Privacy Policy
Privacy Policy
Effective date: September 29, 2026
Your privacy is important to us. This Privacy Policy explains how Encelade ("we", "us", or "our") collects, uses, discloses, and safeguards your information when you use our platform and services.
1. Information We Collect
Information you provide
- Account information: name, email address, and profile picture when you create an account.
- Content: presentations, images, text, and other materials you create or upload to the Service.
- Communications: messages you send to us, feedback, and support requests.
- Payment information: billing details processed through our third-party payment provider. We do not store full payment card numbers.
Information collected automatically
- Usage data: pages visited, features used, time spent, clicks, and interactions within the Service.
- Device information: browser type, operating system, device identifiers, and screen resolution.
- Log data: IP address, access times, and referring URLs.
- Cookies and similar technologies: see our Cookie Policy for details.
Proposal and shared-document analytics
When a customer shares a proposal or other document through a published link, we collect engagement data on the customer's behalf about each person who opens that link (identified by name when they open a personal proposal link, on eligible plans) and, where a recipient chooses to respond, a record of that response:
- Viewer engagement: pages viewed, time spent per page, scroll and completion, device type, browser, operating system, and approximate location (city and country derived from IP address).
- Acceptance records: when a recipient accepts or declines a proposal, we record the action, a timestamp, the IP address and user-agent of the responder, a snapshot of the terms shown at that moment, and — only if the recipient provides them — their name and email address. Providing a name or email is optional and is never required to view a proposal.
This works without cookies or similar storage on your device. The only exceptions are a random browser ID, stored if you allowed analytics cookies on Encelade or after you respond to a proposal so that your response is remembered, and your "Allow" or "No thanks" answer for a document whose sender asks first; in that case nothing is recorded unless you allow it. If you open a shared link, the party that shared it with you (our customer) is the controller of this data and relies on its legitimate interest in understanding how its documents are read; we process it on their behalf. To object, use "Stop tracking" on a personal proposal link or contact the sender.
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service.
- Process transactions and send related information.
- Send you technical notices, updates, security alerts, and administrative messages.
- Respond to your comments, questions, and support requests.
- Monitor and analyze trends, usage, and activities to improve the user experience.
- Detect, investigate, and prevent fraudulent transactions or unauthorized access.
- Generate AI-powered content (presentations, text, layouts) using third-party AI services. When you use our generation features, your input (such as prompts, text, and uploaded materials) may be sent to third-party AI providers for processing. We select providers that maintain appropriate data handling and security practices. When we use our own platform-managed AI keys (the default), these providers process your data solely to generate the requested output and do not use it to train their models. If your workspace supplies its own AI provider keys, the AI features that use them instead send your input to the provider your workspace configured, governed by your workspace's agreement with it, while our other AI features keep running on our platform-managed providers (see Section 4). See our Terms of Service for more details on AI-generated content.
3. API and Third-Party Tool Access
Encelade provides an API and supports the Model Context Protocol (MCP), allowing third-party AI assistants and developer tools to access your data on your behalf.
- Authorization: third-party tools connect using OAuth 2.0 authorization. You must explicitly authorize each connection by providing your API token. No third party can access your data without your authorization.
- Scope of access: API tokens are scoped to specific permissions (e.g., read, write, delete, generate). Third-party tools can only perform actions within the scopes you grant.
- Same protections apply: data accessed through the API or MCP is subject to the same privacy protections, security measures, and retention policies as data accessed through our web interface.
- No additional sharing: we do not share your API tokens or account data with third parties beyond what is necessary to fulfill authorized requests.
- Revocation: you can revoke API tokens at any time from your account settings. Revoking a token immediately prevents all further access by any tool using that token.
4. Google API Services and Limited Use
Encelade integrates with Google services so you can sign in with your Google account and connect Google Sheets, Google Analytics, and Google Calendar as data sources for your presentations and proposals. When you authorize a connection through Google's OAuth consent screen, we access only the data covered by the scopes you approve:
- Sign in with Google: your basic profile — name, email address, profile picture, and Google account identifier — used to create and authenticate your account.
- Google Sheets (read-only spreadsheet content): the contents of the spreadsheets connected as data sources in your decks, used to build charts and statistics; connected spreadsheets are re-read to refresh their data while a deck is open. Authorizing the connection grants Encelade read access to the Google Sheets spreadsheets your account can reach (Google's
spreadsheets.readonlyscope); in practice we read only the spreadsheets connected in your decks, never listing or browsing your Google Drive. You connect a spreadsheet by selecting it through the Google Picker; decks created before the Picker was introduced may reference spreadsheets connected through an earlier selection flow. - Google Analytics (read-only): your GA4 account and property names and the report metrics used in your decks, to build charts and statistics. You can pin a specific property; if you enable live data without pinning one, Encelade lists up to 10 of your GA4 properties and its AI planner selects the property and metrics to query.
- Google Calendar (event read and write): your calendar events — including titles, times, descriptions, and attendees — used to generate meeting decks. Depending on the delivery mode you choose, we may then add the deck link to the source event (in its description or its private properties) or create a separate reminder event, with no attendees, on your own calendar that links to the deck; in manual mode we make no changes to your calendar.
When you connect Google Sheets, Google Analytics, or Google Calendar, we also receive that Google account's basic identifiers — its email address, account ID, and sometimes name — to label and manage the connection, whether or not you use Google to sign in.
