Privacy Policy
Effective September 18, 2026 · Version 2026.09.18
Privacy Policy
The Deliberate Company, LLC — Deliberate
Effective date: 18 September 2026 Last updated: 18 September 2026
1. Our approach: your data stays yours
Deliberate is built local-first, and privacy is a core promise, not a footnote. The most important things to understand:
- Your email and calendar content stay in your own accounts and on your own Mac. The Deliberate desktop application works directly against your connected Google and/or Microsoft accounts. We do not copy the contents of your emails, calendar events, or documents to our servers, we do not store them on our servers, and we do not write them to disk on our side. Anything we hold server-side about your usage is limited account and metadata, not your message contents.
- The AI runs on your own Anthropic Claude account, not through us. We do not send your content to an AI model on our servers; Deliberate uses your own Claude subscription, and that processing is governed by your agreement with Anthropic.
This policy explains the limited personal information the getdeliberate.ai website and our registration/licensing service do collect, and — in §7 and §8 — exactly how the application accesses and uses the Google and Microsoft data you authorize.
2. Who we are
The Deliberate Company, LLC (“Deliberate,” “we,” “us”) is the controller of the personal information described here. Contact: [email protected], 35 W. Main Street, Unit 2272, Frisco, CO 80443.
3. Information we collect
Information you give us
- Waitlist: your name, email, and optionally mobile number, company name, company size, operating system, which apps/tools you use, and a short free-text note about what you’re trying to fix. We also record which page the request came from.
- Account: your name and email, and the identity from your Google or Microsoft sign-in (an account identifier and verified email). We do not receive or store your Google/Microsoft password.
- Billing: your subscription status and history. Payment card details are collected and processed by Stripe, not by us — we do not store your full card number.
- Support: anything you send us when you contact support.
Information from your connected accounts (processed on your device, not warehoused)
- To provide the Service, the desktop app accesses your Google and/or Microsoft email and (where enabled) Google Calendar, under the permissions you grant. This access happens on your Mac, against your own accounts. We do not store this content on our servers. The specific scopes and uses are itemized in §7 (Google) and §8 (Microsoft).
Information collected automatically
- License activation & validation: when you activate Deliberate on a device,
the app sends a signed sign-in token from Google or Microsoft to our server so we
can verify your identity and confirm your subscription; the app re-validates
periodically. We record the fact and time you last activated (
last_activated_at) and issue your device a signed license credential. - Activated devices: so you can see and manage where Deliberate is installed, we record for each activation a device name, the platform, a device identifier generated by the app, and when that device last checked in. You can view your activated devices and remove any of them from your account page; removing one revokes that device’s credential. This record holds nothing about how you use the app and no content from your connected accounts.
- Software updates: the desktop app checks for and installs updates automatically. The update check is an anonymous request for the latest version — it carries no account identifier and is not used for tracking.
- Operational logs & security data: basic website/app logs (e.g., IP address, timestamps, error diagnostics) needed to run and secure the Service.
- Bot protection: Cloudflare Turnstile on sign-up forms may process limited technical signals to tell humans from bots.
- Email delivery status: when we email you (e.g., an invite), our provider Resend reports delivery events (delivered, bounced) so we can manage the list.
- Cookies and website analytics: the website sets strictly-necessary cookies — a signed session cookie and a CSRF-protection token — to keep you logged in and secure. The website also uses Google Analytics (via Google Tag Manager) to understand traffic. Analytics and advertising storage are denied by default and enabled only where you consent or where consent is not legally required; we do not use these signals for cross-site advertising. Google Analytics runs on the website only — there is no analytics or tracking of any kind inside the desktop app.
