Legal
Privacy Policy
Effective date:
This policy explains how SmallForce ("we," "us," or "our") handles personal information when you use our website, applications, hosted company workspace (your "OS"), AI employees, and connected services. For privacy questions, access or deletion requests, or complaints, email support@smallforcehq.com.
SmallForce does not use customer content to train AI models. Your OS stores workspace content, but operating the service also involves platform databases, media storage, and external providers. The sections below explain those boundaries.
1. Scope and responsibilities
SmallForce handles account, billing, support, and service-operation information to run the service. When an organization uses SmallForce to process information about its customers, contacts, or team, that organization determines the purpose of its work and the instructions given to SmallForce. Its privacy notices may also apply.
If you have interacted with a business using SmallForce, contact that business about its use of your information. You can also email us for help directing a request. Organization administrators control who can access their workspace and which accounts, tools, and workflows are connected.
2. Information we process
- Account and organization information: your name, email address, sign-in information, organization details, membership, permissions, and preferences. External sign-in providers may supply profile information you authorize them to share.
- Workspace content: messages, prompts, files, company knowledge, employee instructions, saved context and memories, schedules, generated content, and task results.
- Connected-app information: data made available by the permissions you grant, such as emails and attachments, calendar events, contacts, social posts and messages, reviews, advertising accounts, campaign metrics, and documents. Connections may involve OAuth tokens, API keys, or other credentials you provide. Browser sessions may retain cookies and sign-in state so authorized work can continue.
- Calls and media: phone numbers, call metadata, audio, recordings where enabled, transcripts, summaries, and images or videos you upload or ask us to generate. The information processed depends on the feature and your configuration.
- Billing and support information: purchases, subscriptions, credit usage, transaction references, billing contact information, and correspondence. Payment details are collected by the checkout provider; SmallForce does not store full payment-card numbers.
- Technical and usage information: IP address, browser and device information, session activity, timestamps, page visits, feature usage, errors, and security or action logs. Logs may contain information needed to diagnose a failed request. Timezone and location information may come from your settings, network, or task inputs.
Public tools, such as a business-profile audit, also process the business details and public URLs you submit, publicly available business information, and the resulting report. Do not submit private information to a public tool unless it is needed for that tool.
3. How we use information
We process information to:
- Create accounts, check access, and operate your organization and OS.
- Carry out your instructions, including authorized background and scheduled work.
- Provide AI responses, search company context, generate media, and produce reports.
- Use connected apps to perform the communications, publishing, and business tasks you authorize.
- Manage payments, subscriptions, usage, support, and service notifications.
- Diagnose problems, measure service performance, and improve product usability.
- Prevent abuse, protect accounts, resolve disputes, and meet legal obligations.
Where a legal basis is required, processing may be necessary to provide the service you request, meet a legal obligation, or pursue legitimate interests such as security and service reliability, subject to your rights. We request consent where required. This policy is a notice, not a substitute for consent required for a particular activity.
4. AI processing and our no-training commitment
We use your instructions and relevant company context to perform your tasks, not to train SmallForce models. Saving context or retrieving information from your workspace is different from training a model. We do not sell customer content or make it available to other customers for their model training.
SmallForce uses OpenRouter to access AI models. When a task requires AI processing, relevant prompts, messages, files, tool results, or other context may be sent through OpenRouter to the model provider serving the request. Features such as image generation, transcription, and voice may also use specialized providers.
External providers have their own data-use and retention policies; the handling of a request depends on the provider and the privacy settings that apply to that request. Our no-training commitment does not mean that every provider offers zero retention, or that content never leaves your OS. See OpenRouter's provider data policies for how routing, training restrictions, and retention differ.
5. Where information is stored
- Your OS: each hosted organization has its own runtime and filesystem for workspace files, employee conversations, saved context, and related work. Railway provides hosted infrastructure.
- Platform records: account, membership, authorization, billing, integration, and service-operation records are also stored in platform databases outside the individual OS.
- Media storage: some uploaded, imported, or generated files and media are stored in managed object storage, including Railway buckets, rather than only on the OS filesystem. Private media can be delivered through time-limited signed links.
- External services: connected apps, AI providers, communication providers, and AI hosts may process or retain the information sent to them under their own terms and policies.
A dedicated OS is not a promise of exclusive physical hardware, end-to-end encryption, or storage in your country. Information may be processed outside your country, depending on infrastructure, provider routing, and connected services. Applicable transfer requirements continue to apply; contact us about a specific location or safeguard requirement before submitting information that depends on it.
6. When information is shared
- To run the service: hosting, storage, networking, security, AI, communication, integration, and support providers receive information needed for their part of the service. These include Railway, Cloudflare, OpenRouter, and the providers used by the features you choose.
- For payments: Dodo Payments acts as merchant of record for purchases processed through its merchant-of-record checkout. It handles payment and related transaction information under its own policies. We receive records needed to provide your purchase and manage billing or support.
- Within your organization: authorized members and administrators can access information according to their permissions. A company workspace is not necessarily private from its administrators.
- At your direction: information is shared with the apps, recipients, AI hosts, or audiences involved in authorized actions. Published posts, websites, and shared files can become public. Anyone receiving a shared link may be able to access its content.
- For legal and safety reasons: where required by law, or where necessary and legally permitted to investigate abuse, protect people or systems, or establish or defend legal claims.
- During a business transfer: information may be transferred in a sale, reorganization, or transfer of the service, subject to applicable protections, notice, and consent requirements.
