Your data principals' rights are real,
automated, and on the clock.
Access, rectification, erasure, portability, objection, restriction - responded to within the regulator's deadline, every time.
Last updated 13 August 2026
Google user data
When you connect a Google account to WorkSwarm, you grant access to specific data in that account. This section states exactly what WorkSwarm accesses, what it does with it, and how you take the access back. Nothing here is accessed until you connect the relevant product, and WorkSwarm only ever uses the account you connected - never another person's Google account. Depending on how your workspace is configured, a connection you make may be usable by your teammates' agents and automations inside that workspace.
| Google product | What WorkSwarm accesses | How it is used |
|---|---|---|
| Gmail | Message metadata and content, labels, drafts, and the ability to send on your behalf. | Reads your inbox to build the Email queue, classify what needs a reply, and write a short summary of each thread. Prepares draft replies you review. Sends only the messages you approve, or a campaign you explicitly dispatch. Applies labels you ask for. |
| Google Calendar | Events on the calendars you connect, and your free/busy times. | Lists your schedule in chat, creates and updates events you ask for (including interview and meeting scheduling), and finds focus slots or a time that works across attendees. |
| Google Drive, Docs, and Sheets | File metadata (name, type, size, modified time, link), file and document content you or an automation opens, search results, sharing permissions, and a feed of what changed. | Lets you search and read your files from chat, indexes the files you connect so answers can cite them, and mirrors Drive sharing so a file is only visible in Workswarm to people who can already see it in Drive. Writes (uploading a file, updating a Doc, writing to a Sheet) happen only on an action you confirm. |
| Google Contacts | Read-only: names and contact details from your connections list. | One-time import into your Workswarm contact list, deduplicated against contacts you already have. Workswarm never writes to Google Contacts. |
| Google sign-in | Your email address, name, and Google account identifier. | Creating and signing you into your Workswarm account. Nothing else. |
Sharing and transfer
WorkSwarm does not sell Google user data, does not use it for advertising, and does not transfer it to anyone for those purposes. It is processed by our service providers only to deliver the feature you asked for: AI model providers (Anthropic, Google, OpenAI) when your request needs a model to read or draft something; an embedding provider (AWS Bedrock, or a service WorkSwarm hosts itself) when a connected file is indexed so you can search it; and Composio, the broker behind some Google connections, including the Google Contacts import. Each processes the data only on our instructions and under contract, and none of them is permitted to use it for their own purposes. Our sub-processor register names the third parties that process customer data and is updated with 30 days' notice before a new one goes live. Within WorkSwarm, Google data stays inside your workspace and inherits the sharing you already have in Google.
Limited Use
WorkSwarm's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use Google user data only to provide and improve the features described above; we do not transfer it except as needed to provide those features, to comply with applicable law, or as part of a merger or acquisition with notice; we do not use it for advertising; and no human reads it except with your explicit consent, to resolve a support issue you raise, for security purposes, or where required by law. WorkSwarm does not use Google Workspace APIs data - Gmail, Calendar, Drive, Docs, Sheets, or Contacts content - to develop, improve, or train generalized artificial intelligence or machine learning models. Model providers process this data only to answer the specific request you made, under agreements that prohibit training on it.
What is stored, and for how long
Most Google data is read live and not retained. What WorkSwarm keeps is the minimum needed for the feature to work between requests:
- Gmail: message and thread identifiers, sender, subject, a priority label, and a summary of about 280 characters. Raw message bodies are not stored. The inbox view you see is cached for five minutes and then discarded.
- Drive, Docs, and Sheets: file identifiers and metadata, the sharing permissions used to reproduce your access, and text content of files you index so they can be searched and cited.
- Calendar: nothing is stored. Events are read live each time you ask.
- Contacts: the names and contact details you import, held as WorkSwarm contacts from then on.
- Sign-in: your email, name, and Google account identifier, held for as long as your account exists.
Retained Google data is kept for as long as the connection exists and your workspace uses it, or until you delete it, subject to any shorter retention period your organization sets.
Revoking access and deleting your data
- Disconnect the connector in WorkSwarm under Settings, Connectors. WorkSwarm stops calling that Google account immediately and its tools stop working for every agent and automation.
