appdeck ™
Pricing
Sign in Get started
payments Pricing home Home rocket_launch Get started

Privacy Policy

Last updated: September 8, 2026. Operated by Appdeck, Inc., 4127 2nd Ave S, Billings, MT 59101, United States.

Appdeck (“Appdeck,” “we,” “our,” or “us”) provides a knowledge base where you connect scoped sources (Google services and other third-party tools), ingest that content into a base, and Ask questions with citations. This Privacy Policy explains how we collect, use, share, and delete information when you visit appdeck.ai, use the application at app.appdeck.ai, or otherwise interact with our services.

Questions: privacy@appdeck.ai. Support (when configured): support@appdeck.ai.

1. Information we collect

Account and profile. Name, email address, authentication data, and related account settings. You may sign in with email/password or Sign in with Google.

Billing. If you subscribe, Stripe processes payment details. We receive customer and subscription metadata (for example, plan, status, and billing email). Card numbers are handled by Stripe, not stored by Appdeck.

Base content. Content you create or upload in a base (notes, files, and other records), membership and role information, and usage or metering data needed to operate the product.

Connected sources. When an authorized member connects a source (Google or another third-party connector), we store credentials or OAuth tokens for that person and ingest copies of items that match the configured slice (see Sections 3 and 4).

Support and service communications. Messages you send us and related correspondence.

Marketing site analytics. On appdeck.ai we use Google Analytics to collect standard website analytics such as page views, approximate location derived from IP, device/browser information, and referrer. We do not send Google user content from Connect (mail, files, or calendar data) into advertising or analytics pixels.

2. How we use information

We use information to:

  • Provide, operate, secure, and improve Appdeck (including search, Ask, citations, sync, and billing)
  • Authenticate users and enforce base membership and roles
  • Process subscriptions and usage metering
  • Send service-related notices (security, billing, product changes)
  • Understand marketing-site traffic (Google Analytics)
  • Comply with law and protect the rights and safety of users and Appdeck

We do not sell personal information. We do not use Google user data for advertising, retargeting, or data brokering.

3. Google user data (Connect)

Appdeck’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

What we access (read-only). With your authorization, and only for the slice you configure:

  • Gmail (gmail.readonly): messages, metadata, and in-scope attachments matching a saved search — not your entire mailbox
  • Google Drive (drive.readonly): files and metadata in folders you select — not all of My Drive
  • Google Calendar (calendar.readonly): events for calendars you select, in a bounded time window — not every calendar on the account

We do not send, modify, create, label, or delete content in Gmail, Drive, or Calendar. Access is one-way pull into Appdeck.

Why. We ingest matching items into a knowledge base so members who can read that base can search and Ask questions with citations (and, when available, attribution and origin links for the connecting user).

How Connect works. Authorize with Google → configure the slice (query, folder, or calendar) → we pull and keep the base in sync until you remove the source or disconnect. Scope is consent: Connect is not permission to take everything.

Tokens vs. content. OAuth access and refresh tokens stay with the connecting user, are stored encrypted server-side, and are not shared with other base members or exposed to Base API keys. Ingested content from a source becomes part of that base’s corpus and is visible to members who can read the base. Connect copy and this policy say so because a shared topic base is the product.

Limited Use. Google user data is used only to provide and improve user-facing Connect, search, and Ask features. We do not sell it, use it for ads, or transfer it to third parties for their independent use, except as described for subprocessors (including AI providers that process excerpts to answer questions under contract).

4. Other connected sources (Native and third-party)

Beyond Google, Appdeck may offer connectors to other systems you already use (for example project management, CRM, ERP, or file tools). This section covers that pattern generally. We do not list every connector here; the Connect UI names the vendor and permissions when you authorize.

What we access. With your authorization, and only for the slice you configure (such as a workspace, project, folder, list, or set of record types), we read matching records and related metadata from that system. Connect is not permission to take an entire account by default.

Why. Matching records are ingested into the base so members who can read that base can search and Ask with citations (and, when available, origin links for the connecting user).

How Connect works. Authorize the vendor → choose location and entity types (and any optional filters the connector supports) → we pull and keep the base in sync until you remove the source or disconnect. Tokens or credentials stay with the connecting user, stored encrypted server-side, and are not shared with other members or exposed to Base API keys. Ingested content becomes part of the base corpus and is visible to members who can read the base.

