Legal

Privacy Policy

Last updated: September 27, 2026

1Introduction

Immensity Partners I, Inc. ("Immensity," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform, websites, applications, and related services (collectively, the "Services").

By accessing or using the Services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use the Services.

2Information We Collect

We collect several types of information from and about users of our Services.

2.1Information You Provide to Us

  • Account Information: Name, email address, username, password, job title, organization, and other registration details.
  • Profile Information: Contact details, preferences, and information you add to your user profile.
  • Financial and Transactional Information: Information you submit in connection with the use of our financial and platform features, including account data, transaction records, and related metadata.
  • Communications: Information you provide when you contact us for support, submit feedback, or otherwise communicate with us.
  • Payment Information: Billing details processed through our third-party payment processors.

2.2Information We Collect Automatically

  • Usage Data: Pages viewed, features used, actions taken, timestamps, and session duration.
  • Device and Connection Data: IP address, browser type, operating system, device identifiers, and network information.
  • Cookies and Similar Technologies: Information collected through cookies, web beacons, and similar tracking technologies. See Section 9 for details.

2.3Information From Third Parties

We may receive information about you from third-party services you connect to the platform, identity providers, integration partners, and publicly available sources.

3Google User Data

This section describes exactly what Google user data the Immensity platform accesses, why it accesses it, how it is stored and protected, and how you can withdraw access. It applies whenever you connect a Google account to the Services.

We access Google user data only after you explicitly grant permission on Google's own consent screen, and only for the scopes listed below. We request no other Google scopes. You may decline any scope, and you may revoke access at any time.

3.1Google User Data We Access

  • Basic profile and email address (openid, email, profile): your name, email address, and profile picture. Used to identify your account, display who is signed in, and associate a connected mailbox with the correct user.
  • Gmail messages, read-only (gmail.readonly): the content, headers, attachments, and labels of messages in your mailbox. Used to summarise your inbox, surface messages that need attention, extract information such as invoices and meeting details, and answer your questions about your own correspondence.
  • Gmail drafts and sending (gmail.compose): creating, editing, and sending messages on your behalf. Used to prepare replies and outbound messages that you review. Messages are sent only when you approve them.
  • Google Calendar events (calendar.events): reading and writing events on calendars you have access to. Used to show your schedule, prepare you for upcoming meetings, and create or update events at your direction.
  • Google Drive files, read-only (drive.readonly): the content and metadata of files in your Drive. Used to locate and read documents so the Services can answer questions grounded in your own files and cite the source.
  • Google Drive files created or opened with the Services (drive.file): files that you specifically create with, or open through, the Services. Used to save outputs back to your Drive at your direction.
  • Google Slides presentations (presentations): reading and creating presentation content. Used to generate and update presentations you ask the Services to prepare.

3.2How We Use Google User Data

Google user data is used solely to provide and improve the user-facing features described above and visible in the product. We do not use it for any unrelated purpose. Specifically, we do not:

  • sell Google user data, or transfer it to data brokers or information resellers;
  • use Google user data for advertising of any kind, including retargeting, personalised, or interest-based advertising;
  • use Google user data to determine creditworthiness or for lending purposes;
  • use Google user data to train generalised artificial-intelligence or machine-learning models, and we do not permit our AI service providers to do so with your content.

Google user data is processed by third-party providers only where they act as our service providers to deliver a feature you have requested — for example, cloud hosting and the AI model providers that generate responses on your behalf. These providers are bound by contract to process the data only on our instructions and are not permitted to use your content to train their models.

3.3Human Access to Google User Data

We do not allow our personnel to read your Gmail, Calendar, or Drive content, except in the limited circumstances permitted by Google's policies: where you have given your affirmative agreement for specific messages or files (for example, when you ask us to investigate a problem with a particular item); where it is necessary for security purposes such as investigating abuse; where it is required to comply with applicable law; or where the data has been aggregated and anonymised for internal operations. Production access is limited to a small number of authorised personnel and is logged.

3.4How We Store and Protect Google User Data

Google user data is protected by the measures described in Section 8 (Data Security). In particular, the OAuth access and refresh tokens that authorise our access to your Google account are encrypted individually at rest using keys held in a managed key-management service, and are never written to logs.

3.5Retention and Revoking Access

You may disconnect your Google account at any time from within the Services, or revoke our access directly from your Google Account at myaccount.google.com/permissions. When you disconnect, we delete the stored OAuth tokens for that account and stop accessing your Google data. Content already derived from your Google data is deleted on request as described in Section 7 (Data Retention) and Section 10 (Your Privacy Rights).

3.6Limited Use

Immensity's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

3.7What This Looks Like in the Product

The scopes above are what the Services are technically permitted to do. In plain terms, this is what each one is actually for:

  • Google Calendar — reads your upcoming events so the assistant can prepare you for meetings, and creates, updates or cancels events when you ask it to. It never writes to your calendar unprompted.
  • Google Drive — reads your documents so an answer can cite the file it came from, and saves documents the assistant produces back into your Drive at your direction.
  • Google Slides — builds presentations from your own material, delivered as an editable deck in your account rather than a static export.

