Our approach
We design Companion to keep your workspace under your control. We collect and use information needed to provide the Skills Hub, authenticate members, operate Companions, and keep the service secure. This policy focuses on the Gmail integration and its data practices; your organization may also host its own Companion deployment and set additional rules for its workspace.
Data access
When you connect the Gmail integration, Companion requests exactly two OAuth scopes and no others: gmail.readonly (read your mailbox) and gmail.compose (create drafts). No Gmail send, delete or modify permission is ever requested, and no other Google service is accessed.
Data use
These permissions are used solely to let your AI assistant, at your direction: search and read email threads to answer questions and summarize conversations; and create drafts in your own mailbox for you to review and send yourself. Companion never sends email on your behalf — drafts are created in your own Gmail mailbox and you send them yourself.
Data sharing
Your Gmail data is accessed directly from Google's Gmail API through Google's hosted Gmail endpoint. It is never sold, rented, shared, transferred, or disclosed to any third party other than Google. It is never used to train machine learning models, never used for advertising, and never combined with other data. The only copy of Gmail content that exists outside Google is inside your private Companion conversation transcript, which is visible only to you and workspace members you explicitly invite, and is never shared.
Data protection
Your OAuth access and refresh tokens are stored encrypted at rest using envelope encryption, are never returned by any API, and are never logged. All data access is scoped by organization with forced row-level security and least-privilege database roles. All transport uses TLS. You can revoke access at any time by disconnecting the Gmail integration in Companion settings or via your Google Account permissions page — revocation deletes stored credentials immediately.
Retention and deletion
OAuth credentials are retained only while the Gmail integration remains connected. Disconnecting the integration — or revoking access from your Google Account permissions page — deletes stored credentials from our systems immediately and permanently. Gmail content referenced in a conversation transcript is retained only as long as your Companion conversation exists, and is permanently deleted when you delete the companion or the conversation. Deleting your account deletes all associated data, including stored credentials and transcripts.
Your choices and contact
You can disconnect Gmail from Companion settings or revoke it through your Google Account permissions page. You can delete your Companion, conversation, or account using the controls available in the product. For questions about this policy or a privacy request, contact the administrator for your Companion workspace or The Vibe Company through its public website.