Privacy Policy
Last updated 27 September 2026
This policy explains how BiRoot AI accesses, uses, stores, shares, and deletes information. It covers the biroot.ai website, BiRoot AI Studio, BiRoot accounts, and connections made through Open Connector.
Information we collect
We store information you provide to create an account or contact us, such as your email address, display name, profile picture, and support messages. If you sign in with Google, we receive basic profile information used to identify and authenticate your account. We do not receive your Google password.
Optional cloud features process the account, workspace, device, task, command, and message information needed to provide the feature you enable. Diagnostics are opt-in. BiRoot AI does not run hidden telemetry.
Website analytics
The biroot.ai website uses Google Analytics 4 and Microsoft Clarity to understand which pages and product sections visitors read, how far they scroll, and where they click. Google Analytics runs with IP anonymisation. Visitors in the EEA, the United Kingdom, and Switzerland receive cookieless measurement only, and Clarity does not load for them, unless they give consent. These tools are used only to improve the website; they are not used for advertising, and they are not connected to BiRoot accounts or to anything you do inside BiRoot AI Studio.
Google user data and Gmail
When you choose to connect Gmail, BiRoot AI requests Google permissions needed to search and read messages, create and manage drafts, send email, modify messages and labels, and read or manage Gmail settings. These permissions are requested only after you start the connection and approve Google's consent screen.
BiRoot AI uses Gmail data only to perform user-facing actions that you request or configure. Open Connector stores the OAuth access and refresh tokens needed to keep the connection working. Those tokens are encrypted at rest, and we do not receive or store your Google password.
A workflow may pass the Gmail data needed for that task to the AI provider you selected. The product shows which workflow and tools you chose, and your use of that provider remains subject to its terms and privacy policy. We do not sell Google user data or use it for advertising.
BiRoot AI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Local data
BiRoot AI Studio runs agents on your computer. Source code, repositories, local files, AI provider credentials, and local history remain on your machine by default. Cloud-connected features send only the information needed to provide the feature you enable.
How we use and share information
We use information to authenticate accounts, provide the features you enable, keep the service secure, fix defects, answer support requests, and meet legal obligations. We share information only with service providers needed to operate BiRoot AI, with an AI provider you choose for a workflow, or when required by law. We do not sell personal information or share it with advertisers or data brokers.
Retention, revocation, and deletion
OAuth tokens are retained while the connection is active. You can revoke BiRoot AI's Google access at any time from your Google Account. After revocation, BiRoot AI can no longer access Gmail through that connection.
To delete your BiRoot account, stored connector credentials, or other information we hold, email hello@biroot.com . We will process verified deletion requests within 30 days unless a longer retention period is required by law. Data stored locally on your machine remains under your control.
Security
We use OAuth 2.0, TLS in transit, encrypted credential storage, and restricted production access. No method of transmission or storage is perfectly secure.
Changes and contact
We will update the date above when this policy changes materially. Questions about privacy or Google user data can be sent to hello@biroot.com.