Privacy

Your data principals' rights are real, automated, and on the clock.

Access, rectification, erasure, portability, objection, restriction - responded to within the regulator's deadline, every time.

30 days
DPDP Act erasure SLA
1 month
GDPR subject access SLA
0 backlog
Every DSR SLA met since launch

Last updated 13 August 2026

Google user data

When you connect a Google account to WorkSwarm, you grant access to specific data in that account. This section states exactly what WorkSwarm accesses, what it does with it, and how you take the access back. Nothing here is accessed until you connect the relevant product, and WorkSwarm only ever uses the account you connected - never another person's Google account. Depending on how your workspace is configured, a connection you make may be usable by your teammates' agents and automations inside that workspace.

Google productWhat WorkSwarm accessesHow it is used
GmailMessage metadata and content, labels, drafts, and the ability to send on your behalf.Reads your inbox to build the Email queue, classify what needs a reply, and write a short summary of each thread. Prepares draft replies you review. Sends only the messages you approve, or a campaign you explicitly dispatch. Applies labels you ask for.
Google CalendarEvents on the calendars you connect, and your free/busy times.Lists your schedule in chat, creates and updates events you ask for (including interview and meeting scheduling), and finds focus slots or a time that works across attendees.
Google Drive, Docs, and SheetsFile metadata (name, type, size, modified time, link), file and document content you or an automation opens, search results, sharing permissions, and a feed of what changed.Lets you search and read your files from chat, indexes the files you connect so answers can cite them, and mirrors Drive sharing so a file is only visible in Workswarm to people who can already see it in Drive. Writes (uploading a file, updating a Doc, writing to a Sheet) happen only on an action you confirm.
Google ContactsRead-only: names and contact details from your connections list.One-time import into your Workswarm contact list, deduplicated against contacts you already have. Workswarm never writes to Google Contacts.
Google sign-inYour email address, name, and Google account identifier.Creating and signing you into your Workswarm account. Nothing else.

Sharing and transfer

WorkSwarm does not sell Google user data, does not use it for advertising, and does not transfer it to anyone for those purposes. It is processed by our service providers only to deliver the feature you asked for: AI model providers (Anthropic, Google, OpenAI) when your request needs a model to read or draft something; an embedding provider (AWS Bedrock, or a service WorkSwarm hosts itself) when a connected file is indexed so you can search it; and Composio, the broker behind some Google connections, including the Google Contacts import. Each processes the data only on our instructions and under contract, and none of them is permitted to use it for their own purposes. Our sub-processor register names the third parties that process customer data and is updated with 30 days' notice before a new one goes live. Within WorkSwarm, Google data stays inside your workspace and inherits the sharing you already have in Google.

Limited Use

WorkSwarm's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use Google user data only to provide and improve the features described above; we do not transfer it except as needed to provide those features, to comply with applicable law, or as part of a merger or acquisition with notice; we do not use it for advertising; and no human reads it except with your explicit consent, to resolve a support issue you raise, for security purposes, or where required by law. WorkSwarm does not use Google Workspace APIs data - Gmail, Calendar, Drive, Docs, Sheets, or Contacts content - to develop, improve, or train generalized artificial intelligence or machine learning models. Model providers process this data only to answer the specific request you made, under agreements that prohibit training on it.

What is stored, and for how long

Most Google data is read live and not retained. What WorkSwarm keeps is the minimum needed for the feature to work between requests:

  • Gmail: message and thread identifiers, sender, subject, a priority label, and a summary of about 280 characters. Raw message bodies are not stored. The inbox view you see is cached for five minutes and then discarded.
  • Drive, Docs, and Sheets: file identifiers and metadata, the sharing permissions used to reproduce your access, and text content of files you index so they can be searched and cited.
  • Calendar: nothing is stored. Events are read live each time you ask.
  • Contacts: the names and contact details you import, held as WorkSwarm contacts from then on.
  • Sign-in: your email, name, and Google account identifier, held for as long as your account exists.

Retained Google data is kept for as long as the connection exists and your workspace uses it, or until you delete it, subject to any shorter retention period your organization sets.

Revoking access and deleting your data

  • Disconnect the connector in WorkSwarm under Settings, Connectors. WorkSwarm stops calling that Google account immediately and its tools stop working for every agent and automation.
  • Revoke WorkSwarm directly in your Google Account at myaccount.google.com/permissions. This invalidates the token independently of WorkSwarm.
  • Delete imported contacts or indexed files from within WorkSwarm at any time.
  • Request erasure of everything derived from your Google account by emailing dpo@workswarm.ai. We complete erasure requests within 30 days, or 15 days under the DPDP Act, across primary storage, derived caches, and search indexes, on the same terms as every other right described below.
  • Deleting your WorkSwarm account removes the stored connection and the Google-derived records above.