Immensity uses this data only to serve your own requests, and shows it only to you and the people you authorise. We never sell it, transfer it to third parties for advertising, or use it to train generalised models.

4How We Use Your Information

We use the information we collect to:

  • Provide, operate, maintain, and improve the Services;
  • Create and manage your account and authenticate users;
  • Process transactions and send related information;
  • Respond to inquiries, provide customer support, and send administrative messages;
  • Personalize your experience and deliver relevant content and features;
  • Monitor and analyze usage, trends, and activity to improve the Services;
  • Detect, prevent, and address security incidents, fraud, and other unlawful activity;
  • Comply with legal obligations and enforce our terms and policies; and
  • Send marketing communications, where permitted, from which you may opt out.

6How We Share Your Information

We do not sell your personal information. We may share information in the following circumstances:

  • Service Providers: With vendors, consultants, and service providers who perform services on our behalf (e.g., hosting, analytics, payment processing) under contractual confidentiality obligations.
  • Within Your Organization: With other authorized users in your organization or tenant, consistent with your account's access controls.
  • Business Transfers: In connection with a merger, acquisition, financing, reorganization, or sale of assets.
  • Legal Requirements: When required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Immensity, our users, or others.
  • With Your Consent: With your direction or consent for other purposes disclosed at the time.

6.1Sub-processors

We use the following sub-processors to deliver the Services. Each is bound by contract to process data only on our instructions, and none may use your content to train its models. Third-party services that you choose to connect, such as Google, Slack, or Microsoft, receive data under your own agreement with them and are not our sub-processors.

Sub-processorPurposeLocation
Amazon Web ServicesHosting, databases, file storage, encryption key management, and outbound emailUnited States
AnthropicAI model processing (Claude) to generate the responses and actions you request, including reading scanned documentsUnited States
OpenAIText embeddings for search, audio transcription, and reading scanned documentsUnited States
CloudflareContent delivery, DNS, network security, file storage, and inbound email routingGlobal
PipedreamSecure connection handling for optional third-party integrationsUnited States
Recall.aiRecording and transcribing the meetings you ask our meeting assistant to joinUnited States
ResendDelivering transactional email, such as notifications and sign-in linksUnited States
PostHogProduct analytics within the application, as described in the Cookies sectionUnited States
StripeProcessing subscription payments; card details are entered on Stripe's own pages and never reach our systemsUnited States
ExaWeb search used to prepare meeting briefings, which can include the names and companies of meeting attendeesUnited States
Google WorkspaceOur company email, for correspondence you send us directlyUnited States

We will update this list before a new sub-processor begins processing personal information.

7Data Retention

We retain personal information for as long as necessary to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements. When information is no longer required, we will delete or anonymize it in accordance with our retention policies and applicable law.

8Data Security

We implement administrative, technical, and physical safeguards designed to protect your information, including any sensitive data and any Google user data you connect. Our principal measures are:

  • Encryption in transit: all traffic between you and the Services, and between our own systems, is protected with TLS. Certificates are managed automatically and plaintext connections are not accepted.
  • Encryption at rest: our databases and document storage are encrypted at rest using customer-managed keys in AWS Key Management Service. Credentials for connected accounts — including Google OAuth access and refresh tokens — are additionally encrypted as individual fields using keys held in a managed key-management service, so they remain protected even to someone holding a copy of the database.
  • Secrets management: application secrets and third-party credentials are held in a managed secrets service and injected at runtime. They are never committed to source control or stored in plaintext configuration.
  • Tenant isolation: the Services are multi-tenant, and every request is scoped to the organisation it belongs to. Data access paths carry the tenant context, and an automated guard flags any query that is not scoped to a single tenant so that isolation failures surface rather than pass silently.
  • Access control: access to the platform is governed by role-based permissions within your organisation. Internal access to production systems is restricted to a small number of authorised personnel on a least-privilege basis, and administrative sessions are logged.
  • Network isolation: our application and database systems run inside a private network. Databases are not reachable from the public internet, and access is limited to our own services.
  • Sensitive content handling: the contents of your mailbox, calendar, and files are used only to produce the features you have asked for. They are not used for advertising, are not sold, and are not used to train generalised AI models. Our personnel do not read them except in the limited circumstances set out in Section 3.3.
  • Deletion: disconnecting a connected account deletes the stored credentials for it. Deletion of your wider data is described in Section 7 and Section 10.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal data, we will notify you and any relevant regulator as required by applicable law.

9Cookies and Tracking Technologies

This section lists every cookie and similar technology we use, what each one is for, how long it lasts, and who receives the data. "Similar technologies" means browser storage such as localStorage, which the law treats the same way as a cookie.

