Enterprise-Grade Security
All data encrypted at rest (AES-256) and in transit (TLS 1.2+). Compliant with Google API Services User Data Policy for Gmail/Calendar access.
Legal
How Sellify collects, uses, protects, and gives you control over personal information and connected-service data.
All data encrypted at rest (AES-256) and in transit (TLS 1.2+). Compliant with Google API Services User Data Policy for Gmail/Calendar access.
Connect Google (Gmail/Calendar) or Microsoft 365 (Outlook) securely via OAuth. We access ONLY minimum data needed for CRM views and scheduling. Never used for advertising or undisclosed purposes.
Connected email/calendars enable in-app email threads for prospects/deals and AI SDR scheduling that checks availability and books meetings on your behalf.
You can connect/disconnect integrations at any time, manage scopes with Google/Microsoft, and request access, export, or deletion of your data.
We collect: account data (name, email, auth/session data); organization/workspace and member roles; content you submit (AI chat, uploads, recordings, transcripts); billing and subscription info; usage/analytics events and device/browser data; support/feedback interactions. If you connect email or calendar, we also process mailbox metadata and content necessary for CRM and scheduling features, including message bodies, participants, timestamps, attachments you open in‑app, calendar event details, availability, and invitee responses.
When you connect Gmail/Google Calendar or Outlook/Office 365, we strictly comply with Google's API Services User Data Policy and Microsoft's requirements. We access ONLY the minimum data necessary for CRM and scheduling features. Email and calendar data is used SOLELY for the disclosed purposes - never for advertising, market research, or any undisclosed purpose. Your email content is not reviewed by humans except for support with your explicit consent. We request scopes only as needed to: read/sync messages and threads relevant to your prospects/deals; send emails you trigger or that the AI SDR is authorized to send; read availability and create/update/cancel calendar events to book meetings. OAuth tokens are encrypted and stored securely. Disconnecting the integration immediately stops all access, and you can request deletion of previously synced data.
When enabled, the AI SDR can check your connected calendar availability, propose times, and book meetings with prospects by creating events and sending invites from your connected calendar/mailbox. You can configure working hours and preferences, disable automations, and audit sent messages and events in your CRM timeline.
We use your data to operate and improve the service: show in‑app email threads tied to prospects/deals; generate AI insights; schedule and manage meetings; deliver notifications; provide support; ensure security; and comply with law. We may use de‑identified/aggregated data to improve features. We do not sell personal data.
To provide the service we use established providers, including Google APIs and Microsoft Graph (integrations), OpenRouter and underlying model providers (AI generation), Stripe (billing), S3‑compatible storage (files), Deepgram (audio transcription), PostHog (analytics), Resend (email), Intercom (support chat), and Inngest (background jobs). These providers process data only as necessary to operate the service subject to their terms.
We retain data for as long as needed to provide the service and as required by law. Disconnecting email/calendar stops future syncing and removes access tokens; previously synced CRM data may remain until you delete it or request deletion. You can request deletion of your account or specific content, subject to legal/operational requirements (e.g., billing records).
We employ comprehensive security measures including: encryption in transit (TLS 1.2+) and at rest (AES-256) for all data stored in our PlanetScale database and Cloudflare R2 storage; OAuth 2.0 for third-party integrations; regular security assessments; monitoring and alerting; secure development practices. Security incidents that may affect your data will be reported within 72 hours as required by applicable regulations. While no system is 100% secure, we continuously work to maintain the highest security standards.
You may access, update, export, or delete personal data where applicable. You can disconnect integrations in settings and revoke OAuth access via Google/Microsoft. You can opt out of non‑essential marketing emails; operational emails (e.g., receipts, security) are required to provide the service.
We use cookies and similar technologies for essential operations and analytics (e.g., PostHog). You can control certain cookies via your browser settings, but essential cookies are required for core functionality.
Primary data processing and storage occurs in US East region (us-east-1) through our infrastructure providers PlanetScale (database) and Cloudflare R2 (object storage). We use Standard Contractual Clauses for any international data transfers where required. Our sub-processors are carefully selected and contractually obligated to maintain appropriate security measures. We will notify you of material changes to our sub-processors where feasible.
We commit to using data obtained through Google APIs, including Gmail and Google Calendar data, in accordance with Google's Limited Use requirements. This means: (1) We only use access to read, write, modify, or control Gmail message bodies, metadata, headers, and settings to provide a user-facing feature that is prominently described in our user interface and marketing materials; (2) We do not transfer this data to others unless necessary to provide and improve these user-facing features, comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users; (3) We do not use this data for serving advertisements; (4) We do not allow humans to read this data unless we have your affirmative agreement for specific purposes, it is necessary for security purposes, or it is aggregated and anonymized.
We may update this Privacy Policy from time to time. If changes are material, we will provide reasonable notice (e.g., in-app or email). Your continued use after changes become effective constitutes acceptance.
Contact the Sellify team and include the document name in your message.
support@sellify.ai