Privacy Policy

Effective September 18, 2026 · Version 2026.09.18

Privacy Policy

The Deliberate Company, LLC — Deliberate

Effective date: 18 September 2026 Last updated: 18 September 2026

1. Our approach: your data stays yours

Deliberate is built local-first, and privacy is a core promise, not a footnote. The most important things to understand:

This policy explains the limited personal information the getdeliberate.ai website and our registration/licensing service do collect, and — in §7 and §8 — exactly how the application accesses and uses the Google and Microsoft data you authorize.

2. Who we are

The Deliberate Company, LLC (“Deliberate,” “we,” “us”) is the controller of the personal information described here. Contact: [email protected], 35 W. Main Street, Unit 2272, Frisco, CO 80443.

3. Information we collect

Information you give us

Information from your connected accounts (processed on your device, not warehoused)

Information collected automatically

We use personal information to: create and manage your account and licenses; verify licenses and provide, secure, and improve the Service; process your subscription and send required billing notices (including the 5/3/1-day pre-charge reminders); operate the waitlist and send invitations; respond to support; and comply with law.

Where GDPR/UK GDPR applies, our legal bases are: performance of a contract (providing the Service and billing), legitimate interests (securing and improving the Service, preventing abuse, managing the waitlist), consent (where required, e.g., certain marketing and the scopes you grant to connect an account), and legal obligation (e.g., tax records).

We do not sell your personal information, and we do not “share” it for cross-context behavioral advertising as those terms are defined under California law (CCPA/CPRA). We do not use data obtained through Google or Microsoft APIs for advertising (see §7, §8).

5. Who can access your account

Access to account data is limited to authorized Deliberate staff who need it to operate the Service and provide support. For troubleshooting, authorized staff may temporarily act on behalf of an account (“impersonation”); this is restricted to staff, logged, and used only to diagnose and resolve issues. Staff cannot see your email or calendar content, because that content is never stored on our servers.

6. Service providers and subprocessors

We use a small set of vetted providers to operate the Service. Stripe processes payments as our payment processor; see Stripe’s Privacy Policy at https://stripe.com/privacy.

Provider Purpose What it handles
Stripe Payments / subscriptions Your name, email, and payment card details; subscription/billing data. Card data is handled by Stripe, not stored by us. — https://stripe.com/privacy
Resend Transactional email delivery Your name/email and delivery status of messages we send you
Render Application hosting & databases The account, licensing, billing-status, and waitlist data described above (never your email/calendar content)
Cloudflare Bot protection (Turnstile) Limited technical signals on sign-up
Google / Microsoft Sign-in (OAuth) and your own connected accounts Your sign-in identity; and, on your Mac, access to your own email/calendar under permissions you grant (see §7, §8)
Anthropic (Claude) AI, via your own subscription Content you choose to have the assistant work on is processed under your Anthropic account and agreement — not through our servers

7. Your Google user data: access, use, and Limited Use

The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements. Our use also complies with the Google Workspace API user data and developer policy. (The bolded sentence is Google’s required affirmative Limited Use statement, stated verbatim.)

Scopes we request and why (we request them in context, only when a feature needs them):

How we access, use, store, and share this data (mapped to Google’s Limited Use requirements):

8. Your Microsoft account data: access and use

When you connect a Microsoft account, Deliberate accesses your Microsoft 365 / Outlook email and calendar through the Microsoft Graph API under the permissions you grant, and handles that data the same local-first way described in §7. Our use of the Microsoft APIs complies with the Microsoft APIs Terms of Use and the Microsoft identity platform policies, and this policy is intended to be at least as protective of your data as the Microsoft Privacy Statement.

Scopes we request (in context): sign-in (openid, profile, email, offline_access), User.Read, mail read/read-write, mail send (used only when you approve and send — never automatically), and calendar read-write.

Access, use, storage, sharing, human access, retention, and deletion follow the same rules as §7: on-device processing only; no content on our servers; no sale, no advertising use, no third-party transfer except at your direction, for legal compliance, or a merger with notice; no human reading of your content except the narrow security/consent/legal exceptions; and you can disconnect the Microsoft account in Deliberate or revoke access at https://myaccount.microsoft.com/ (or via your organization’s admin) at any time.

9. International transfers

We are based in the United States and our providers may process data in the US and elsewhere, and your information is processed in the United States. We do not currently offer accounts in the European Economic Area or the United Kingdom. Where any transfer of personal data from the EEA, UK, or Switzerland does occur, we rely on appropriate safeguards such as the Standard Contractual Clauses.

10. How long we keep information

11. Your rights and choices

Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal information, to object to certain processing, and (in California) to know what we collect and to limit certain uses — free from discrimination for exercising these rights. To exercise any right, email [email protected]; we will verify and respond as required by law. You can also disconnect a Google/Microsoft account at any time to revoke our access, and cancel your subscription through the billing portal. If you are in the EEA or the UK, you may also lodge a complaint with your local supervisory authority.

12. Security

We protect personal information with administrative, technical, and physical safeguards appropriate to its sensitivity — encryption in transit, encrypted credentials and tokens, and least-privilege access. Our architecture is itself a safeguard: because your email/calendar content never reaches our servers, it is not exposed by a compromise of our infrastructure. For the restricted Google scopes we use, we maintain the security assessment (CASA) Google requires. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.

13. Children

The Service is not directed to, and we do not knowingly collect personal information from, children under 18. If you believe a child has provided us information, contact us and we will delete it.

14. Changes to this policy

We may update this policy. If changes are material, we will notify you (for example, by email or in-app) and update the “Last updated” date. Continued use after changes take effect means you accept the updated policy.

15. Contact

The Deliberate Company, LLC 35 W. Main Street, Unit 2272, Frisco, CO 80443 Privacy & support: [email protected] · Web: https://getdeliberate.ai Stripe’s Privacy Policy: https://stripe.com/privacy