1Introduction
Immensity Partners I, Inc. ("Immensity," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform, websites, applications, and related services (collectively, the "Services").
By accessing or using the Services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use the Services.
2Information We Collect
We collect several types of information from and about users of our Services.
2.1Information You Provide to Us
- Account Information: Name, email address, username, password, job title, organization, and other registration details.
- Profile Information: Contact details, preferences, and information you add to your user profile.
- Financial and Transactional Information: Information you submit in connection with the use of our financial and platform features, including account data, transaction records, and related metadata.
- Communications: Information you provide when you contact us for support, submit feedback, or otherwise communicate with us.
- Payment Information: Billing details processed through our third-party payment processors.
2.2Information We Collect Automatically
- Usage Data: Pages viewed, features used, actions taken, timestamps, and session duration.
- Device and Connection Data: IP address, browser type, operating system, device identifiers, and network information.
- Cookies and Similar Technologies: Information collected through cookies, web beacons, and similar tracking technologies. See Section 9 for details.
2.3Information From Third Parties
We may receive information about you from third-party services you connect to the platform, identity providers, integration partners, and publicly available sources.
3Google User Data
This section describes exactly what Google user data the Immensity platform accesses, why it accesses it, how it is stored and protected, and how you can withdraw access. It applies whenever you connect a Google account to the Services.
We access Google user data only after you explicitly grant permission on Google's own consent screen, and only for the scopes listed below. We request no other Google scopes. You may decline any scope, and you may revoke access at any time.
3.1Google User Data We Access
- Basic profile and email address (
openid,email,profile): your name, email address, and profile picture. Used to identify your account, display who is signed in, and associate a connected mailbox with the correct user. - Gmail messages, read-only (
gmail.readonly): the content, headers, attachments, and labels of messages in your mailbox. Used to summarise your inbox, surface messages that need attention, extract information such as invoices and meeting details, and answer your questions about your own correspondence. - Gmail drafts and sending (
gmail.compose): creating, editing, and sending messages on your behalf. Used to prepare replies and outbound messages that you review. Messages are sent only when you approve them. - Google Calendar events (
calendar.events): reading and writing events on calendars you have access to. Used to show your schedule, prepare you for upcoming meetings, and create or update events at your direction. - Google Drive files, read-only (
drive.readonly): the content and metadata of files in your Drive. Used to locate and read documents so the Services can answer questions grounded in your own files and cite the source. - Google Drive files created or opened with the Services (
drive.file): files that you specifically create with, or open through, the Services. Used to save outputs back to your Drive at your direction. - Google Slides presentations (
presentations): reading and creating presentation content. Used to generate and update presentations you ask the Services to prepare.
3.2How We Use Google User Data
Google user data is used solely to provide and improve the user-facing features described above and visible in the product. We do not use it for any unrelated purpose. Specifically, we do not:
- sell Google user data, or transfer it to data brokers or information resellers;
- use Google user data for advertising of any kind, including retargeting, personalised, or interest-based advertising;
- use Google user data to determine creditworthiness or for lending purposes;
- use Google user data to train generalised artificial-intelligence or machine-learning models, and we do not permit our AI service providers to do so with your content.
Google user data is processed by third-party providers only where they act as our service providers to deliver a feature you have requested — for example, cloud hosting and the AI model providers that generate responses on your behalf. These providers are bound by contract to process the data only on our instructions and are not permitted to use your content to train their models.
3.3Human Access to Google User Data
We do not allow our personnel to read your Gmail, Calendar, or Drive content, except in the limited circumstances permitted by Google's policies: where you have given your affirmative agreement for specific messages or files (for example, when you ask us to investigate a problem with a particular item); where it is necessary for security purposes such as investigating abuse; where it is required to comply with applicable law; or where the data has been aggregated and anonymised for internal operations. Production access is limited to a small number of authorised personnel and is logged.
3.4How We Store and Protect Google User Data
Google user data is protected by the measures described in Section 8 (Data Security). In particular, the OAuth access and refresh tokens that authorise our access to your Google account are encrypted individually at rest using keys held in a managed key-management service, and are never written to logs.
3.5Retention and Revoking Access
You may disconnect your Google account at any time from within the Services, or revoke our access directly from your Google Account at myaccount.google.com/permissions. When you disconnect, we delete the stored OAuth tokens for that account and stop accessing your Google data. Content already derived from your Google data is deleted on request as described in Section 7 (Data Retention) and Section 10 (Your Privacy Rights).
