Private beta now open · Founding-cohort pricing locked through 2026 ·Request access →

Legal

Privacy Policy

Last Updated: June 28, 2026

SyncGrid Scale, operated by SyncGrid LLC ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the SyncGrid Scale boardroom — including your business intelligence profile, CRM contacts, conversation history, and connected Google Workspace data.

1. Information We Collect

Account Information

Your name, email address, and Google account profile data obtained through Firebase Authentication when you sign in.

Business Intelligence Profile

Information you share with the BI Director during interviews — business identity, customer market (ICP, pains, desires), voice and brand attributes, content strategy, and growth system details. You may store multiple business profiles per account.

CRM Data

Contacts, deal stages, interactions, notes, and follow-up schedules that you enter or that the CRM Director records on your instruction.

Conversation History

The messages you send and receive within the boardroom. We persist conversation sessions so you can return to past threads. Conversations are scoped to your account and the specific business profile under which they occurred.

Files You Upload

Documents and images you attach in the boardroom (PDFs and images, up to 5 files and 10 MB each) are sent to our AI provider to fulfill that request and are stored as part of your conversation history so the boardroom can refer back to them. We do not copy uploaded files into a separate file store or to third-party cloud storage; they reside within the encrypted session record, scoped to your account and business profile. You are responsible for the files you upload and must not upload content you are not authorized to share. See Section 9 for how long uploaded files are retained and how to delete them.

Google Workspace OAuth Tokens

When you authorize Gmail, Google Calendar, or Google Drive access, we store OAuth refresh tokens (encrypted) to enable the directors to compose and send emails, create calendar invites, and attach files on your behalf — strictly within approval-gated workflows.

Prospecting Queries

Search criteria and results when the Prospecting Director sources businesses via the Google Places API (e.g., "10 dentists in Austin matching ICP X"). Results are scoped to your business profile.

Payment Information

Payment details are processed by Stripe. We never store full credit card numbers.

Device and Usage Data

IP address (hashed), browser type, operating system, and usage events for the purpose of debugging, monitoring, and improving the service.

2. AI Training Guarantee

Your data is never used to train AI models. This includes your business profile, voice DNA, CRM contacts, conversation history, and any content generated on your behalf. Your intellectual property and customer data remain 100% yours. Generation runs on Google's Vertex AI under contracts that prohibit training on customer inputs.

3. Multi-Tenant Data Isolation

Your profile is yours alone. Every read and write of business profile data and CRM data passes through a fail-closed ownership guard that verifies your user ID against the data's owner. The guard:

  • Cannot be bypassed by any tool, agent, or director
  • Logs every blocked access for security audit
  • Scopes every query by (userId, scaleProfileId) — no cross-tenant reads

4. Google Workspace Integration

What we access via OAuth:

  • Gmail (send scope): Used to send outreach on your behalf. The directors compose each email and present it to you for review inside the app; an email is sent only after you explicitly approve it. We do not read your inbox, and we never send email without your explicit approval.
  • Calendar: Used to draft meeting invites for booked discovery calls. Approval-gated.
  • Drive (optional): Used to attach branded decks or assets when generating outreach. Approval-gated.
  • What we never do: read your existing inbox, scan your contacts, or auto-send anything without your click.

You can revoke access at any time from your Google Account permissions or from Settings inside SyncGrid Scale.

Limited Use.SyncGrid Scale's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we use Google user data only to provide and improve the user-facing features described above; we do not use it for advertising; we do not sell it; we do not transfer it to others except as necessary to provide the service, comply with applicable law, or with your explicit consent; and no human reads your Google data except where you explicitly approve an action, where necessary for security, or where required by law.

5. How We Use Your Information

  • Provide and maintain the boardroom
  • Let the directors do their work in your voice (read profile, draft outreach, manage pipeline)
  • Process subscriptions and manage your account
  • Send technical and account notices
  • Respond to support requests
  • Monitor usage to debug issues and improve the product
  • Protect against fraud and abuse
  • Comply with legal obligations

6. Data Sharing

We may share your information with:

  • Service Providers: Google Cloud Platform (infrastructure), Vertex AI (LLM inference), Firebase (authentication), Cloud SQL Postgres (session storage), Stripe (payments)
  • Legal Requirements: When required by law, court order, or government request
  • Business Transfers: In connection with mergers, acquisitions, or asset sales

We do NOT sell your personal data, profile data, or CRM data to third parties.

Law Enforcement & Government Data Requests

SyncGrid LLC maintains the following policies for handling requests from public authorities:

  • Legal Review Required: All requests are reviewed for legal validity before any disclosure
  • Right to Challenge: We reserve the right to challenge overly broad, vague, or unlawful requests
  • Data Minimization: We disclose only the minimum information necessary
  • User Notification: Unless prohibited by law or court order, we notify affected users so they may seek counsel

7. Data Security

  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption at rest (Firestore, Cloud SQL, Secret Manager)
  • OAuth refresh tokens stored exclusively in Google Secret Manager
  • Fail-closed multi-tenant isolation guard on every read/write
  • Per-customer service account isolation on Cloud Run
  • Audit logging on all profile and CRM mutations

8. Your Rights (GDPR / CCPA)

Legal Basis for Processing (GDPR)

If you are in the European Economic Area (EEA) or United Kingdom, we process your personal data under the following legal bases:

  • Consent: When you connect Gmail, Calendar, or Drive via OAuth
  • Contract: Processing necessary to provide the boardroom services you subscribed to
  • Legitimate Interests: Improving the service, preventing fraud, ensuring security
  • Legal Obligation: Complying with applicable laws and regulations

Your Data Rights

  • Right to Access: Request a copy of your data
  • Right to Deletion: Request permanent deletion of your account and associated data
  • Right to Portability: Export your profile and CRM data in JSON format
  • Right to Correction: Update your information at any time
  • Right to Withdraw Consent: Revoke OAuth permissions; we delete associated tokens within 24 hours

To exercise any of these rights, contact us at joey@syncgrid.io. We will respond within 30 days.

9. Data Retention

  • Profile and CRM data: Retained until you delete the profile or your account
  • Conversation history: Retained until you delete the conversation or your account
  • Uploaded files and documents: Stored within the associated conversation and deleted when you delete that conversation or your account
  • OAuth tokens: Retained while connection is active; deleted immediately upon revocation
  • Audit logs: 365 days (compliance)
  • Payment records: As required by tax law

10. Cookies

We use essential cookies for authentication and session persistence. Analytics cookies are used only with your consent. You can manage cookie preferences in your browser settings.

11. Children's Privacy

SyncGrid Scale is not intended for individuals under 18. We do not knowingly collect personal information from minors. If we learn that we have collected such data, we will delete it promptly and terminate the associated account.

12. International Transfers

Your data may be processed in the United States. We ensure appropriate safeguards are in place for international transfers in compliance with GDPR.

13. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via email or in-app notification. Continued use after changes constitutes acceptance.

14. Contact Us

Privacy requests and questions: joey@syncgrid.io

SyncGrid LLC — Registered in Texas, USA