Privacy Policy
This policy explains what Siftable collects, why we use it, when we disclose it, and the choices available to you.
1. Scope and Who We Are
This Privacy Policy applies to Siftable's websites, software, APIs, command-line tools, integrations, agent interfaces, and related services (the "Services"). The Services are operated by ExecuFunction Inc. ("ExecuFunction," "Siftable," "we," "us," or "our"), a Delaware corporation.
For individual and self-service accounts, ExecuFunction generally acts as the controller of personal information described in this policy. When an organization provides Siftable to its personnel or enters into a separate data processing agreement with us, the organization may be the controller and ExecuFunction may process information on its behalf. In that situation, direct requests about organization-controlled data to the organization first.
You can contact us about privacy at privacy@execufunction.com.
2. Information We Collect
2.1 Account and Organization Information
We collect account identifiers and profile information, such as your name, email address, profile image, locale, time zone, authentication identifiers, organization membership, role, and account settings. If you sign in with Google, we receive the profile information you authorize Google to provide.
2.2 Customer Content and Work Data
We process information that you or your organization submit to the Services, including tasks, notes, contacts, projects, datasets, documents, calendar records, messages, files, memories, workflow instructions, and other workspace content. This information may include personal information about other people. You or your organization are responsible for having permission to provide it.
2.3 Connected-Service Information
When you connect a third-party service, we receive the data and authorization tokens needed for the features you enable. For Google Calendar, this may include calendar lists, event titles and descriptions, start and end times, locations, attendees, recurrence information, availability, and identifiers needed to synchronize or create events.
2.4 AI, Chat, Voice, and Automation Data
We process prompts, messages, relevant workspace context, generated responses, voice transcripts, tool calls, requested and completed actions, approval decisions, execution status, and evidence produced by agent or automation workflows. If a voice feature requires audio for transcription or real-time interaction, audio may be transmitted to the service that performs that function; the product interface or feature documentation will describe any materially different storage behavior.
2.5 Credentials and Model Connections
If you use Siftable Vault or connect a model-provider account, we process encrypted credentials and related metadata, such as the connection name, provider, permitted models, validation status, and lifecycle events. Secret values are not included in ordinary data exports.
2.6 Billing and Transaction Information
We collect plan, subscription, organization seat, usage-wallet, authorization, balance, charge, refund, and invoice information. Our payment processor handles payment-card and bank-account details; we receive transaction identifiers, status, and limited billing details rather than full card numbers.
2.7 Device, Usage, Security, and Communications Data
We collect device and browser information, IP address, request and feature events, token and usage amounts, timestamps, diagnostics, error reports, security events, and audit records. We also process communications you send us and your preferences for service, analytics, and marketing messages.
3. Sources of Information
We collect information directly from you; from your organization and its administrators; from services you connect; from payment, identity, model, and infrastructure providers; and automatically when you use the Services. We may combine information from these sources when needed for the purposes below.
4. How We Use Information
We use personal information to:
- provide, personalize, synchronize, and support the Services;
- authenticate users and administer accounts, organizations, permissions, subscriptions, and usage wallets;
- process prompts, generate responses, and carry out user-configured agent or automation actions;
- maintain reliability, troubleshoot errors, measure performance, and improve product features;
- protect users, investigate abuse, prevent fraud, enforce our Terms, and secure the Services;
- process payments, maintain transaction records, and meet tax and accounting obligations;
- send service messages and, where permitted, product or marketing communications;
- respond to requests, exercise legal rights, and comply with law.
Where the European Economic Area, United Kingdom, or similar laws require a legal basis, we rely on performance of a contract, our legitimate interests in operating and securing the Services, your consent when requested, and compliance with legal obligations. We may also process information to establish, exercise, or defend legal claims. You may withdraw consent at any time, but withdrawal does not affect prior processing.
5. AI Processing and Automated Actions
When you use an AI feature, Siftable sends your Input and the context needed for the request to the selected model provider, which varies by feature and configuration and may be a provider you connect yourself. Context can include Customer Content, connected-service data, tool descriptions, and prior messages. We receive the provider's response and may store the Input, Output, tool activity, and execution records as part of your workspace or session history.
We do not use Customer Content, Input, or Output to train our machine-learning models or general-purpose third-party AI models. We use providers under business terms or settings intended to prevent provider training on this data. If you connect your own model-provider account, that provider's terms, retention practices, and your account settings govern its processing.
AI features can propose or perform actions that you request or configure. You can use available permissions, approval controls, and processing restrictions to limit those actions. Siftable is not designed to make decisions that produce legal or similarly significant effects about individuals without human direction.
6. How We Disclose Information
We disclose personal information only as described below:
- Service providers. We use providers for cloud hosting and storage, AI models, authentication, payments, email delivery, analytics, error monitoring, job orchestration, support, and isolated code execution. Depending on the feature and configuration, providers may include Google Cloud, Google, Anthropic, OpenAI, OpenRouter, Stripe, SendGrid, PostHog, Sentry, Inngest, and E2B. These examples are illustrative rather than exhaustive; the providers actually used depend on which features you enable.
- Services you connect. We exchange information with third-party services when you direct us to connect or act through them.
- Your organization. Organization administrators and other authorized users may access information in shared workspaces according to their roles and settings.
- Legal and safety reasons. We may disclose information when reasonably necessary to comply with law or legal process; protect rights, safety, and security; investigate fraud or abuse; or enforce our agreements.
