[ LEGAL ]

Privacy Policy

1. Information we collect

We collect information you provide directly, including your name, email address, and authentication data. When you create a Squadroom workspace, we collect the configuration data, organization details, and third-party API credentials that you provide to power your agents.

We also automatically collect platform usage data. This includes dashboard interaction logs, agent task histories, system events, and diagnostic information necessary to keep the platform reliable.

For payments, we process billing details securely via our payment provider. We do not store credit card numbers on our servers.

2. Data isolation and security

Each customer workspace is isolated. Your data, agent history, and API credentials are kept separate from other customers through access controls that restrict data to its owning workspace.

We transmit all data securely over HTTPS/TLS. API keys provided for BYOK (Bring Your Own Key) integrations are encrypted at rest and are never accessible by our support team or shared with other customers.

3. Third-party sub-processors and AI routing

Squadroom utilizes trusted third-party services to deliver our platform. These sub-processors include:

  • Dodo Payments: For secure payment processing and subscription management.
  • Convex: Our backend and database platform, which stores your account, workspace, and application data.
  • PostHog: For product analytics, which helps us understand usage patterns and improve the platform.
  • Composio: For third-party tool and integration connectivity, which brokers authorized access to the external services you connect.
  • Telegram: For messaging integrations, where webhook data is processed strictly to facilitate communication between your workspace and your Telegram groups.

When your agents interact with language models, our platform securely routes requests to the providers associated with the API keys you provide. These providers (e.g., OpenAI, Anthropic) process your data in accordance with their respective API privacy policies, which generally stipulate that API data is not used to train shared or public models.

4. How we use your data

We use your data strictly to operate, maintain, and improve the Squadroom platform. This includes executing your autonomous agent tasks, maintaining your dashboard state, processing your payments, and communicating with you regarding security updates or platform changes.

We do not sell your personal information, user data, or your agent activity logs to third parties under any circumstances. We do not use your proprietary workspace data to train our own foundation models.

5. Data retention and deletion

We retain your personal data and workspace information for as long as your account remains active. When you delete an agent or task, it is removed from your workspace immediately.

If you choose to delete your Squadroom account, we will initiate a hard deletion of your personal data, workspace configurations, and agent logs from our active databases within 30 days. Encrypted backups may be retained for an additional 60 days for disaster recovery purposes before being permanently destroyed.

6. Your data rights (GDPR & CCPA)

You maintain full control over your personal data. Depending on your jurisdiction, you have the right to:

  • Access a copy of the personal data we hold about you.
  • Correct any inaccuracies in your personal data.
  • Export your data in a portable, machine-readable format.
  • Request complete erasure of your account and associated information (the "right to be forgotten").

To exercise any of these rights, please contact us at [email protected] from the email address associated with your account. We will process your request within 30 days.

7. Changes to this policy

We may update this policy periodically as our platform evolves or as legal requirements change. Material changes will be communicated via email to the primary account holder and via an in-app notice in your dashboard. Your continued use of Squadroom after such changes constitutes acceptance of the updated privacy practices.

Last updated: June 2026