PersonaOS
Privacy Policy
Effective July 2, 2026
PersonaOS provides AI digital employees for teams. An AI employee drafts work grounded in the company context you explicitly connect, and its output is held for human review before anything leaves your workspace. This policy explains what data we access, how we use it, and the controls you keep.
What we access, and only with your consent
PersonaOS accesses external sources only after the account owner completes the provider's own consent screen, and only with read-only scopes:
- Google Workspace: Gmail messages (read-only), Google Drive files (read-only), and Google Calendar events (read-only) when you select those sources.
- Microsoft 365: Outlook mail (read), OneDrive files (read), and calendar events (read) when you select those sources.
PersonaOS does not request send, write, or delete permissions on your mailbox or files. Connecting a source is per-workspace and per-source; nothing is accessed before consent.
How we use this data
- Synced content is stored as your workspace's grounding corpus so your AI employee can cite real company context in the drafts it produces for your review.
- Relevant excerpts are processed by large-language-model providers to generate drafts and summaries. This processing is transient; we do not permit our model providers to train their models on your data, and we do not use your data to train our own or any generalized AI/ML models.
- We do not sell your data, use it for advertising, or share it with third parties beyond the infrastructure subprocessors that run the product (hosting, database, and model providers).
PersonaOS's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Storage and security
- Synced documents and workspace data are stored in our managed Postgres database (Supabase), encrypted at rest and in transit.
- OAuth tokens are stored server-side only, are never exposed to the browser, and are used solely to run the syncs you consented to.
- Every AI action is audit-logged, and external actions are gated behind human approval.
Retention, revocation, and deletion
- You can disconnect any source from your workspace settings at any time, which stops all syncing for that source.
- You can also revoke PersonaOS's access directly at your Google Account permissions or your Microsoft account's app permissions.
- To delete synced content or your workspace entirely, contact us at dabraventuresllc@gmail.com and we will delete it within 30 days.
Contact
Questions about this policy or your data: dabraventuresllc@gmail.com.
See also our Terms of Service.