enhance features and performance
- Send communications: Provide service updates, billing notifications, and support
- Ensure security: Detect and prevent fraud, abuse, and security threats
3. AI Processing and Third-Party Services
3.1 Anthropic Claude API
We use Anthropic's Claude API to process your email content for categorization and draft generation. Important: Anthropic does not use customer data to train their AI models. Your email content is processed in real-time and is subject to Anthropic's privacy practices at https://www.anthropic.com/privacy.
3.2 Data Processing
- Email content is processed in memory and is not permanently stored on our servers
- We store only email metadata (sender, subject, category, timestamp) in our database
- Draft responses are generated on-demand and stored temporarily
- Your actual email content remains in your Gmail account at all times
5. Data Security
We implement industry-standard security measures to protect your information:
- Encryption in transit: All data transmitted using TLS/SSL encryption (HTTPS)
- Encryption at rest: Database and OAuth tokens encrypted using industry-standard algorithms
- Access controls: Role-based permissions ensure users can only access their organization's data
- Secure infrastructure: Hosted on SOC 2 Type II certified platforms (Heroku)
- Regular security audits: Ongoing monitoring and vulnerability assessments
- OAuth 2.0: Google-approved authentication (we never see your Gmail password)
While we implement strong security measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
6. Your Rights and Choices
You have the following rights regarding your information:
6.1 Access and Portability
You can request a copy of your personal data by contacting us at support@focustaradvisors.com. We will provide your data in a structured, machine-readable format.
6.2 Correction and Update
You can update your account information and preferences at any time through the Service settings.
6.3 Deletion
You can request deletion of your account and associated data through the Service or by contacting us. Upon deletion request, we will:
- Revoke OAuth access to your Gmail account
- Delete your account data within 30 days
- Retain only information required for legal or business purposes (e.g., billing records)
6.4 Revoke Access
You can revoke our access to your Gmail account at any time through your Google Account settings at https://myaccount.google.com/permissions. This will immediately disable the Service.
7. Data Retention
We retain your information as follows:
| Data Type | Retention Period |
|---|---|
| Account data | Retained while your account is active |
| Email content | Processed in real-time, not permanently stored |
| Usage data | Retained for 24 months for service improvement |
| Billing records | Retained for 7 years as required by law |
| Audit logs | Retained for 90 days for security purposes |
8. International Data Transfers
Our servers are located in the United States. If you access the Service from outside the U.S., your information will be transferred to, stored, and processed in the United States. By using the Service, you consent to this transfer.
9. Children's Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information, please contact us and we will delete such information.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new Privacy Policy on this page and updating the "Effective Date" above. We will also send you an email notification for significant changes. Your continued use of the Service after changes become effective constitutes acceptance of the revised Privacy Policy.
12. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to Know: Request disclosure of personal information collected, used, or shared
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out: We do not sell personal information
- Right to Non-Discrimination: We will not discriminate against you for exercising your rights
To exercise these rights, contact us at support@focustaradvisors.com.
13. European Privacy Rights (GDPR)
If you are in the European Economic Area (EEA), you have rights under the General Data Protection Regulation (GDPR):
- Right of Access: Obtain confirmation and a copy of your data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your data
- Right to Restrict Processing: Limit how we use your data
- Right to Data Portability: Receive your data in a portable format
- Right to Object: Object to processing based on legitimate interests
To exercise these rights or file a complaint with a supervisory authority, contact us at support@focustaradvisors.com.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy, please contact us:
Focustar Advisory Services LLC