- App telemetry (DRAFT — telemetry initiative 2026-09; founder + counsel review pending): the desktop app reports that it is running and how it is behaving — when the app is open, which version you run, your device’s OS and architecture, your general region (country and state/province only), and operational counts such as errors, speed, and usage volumes. What it never reports: no email content, no message text, no subject lines, no calendar contents, no rule contents, and no third-party analytics of any kind in the app. Your IP address is used only to resolve that general region and is discarded immediately — never stored, never logged. Raw telemetry records expire after 30 days; only aggregate statistics are kept longer. We can technically link activity to an account; we do not — any query at the individual level is written to an audit log, and nothing about how you use the app is ever sent to our marketing systems.
4. How we use information and our legal bases
We use personal information to: create and manage your account and licenses; verify licenses and provide, secure, and improve the Service; process your subscription and send required billing notices (including the 5/3/1-day pre-charge reminders); operate the waitlist and send invitations; respond to support; and comply with law.
Where GDPR/UK GDPR applies, our legal bases are: performance of a contract (providing the Service and billing), legitimate interests (securing and improving the Service, preventing abuse, managing the waitlist), consent (where required, e.g., certain marketing and the scopes you grant to connect an account), and legal obligation (e.g., tax records).
We do not sell your personal information, and we do not “share” it for cross-context behavioral advertising as those terms are defined under California law (CCPA/CPRA). We do not use data obtained through Google or Microsoft APIs for advertising (see §7, §8).
5. Who can access your account
Access to account data is limited to authorized Deliberate staff who need it to operate the Service and provide support. For troubleshooting, authorized staff may temporarily act on behalf of an account (“impersonation”); this is restricted to staff, logged, and used only to diagnose and resolve issues. Staff cannot see your email or calendar content, because that content is never stored on our servers.
6. Service providers and subprocessors
We use a small set of vetted providers to operate the Service. Stripe processes payments as our payment processor; see Stripe’s Privacy Policy at https://stripe.com/privacy.
| Provider | Purpose | What it handles |
|---|---|---|
| Stripe | Payments / subscriptions | Your name, email, and payment card details; subscription/billing data. Card data is handled by Stripe, not stored by us. — https://stripe.com/privacy |
| Resend | Transactional email delivery | Your name/email and delivery status of messages we send you |
| Render | Application hosting & databases | The account, licensing, billing-status, and waitlist data described above (never your email/calendar content) |
| Cloudflare | Bot protection (Turnstile) | Limited technical signals on sign-up |
| Google / Microsoft | Sign-in (OAuth) and your own connected accounts | Your sign-in identity; and, on your Mac, access to your own email/calendar under permissions you grant (see §7, §8) |
| Anthropic (Claude) | AI, via your own subscription | Content you choose to have the assistant work on is processed under your Anthropic account and agreement — not through our servers |
7. Your Google user data: access, use, and Limited Use
The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements. Our use also complies with the Google Workspace API user data and developer policy. (The bolded sentence is Google’s required affirmative Limited Use statement, stated verbatim.)
Scopes we request and why (we request them in context, only when a feature needs them):
- Sign-in (
openid,email,profile): to identify you and your account. - Gmail (read, modify, and compose): so Deliberate can triage your inbox and prepare drafts on your Mac. Deliberate never sends on your behalf — you review and send.
- Google Calendar (read and events): to show and help you manage your schedule.
- Google Tasks / Contacts: these permissions appear on the consent screen, but the app does not currently read your Google Tasks or your saved contacts — correspondent suggestions are built from the headers of mail you have already received. We are removing these permissions from the consent screen.
How we access, use, store, and share this data (mapped to Google’s Limited Use requirements):
- Limited to prominent user-facing features. We limit our use of Google user data to providing or improving user-facing features that are prominent in Deliberate’s user interface (inbox triage, drafting, calendar). Processing happens on your device.
- Storage. Your Google email and calendar content is not transmitted to, stored on, or logged by our servers. Access tokens are stored encrypted on your own Mac (in the OS keychain) — never on our servers or across our app’s bridge.
- No transfers, except as permitted. We do not transfer Google user data to third parties, except: to provide or improve the user-facing features above at your direction; where necessary to comply with applicable law; or as part of a merger, acquisition, or sale of assets with notice to you.
