1. The short version
We process your business information solely to run your agents, produce deliverables, and act on your instructions. We do not sell your data or use it for advertising. Files you upload are never stored — they are parsed in memory and discarded. What is kept is what your team produces: conversations, documents, and the distilled facts — and, if you import contacts, those people's details, because that list exists to be worked with.
2. What is kept and what is not
- Never stored: the raw file you upload — document or CSV. It is parsed in memory on the server and discarded; only what is derived from it remains (distilled facts, or contact rows if you imported contacts).
- Stored while your account exists: your identity, company facts, agent conversations, generated documents, approvals, and schedules.
- Contacts you import: the name, email and work details of third parties you upload. This is other people's data, so: it is stored isolated in your own tenant, never shared between accounts or used to train models, and deleting an import deletes its contacts immediately. You remain responsible for having a lawful basis to contact them — and no email ever leaves without your signature.
- Invoices you issue: your client's name and email, the line items and totals — enough to generate the PDF and send it to them. Payment happens on YOUR own payment link: the money never passes through us, and we store no card or bank details.
- Ephemeral: the public demo and its try-it chat persist nothing.
3. Who processes it
To do the work, your content passes through these providers. This list is complete as of the date above.
| Provider | Purpose | What it receives |
|---|---|---|
| OpenRouter (and the model providers it routes to) | Runs the agents — chat replies, deliverables, research queries, document distillation | Your prompts, conversation history, company facts, and extracted document text |
| Supabase (Postgres, AWS us-west-2) | Stores your account and everything your team produces | Identity, company facts, conversations, documents, approvals, schedules |
| Brave Search | Web search when an agent needs current information | Search queries generated from your request — not your documents |
| Resend | Sends transactional and founder-approved outbound email | Recipient address, subject and body of email you approve |
| Google · LinkedIn (only if you use them) | Optional sign-in; and, only if you explicitly connect Google, reading your Google Contacts | Your email and basic profile at sign-in; contact name, email, employer, job title and phone number if you run a sync |
| Telegram | Optional chat channel, only if you link it | Messages and documents exchanged in that channel |
| Notion | Beta signup tracking | Signup name, email, company, LinkedIn |
| Netlify / Fly.io | Hosting the web app and the agent service | Request metadata and application logs |
| Error monitoring webhook | Alerts us when something breaks | Exception text and route names |
We do not use your content to train models and we do not sell it. Each provider's own retention and training terms are theirs; we are verifying them and will update this notice with what we confirm rather than assume.
4. Connected accounts and sign-in
- Signing in: you can sign in with an email link, with Google, or with LinkedIn. With the latter two we receive your email and basic profile — nothing more — and never your password.
- Connecting Google (optional): only if you ask for it, to sync your contacts. We request exactly two permissions — basic identity, and contacts in READ-ONLY mode. We do not request Gmail, Calendar, or Drive: if those are ever needed, they will be requested separately and with your consent.
- Where those tokens live: in a table with no access policies at all — not you, not another account, and not the user-facing side of the app can read it; only the agent service can. That is deliberate: a Google token is a key to data that isn't ours.
- Disconnecting: deletes the tokens in the same instant, by a database rule rather than a scheduled job. Contacts already imported remain yours until you delete that import.
- Limited Use: StartupOPS's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use your Google Contacts only to build the contact list inside your own workspace, at your request; we never sell this data, use it for advertising, or use it to train generalized AI/ML models.
5. Isolation
Each company operates in an isolated tenant enforced by Row Level Security in Postgres, covered by automated cross-tenant isolation tests.
6. Retention and deletion
We keep your data while your account exists. You can delete company-memory facts, remove knowledge sources, delete individual contacts, and delete a whole import from inside the app at any time — deleting an import deletes its contacts with it. To export or delete your entire account, email us and we will action it within 30 days. During closed beta account deletion is handled manually rather than by a button — we would rather say so than imply automation that does not exist yet. When an account is deleted, EVERYTHING tied to it goes: conversations, documents, facts, contacts, invoices, and the tokens for any connected account. That is verified by tests, not assumed.
7. If you never had an account (demo and waitlist)
If you left your details on the public demo to get the report, or joined the waitlist, we keep what you typed — name, company, email, and for the report the conversation with Nora. Since you never had an account, there is no account to delete: so those records are removed automatically after 12 months. If you want them gone sooner, email us and we will delete them.
8. Outbound email
An agent can draft an email, but never sends one on its own — you always approve it first. It sends from our verified domain with your display name and your address as Reply-To.
9. Contact
Privacy questions: menatech@menatech.cloud