9.1Strictly Necessary

These are required for the Services to work — to keep you signed in, to remember your cookie choices, and to keep the sign-up form and our API from being abused. They are set without asking, because the Services cannot be delivered without them.

Strictly necessary — set on every visit
NamePurposeLifetimeRecipient
immensity_refreshKeeps you signed in between visits. Holds a rotating refresh token; readable only by our servers, never by scripts in your browser.Up to 90 daysImmensity (first party)
immensity_consentStores the cookie choices you made on the banner, with the date and the version of this policy you were shown, so we do not ask again and can honour your choice.6 monthsImmensity (first party)
__cf_bm, cf_clearanceTells automated traffic apart from real people, protecting sign-up and the API from abuse. Set by Cloudflare, which serves and protects our sites.30 minutes to 1 yearCloudflare, Inc.

Similar technology (no cookie): Cloudflare may load a Web Analytics / Insights beacon (static.cloudflareinsights.com/beacon.min.js) on our Cloudflare-served sites. It collects cookieless performance and real-user monitoring (RUM) metrics at the CDN edge so we can keep the sites fast and available. It is not marketing analytics, does not set an analytics cookie, and is not used for advertising. Recipient: Cloudflare, Inc.

9.2Analytics — Only With Your Consent

We use one analytics product, and it is off until you turn it on. Nothing below is set, and no analytics data is collected, unless you choose "Accept" on the cookie banner.

Analytics — set only after you consent
NamePurposeLifetimeRecipient
ph_<id>_posthogProduct analytics: which features are used and where people get stuck, so we can improve the Services. Holds a randomly generated identifier — not your name or email address.12 monthsPostHog, Inc. (United States)

PostHog processes this data on our behalf under a data-processing agreement, on servers in the United States. See Section 11 (International Data Transfers). Our public marketing pages set no analytics cookies at all.

9.3Preferences

These are stored in your browser only and are never sent to us or to anyone else. They remember display choices — light or dark appearance, whether the sidebar is collapsed, which interface version you are using — and are written only when you make the choice.

Preference storage — stays in your browser
NamePurposeLifetimeRecipient
immensity-theme, lc-themeRemembers whether you chose the day or night appearance.Until you clear your browser storageNobody — stays on your device
sidebar_collapsed, interface flagsRemembers layout choices inside the application so it looks the same next time.Until you clear your browser storageNobody — stays on your device

9.4Your Choice, and How to Change It

The first time you use the application we show a banner with two equally available options: accept analytics cookies, or reject them. Nothing in Section 9.2 is set unless you accept. Rejecting is a single click and takes effect immediately — you are not asked again, and the Services work normally either way.

Our public marketing pages (this site) set no analytics cookies at all, so there is nothing optional to turn on or off here. Product analytics (PostHog) runs only in the Immensity application after you consent.

You can change your mind at any time: open Cookie preferences from the footer of any page on this site (an explanation of what applies where), or from Settings → Privacy inside the application, where you can withdraw consent. Withdrawing consent stops analytics collection immediately and deletes the analytics cookie from your browser.

We do not use cookies for advertising, we do not sell or share personal information for cross-context behavioural advertising, and we do not allow third parties to place advertising or tracking cookies through the Services. Browser controls such as clearing cookies also remain available to you, but you do not need them to refuse analytics — the banner and Settings controls are enough.

10Your Privacy Rights

Depending on your jurisdiction, you may have the right to:

  • Access, correct, or delete your personal information;
  • Object to or restrict certain processing;
  • Request portability of your information;
  • Withdraw consent where processing is based on consent; and
  • Lodge a complaint with a supervisory authority.

To exercise these rights, contact us using the details in Section 14. We will respond consistent with applicable law. We will not discriminate against you for exercising your rights.

To delete personal data or close an account, see Delete your data for self-service steps in the product and how to email the Privacy Team. A companion page for closing the account entirely is linked from there.

10.1California Residents

If you are a California resident, the California Consumer Privacy Act (CCPA/CPRA) provides additional rights, including the right to know, the right to delete, the right to correct, and the right to opt out of the sale or sharing of personal information. We do not sell personal information.

11International Data Transfers

Your information may be transferred to, and processed in, countries other than the country in which you reside. Where required, we use appropriate safeguards, such as standard contractual clauses, to protect your information when transferred internationally.

12Children's Privacy

The Services are not directed to children under the age of 16, and we do not knowingly collect personal information from children. If we learn that we have collected such information, we will take steps to delete it.

13Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will revise the "Last Updated" date and, where appropriate, provide additional notice. Your continued use of the Services after changes take effect constitutes acceptance of the updated policy.

14Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact:

Immensity
Attn: Privacy Team
admin@immensity.capital

For data or account deletion requests, you can also use the public instructions at Delete your data, or email the address above with the subject Data deletion request or Account deletion request.