Privacy
Privacy Policy
Last updated: June 29, 2026
GenieDesk handles customer operations data with a simple operating principle: collect what is needed to prepare useful work, keep humans in control of approvals, and protect the context entrusted to the desk.
Overview
GenieDesk is an AI-assisted customer operations desk that helps users review customer email, gather context from connected tools, prepare replies, and propose backend actions for human approval. This Privacy Policy explains what information we collect, how we use it, and the choices you have.
By using GenieDesk, you agree to the collection and use of information described in this Privacy Policy.
Information we collect
We collect information you provide directly, information created through your use of GenieDesk, and information from services you choose to connect.
- Account information, such as your email address, display name, authentication identifiers, and workspace settings.
- Integration information, such as connected account labels, OAuth tokens, permissions, provider metadata, and the content GenieDesk needs to perform the workflows you request.
- Customer operations content, such as Gmail messages, threads, draft replies, proposed actions, playbooks, knowledge folders, synced documents, and source material you upload or connect.
- Usage and diagnostic information, such as proposal history, approval status, logs, errors, device/browser information, and security events.
- Billing information, such as subscription status, plan metadata, Stripe customer identifiers, and payment event metadata. Payment card details are handled by Stripe and are not stored by GenieDesk.
Google data we collect
When you choose to connect a Google account, GenieDesk may collect and process the Google user data needed for the specific Google features you enable.
- Google profile information, such as your name, email address, profile image, and Google account identifier, to authenticate you and show the connected account.
- Gmail data, such as message and thread metadata, labels, sender and recipient fields, subjects, message bodies, and drafts or sent messages when you approve email workflows.
- Google Calendar data, such as calendar lists, event details, attendees, times, locations, conferencing information, and calendar changes that you approve.
- Google Docs data, such as document titles, identifiers, content, comments or document structure available through the authorized APIs, and document edits that you approve.
- Google Sheets data, such as spreadsheet titles, identifiers, sheet structure, cell values, formulas, ranges, and spreadsheet edits that you approve.
- OAuth information, such as access tokens, refresh tokens, granted scopes, token type, connection status, and provider metadata needed to maintain or disconnect the integration.
How we use information
- Provide, maintain, secure, and improve GenieDesk.
- Authenticate users and protect accounts from unauthorized access.
- Connect to Gmail, Google Calendar, Google Docs, Slack, Notion, Stripe, and other services you authorize.
- Read, summarize, draft, classify, and prepare customer operations work for your review.
- Queue proposed replies and backend actions so you can approve, skip, or complete them.
- Provide customer support, troubleshoot issues, and communicate service updates.
- Process subscriptions, trials, invoices, entitlements, and billing events.
- Comply with legal obligations and enforce our Terms of Service.
Google user data
If you connect Google services, GenieDesk requests access only to the scopes needed for the features you choose to use. GenieDesk uses Google user data to provide customer email review, knowledge syncing, calendar assistance, document context, and human-approved action workflows.
GenieDesk accesses Google user data only after you authorize the connection through Google's OAuth flow. Depending on the permission level you choose, GenieDesk may use read-only access to gather context or read-write access to prepare actions that remain queued for your approval before customer-facing replies or changes are completed.
GenieDesk does not use Google user data for advertising, retargeting, personalized advertising, selling to data brokers, determining creditworthiness, lending, surveillance, or creating unrelated databases. GenieDesk does not use Google user data to train generalized AI or machine learning models.
GenieDesk personnel do not read Google message, document, spreadsheet, or calendar content unless you ask us to help with a support request, you give us permission, access is necessary for security or abuse investigation, or access is required by law.
GenieDesk's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google permissions and user control
You control whether GenieDesk can access your Google account. You can choose not to connect Google services, disconnect a Google integration in GenieDesk, or revoke GenieDesk's access from your Google Account permissions page.
When you disconnect or revoke access, GenieDesk stops using the disconnected Google account for new syncs, context gathering, drafts, or proposed actions. You can also request deletion of stored Google-derived content by contacting us at the privacy email below.
AI processing
GenieDesk may send relevant prompts, customer messages, source excerpts, proposed actions, and workflow context to AI model providers so the product can prepare replies, summarize information, and propose next steps. GenieDesk is designed to keep customer-facing replies and backend changes in a review queue until you approve them.
You are responsible for reviewing AI-prepared output before approving it. Do not use GenieDesk to process information you are not authorized to provide to the service.
How we share information
We do not sell your personal information or Google user data. We share information only as needed to operate GenieDesk, comply with law, or with your direction.
- Service providers that help us host, secure, analyze, support, and deliver GenieDesk, such as cloud infrastructure, authentication, AI model, and billing providers. These providers may process data only to provide services to GenieDesk.
- Connected integrations you authorize when GenieDesk reads data from or prepares approved actions for those services.
- Legal, safety, or compliance recipients when required to protect GenieDesk, users, customers, or the public.
- Successors in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to appropriate confidentiality protections.
Google data sharing and transfers
GenieDesk does not sell Google user data. GenieDesk transfers or discloses Google user data to third parties only when necessary to provide the user-facing features you request, comply with applicable law, protect against security threats or abuse, or complete an action you explicitly direct.
For AI-assisted features, GenieDesk may send limited excerpts of Google user data and related workflow context to AI model providers so GenieDesk can summarize messages, draft replies, classify requests, retrieve relevant context, and prepare proposed actions. We configure these providers to process that data for GenieDesk's requested functionality, not to train their generalized models.
Data retention
We retain information for as long as needed to provide GenieDesk, maintain security and audit records, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods may vary by data type, workspace configuration, legal requirements, and backup schedules.
Google OAuth tokens are retained while the integration remains connected and are deleted or invalidated when you disconnect the integration, subject to backup and security log retention. Synced Google content, proposal history, and audit records are retained while needed for your workspace features, security, support, compliance, and billing records.
When the applicable retention period expires, we delete or de-identify information unless a longer retention period is required or permitted by law. You may disconnect integrations or request deletion of account data by contacting us. Some information may remain in backups, logs, billing records, or legal compliance records for a limited period before deletion or de-identification.
Security
We use technical and organizational safeguards intended to protect information, including Google user data, against unauthorized access, loss, misuse, and alteration. These safeguards include access controls, encryption in transit, encryption or protected storage at rest for sensitive credentials, logging and monitoring, and limiting access to personnel and service providers with a need to support the service. No internet service can guarantee absolute security, so you should use strong account credentials and keep connected account access under your control.
Your choices and rights
- You can choose which integrations to connect and can disconnect integrations from GenieDesk or the provider account settings.
- You can review, approve, skip, or decline proposed actions before GenieDesk completes customer-facing or backend work.
- Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to certain processing of your personal information.
- To make a privacy request, contact privacy@geniedesk.app. We may need to verify your identity before completing the request.
Children
GenieDesk is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
International data transfers
GenieDesk and its service providers may process information in the United States and other countries. Those countries may have data protection laws that differ from the laws where you live.
Changes to this policy
We may update this Privacy Policy from time to time. We will update the date above and notify users before making a material change to how GenieDesk accesses, uses, stores, or shares Google user data. We will provide that notice prominently in GenieDesk and, when appropriate, by email. When applicable law or Google policy requires consent, we will obtain it before applying the change to your Google user data.
Contact
Questions about this Privacy Policy can be sent to privacy@geniedesk.app.