- Revoke WorkSwarm directly in your Google Account at myaccount.google.com/permissions. This invalidates the token independently of WorkSwarm.
- Delete imported contacts or indexed files from within WorkSwarm at any time.
- Request erasure of everything derived from your Google account by emailing dpo@workswarm.ai. We complete erasure requests within 30 days, or 15 days under the DPDP Act, across primary storage, derived caches, and search indexes, on the same terms as every other right described below.
- Deleting your WorkSwarm account removes the stored connection and the Google-derived records above.
Matches (personal and professional connections)
Matches is optional. If you never open it, none of this applies to you.
What we collect and publish
Only the fields you explicitly reviewed on the publish screen are published to the Matches directory: your short intro, connection intents, interest tags, languages, availability, meeting modes, location preference, and country. These fields are free text you wrote yourself, so anything you type into them - including your name or a phone number, if you choose to type one - is published. Review each field before you publish. Your imported chat history, your private notes, your draft profile, and your interview answers are never published.
Blocking and reporting
Every candidate you see in Matches carries a block or report control. Blocking is permanent and works both ways: neither of you will see the other in Matches again. They are never told.
Declining an introduction
If you decline an introduction request, that pair is suppressed permanently, the same way a block is. Neither of you will be matched with the other again.
Erasure
Delete my Matches data removes your directory subject and your published profile from the directory. Two things survive erasure by design: publication receipts, because they are the immutable evidence that we honoured your earlier choices, and pair suppressions from blocks and declined introductions, because deleting a suppression would let a person you blocked or declined reach you again.
Portability
Your data export includes your own published Matches profile data and the introductions you initiated. It never includes another person's private data, even when that person appears in an introduction you initiated.
Local desktop data
Anything you import from Claude or ChatGPT, and the private profile built from it, stay encrypted on your own computer in the WorkSwarm desktop app. We never receive them. You can delete this local data at any time from the Matches local setup panel on the desktop app. Deleting it is local-only and does not touch your published profile.
Grievance path
Complain to our Grievance Officer, Vijay Varma Srivatsavai, at grievance@workswarm.ai. We acknowledge every grievance within 24 hours and resolve it within 15 days. If we do not resolve your complaint, you may complain to the Data Protection Board of India.
How to exercise these rights
If you are signed in, use the privacy section under Settings to access, export, or erase your Matches data, or to raise a grievance. If you are not signed in, or no longer have an account, use the public grievance intake page, which does not require an account.
The eight data subject rights
Right to Access
Request all data tied to you across services. Verified via email, MFA, or government ID. Portable export (JSON/CSV) within 30 days (15 days for DPDP Act).
Right to Rectification
Correct any data. Lineage records before-and-after state for audit.
Right to Erasure
Cascade across all storage: primary, derived caches, search indexes, backup catalogs. Backups: cryptographic erasure (key destruction). Audit logs pseudonymized but retained.
Right to Portability
Structured export (JSON, CSV) of your conversation history, project artifacts, and member metadata.
Right to Object
Stops processing under contested purposes. Principal-specific processing-suspension flag honored across all services.
Right to Restrict
Data may be stored but not actively used. Queries respect the restriction marker.
Right to Automated decisions
WorkSwarm's AI is advisory - high-blast-radius actions require human approval. This right is satisfied by design.
Right to Non-discrimination
You cannot be denied service or charged differently for exercising any right. Contractually prohibited.
Consent management
Every collection of sensitive data carries a consent token that records:
- Who consented (data principal identifier)
- When (timestamp, signed)
- What for (purpose code from controlled list)
- Until when (expiry - defaults to purpose completion)
- By what method (clickwrap, signed form, voice, parental)
- Withdrawal record (if revoked)
Withdrawal triggers cessation of processing, deletion or de-identification, and downstream sub-processor notification.
Retention & deletion
| Data class | Default TTL |
|---|---|
| Conversation message | 7 years (audit) |
| Voice recording | 90 days |
| AI prompt log | 30 days redacted, 7 years pseudonymized |
| Audit log | 7 years (SOC 2, SOX, IRDAI) |
| User profile | Until deletion request + 30-day grace |
| Billing record | 8 years (Companies Act) |
PII redaction at every boundary
Every outbound boundary - LLM provider, connector, audit destination, SIEM - passes through a configurable redaction layer.