Automatio Privacy Policy
We at Automatio are committed to protecting users' privacy and to being transparent on how we do it. This privacy policy describes our privacy practices in detail.
This policy provides information on why, how, and what data we collect, with whom we share it, and what you can do about it. It also contains information on the security measures, data transfers, and changes to the policy.
It contains the information that is essential to inform you of our privacy practices and to allow you to make an informed decision on exercising your privacy rights. If you want to know more, contact us at support@automatio.ai.
Collecting and Processing Your Personal Information
We do collect your personal data, which means that we are a data controller under the GDPR and other data protection laws. The controller is Automatio OÜ, a company registered in Estonia.
We use third-party tools for processing the data on our behalf. They are data processors under the GDPR and other data protection laws.
We collect and process data according to the data protection laws applicable to the relationship between us and you. The legal basis of collection and processing depends on the specific data and the specific context of the collection. Among others, it may include:
- We need to enter in a contract with you, such as when you create a user account on Automatio
- We need personal data in order to provide you with some features of our services, such as when you connect your Google account with Automatio
- Your explicit consent
- Our legitimate interest
- Payment processing
- Complying with the laws
How We Collect Personal Information
We collect your personal data in two ways:
- Data that you provide to us. This may be the data you provide us for creating a user account, when contacting us for customer support, or in another way.
- Data we collect by tracking technologies. We collect this data through third-party services. Most often they use cookies for collecting the data.
Categories of Personal Information We Collect
We collect and process the following categories of personal data:
On arrival to the website
- IP address
- Device fingerprints
- Data on your behaviour on our website
On creating a user account
- Full name
- Email address
Where you came from, when you create an account
When you create an account we record, once, a short label for how you found us: the campaign or source tag on the link you followed (for example utm_source=chatgpt.com), the name of the website you came from (never the page, and never what you searched for), or the app that started your connection (for example Claude, ChatGPT or a WordPress site). We do not store your IP address, browser details, the full address of any page, or advertising click identifiers for this, and we do not set cookies or use browser storage for it. We use it to understand which channels bring people to Automatio, on the basis of our legitimate interest. We delete it 25 months after you sign up, or with your account, and you can object to it at any time at support@automatio.ai.
On using certain features of our services
When you connect your Google account to Automatio, we may access the following data depending on the permissions you grant:
- Your Google email address and profile information
- Your Gmail messages, drafts, labels, attachments, and email filters
- Your Google Calendar events and calendar subscriptions
- Your Google Sheets spreadsheets and Google Drive files created or opened by the application
We access this data only when you explicitly request it through our AI interface. We do not permanently delete your emails — all email deletions use Gmail's trash with 30-day recovery.
When the AI agent looks at your other chats
When you ask the agent to find or reuse something from another conversation or project ("find the chat where we talked about X", "take the login page from my other project"), it can read the text of your other chats: the chats in your account, and chats shared with you unless their owner marked them as hidden from agents. It reads the text of the messages, never the output of tools. It can also read the saved files of the projects you own, from the last saved copy of each project: never the files that hold credentials (such as .env files and keys), the project's version history or the platform's own files, and credential-shaped values in the files it does read are replaced. When you ask it to, it can also copy files from one of your projects into another of your projects, directly between the saved copy and the project's sandbox. The text and files it reads are shown in the conversation you asked from, so they are covered by that conversation's own retention and sharing settings. They are processed by the same AI providers as the rest of that conversation.
- The agent asks first. A card in the chat lets you allow it for 30 minutes, for that chat, or everywhere. You can change this to Off or Allow, for one chat or as your account default, in the Agent menu of the message box.
- "Hide from agents" in a chat's menu in the sidebar keeps that chat, its files and the project built in it out of every other chat's agent's reach, and out of memory.
- Runs that nobody is watching (scheduled automations, background tasks and API calls) never read your other chats.
- Text or files from one chat or project are never written into a chat that other people can read (a shared chat, a public link or a shared canvas).
Temporary chats
A temporary chat is one you switch on before the first message. It does not appear in your chat history or in search, nothing you say in it is added to memory, and no other chat's agent can read the conversation or list its files. Automatio deletes it, with the files made in it, from your account after a day with no activity (checked once an hour). "Keep chat", available between replies, turns it into a normal chat first; what was said while it was temporary is still never added to memory.
- While you use it, a temporary chat is saved on our servers like any other chat. It is hidden and short-lived, not unsaved.
