Privacy Policy
1. Information We Collect
Account Information
When you register, we collect your name, email address, and password (stored as a secure hash). If you authenticate via a third-party provider (e.g., Google), we receive basic profile information from that provider.
Usage Data
We automatically collect information about how you interact with SmoothiePlace, including pages visited, features used, agent configurations created, and conversation logs generated through the platform.
User-Provided Content
We store content you create within the platform: AI agent configurations, system prompts, uploaded documents (for RAG indexing), and conversation histories between your agents and your end users.
Third-Party API Queries
If you enable third-party integrations for your agents, we process the data required to fulfill those queries on your behalf and on behalf of your end users, as instructed by you. Authentication for those integrations is handled by Composio (see Section 3).
Technical Information
We collect IP addresses, browser type, device identifiers, and log data for security and operational purposes.
2. How We Use Your Information
- Provide, operate, and maintain the SmoothiePlace platform.
- Process your instructions and run AI agents on your behalf.
- Send transactional emails (account verification, password reset, billing notifications).
- Improve the platform through aggregated, anonymized analytics.
- Detect, prevent, and address fraud, abuse, and security incidents.
- Comply with legal obligations.
We do not sell your personal data to third parties. We do not use your data to train AI models without your explicit consent.
3. Data Sharing and Disclosure
Service Providers
We share data with trusted sub-processors that help us operate the platform:
- Composio Inc. — delegated authentication and tool execution for third-party integrations (composio.dev). Composio manages the OAuth flows, securely stores and refreshes the access and refresh tokens for the external accounts you connect (such as Google Workspace, GitHub, Slack, or Notion), and executes the API calls your agents request against those accounts on your behalf. See Section 4 for details on how this applies to Google user data.
- Supabase — database and authentication (supabase.com)
- Anthropic — AI model inference (anthropic.com)
- Google Cloud — embedding models and infrastructure
- Railway — cloud hosting (railway.app)
- Zoho — transactional email
These providers are contractually bound to handle your data only as directed and in compliance with applicable privacy laws.
Where Your Data Is Processed
Our sub-processors operate cloud infrastructure located primarily in the United States. When your agent executes an action against a connected third-party account, the request metadata and payload transit through Composio's infrastructure in order to be authenticated and forwarded to the destination service. If you are located outside the United States, this constitutes an international transfer of data.
Legal Requirements
We may disclose information if required by law, court order, or governmental authority, or to protect the rights, property, or safety of SmoothiePlace, our users, or the public.
4. Google API Services — User Data
What Google Data We Access
When you choose to connect your Google account to enable the Personal Assistant agent, SmoothiePlace may request access to the following Google services on your behalf, using only the scopes you explicitly authorize:
- Gmail (
gmail.modify) — Read, search, and send emails to allow your agent to retrieve, draft, and respond to messages as you instruct. - Google Drive (
drive) — List, read, and create files in your Drive so your agent can retrieve documents or create new ones on your request. - Google Docs (
documents) — Read and write Google Docs documents so your agent can draft, edit, or extract content from documents on your behalf. - Google Slides (
presentations) — Create, read, and edit Google Slides presentations so your agent can generate decks or retrieve slide content on your behalf. - Google Calendar (
calendar) — List and create calendar events so your agent can schedule, check availability, or create reminders on your behalf. - Google Sheets (
spreadsheets) — Read and write data to spreadsheets you specify, enabling your agent to log information, generate reports, or retrieve records.
How We Use Google User Data
Google user data accessed through the above scopes is used exclusively to perform the specific actions you direct your agent to take. We do not use this data for any other purpose, including:
- We do not sell or transfer your Google user data to third parties.
- We do not use your Google user data to serve advertisements.
- We do not use your Google user data to train AI models.
- We do not allow humans to read your Google user data, except as necessary to provide or improve user-facing features, or where required by law.
Who Holds Your Google Credentials
SmoothiePlace does not store your Google OAuth access or refresh tokens. Authentication is delegated to Composio Inc., our integrations sub-processor, which conducts the OAuth flow, holds those tokens encrypted at rest and in transit under its own security standards, refreshes them as needed, and executes the Google API calls your agent requests. SmoothiePlace never receives your Google password, and never has plain-text access to your Google tokens.
This is a change from an earlier version of this policy: until July 2026 SmoothiePlace operated its own Google OAuth integration and stored those tokens directly. That integration has been retired and replaced by Composio.
There is one category of credential that SmoothiePlace does store, and it is a different thing: the credentials for the channels you deploy your agents to — for example a Telegram bot token, or a Slack bot token and signing secret. These let your agent receive and answer messages on that channel; they do not grant access to your personal accounts. They are stored encrypted at rest, and are never shared with Composio.
SmoothiePlace stores no other access credentials on your behalf.
Data Retention for Google User Data
The content of your emails, files, calendar events, and spreadsheet data is processed in memory to execute your agent's actions and is not persisted to our databases beyond the duration of a single session, unless you explicitly configure your agent to store specific data.
Google user data is never used to train foundation models, ours or anyone else's, and is not transferred to any party other than those strictly necessary to execute the action you requested (namely Composio, as the authentication and execution layer, and Google itself).
Your Control
You can disconnect a Google account at any time, by either route:
- From SmoothiePlace — in your integrations panel. Disconnecting there instructs Composio to delete the stored connection and its tokens; it is a revocation, not merely a hidden entry.
- From Google directly — on your Google Account permissions page, which revokes the grant at the source.
After revocation by either route, your agent can no longer access any Google service until you reconnect.
Scope Justifications
- gmail.modify — Required to allow the agent to both read incoming emails and send/reply to emails as instructed. Read-only scope is insufficient because the Personal Assistant use case requires composing and sending messages on the user's behalf.
- drive — Required to read file content from Google Drive and to create new files as requested. The narrower drive.readonly scope is insufficient when users need the agent to create or update files.
- documents — Required to read and write Google Docs documents. Used when the agent drafts new documents, edits existing ones, or extracts structured content from Docs files.
- presentations — Required to create, read, and edit Google Slides presentations. Used when the agent generates presentation decks or reads slide content as context.
- calendar — Required to list events and to create new events. calendar.readonly is insufficient for the scheduling use case.
- spreadsheets — Required to both read spreadsheet data and write to spreadsheets for logging, CRM updates, and record keeping.
5. Data Retention
We retain your account data for as long as your account is active. Conversation logs are retained for a maximum of 12 months by default. You may request deletion of your data at any time by contacting us at [email protected].
Upon account termination, we delete or anonymize your personal data within 30 days, except where retention is required by law.
6. Data Security
We implement industry-standard security measures including TLS encryption in transit, encryption at rest, Row-Level Security (RLS) in our database, and regular access reviews. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
7. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access — request a copy of the personal data we hold about you.
- Correction — request correction of inaccurate data.
- Deletion — request deletion of your personal data.
- Portability — receive your data in a machine-readable format.
- Opt-out — opt out of non-essential communications.
To exercise any of these rights, contact us at [email protected].
8. Cookies
We use strictly necessary cookies to maintain your authentication session. We do not use tracking or advertising cookies. You can configure your browser to refuse cookies, but this may affect platform functionality.
9. Children's Privacy
SmoothiePlace is not directed to individuals under 18 years of age. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal information, please contact us immediately.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page with an updated effective date and, where appropriate, by email. Your continued use of the platform after changes constitutes acceptance of the updated policy.
11. Contact
For questions, requests, or concerns about this Privacy Policy, please contact:
- Email: [email protected]
- General: [email protected]
- Website: smoothieplace.ai