Matches (personal and professional connections)

Matches is optional. If you never open it, none of this applies to you.

What we collect and publish

Only the fields you explicitly reviewed on the publish screen are published to the Matches directory: your short intro, connection intents, interest tags, languages, availability, meeting modes, location preference, and country. These fields are free text you wrote yourself, so anything you type into them - including your name or a phone number, if you choose to type one - is published. Review each field before you publish. Your imported chat history, your private notes, your draft profile, and your interview answers are never published.

Blocking and reporting

Every candidate you see in Matches carries a block or report control. Blocking is permanent and works both ways: neither of you will see the other in Matches again. They are never told.

Declining an introduction

If you decline an introduction request, that pair is suppressed permanently, the same way a block is. Neither of you will be matched with the other again.

Erasure

Delete my Matches data removes your directory subject and your published profile from the directory. Two things survive erasure by design: publication receipts, because they are the immutable evidence that we honoured your earlier choices, and pair suppressions from blocks and declined introductions, because deleting a suppression would let a person you blocked or declined reach you again.

Portability

Your data export includes your own published Matches profile data and the introductions you initiated. It never includes another person's private data, even when that person appears in an introduction you initiated.

Local desktop data

Anything you import from Claude or ChatGPT, and the private profile built from it, stay encrypted on your own computer in the WorkSwarm desktop app. We never receive them. You can delete this local data at any time from the Matches local setup panel on the desktop app. Deleting it is local-only and does not touch your published profile.

Grievance path

Complain to our Grievance Officer, Vijay Varma Srivatsavai, at grievance@workswarm.ai. We acknowledge every grievance within 24 hours and resolve it within 15 days. If we do not resolve your complaint, you may complain to the Data Protection Board of India.

How to exercise these rights

If you are signed in, use the privacy section under Settings to access, export, or erase your Matches data, or to raise a grievance. If you are not signed in, or no longer have an account, use the public grievance intake page, which does not require an account.

The eight data subject rights

Right to Access

Request all data tied to you across services. Verified via email, MFA, or government ID. Portable export (JSON/CSV) within 30 days (15 days for DPDP Act).

Right to Rectification

Correct any data. Lineage records before-and-after state for audit.

Right to Erasure

Cascade across all storage: primary, derived caches, search indexes, backup catalogs. Backups: cryptographic erasure (key destruction). Audit logs pseudonymized but retained.

Right to Portability

Structured export (JSON, CSV) of your conversation history, project artifacts, and member metadata.

Right to Object

Stops processing under contested purposes. Principal-specific processing-suspension flag honored across all services.

Right to Restrict

Data may be stored but not actively used. Queries respect the restriction marker.

Right to Automated decisions

WorkSwarm's AI is advisory - high-blast-radius actions require human approval. This right is satisfied by design.

Right to Non-discrimination

You cannot be denied service or charged differently for exercising any right. Contractually prohibited.

Consent management

Every collection of sensitive data carries a consent token that records:

  • Who consented (data principal identifier)
  • When (timestamp, signed)
  • What for (purpose code from controlled list)
  • Until when (expiry - defaults to purpose completion)
  • By what method (clickwrap, signed form, voice, parental)
  • Withdrawal record (if revoked)

Withdrawal triggers cessation of processing, deletion or de-identification, and downstream sub-processor notification.

Retention & deletion

Data classDefault TTL
Conversation message7 years (audit)
Voice recording90 days
AI prompt log30 days redacted, 7 years pseudonymized
Audit log7 years (SOC 2, SOX, IRDAI)
User profileUntil deletion request + 30-day grace
Billing record8 years (Companies Act)

PII redaction at every boundary

Every outbound boundary - LLM provider, connector, audit destination, SIEM - passes through a configurable redaction layer.

AadhaarAlways redacted unless within Aadhaar Vault scope
PANRedacted to last-4
Credit cardRejected - WorkSwarm does not process card data
PhonePseudonymized to deterministic hash for analytics
EmailPseudonymized for analytics, real for outbound delivery
Free-text PIIDetected via regex + NER; redacted in logs, surfaced to user

Privacy contacts

Data Protection Officer
dpo@workswarm.ai
Grievance Officer (India, IT Rules 2021)
grievance@workswarm.ai
EU Representative (GDPR Art. 27)
eu-rep@workswarm.ai
UK Representative (UK GDPR)
uk-rep@workswarm.ai