- Files you upload in it, and files the agent makes in it, are in your file library while the chat lives, and are deleted with it. A file that another of your chats has used since is kept. Deleting the chat does not remove the copies of AI prompts and responses held by the monitoring service named above for its own retention period, or documents the agent created.
- A temporary chat that something depends on is kept instead of deleted, as a normal chat: a project built in it, a link or invitation, a canvas card or an automation. While a task, a batch or a campaign is still running in it, it is not deleted. Sending us a problem report about a temporary chat keeps it too, so that we can look at it. If the assistant itself files a problem report from a temporary chat, the chat is still deleted, but the report keeps a short excerpt of it.
When you pay, your payment information is collected and processed by Stripe, our payment processor. We do not get in touch with your payment data.
Why We Collect Personal Information
We collect and process your personal data for the following reasons:
- To operate and maintain our service and our website
- To enable you to use our service
- To monitor how users behave and use our website and service
- To gather analytics data related to improving our service
- To communicate with you
- To provide customer support
- To detect, prevent, and address any technical issues
With Whom We Share Your Personal Data
We use third-party tools that help us facilitate and operate our website and our service. These third-party tools process the data we collect from you on our behalf.
For each purpose, we share your data with:
Providing our services
To provide our services, we need to make a connection between our application and your Google account. We use Google APIs for that purpose. In the process, there is an exchange of your personal data between Automatio and Google. We exchange your personal data according to this Privacy Policy and Google API Services User Data Policy.
When processing your Google Workspace data (Gmail, Google Sheets, Google Calendar), our AI processes your data ephemerally — only for the duration of your specific request. No Google user data is retained by the AI model after your request is fulfilled. We do not use, retain, or transfer data obtained through Google Workspace APIs to develop, improve, or train generalized artificial intelligence or machine learning models.
Google API Services Limited Use Disclosure
Automatio's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How Google Workspace data is processed
Google Workspace data (Gmail, Google Sheets, Google Calendar, Google Drive) is processed exclusively by Google Gemini AI models. Data obtained through Google APIs is never sent to, processed by, or used by any third-party AI provider, including but not limited to DeepSeek, xAI (Grok), Moonshot (Kimi), Zhipu AI, Alibaba (Qwen), Minimax, OpenAI, Anthropic, or Meta.
This separation is enforced at multiple layers of our system:
- User interface enforcement: The model selector for Gmail, Google Sheets, and Google Calendar agents only displays Google Gemini models. Users cannot select any non-Google AI provider for these features.
- Server-side enforcement: Our orchestrator validates the AI model before processing any request that involves Google APIs. If a non-Google model is somehow specified, the request is automatically routed to Google Gemini 3 Flash. This check runs server-side and cannot be bypassed by the client.
- Architectural separation: Third-party AI providers (DeepSeek, Grok, etc.) remain available exclusively for features that do not access any Google API — such as web search, general conversation, and code generation in our sandbox environment. These features never receive Google user data as input.
We do not use Google user data to develop, improve, or train any generalized or non-personalized artificial intelligence or machine learning models. Data accessed through Google APIs is used solely to provide the user-facing features the user explicitly requests, and is not retained by any AI model after the request is completed.
Analytics and cookies
We analyze how our website is used with two tools. Only the first needs your choice:
- Google Analytics 4 (Google), only after you press Accept in the cookie banner. It sets two cookies, each for up to two years:
_ga, which tells visitors apart, and_ga_<container-id>, which keeps the state of a visit. It sends Google each page you view, where you came from, your device and browser type and your approximate location, together with the technical data any request carries, such as your IP address. Google keeps analytics data for no longer than 14 months. The basis is your consent, which you can withdraw at any time. - Vercel Web Analytics (Vercel, our hosting provider) sets no cookie. It counts page views using a hash of the request that is discarded after 24 hours, and records the page, the referrer, your country, region and city, and your device, browser and operating system type. The basis is our legitimate interest in measuring how the site is used.
We also set cookies so that the site works and stays secure: your sign-in session; fp_visitor (10 minutes, on the sign-in and sign-up pages, used to detect abuse such as mass account creation); and automatio_invite (30 days, set only if you open an invite link, used to credit that link to your account if you sign up).
Your choice. The banner appears on your first visit and asks again after 12 months. Reject and Accept are equal, and nothing from Google loads until you accept. “Cookie settings” in the footer reopens the choice; if you reject, or reopen it, we remove the Google Analytics cookies from your browser. The choice itself is kept in your browser's storage and is not sent to us.
