NAO

Privacy Policy

Last updated: August 24, 2026

1. What NAO does

NAO is an executive operating system that helps users analyze company information, research external sources, connect business tools, prepare drafts, and execute approved actions. NAO may process company information, user-provided content, and data retrieved from services the user chooses to connect.

2. Information we process

Depending on how you use NAO, we may process account information, company profiles, documents, business metrics, messages, calendar data, email metadata and content, connector data, research results, approvals, execution logs, and usage telemetry. We only request connector permissions needed for the features you enable.

3. Connected accounts and Google user data

When you connect Gmail or Google Workspace, NAO may access the email address of the connected account and, when you enable Email Intelligence, read Gmail message bodies and threads so it can search business email, detect replies to business outreach initiated or tracked through NAO, summarize inbound replies, extract decision-relevant terms, preserve conversation context, and prepare suggested responses. NAO may send an email from the connected account only after the user reviews and explicitly approves the message.

NAO's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. Email actions and approvals

NAO may prepare email drafts using company context, research results, and connected email thread context. For Gmail/Google Workspace, external email sending is explicitly approval-gated: NAO shows the recipient, subject, and message content for user review before sending. Email Intelligence does not require permission to delete, archive, relabel, or otherwise modify the user's Gmail mailbox.

5. How information is used

We use information to provide the service, answer requests, perform research, generate recommendations, prepare and execute approved actions, improve reliability and security, maintain audit history, and support users. We do not use customer private company data to expose another customer's confidential information.

6. Data sharing

We may process data through infrastructure, AI, and integration service providers only as necessary to deliver the user-requested feature and subject to applicable safeguards. Google user data is not transferred for advertising, data brokerage, creditworthiness, or unrelated model training. We may disclose information where required by law or when necessary for security, fraud, or abuse prevention.

7. Data retention and deletion

We retain information only for as long as reasonably necessary to provide the enabled NAO feature, maintain security and required auditability, or comply with applicable legal obligations. Connector access tokens and derived business context are scoped to the connected user. Disconnecting a provider stops future connector access. Users may also revoke Google access directly from their Google Account and may request deletion of stored account or connector-derived data through NAO support, subject only to applicable legal, security, fraud-prevention, and required audit obligations.

8. Security

We use technical and organizational safeguards designed to protect data, including access controls, tenant separation, approval gates for sensitive actions, audit logging, and minimization of secrets and credentials exposed to application code.

9. International processing

Service providers may process data in countries other than your own. Where applicable, we use contractual and technical safeguards appropriate to the service and data involved.

10. Your choices and data deletion

You can choose which connectors to enable, revoke connector access, decline approval requests, and request deletion or correction of account information where supported. Disconnecting a provider stops future NAO access through that connector. You can also revoke Google access directly from your Google Account security settings. Account or company data deletion requests can be submitted through NAO support; applicable records are deleted or de-identified subject to security, legal, fraud-prevention, and audit obligations.

11. Google API Limited Use

NAO's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide or improve prominent user-facing features requested by the user. It is not sold, used for advertising or advertising profiles, used to determine creditworthiness or lending purposes, or used to train generalized AI/ML models unrelated to the user's requested NAO feature. Human access to Google user data is prohibited except when the user gives affirmative consent for a specific support purpose, when necessary for security or abuse investigation, when required by law, or when the data has been aggregated and anonymized for internal operations in accordance with applicable Google policy.

12. Contact

For privacy questions or requests, contact the NAO support address shown on the service's OAuth consent screen or account support interface.