Privacy policy
Plain language, because a policy nobody understands protects nobody. This service is operated by Single Grain. It connects accounts you already own to agents you already use, and reads them on your instruction.
What we store
Your account email. Your password and sign-in credentials are held by Clerk, the identity provider that runs our sign-in, and we do not receive them. The credentials for accounts you connect, whether an OAuth refresh token or a key you paste, encrypted at rest with a key bound to your organization. A log of every call made with your API keys that records the shape of each request, meaning which service, which endpoint, the status and the duration, and never its contents.
Connectable services today: Google, Slack, HubSpot, Stripe, Gong, Coda and Asana. Every one of them is connected by you, with your own account. All of them are read-only except Slack, where the assistant also replies with a message in the workspace that installed it, and can add itself to a public channel so you do not have to invite it. That is the whole of what it writes: it uploads no files, edits no canvases and changes nothing that was already there. It acts as itself, with the permissions that workspace granted, and Slack lists every one of them on the install screen before you agree.
Some tools work without you connecting anything, because they run on our own accounts and are charged to your credit balance. Today those vendors are DataForSEO, OpenAI, Perplexity, Exa, Apify and Hunter. None of them holds data belonging to you or to any other customer.
What we never do
We never sell your data and we never share it with a third party for their own purposes. We never read your connected accounts except when your own API key asks a tool to. One organization's credentials and data are never reachable from another organization's requests: the database enforces this with row-level security, and each connected platform enforces it again, because the credential is yours and not ours.
We do not use your data, from any connected service, to develop, train, or improve any generalized artificial intelligence or machine learning model.
Google user data
This application's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Google user data is used only to provide or improve the features you visibly requested; it is never transferred to others except as needed to provide those features, to comply with applicable law, or as part of a merger or acquisition; it is never used for advertising; and it is never used to develop, improve, or train generalized artificial intelligence or machine learning models. No human reads your Google data, except with your explicit permission for a support request you raised, where it is necessary for security, or where the law requires it.
What we ask Google for, and why. Each one is read-only:
- Analytics and Search Console: so an agent can report your own traffic and search performance.
- Sheets, Docs and Calendar: so an agent can read a document or schedule you point it at.
- YouTube: so an agent can report your own channel's performance.
- Your email address: so the connection can be labelled with the account it belongs to, which matters when you connect several.
We deliberately do not request access to Google Drive or Gmail.
Where your Google data goes, and where it does not. This service holds no artificial intelligence or machine learning model of its own, and no code path here takes data from a connected account and sends it to an AI provider. Reading your Google account and asking a model something are separate tools, and nothing joins them: the joining, if any, is done by your own agent on your own instruction. That agent and the model behind it are yours, running on your own account with whichever provider you chose.
One tool is an exception worth naming plainly, because we would rather say it than have you discover it. We offer an OpenAI-backed tool on our own credential, metered per call, for agents that want a model without holding a key. If your agent calls it, whatever your agent puts in the prompt goes to OpenAI's API. We never put your connected-account data there ourselves, and OpenAI's API terms state that data submitted through the API is not used to train their models. We never use your data, from Google or from any other connected service, to develop, improve, or train any model, our own or anyone else's.
You can revoke our access to your Google account at any time, either by disconnecting it here or at myaccount.google.com/permissions.
How long we keep it
Your account, your connected credentials and your call log are kept for as long as your organization exists, and are deleted when it is. Nothing here expires on a timer, so there is no window in which we hold something you thought was gone.
Getting a copy, or getting rid of it
Disconnecting a service deletes its stored credential immediately. Revoking an API key stops it immediately.
For anything else, email the address below and a person answers within one business day. Ask for a copy of what we hold about your organization and we send it as a file you can keep. Ask us to delete your account and everything it stored, and it happens within 30 days.
Contact
support@singlebrain.com · policy last updated 2026-08-20