Error monitoring & AI quality monitoring
When something in the app breaks, we need to be able to see what happened. Two services help us do that:
- Sentry receives crash reports: the error and where in our code it happened, the page you were on, your browser and operating system, and your account's internal ID. It does not receive your IP address, cookies, name or email, and it never records your screen. Data is stored in the European Union.
- Langfuse receives AI prompts and responses, along with the model used, token counts and your account's internal ID, so we can monitor quality, speed and cost. Data is stored in the European Union.
Problem reports you send us
Every AI response has a “Report a problem” button. Nothing below is collected unless you choose to use it. When you send a report we receive what you wrote, a pointer to that conversation and message, technical details about the run (model, code version, which tools ran), recent browser errors, your browser and screen size, and — only if you attach one — a screenshot.
Attaching a screenshot is always optional and never automatic. You see the exact image before it is sent and can remove it. It captures whatever was visible on the part of your screen you shared, so please check it first. Stored images sit at an unguessable address that is not listed or indexed. Reports and their screenshots are deleted when you delete your account.
Payment
We use Stripe to process payments. We don't get in touch with your credit card number or any other payment information. You provide such data directly to Stripe.
Automatio Browser Extension
The Automatio AI browser extension provides our AI assistant in your browser's side panel. It connects to your existing Automatio account using your current login session — it does not collect a separate username or password. The data practices, Google API Limited Use terms, and your rights described in this policy apply equally to the extension.
Data the extension accesses and sends
- Your messages. The text and voice prompts you send in the side panel are transmitted to Automatio to generate responses, the same as using the web app.
- Voice recordings. When you use voice input, the audio you record is sent to Automatio and transcribed to text using a speech-to-text provider (OpenAI Whisper). Recording only happens after you grant microphone permission and press record.
- Page content you choose to share. When you use the "@page" mention, the "Ask Automatio" right-click menu, or a browser-automation command, the extension reads content from the current page — such as text, HTML, the page URL and title, and screenshots of the visible tab — and sends it to Automatio to fulfil your request. This happens only in response to an explicit action by you.
- On-device settings. Your preferences (selected model, theme) are stored locally in your browser and are not used to identify you.
- Tools you build. Tools you create are saved to your Automatio account, so they are available in every browser you sign in to, and a copy is kept on the device that runs them. When you ask the assistant to write or fix a tool, its description, its code, and a short summary of the test run (errors, and up to 500 characters of the tool's output, which can contain page text) are sent to Automatio.
Tools you build and run
A tool runs on the page in front of you, inside a sandbox that has no network access of its own. What leaves your browser during a run is only what that tool asks for: a prompt tool sends the page text or your selection to Automatio to write its answer; a tool may ask Automatio to run one of our own tools on its behalf (a web search, a data lookup, an AI call), which sends that tool's query to your account and charges its credits; a recording or file you give a tool's form stays on the device unless the tool sends it, and a transcription sends the audio to Automatio the way voice input does.
Some tools work on your bookmarks or read your browsing history. The extension has no access to either until such a tool asks and you allow it in Chrome's own prompt, and only tools that say they need it can use it after that. History is only ever read, never deleted. What a tool reads stays in your browser unless that tool sends it on through the Automatio calls described above, and you can take the permission back at any time from the extension's details page in Chrome.
A tool can also call other services' APIs — your own backend, an app you deployed, or a service like Stripe — but only the addresses it lists, which you see on the tool and before installing it. Those requests go straight from your browser to that service, over https, without your cookies. If a service needs a key, you type it once on your device: it is stored only there, is never sent to Automatio, and is only ever sent to the one address the tool names for it.
Sharing a tool creates an unlisted link and stores that tool's name, description and code on our servers so anyone holding the link can install it — so do not publish a tool whose code contains anything private. A tool you install from someone else's link runs in the same sandbox as your own, shows what it is allowed to do before you install it, and follows the author's later updates until you pin it to a version or remove it.
Website access
The extension requests access to all websites because you can direct it to read from, or automate (click, fill, scroll, extract, screenshot), any site of your choosing, and those sites cannot be known in advance. It only reads a page or performs actions when you explicitly ask it to. It does not track your browsing history and does not run in the background on sites where you are not using it.
Limited use
Data handled by the extension is used solely to provide the features you request. We do not sell it, we do not transfer it to third parties other than the service providers that help deliver these features, and we do not use it to determine creditworthiness or for lending purposes. Any Google Workspace data accessed through the extension follows the same Limited Use terms described above.
