/ LEGAL
Privacy Policy
Effective: July 11, 2026
1. Who we are
2. Data we collect
- Account data, name, email address, and authentication identifiers when you sign up or are invited to a workspace.
- Connected source content, when a workspace member connects a source (Google Gmail, Google Drive, Slack, or a custom API), we ingest the content that source exposes (e.g. email text, document text, channel messages) so it can be searched and used to answer your team's questions.
- Usage and audit data, actions taken in the product (syncs, queries, configuration changes) are recorded in workspace audit logs, along with technical logs needed to operate the service.
3. How we use data
4. Google user data
When you connect a Google account, CiteSilo requests access to Gmail (gmail.readonly to read and ingest your email, and gmail.send so an automation you configure can send email on your behalf), Google Drive (drive.file, which limits our access to only the files and folders you explicitly choose through the Google Picker, not your entire Drive), plus your basic profile (email address and name). We use this access only to provide CiteSilo's features: ingesting your content into your private workspace index so you can search it and ask questions about it, and sending email only when a workspace admin sets up an automation that does so.
CiteSilo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- Google data is used only to provide user-facing features of CiteSilo, search and cited answers inside your workspace.
- We do not use Google data for advertising, and we do not sell it.
- Humans do not read your Google data except with your explicit permission (e.g. support), where required for security or abuse investigation, or where required by law.
- OAuth tokens are encrypted at rest (AES-256-GCM). Disconnecting Google deletes the stored tokens and purges the ingested content from your workspace.
5. Service providers (subprocessors)
6. Storage, security, and data location
CiteSilo runs on European infrastructure. Your workspace content is stored in the EU (Supabase, Ireland), and the AI processing that answers your questions and embeds your text runs in the EU (Google Cloud Vertex AI, Netherlands). Your content is not used to train AI models.
Data is encrypted in transit (TLS) and at rest. Source credentials and OAuth tokens are additionally encrypted with AES-256-GCM application-layer encryption. Workspaces are isolated with row-level security; access within a workspace is controlled by roles (admin, member, viewer) and per-source visibility settings. All sensitive actions are written to an audit log visible to your workspace admins.