Privacy Policy
Last updated July 16, 2026
This policy explains what data Compify — a product operated by Cobalt Tech Solutions LLC (“Compify,” “we,” “us”) — collects, how and why we use it, who we share it with, how long we keep it, and the rights you have. It applies to compify.dev, app.compify.dev, api.compify.dev, mcp.compify.dev, and the Compify application (together, the “Service”). Capitalized terms not defined here have the meaning given in our Terms of Service at https://compify.dev/terms.
1. Our roles: controller and processor
Compify is a connector gateway: you link your third-party accounts (“Connected Accounts”) once, and you and the AI agents you connect can then read from and act on those accounts through the Service.
For the personal data we hold about you as our user — your account, billing, and usage data — Cobalt Tech Solutions LLC is the data controller.
For personal data contained in the content that flows through the Service when tool calls run against your Connected Accounts, you (or your organization) are the controller and Compify acts as your processor or service provider: we process that data only to execute the instructions you and your connected AI agents issue. We have no direct relationship with the individuals whose personal data may appear in that content; if you are such an individual, please direct requests to the Compify customer whose account processed your data.
Questions or requests about this policy: privacy@compify.dev.
2. Information we collect
- Account data — name, email address, and profile image, collected through our authentication provider (Clerk) when you sign up, including basic profile data returned by Google or another sign-in provider you choose.
- Connected Account credentials — the OAuth access and refresh tokens and API keys you grant so the Service can act on your Connected Accounts. These are encrypted at rest and used solely to execute the tool calls you and your AI agents issue.
- Tool-call logs and metadata — which connector and tool were called, when, by which workspace member or agent, and with what result status. We store logs and operational metadata; the content of your Connected Accounts is transmitted through the Service to fulfil each tool call and is not retained beyond what is needed to deliver the response and maintain short-lived operational logs.
- Workspace data — workspace names, memberships, roles, and invitations.
- Billing data — subscription tier and billing status. Card details are collected and stored by Stripe, our payment processor; we never store full card numbers.
- Usage and device data — pages visited, features used, IP address, browser type, and diagnostic logs used to operate, secure, and improve the Service.
- Cookies — see “Cookies and analytics” below.
3. How we use information
We use data to: provide and authenticate the Service; execute the tool calls you and your AI agents issue against your Connected Accounts; process payments; send transactional account, security, and service emails (via Resend); monitor, secure, and improve the Service and prevent abuse; and comply with legal obligations.
Three commitments, stated plainly:
- We do not sell your personal data.
- We do not use your data or your Connected Account data for advertising.
- We do not use your Customer Content or Connected Account data to develop, train, or improve artificial-intelligence or machine-learning models.
4. AI agents and third-party services
When you connect a third-party service and issue tool calls — directly or through an AI agent such as Claude or ChatGPT — you are instructing Compify and that service to exchange data according to the scopes you granted. Data sent to or received from a third-party service or AI provider is handled by that party under its own terms and privacy policy; Compify is not responsible for the data practices of services you choose to connect. You can disconnect any Connected Account at any time, which deletes the stored credential and, where the provider supports it, revokes the grant upstream.
5. Google API Services — Limited Use disclosure
Compify's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, for data obtained through Google APIs (for example Gmail, Drive, Calendar, Sheets):
- we only use it to provide and improve the user-facing features you request — executing the tool calls you and your agents issue;
- we do not use it for advertising of any kind;
- we do not sell it or transfer it to third parties except to provide the features you requested, with your consent, for security purposes, or to comply with law;
- we do not allow humans to read it except with your explicit permission, where necessary for security or abuse investigation, to comply with law, or where it has been aggregated and anonymized;
- we do not use it to develop, train, or improve generalized artificial-intelligence or machine-learning models.
You can review and revoke Compify's access to your Google data at any time at https://myaccount.google.com/permissions.
6. How we share information
We share personal data only as needed to run the Service:
- Subprocessors — vendors listed in the next section, bound by data-protection obligations.
- Third-party services and AI providers you connect — at your direction, when tool calls run (these are not subprocessors; you engage them directly).
- Workspace administrators — admins of a workspace you belong to can see workspace data, including connections, logs, and member activity.
- Legal and safety — when required by law, to enforce our terms, or to protect the rights, property, or safety of Compify, our users, or the public.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this policy.
7. Subprocessors
We currently use the following subprocessors to deliver the Service and will give notice of material additions:
- Clerk, Inc. (US) — authentication and user management.
- Stripe, Inc. (US) — payment processing and billing.
- Resend / Plus Five Five, Inc. (US) — transactional email delivery.
- Amazon Web Services, Inc. (US) — object storage (S3) for files you upload.
- Cloud hosting provider (US/EU) — servers and databases running the application.
- Cloudflare, Inc. (global) — DNS, CDN, and network security.
8. Data retention and deletion
- Connected Account credentials — kept until you disconnect the account or delete your Compify account, then deleted, with the upstream grant revoked where the provider supports it.
- Tool-call logs and metadata — retained for up to 90 days for security, debugging, and abuse prevention, then deleted or de-identified.
- Account and workspace data — kept for the life of your account.
- Billing records — retained as required by tax and accounting law.
When you delete your account, we delete or de-identify your personal data within a commercially reasonable period, except where retention is legally required. Residual copies may persist briefly in encrypted backups before aging out. To request deletion, email privacy@compify.dev or use the in-app account controls.
9. Security
We protect data with TLS encryption in transit and encryption at rest; Connected Account credentials are additionally encrypted with authenticated encryption before storage. Access is scoped and least-privilege, and administrative access is logged. No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but we will notify affected users and regulators of a personal-data breach as required by law.
10. International transfers
The Service is operated from the United States, and your data is processed there and in the locations of our subprocessors. Where we transfer personal data from the EEA, the United Kingdom, or Switzerland, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK Addendum.
11. Your rights (GDPR)
Where the GDPR or UK GDPR applies, you have the right to access, rectify, erase, and export (portability) your personal data, to restrict or object to certain processing, and to withdraw consent at any time without affecting prior processing. Our legal bases are: performance of our contract with you (providing the Service); legitimate interests (securing and improving the Service); consent (optional communications and non-essential cookies); and legal obligation. To exercise a right, email privacy@compify.dev; we will respond within the legally required timeframe. You may also lodge a complaint with your local supervisory authority.
12. US state privacy rights (CCPA/CPRA and others)
If you live in California or another US state with a comprehensive privacy law, you have the right to know what personal information we collect, to access, correct, and delete it, and to opt out of its “sale” or “sharing” for cross-context behavioral advertising. Compify does not sell personal information and does not share it for cross-context behavioral advertising. We will not discriminate against you for exercising any right. You may submit requests, including through an authorized agent, to privacy@compify.dev; if we deny a request you may appeal by replying to our decision.
13. Cookies and analytics
We use strictly necessary cookies to keep you signed in and secure the Service (set by our authentication provider), and limited first-party analytics to understand product usage. We do not use third-party advertising cookies. You can control cookies in your browser settings; blocking strictly necessary cookies may break sign-in.
14. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact privacy@compify.dev and we will delete it.
15. Changes to this policy
We may update this policy from time to time. We will post the new version here with an updated date and, for material changes, notify you through the Service or by email. Continued use after the effective date means you accept the revised policy.
16. Contact
Privacy questions, requests, or complaints: privacy@compify.dev. General support: support@compify.dev. Security reports: security@compify.dev.