Octopus22

Legal

Privacy Policy

Last updated · June 17, 2026

Overview

Octopus22 builds a “Company Brain”: connected AI agents that work across the tools your business already uses. To do that, we handle data on your behalf. This policy explains what we collect, why, how we protect it, and the choices you have. We’ve written it in plain language and kept the jargon out.

This policy applies to our website, app, and services (together, the “Service”). By using the Service you agree to the practices described here.

Data we collect

We collect three kinds of data:

  • Account data: your name, email, company, and billing details when you sign up.
  • Connected-tool data: when you connect a tool (e.g. email, chat, a store, or a CRM), we access the data you authorize so your agents can read it and act on it. You choose what to connect and what each agent is allowed to touch.
  • Usage data: how you and your agents use the Service: actions taken, logs, device and browser info, and diagnostics that help us keep things running.

How we use your data

We use your data only to provide and improve the Service. Specifically, to:

  • Build and maintain your Company Brain from the tools you connect.
  • Let agents carry out the tasks you assign, within the permissions you set.
  • Operate billing, support, security, and account management.
  • Diagnose problems and improve performance and reliability.

We do not sell your data, and we do not use your business content to train any generalized or foundation AI/ML models.

AI processing

The Service uses third-party AI model providers to power agent reasoning and actions. When an agent runs, the relevant context may be sent to these providers to generate a response. We work with providers that contractually commit not to train their models on data sent through their business APIs.

Agents act inside the boundaries you configure: what they can read, draft, or do, plus any approvals and spending limits you set. You can review every action an agent takes.

Google user data (Limited Use)

When you connect a Google service, Octopus22 accesses your Google user data only through the scopes you grant. Depending on what you connect, this may include Gmail (read, compose, send, and organize messages), Google Drive (read and manage files), Google Calendar (read and manage events), BigQuery (run queries against your datasets), and Compute Engine (view and manage resources), so your agents can perform the tasks you assign.

Octopus22’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, we do not use Google user data for advertising, and we do not sell it. We do not use Google user data to train or improve any generalized or foundation AI/ML models. Google data is sent to AI providers only to perform your requested task, under contracts that prohibit training on it. We do not allow humans to read your Google user data except: with your explicit consent, where necessary for security or to comply with law, or when the data has been aggregated and anonymized. Google user data is stored encrypted, retained only as long as needed to provide the Service, and deleted when you disconnect the tool or close your account.

How we share data

We share data only with:

  • Service providers (sub-processors) who help us run the Service (for hosting, AI processing, payments, and analytics) under contracts that require they protect your data and use it only on our instructions.
  • Tools you connect, to the extent needed to perform the actions you authorize.
  • Legal and safety: when required by law, or to protect the rights, safety, and security of our users and the Service.

We never sell or rent your personal information.

Security

We protect your data with encryption in transit and at rest, access controls, and regular security reviews. Credentials for your connected tools are stored in an encrypted vault and are never exposed to agents in plain text.

No system is perfectly secure, but we work hard to safeguard your information and to notify you promptly if a breach affecting your data ever occurs.

Data retention

We keep your data for as long as your account is active or as needed to provide the Service. When you delete data or close your account, we remove or anonymize it within a reasonable period, except where we must retain it to meet legal, accounting, or security obligations.

Your rights & choices

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can:

  • Disconnect any connected tool at any time.
  • Pause your agents, or pause everything, with one click.
  • Review and edit what the Company Brain has stored about your business.
  • Request a copy of your data, or ask us to delete it, by contacting us below.

We will respond to verified requests as required by applicable law.

Cookies

We use a small number of cookies and similar technologies to keep you signed in, remember your preferences, and understand how the Service is used. You can control non-essential cookies through your browser settings or our cookie controls where available.

International transfers

We may process and store data in countries other than where you live. Where we transfer personal data across borders, we use appropriate safeguards (such as standard contractual clauses) to protect it.

Children

The Service is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, please contact us and we will delete it.

Changes to this policy

We may update this policy from time to time. When we make material changes, we’ll update the date above and, where appropriate, notify you in the app or by email. Continued use of the Service after changes take effect means you accept the updated policy.

Contact us

Questions about this policy or your data? Email us at legal@octopus22.com.

See also our Terms of Service.