We do not sell personal information or use private workspace content to target advertising. Human access to customer content is limited to authorized support, operations, security, and legal needs. The stricter restrictions for Google user data below also apply.
7. ChatGPT, Claude, and other MCP connections
When you connect an AI host such as ChatGPT, Claude, or Codex through the Model Context Protocol (MCP), you authorize access to a selected SmallForce organization and permission groups. Access depends on that authorization and your current organization membership and role.
The host receives the tool results and interface data returned for authorized requests. These may include company records, messages, reports, media, and file links. Its own privacy policy governs how it handles the information after receipt. SmallForce's no-training commitment does not change your separate agreement with that host.
You can revoke the connection through the available connection controls or ask us for help by email. Revocation stops future authorized access through that connection; it does not erase results already saved by the host, delete the SmallForce organization, or cancel its subscription. Requests to delete host-held copies must also be addressed to that host.
8. Google user data
When you connect Google services, we use the authorized data to provide the features you request, such as working with your mail, calendar, files, or business information. SmallForce's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements, and the applicable Google Workspace user data policy.
We do not sell this data, use it for advertising, or use it to train general-purpose AI models. Transfers are limited to permitted user-facing features with your consent, security needs, legal requirements, or a business transfer with the required prior consent. Human access is limited to your explicit agreement to view specific data, security or legal needs, or permitted aggregated and anonymized internal operations.
You can remove access in your Google account's connection settings and disconnect the integration in SmallForce. To request deletion of previously stored Google data, email our privacy contact below.
9. Cookies and website analytics
Cookies and similar browser storage support sign-in, security, preferences, and session continuity. Blocking essential storage may prevent these features from working. Our Cookie Policy lists the storage we use, its purposes and duration, and how to change your choice.
We use PostHog for analytics on our production website and dashboard. Events include page views, signup-link clicks, completed registration and checkout starts; confirmed payments are reported by our server. Browser identifiers connect visits across our website and dashboard; an account identifier connects signed-in usage. Campaign labels help us understand how visitors found SmallForce. We do not enable session recordings or automatic form and click capture, and do not send private workspace content, connected-app data, passwords, or access tokens. Development and preview sites do not send PostHog events. Analytics is on by default when enabled for the site. You can turn it off by choosing Reject all in the cookie banner, or using Cookie settings in the footer or dashboard account settings. The banner disappears after either choice, which is remembered across the website and dashboard. We honor Global Privacy Control signals.
We use Meta Pixel and Conversions API measurement for public page visits, signup, checkout, and payments. When measurement is enabled for the site, it is on by default and may share browser identifiers and a hashed email address with Meta for advertising measurement. Private workspace content is excluded. You can turn it off or change your choice using Cookie settings in the website footer or your dashboard account settings. We honor Global Privacy Control signals.
You can manage cookies and site storage in your browser. Where processing relies on consent, you can withdraw that consent. Email us if you need help with a privacy preference. Service, billing, and security records are separate from optional website analytics.
10. Retention and deletion
We retain information for the purposes described in this policy. Retention depends on the information, whether your account or organization is active, the work you ask us to perform, and any billing, security, dispute, or legal requirements. Workspace files, memories, and task history may remain available until deleted or the workspace is closed.
Advertising conversion records have no automatic expiry. We retain them for measurement and delivery history until the associated account or organization is deleted, or a deletion request is handled.
You can request account or organization deletion, or deletion of specific information, by emailing support@smallforcehq.com. We may need to verify your identity and authority over an organization. We will explain any information we must retain and respond within applicable legal time limits. Backup copies may persist until their retention cycle ends; retained copies remain subject to this policy.
Disconnecting an app, cancelling a subscription, and deleting data are separate actions. Copies already delivered to recipients, published on another platform, or stored by an external AI host are subject to that recipient's controls and retention practices. If your information belongs to an organization's records, its administrator may also need to handle your request.
11. Security
We use measures such as authenticated access, organization-scoped permissions, encrypted network connections, and access-controlled storage. Private media links can expire. These measures reduce risk but do not make any online service completely secure.
Protect your account and connected-service credentials, review team permissions, and report suspected unauthorized access to our support email. If a security incident requires notification, we will notify affected people or organizations and authorities as required by law.
12. Your privacy choices and rights
Depending on applicable law, you may request access, correction, deletion, or a portable copy of personal information; object to or restrict certain processing; withdraw consent; or complain to a privacy regulator. These rights may have exceptions, including where fulfilling a request would disclose another person's information.
Send requests to support@smallforcehq.com. Include enough information to identify the account and your request, but do not email passwords or full payment-card details. We may ask for proportionate verification. We do not penalize you for exercising rights granted by applicable privacy law.
You can ask to stop promotional emails without stopping necessary account or security communications. Device settings control push notification permissions. Organization controls and provider settings let you manage connected-account access where available.
13. Children
SmallForce accounts are intended for adults aged 18 or older. We do not knowingly solicit personal information from children for their own accounts. Organizations remain responsible for the information they submit and the notices or permissions required for their work. Contact us if you believe a child has provided information improperly so we can investigate and take appropriate action.
14. Changes and contact
We will update the date above when this policy changes. For material changes, we will provide notice through the service or by email as appropriate, and obtain consent where required before a new use of information. An update does not remove rights you already have under law.
Privacy contact and support: support@smallforcehq.com. For subscription and refund information, read our Terms of Service.