- No advertising. We do not use Google user data for serving advertising.
- No human reading, except the permitted cases. We do not allow humans to read Google user data unless: (a) we first obtain your affirmative agreement to view specific messages, files, or other data; (b) it is necessary for security purposes (for example, investigating a bug or abuse) or to comply with applicable law; or (c) the data is aggregated and anonymized and used for internal operations. Because content stays on your device, none of it is available to our staff in the ordinary course.
- Retention & deletion. Because we do not store your Google content, there is nothing on our side to retain. You can disconnect the Google account in Deliberate at any time, or revoke the app’s access at https://myaccount.google.com/permissions.
8. Your Microsoft account data: access and use
When you connect a Microsoft account, Deliberate accesses your Microsoft 365 / Outlook email and calendar through the Microsoft Graph API under the permissions you grant, and handles that data the same local-first way described in §7. Our use of the Microsoft APIs complies with the Microsoft APIs Terms of Use and the Microsoft identity platform policies, and this policy is intended to be at least as protective of your data as the Microsoft Privacy Statement.
Scopes we request (in context): sign-in (openid, profile, email,
offline_access), User.Read, mail read/read-write, mail send (used only when you
approve and send — never automatically), and calendar read-write.
Access, use, storage, sharing, human access, retention, and deletion follow the same rules as §7: on-device processing only; no content on our servers; no sale, no advertising use, no third-party transfer except at your direction, for legal compliance, or a merger with notice; no human reading of your content except the narrow security/consent/legal exceptions; and you can disconnect the Microsoft account in Deliberate or revoke access at https://myaccount.microsoft.com/ (or via your organization’s admin) at any time.
9. International transfers
We are based in the United States and our providers may process data in the US and elsewhere, and your information is processed in the United States. We do not currently offer accounts in the European Economic Area or the United Kingdom. Where any transfer of personal data from the EEA, UK, or Switzerland does occur, we rely on appropriate safeguards such as the Standard Contractual Clauses.
10. How long we keep information
- Account, profile & licensing: for as long as your account is active. If you ask us to delete your account, we action the request within the period the applicable law allows and confirm when it is done.
- Billing & tax records: retained as required by law, typically 7 years.
- Waitlist: until you ask to be removed or the alpha program ends.
- Logs/security data: a limited rolling window sufficient for operations and security.
- App telemetry (DRAFT — telemetry initiative 2026-09): raw event records expire automatically after 30 days; de-duplication keys after 90 days. Aggregate statistics (daily counts with no content) are retained indefinitely. Email us and we will delete yours.
- Your Google/Microsoft email & calendar content: not retained by us, because it is never stored on our servers.
11. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal information, to object to certain processing, and (in California) to know what we collect and to limit certain uses — free from discrimination for exercising these rights. To exercise any right, email [email protected]; we will verify and respond as required by law. You can also disconnect a Google/Microsoft account at any time to revoke our access, and cancel your subscription through the billing portal. If you are in the EEA or the UK, you may also lodge a complaint with your local supervisory authority.
12. Security
We protect personal information with administrative, technical, and physical safeguards appropriate to its sensitivity — encryption in transit, encrypted credentials and tokens, and least-privilege access. Our architecture is itself a safeguard: because your email/calendar content never reaches our servers, it is not exposed by a compromise of our infrastructure. For the restricted Google scopes we use, we maintain the security assessment (CASA) Google requires. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
13. Children
The Service is not directed to, and we do not knowingly collect personal information from, children under 18. If you believe a child has provided us information, contact us and we will delete it.
14. Changes to this policy
We may update this policy. If changes are material, we will notify you (for example, by email or in-app) and update the “Last updated” date. Continued use after changes take effect means you accept the updated policy.
15. Contact
The Deliberate Company, LLC 35 W. Main Street, Unit 2272, Frisco, CO 80443 Privacy & support: [email protected] · Web: https://getdeliberate.ai Stripe’s Privacy Policy: https://stripe.com/privacy