3.6Limited Use
Immensity's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
3.7What This Looks Like in the Product
The scopes above are what the Services are technically permitted to do. In plain terms, this is what each one is actually for:
- Google Calendar — reads your upcoming events so the assistant can prepare you for meetings, and creates, updates or cancels events when you ask it to. It never writes to your calendar unprompted.
- Google Drive — reads your documents so an answer can cite the file it came from, and saves documents the assistant produces back into your Drive at your direction.
- Google Slides — builds presentations from your own material, delivered as an editable deck in your account rather than a static export.
Immensity uses this data only to serve your own requests, and shows it only to you and the people you authorise. We never sell it, transfer it to third parties for advertising, or use it to train generalised models.
4How We Use Your Information
We use the information we collect to:
- Provide, operate, maintain, and improve the Services;
- Create and manage your account and authenticate users;
- Process transactions and send related information;
- Respond to inquiries, provide customer support, and send administrative messages;
- Personalize your experience and deliver relevant content and features;
- Monitor and analyze usage, trends, and activity to improve the Services;
- Detect, prevent, and address security incidents, fraud, and other unlawful activity;
- Comply with legal obligations and enforce our terms and policies; and
- Send marketing communications, where permitted, from which you may opt out.
5Legal Bases for Processing
Where applicable law (such as the EU/UK General Data Protection Regulation) requires it, we process your personal information on the following legal bases: performance of a contract, your consent, our legitimate interests, and compliance with legal obligations.
7Data Retention
We retain personal information for as long as necessary to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements. When information is no longer required, we will delete or anonymize it in accordance with our retention policies and applicable law.
8Data Security
We implement administrative, technical, and physical safeguards designed to protect your information, including any sensitive data and any Google user data you connect. Our principal measures are:
- Encryption in transit: all traffic between you and the Services, and between our own systems, is protected with TLS. Certificates are managed automatically and plaintext connections are not accepted.
- Encryption at rest: our databases and document storage are encrypted at rest using customer-managed keys in AWS Key Management Service. Credentials for connected accounts — including Google OAuth access and refresh tokens — are additionally encrypted as individual fields using keys held in a managed key-management service, so they remain protected even to someone holding a copy of the database.
- Secrets management: application secrets and third-party credentials are held in a managed secrets service and injected at runtime. They are never committed to source control or stored in plaintext configuration.
- Tenant isolation: the Services are multi-tenant, and every request is scoped to the organisation it belongs to. Data access paths carry the tenant context, and an automated guard flags any query that is not scoped to a single tenant so that isolation failures surface rather than pass silently.
- Access control: access to the platform is governed by role-based permissions within your organisation. Internal access to production systems is restricted to a small number of authorised personnel on a least-privilege basis, and administrative sessions are logged.
- Network isolation: our application and database systems run inside a private network. Databases are not reachable from the public internet, and access is limited to our own services.
- Sensitive content handling: the contents of your mailbox, calendar, and files are used only to produce the features you have asked for. They are not used for advertising, are not sold, and are not used to train generalised AI models. Our personnel do not read them except in the limited circumstances set out in Section 3.3.
- Deletion: disconnecting a connected account deletes the stored credentials for it. Deletion of your wider data is described in Section 7 and Section 10.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal data, we will notify you and any relevant regulator as required by applicable law.
10Your Privacy Rights
Depending on your jurisdiction, you may have the right to:
- Access, correct, or delete your personal information;
- Object to or restrict certain processing;
- Request portability of your information;
- Withdraw consent where processing is based on consent; and
- Lodge a complaint with a supervisory authority.
To exercise these rights, contact us using the details in Section 14. We will respond consistent with applicable law. We will not discriminate against you for exercising your rights.
To delete personal data or close an account, see Delete your data for self-service steps in the product and how to email the Privacy Team. A companion page for closing the account entirely is linked from there.
10.1California Residents
If you are a California resident, the California Consumer Privacy Act (CCPA/CPRA) provides additional rights, including the right to know, the right to delete, the right to correct, and the right to opt out of the sale or sharing of personal information. We do not sell personal information.
11International Data Transfers
Your information may be transferred to, and processed in, countries other than the country in which you reside. Where required, we use appropriate safeguards, such as standard contractual clauses, to protect your information when transferred internationally.
12Children's Privacy
The Services are not directed to children under the age of 16, and we do not knowingly collect personal information from children. If we learn that we have collected such information, we will take steps to delete it.
13Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will revise the "Last Updated" date and, where appropriate, provide additional notice. Your continued use of the Services after changes take effect constitutes acceptance of the updated policy.
14Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact:
For data or account deletion requests, you can also use the public instructions at Delete your data, or email the address above with the subject Data deletion request or Account deletion request.