Automatio in Discord and Telegram
You can use your Automatio agent from Discord and Telegram. It is the same agent, account, credits and chat history as the web app, so the data practices, Google API Limited Use terms and your rights described in this policy apply equally there.
What we store when you connect
- Your chat-app identity. Your Discord or Telegram user ID and username, linked to your Automatio account. Discord is connected through Discord's own authorization screen, which shares only your user ID and username; Telegram is connected with a one-time link that you open yourself.
- Which chat you are in. The ID of the Discord conversation or Telegram chat, so each message continues the right Automatio chat.
What Automatio receives and what it does not
- Only what you send it. Messages you send to the Automatio bot, messages that mention it, the commands you run and their options, files you attach, and a message you choose with "Ask Automatio" — as it appears in the form you submit, with your instruction.
- Not your other conversations. Automatio does not read your other direct messages, group chats or server channels, and it does not read channel history. Added to a server, the Automatio bot is not given permission to read message history — Discord shows the permissions it asks for before you add it.
- How it is processed. What you send is saved as a chat in your Automatio account, where you can see and delete it, and is processed by the same AI providers as any Automatio chat. A file you send with a message is copied into your Automatio files (the same place as a file you upload on the web), because Discord's and Telegram's own links to it expire; you can delete it there. Images and files the agent creates are sent back to the chat app. We do not use Discord or Telegram message content to train AI models.
Who can see replies
In Discord, replies are visible only to you, except in your own direct message with the Automatio bot, when you choose to show an answer to the chat, or when you mention the bot in a server — that answer is posted in the channel, for everyone there. Anything you share is visible to everyone in that conversation. In Telegram, the bot replies only in your private chat with it. Messages posted in Discord or Telegram are also stored by those services under their own privacy policies.
Disconnecting and deletion
Disconnect at any time under Integrations → Chat apps, or send /disconnect to the Telegram bot. Disconnecting deletes the stored link. Your Automatio chats stay in your account until you delete them (a temporary chat deletes itself after a day, see above); deleting a chat deletes its messages from Automatio. The files made in a chat stay in your file library unless you choose to delete them with the chat, or delete them there.
Your Rights as the Owner of Your Personal Data
Data protection laws give you rights as the owner of personal data. Depending on where you are from, you may have one or more of the following data subject rights:
- Right to know whether we collect and process information about you and what categories of data we collect and process
- Right to access your data
- Right to rectification, i.e. to correct your inaccurate data
- Right to object to the processing of your data
- Right to the restriction of data processing
- Right to erasure of your data
- Right to data portability, which means that you may transfer the data we have about you to another data controller
- Right to request not to be subject to automated processing, including profiling
How Can You Exercise Your Rights as the Owner of Personal Data
You may submit requests for exercising your data subject rights by contacting us:
- By email at support@automatio.ai
You also have the right to lodge a complaint with a supervisory authority. In Estonia this is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), at aki.ee or info@aki.ee.
We may request information from you in order to verify your identity before providing any personal information. You may exercise your rights only in relation to your own data, so we have to be sure that we communicate with the right person.
Location and Transfer of Your Personal Data
We use third-party services for storing your personal data. We store and transfer the data according to the applicable data protection laws. In addition, we have contracts with the third-party services we use, so they are contractually bound to keep your data safe and to handle it according to the laws.
If you are a user from the European Union, we make efforts to store your data in a member-state of the European Union. It may be transferred to a third country only based on an adequacy decision, on standard contract clauses, or another basis according to the GDPR.
Security of Your Personal Data
We take appropriate technical and organizational measures to protect your personal data against destruction, loss, alteration, unauthorized use or access. The technical measures include encryption of the databases and backups.
Our third-party service providers are reputable companies that also use appropriate safeguards to keep your data secure. They are contractually bound to do so.
Finally, it is up to you to keep your data safe by protecting your username and your password in order to avoid unauthorized access to your account and the data associated with the account.
Protecting Your Child's Privacy
We do not knowingly collect and process personal data of children below 16 years of age. If you are a parent or a guardian of a child of whom we may have collected or processed personal data, please contact us. If we become aware that we collected such data, we will delete it immediately.
Changes to This Privacy Policy
We may update this privacy policy from time to time. If we do, we will notify you of the changes by email, blog post, or another method we find suitable.
Contact Us
For any information about this privacy policy, contact us at support@automatio.ai.
Last update: September 2026