- Business transactions. Information may be transferred as part of a financing, merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality protections.
- With your direction. We disclose information when you ask us to or give consent.
We do not sell personal information. We do not disclose personal information for cross-context behavioral advertising.
7. Google User Data
7.1 Data We Access
If you sign in with Google, we request basic identity scopes such as openid, email, and profile. If you connect Google Calendar, we request read and write access to the calendar data needed to display schedules, find availability, synchronize events, avoid conflicts, and create or update events you request.
7.2 Storage, AI Processing, and Disconnection
We encrypt stored Google OAuth tokens. We may cache Calendar records in Siftable so the Services can synchronize and use them in requested scheduling and AI features. We send Google user data to a model provider only when needed to provide a user-facing feature you request.
Using Siftable's Calendar disconnect control marks the account as disconnected. It may not immediately delete stored Google OAuth credentials or block every manually requested synchronization path. To stop Siftable's Google API access, revoke access from your Google Account permissions. Calendar records already stored as Siftable workspace data may remain until you delete them or your account, subject to the retention rules below.
7.3 Google Limited Use Disclosure
Siftable's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not use Google user data for advertising. We do not use it to create, train, or improve a generalized AI or machine-learning model. We transfer it only as needed to provide or improve a user-facing feature, for security, with your consent, or as required by law. Humans may access Google user data only with your affirmative agreement for a specific purpose, when necessary for security or support and permitted by Google policy, or when required by law.
8. International Data Transfers
ExecuFunction is based in the United States, and we and our service providers may process information in the United States and other countries. Those countries may have data-protection laws different from the laws where you live. Where required, we use appropriate safeguards for restricted transfers, which may include contractual protections such as the European Commission's Standard Contractual Clauses or the United Kingdom's approved transfer mechanisms.
9. Retention and Deletion
We retain information for as long as reasonably necessary to provide the Services, maintain security and integrity, comply with law, resolve disputes, and enforce agreements. The period depends on the type of information, why we use it, your settings, organization requirements, and applicable law.
- Account and workspace content is generally kept until you delete it or close the account, subject to organization ownership and the exceptions below.
- Connected-service credentials may remain stored after an in-product disconnect. For Google Calendar, revoke access through Google Account permissions to stop Siftable's Google API access. We retain or delete other connected-service credentials according to the integration's behavior, account controls, operational needs, and legal obligations. Records previously imported into Siftable follow the retention rules for workspace content.
- Assistant action and execution records may remain stored as workspace or operational records until you delete applicable content or close the account, or until we remove or de-identify them under our data-management processes. Product configuration currently limits how far back certain assistant records are returned by default; that lookback limit is not an automatic deletion schedule. Operational, audit, fraud-prevention, and security records may be retained longer when needed to protect the Services.
- Billing and transaction records are retained as required for accounting, tax, dispute, and legal purposes.
- Backups may retain deleted information for a limited period until they are overwritten or aged out.
When you request account deletion, Siftable deletes or de-identifies personal account data from active systems. Some information may remain because it belongs to an organization or shared workspace, is needed to preserve transaction or security records, is part of a backup, or must be retained for legal or system-integrity purposes. Certain datasets or resumable-work evidence may be retained in de-identified or pseudonymized form when deleting them would impair shared data or an authorized recovery process. Audit records may be retained after removing the direct account link.
10. Your Rights and Choices
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of your personal information; receive a portable copy; withdraw consent; and appeal a denied request. Siftable provides controls and endpoints for data export, correction through ordinary editing, account deletion, AI-processing restriction, and consent preferences covering core service, AI processing, analytics, and marketing.
- Access and portability. Request or download a structured JSON export. Exports include Vault and model-connection metadata but not secret values.
- Correction. Edit account and workspace information through the Services or ask us to correct it.
- Deletion. Use available account controls or contact us to request deletion, subject to the retention exceptions above.
- AI restriction. Use the processing-restriction control to store your data without using it in Siftable AI features where that control applies.
- Consent and communications. Manage available core-service, AI-processing, analytics, and marketing consent preferences. You can unsubscribe from marketing email, but we may still send service and transactional messages.
- Objection and appeal. Contact us to object to processing based on legitimate interests or to appeal a privacy-request decision.
To exercise a privacy right, use the available controls in the Services or email privacy@execufunction.com. We may need to verify your identity and authority. We will respond within the period required by applicable law.
If European data-protection law applies, you may complain to the supervisory authority where you live or work. A list of European supervisory authorities is available from the European Data Protection Board.
11. Security
We use administrative, technical, and organizational safeguards designed to protect personal information. These include encrypted network connections, encryption for sensitive stored credentials, access controls, tenant-aware database protections, hashed personal access tokens, audit and security logging, monitoring, and restricted production access. No system is completely secure, and we cannot guarantee that unauthorized access or loss will never occur.
For more information, see our Security page. If you believe you found a security issue, contact security@execufunction.com.
12. Children
The Services are not directed to children under 18, and we do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact privacy@execufunction.com.
13. Changes to This Policy
We may update this Privacy Policy as the Services and legal requirements change. We will update the date and version above. If a change materially affects how we use personal information, we will provide notice by email, in-product message, or another reasonable method before the change applies when required. We will request new consent when the law or Google API policy requires it.
14. Contact Us
Questions or requests about this Privacy Policy may be sent to:
- Privacy: privacy@execufunction.com
- General: hello@execufunction.com