PRIVACY POLICY
How EngineDeck handles your information
Last updated September 18, 2026
The short version. EngineDeck reads the business information a company owner chooses to connect, stores it in a private workspace that belongs to that company, and uses it to show what needs attention with links back to the original records.
EngineDeck never sends, edits, moves or deletes email. Disconnecting a source hides its content immediately, and you can ask us to delete it permanently.
Who we are
EngineDeck ("we", "us") provides a private company workspace that brings information from a business's connected sources into one view. This policy covers the EngineDeck website at enginedeck.ai and the EngineDeck company workspace. It applies to the business owner who connects sources and to the members that owner adds to the company workspace.
What we collect
- Account information. Your name, work email address and password hash for signing in, and your membership in a company workspace.
- Connected source content. When a company owner connects a source, we import a bounded window of recent records from it. For Gmail this is message headers (sender, recipients, subject, date, labels), message text, provider identifiers and links back to the original message. Attachments are not imported.
- Derived information. Classifications, relationship and project notes, and other findings we generate from the connected content, always stored with references to the exact source records they came from.
- Usage and audit records. Sign-ins, source connections and disconnections, scheduled jobs, AI usage counts and costs, and other events needed to operate and secure the service.
- Contact form details. If you write to us through the website, the name, email, business name and message you provide.
We do not sell personal information and we do not use connected content for advertising.
Google user data
If a company owner connects a Google account, EngineDeck requests read-only access to Gmail (the gmail.readonly scope) and nothing else. We use that access only to:
- import a bounded window of recent messages into the company's private workspace, on a schedule the owner controls;
- show the owner which recent messages may need a reply, and which organizations and people the business works with, each linked to the original message in Gmail;
- build cited notes about projects, decisions, commitments and open questions from that correspondence.
EngineDeck cannot send, draft, modify, label, archive or delete messages, and does not request access to Calendar, Drive, Contacts or your Google profile beyond the account address used to connect.
Google refresh tokens are stored encrypted in a managed secrets vault, referenced by company, and are never written to ordinary database rows, logs or messages. Disconnecting Gmail in the workspace immediately hides all imported content and findings, revokes our access with Google, and removes the stored token.
EngineDeck's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
AI processing
To produce findings, EngineDeck sends limited excerpts of connected content to an AI model provider under our own account. Requests are made with storage disabled where the provider supports it, and no person reviews your content to train models. Every finding we show is stored with links to the specific source records it was based on, so you can check it yourself. Each company has a daily AI spending cap; when it is reached, processing pauses rather than failing silently.
Sharing
We share information only with the service providers needed to run EngineDeck: hosting and database infrastructure, the AI model provider described above, and email delivery for contact-form notifications. Each processes information on our behalf under their own terms. We do not share one company's content with another company, and we do not share connected content with advertisers or data brokers. We may disclose information if required by law or to protect the safety and integrity of the service.
Retention and deletion
- While connected. Imported content is kept in the company workspace so findings can cite it. Older records outside the configured window are not imported unless the owner requests a bounded historical import.
- On disconnect. Imported content and derived findings are hidden immediately and stop appearing anywhere in the workspace.
- On request. A company owner can ask us to permanently delete the content imported from a source. See the data deletion page for the process and what is retained.
- Operational records. Audit, usage and billing ledgers are retained as needed for security, accounting and legal obligations. They contain counts and identifiers, not message text.
Security
Every stored record is labelled with the company it belongs to, and database access rules enforce that separation for every query. Credentials are encrypted at rest in a managed vault. Scheduled processing runs with company-scoped access and is checked against current membership at every step. Connections to Google and our providers use TLS. No system is perfectly secure, and we will notify affected owners if we become aware of a breach involving their data.
Your choices
- Connect or disconnect a source at any time from the workspace.
- Correct or dismiss any finding from within the workspace.
- Ask us to export, correct or delete information we hold about you or your company by contacting us below.
- Remove EngineDeck's access from your Google account at any time at myaccount.google.com/connections. We detect the removal on the next scheduled sync and hide the imported content.
We do not knowingly collect information from children under 16. EngineDeck is a business service.
Contact
Questions or requests about this policy: privacy@enginedeck.ai. We will update this page when our practices change and note the date above.