Privacy Policy
Effective June 4, 2026. This policy describes the data ExecOS processes on behalf of customers and the choices available to you.
1. Who we are
ExecOS ("we", "us") provides a workspace where executive assistants manage calendars, inboxes, meetings, contacts, and related artefacts for the executives they support. For customer-uploaded data, ExecOS acts as a data processor; the customer workspace is the controller.
2. What we collect
- Account data: name, email, password hash, sign-in provider, last sign-in.
- Workspace content: meetings, notes, agendas, tasks, contacts, inbox items, trips, weekly reports, and other records you create.
- Billing data: processed by Stripe; we store subscription status, plan, and customer/subscription IDs only.
- Operational logs: request metadata, error traces, audit logs of sensitive actions (role changes, invites, deletions, exports).
3. How we use it
To deliver the service, authenticate users, enforce workspace isolation, generate AI summaries you request, send transactional email, and meet legal obligations. We do not sell personal data and we do not use customer content to train third-party models.
4. Subprocessors
We rely on a small set of vetted providers to deliver the service. A current list:
- Supabase — managed Postgres + auth (EU/US regions).
- Cloudflare — edge runtime, DNS, and content delivery (global).
- Lovable AI Gateway — model routing for AI features (US).
- Stripe — billing and payments (US/EU).
- Google (Calendar, Gmail, Drive) — only when an executive connects their own Google account through Settings → Integrations.
- Slack — workspace messaging, only when a workspace admin connects Slack.
- Email delivery provider — transactional mail (auth, invites, receipts).
4a. Third-party integrations and scopes
ExecOS only requests the scopes it needs to deliver features you actively use. Tokens are stored encrypted, scoped per executive, and revocable at any time from Settings → Integrations. Assistants only see the integrations the executive has explicitly granted them. We never use customer content to train third-party models, and we do not retrieve data outside the listed scopes.
- Google Calendar —
calendar.events,calendar.readonly. Read meetings for the executive's dashboard and calendar views; create or update events when the executive or their assistant schedules through ExecOS. - Gmail —
gmail.send,gmail.modify. Send follow-ups drafted in ExecOS from the executive's own address; mark inbox items as handled when the assistant triages them. ExecOS does not read the full mailbox. - Google Drive —
drive.file(restricted). ExecOS can only see files it creates or files the user explicitly opens with it. It cannot list, read, or modify the rest of the drive. - Slack —
chat:write,channels:read. Post workspace digests and meeting notifications to the channels the admin selects.
If Google or Slack access is revoked from the provider, ExecOS surfaces the disconnection in the Integrations page and stops attempting to use those scopes.
5. Security
Data is encrypted in transit (TLS) and at rest by our managed database provider. Tenant isolation is enforced with row-level security policies. Service-role credentials are server-only. See our Security page for details.
6. Your rights
You can export your workspace as JSON from Settings → Account. You can permanently delete your account and (if you are the sole admin) the entire workspace from the same screen. EEA/UK residents may exercise GDPR rights by emailing privacy@execos.app.
7. Retention
Active workspace content is retained while your account exists. On deletion, we remove your records from the live database immediately and from encrypted backups within 30 days.
8. Contact
Questions, GDPR requests, and data-protection enquiries: privacy@execos.app. This address reaches our Data Protection contact. We respond within 30 days.