Privacy Policy
A plain-language summary of what SymaOS reads, what it stores, who can see it, and how to ask for it back or have it deleted.
Draft document
This text is an engineering placeholder pending review by qualified legal counsel. It is published so SymaOS can be evaluated end-to-end before public launch, but it is not legal advice and must not be relied upon for production decisions. The launch gate (SYMAOS_LEGAL_APPROVED=false) keeps public signup, paid plan activation, and App Store submission blocked until lawyer-reviewed versions ship.
Effective date
June 12, 2026
1. Who we are
SymaOS ("we", "us", "our") operates the SymaOS personal operating system: a web dashboard, an iOS / Android companion application, and the underlying APIs that organize email, calendar, tasks, and approvals on behalf of a single end user.
For the purposes of the EU/UK GDPR, the California Consumer Privacy Act (CCPA / CPRA), and equivalent regimes, SymaOS acts as the data controller for account data and as a data processor for content read on your behalf from connected providers (Google Workspace, Microsoft 365, etc.).
2. What we collect
We deliberately keep the surface area small. We collect:
- Identity data: the email address you sign in with and any optional display name. We do not collect demographic data, government identifiers, or health data.
- Authentication metadata: hashed session tokens, session timestamps, IP address, user agent, and OAuth state nonces used to prevent CSRF on third-party callbacks.
- Connector tokens: encrypted OAuth access and refresh tokens for the providers you choose to connect (Gmail, Google Calendar, Microsoft 365). Tokens are encrypted at rest with an envelope key controlled by SymaOS.
- Derived task and calendar metadata: normalized tasks, schedules, briefs, and audit entries. We minimize raw message body retention - we extract evidence snippets needed for traceability and discard the rest as soon as the extraction is committed.
- Billing data: Stripe customer and subscription identifiers, plan, status, and high-level usage counters. SymaOS never sees or stores card numbers - card data is handled exclusively by Stripe.
3. How we use your data
We process the data above strictly to:
- Operate the daily brief, planning, and approval loops.
- Authenticate you and maintain a single canonical account regardless of which identity provider you used to sign in.
- Bill the correct plan, enforce entitlements, and account for AI usage costs.
- Detect abuse, debug failures, and recover from incidents using short-lived structured logs scrubbed of sensitive content.
We do not sell your data, share it with advertising networks, or use it to train third-party foundation models on your private corpus.
4. AI processing
When SymaOS extracts tasks or composes a brief, evidence snippets may be sent to a third-party large language model provider for summarization. These snippets are processed under zero-retention terms wherever the provider supports them. Raw email bodies and calendar events are never used to train external models.
A complete list of AI sub-processors is published on our sub-processors page.
5. Legal bases (EU / UK)
- Contract: processing required to deliver the SymaOS service you signed up for.
- Legitimate interest: security, abuse prevention, and aggregate, non-identifying product analytics.
- Consent: connecting an optional provider (Google, Microsoft) or enabling AI-assisted features.
- Legal obligation: tax records, fraud prevention, responding to lawful access requests.
6. Sharing and sub-processors
SymaOS shares data only with the vetted sub-processors required to run the product (cloud hosting, database, queueing, payments, AI providers, error tracking). Each sub-processor is bound by a data processing agreement and listed at /sub-processors.
We do not transfer your data outside of contractually permitted regions without appropriate safeguards (Standard Contractual Clauses or equivalent).
7. Retention
Detailed retention windows are published at /retention. As a summary: account data lives as long as the account is active; audit and billing records are retained for the legally required window; raw message bodies are not persisted after extraction.
8. Your rights
Subject to applicable law, you may at any time access, correct, export, restrict, object to, or erase your personal data. You may also withdraw consent for optional integrations and AI processing.
- Access & export: the in-product audit log shows every user-visible action; you can request a structured export at
privacy@symaos.com. - Erasure: trigger account deletion from
Settings → Account → Delete accountor via theDELETE /api/account/dataendpoint. Deletion revokes all sessions, disconnects every integration, cancels active subscriptions at the period end, and removes user data on the cooling-off schedule documented on the retention page. - Complaint: EU/UK users may lodge a complaint with their local supervisory authority.
9. Security
Encryption in transit (TLS 1.2+), encryption of secrets at rest (Fernet / KMS-managed envelope keys), least-privilege OAuth scopes, per-user tenancy enforced in every query, hashed session tokens, centralized audit logging, and a published vulnerability disclosure policy at /security.
10. Children
SymaOS is not directed at children under 16 and we do not knowingly process their data. If you believe a minor has signed up, contact privacy@symaos.com and we will delete the account.
11. Changes to this policy
Material changes will be announced in the product and via email at least 14 days before they take effect. The effective date at the top of this document reflects the most recent revision.
12. Contact
Privacy questions: privacy@symaos.com.
Security reports: security@symaos.com.
Data Protection Officer: dpo@symaos.com.