Read vs write. Unless the Connect UI and vendor authorization expressly request write access, connectors are one-way pull into Appdeck. We do not create, modify, or delete records in the origin system through a read-only connection.

Uploads and notes. Members may also add content directly (uploads, notes, and similar). The same team-visibility and deletion rules apply to that content once it is in a base.

We do not promise IT-free connection to Microsoft 365 work accounts that require tenant admin consent.

5. Artificial intelligence

When you Ask (or use related AI features), we may send relevant excerpts and prompts to a model provider — not your whole mailbox, Drive folder, calendar, or connected third-party account at once. Providers we use or may use for Ask and related completions:

  • OpenAI (including embeddings such as text-embedding-3-small)
  • Anthropic
  • Google (Gemini)

We instruct providers not to train models on your customer content under their API / business terms, and we verify no-training / data-sharing controls before enabling a provider for customer traffic. Providers process excerpts only to return answers and related product features under those terms.

6. Base API

Base owners may mint API keys that can read or write already stored base content (including items previously ingested from connected sources), according to key permissions. API keys do not receive OAuth tokens or credentials for Google or other connectors and cannot call live origin APIs on a user’s behalf. Keys are not an independent OAuth path for third parties. The base owner is responsible for integrations they enable. We do not sell or broker connected-source user data through the API to unrelated third parties.

7. Subprocessors and service providers

We use trusted providers to run Appdeck:

  • Google (Firebase / Google Cloud / Google APIs) — hosting, database, storage, functions, authentication, and Connect APIs
  • OpenAI, Anthropic, Google (Gemini) — AI completions and embeddings as described above
  • Stripe — payments and subscriptions
  • Resend (or equivalent) — transactional email
  • Google Analytics — marketing site analytics only

Application data is hosted primarily in the United States (Google Cloud / Firebase, primarily the us-central1 region). Subprocessors may process data in other regions under their terms. We do not promise EU-only residency.

8. Retention and deletion

Remove source / disconnect (live connection). Removing a connected source stops sync, may revoke related tokens or credentials, and deletes items in that base that were ingested from that source. While a source remains connected, if an item is deleted in the origin system we may keep our existing copy until you disconnect or delete it in Appdeck.

Delete items or a base. You can delete ingested items. Deleting a base removes that base’s corpus (including connector-derived copies and associated index data).

Delete account. Deleting your account in Settings is the wipe mechanism. It removes your authentication and profile, your OAuth connections and tokens, bases you own (end-to-end), and items ingested via sources you connected — including in bases you only joined. Bases you joined keep content that did not come from your connections; your membership is removed.

privacy@. Email privacy@appdeck.ai if you need us to confirm that product deletion completed. We respond to verified requests within 30 days. Email cannot perform extra deletion beyond what the product already does; there is no separate manual wipe console.

Backups. After data is removed from live systems, residual copies may remain in encrypted backups for a limited period (generally up to 30 days) until those backups expire or rotate. We do not restore deleted user data from backups into the live product except as part of whole-service disaster recovery.

9. Security

We use TLS in transit, encrypt OAuth refresh tokens at rest, and enforce authentication and base-scoped access controls. Human access to customer content is denied by default and limited to what is needed to operate and secure the service. No security program is perfect; please use strong account hygiene and report concerns to privacy@appdeck.ai.

10. Children

Appdeck is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact privacy@appdeck.ai and we will take appropriate steps.

11. International users

We are based in the United States. If you access Appdeck from another country, you understand that your information may be processed in the United States and other locations where our providers operate.

12. Changes

We may update this Privacy Policy from time to time. We will post the updated policy on this page and revise the “Last updated” date. For material changes, we may also provide additional notice (for example, in-app or by email). Continued use after the effective date constitutes acceptance of the updated policy where permitted by law.

13. Governing law

This Privacy Policy is governed by the laws of the State of Delaware, United States, without regard to conflict-of-law rules, except where mandatory local law applies.

14. Contact

Appdeck, Inc.
4127 2nd Ave S
Billings, MT 59101
United States
privacy@appdeck.ai

appdeck ™

One place to bring it all together.

Product

  • Home
  • Pricing

Legal

  • Privacy
  • Terms
© 2026 Appdeck. All rights reserved.