Privacy Policy
Last updated: 2 June 2026
This Privacy Policy explains how Gatherly ("Gatherly", "we", "us") collects, uses, stores, and protects information when you use our application at gatherly.tech and related services (the "Service"). By using the Service you agree to this policy.
Information we collect
- Account information — your name, email address, organisation, and authentication details.
- Content you provide — documents, notes, contacts, and settings you add to the Service.
- Connected-service data — data we access on your behalf from services you connect (see below).
- Usage and diagnostic data — logs and error reports used to operate and improve the Service.
Google user data we access
When you connect a Google account, Gatherly requests only the scopes needed to provide its features, and only accesses data to deliver functionality you initiate:
- Gmail (read, modify, compose, and basic settings) — to triage your inbox, apply labels/smart folders, summarise threads, and draft replies and emails that you review, approve, and send.
- Google Drive (read-only) — to index documents you choose into your Knowledge Base and to use as source material for content.
- Google Calendar (read and events) — to show your schedule, prepare meetings, and create or update events you request.
- Basic profile and email — to identify your connected account.
How we use this data
Connected-service data is used solely to provide and improve the user-facing features described above (for example, generating an email draft you asked for, or surfacing the right document). We do not use it for advertising, and we do not sell it.
Limited Use disclosure
Gatherly's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use Google user data to provide or improve user-facing features that are prominent in the Service.
- We do not transfer or sell Google user data for advertising, marketing, or other purposes.
- We do not allow humans to read Google user data unless we have your consent for specific messages, it is necessary for security or to comply with law, or the data is aggregated and anonymised for internal operations.
- We do not use Google user data to train generalised AI/ML models. Where AI features process your data, it is to produce output for you in that moment and is not used to train third-party foundation models.
How we store and protect data
Data is stored in our infrastructure provider, Supabase (PostgreSQL), with row-level security isolating each organisation's data. Access tokens are stored securely and used only to make requests on your behalf. We use industry-standard safeguards to protect your information.
Sharing and third parties
We share data only with infrastructure and processing providers that help us run the Service — for example Google (the APIs you connect), Supabase (database and hosting), Stripe (billing), and AI processing providers used to generate features you request. We do not sell your data.
Data retention and deletion
We retain your data while your account is active. You can disconnect any Google account at any time from Settings → Integrations, which revokes our access. You may also revoke access directly at your Google Account permissions. On account deletion we remove your data within a reasonable period, except where retention is required by law.
Your choices
- Connect or disconnect services at any time.
- Request access to, correction of, or deletion of your data.
- Contact us with any privacy question.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above.
Contact
Questions about this policy? Email privacy@gatherly.tech.