You can disconnect the Google Sheets, Google Analytics, and Google Calendar connectors from your Encelade account settings at any time, which stops Encelade from accessing the associated Google data. To revoke the underlying Google authorization — including the access granted by Sign in with Google — visit your Google Account permissions.
Encelade's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Consistent with those requirements, we use data received from Google APIs only to provide and improve the user-facing features described above. We do not transfer this data to others except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets — and in that last case only after obtaining your explicit prior consent. We do not use Google user data for advertising, and we do not use it to develop, train, or improve generalized or non-personalized AI or machine-learning models. We do not allow humans to read it unless we have your affirmative consent for specific items, it is necessary for security purposes or to comply with applicable law, or the data has been aggregated and anonymized and is used for internal operations.
Some features use the Google data you connect as input to the AI-powered generation described in Section 2 — for example, a calendar event's title, time, description, and attendees when you generate a meeting deck, or the values in a connected spreadsheet when you build charts and statistics. When generation runs on our own platform-managed AI keys (the default), that data is processed by our third-party AI providers (currently Anthropic, and where applicable OpenAI and Google's Gemini API) acting solely as our service providers under commercial API terms that let them use it only to produce the output you requested — to create and refresh your own presentation or proposal. Under those terms they do not use it to train, develop, or improve their models, and we engage them as sub-processors — listed in our Data Processing Addendum — not as independent controllers of your Google data.
If your workspace supplies its own AI provider keys (a bring-your-own-key option available on Team and Enterprise plans), the AI features that support that option send their requests — including any connected Google data used in them — to the AI provider and endpoint your workspace configured, under the agreement between your workspace and that provider rather than the sub-processor terms described above; your workspace administrator is responsible for ensuring that provider's data handling meets your requirements. Our other AI features — for example generating a deck from a calendar event or editing a deck through AI chat — continue to run on our platform-managed providers described above, even for those workspaces.
5. Legal Basis for Processing
If you are located in the European Economic Area (EEA), United Kingdom, or another jurisdiction that requires a legal basis for processing personal data, we rely on the following bases:
- Contract performance: processing necessary to provide the Service you signed up for, including account management, content generation, and payment processing.
- Legitimate interests: processing for purposes such as improving the Service, ensuring security, preventing fraud, and conducting analytics — where these interests are not overridden by your data protection rights.
- Consent: where you have given explicit consent, such as for optional analytics cookies or marketing communications. You may withdraw consent at any time.
- Legal obligation: processing necessary to comply with applicable laws and regulations.
6. Sharing Your Information
We do not sell your personal information. We may share information in the following circumstances:
- Service providers: with third-party vendors who perform services on our behalf (hosting, analytics, payment processing).
- Legal requirements: when required by law, regulation, or legal process.
- Protection of rights: to protect the rights, property, or safety of Encelade, our users, or the public.
- Business transfers: in connection with a merger, acquisition, or sale of assets.
- With your consent: when you direct us to share your information with third parties.
7. Data Retention
We retain your personal information for as long as your account is active or as needed to provide you the Service. We may also retain and use your information to comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods by data category:
- Account information: retained while your account is active, deleted within 30 days of account deletion.
- Presentation content: retained while your account is active, deleted within 30 days of account deletion.
- Server and access logs: retained for up to 90 days for security and debugging purposes.
- Payment and billing records: retained for up to 10 years as required by applicable tax and accounting regulations.
- Analytics data: aggregated and anonymized within 24 months of collection.
- Proposal viewer analytics: per-recipient engagement records tied to a shared proposal are identifiable (not anonymized) and are retained while the associated project is active, then deleted within 30 days of the project's or the account's deletion.
- Proposal acceptance records: because they evidence a recipient's response to an offer, acceptance and decline records — including the responder's IP address, user-agent, any name or email provided, and the terms snapshot — are retained for the life of the account and for up to 6 years thereafter where needed to establish, exercise, or defend legal claims, unless earlier deletion is required by law.
- Support communications: retained for up to 3 years after your last interaction for quality and training purposes.
When you delete your account, we will delete or anonymize your personal information within 30 days, except where longer retention is required by law or described above.
8. Data Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
9. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access: request a copy of the personal information we hold about you.
- Correction: request correction of inaccurate or incomplete information.
- Deletion: request deletion of your personal information.
- Portability: request a portable copy of your data in a structured, machine-readable format.
- Objection: object to processing of your information in certain circumstances.
To exercise any of these rights, contact us at privacy@encelade.ai.
10. California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act and the California Privacy Rights Act ("CCPA/CPRA") provide you with additional rights regarding your personal information:
- Right to know: you may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purposes for collection, and the categories of third parties with whom we share it.
- Right to delete: you may request that we delete personal information we have collected from you, subject to certain exceptions.
- Right to correct: you may request that we correct inaccurate personal information we maintain about you.
- Right to opt out of sale or sharing: we do not sell your personal information. We do not share your personal information for cross-context behavioral advertising purposes.
- Right to non-discrimination: we will not discriminate against you for exercising any of your CCPA/CPRA rights.
To exercise any of these rights, contact us at privacy@encelade.ai. We will verify your identity before processing your request and respond within 45 days as required by law.
11. International Transfers
Your information may be transferred to and processed in countries other than the country in which you reside. We ensure that appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission, to protect your information in accordance with this Privacy Policy.
12. Children's Privacy
The Service is not directed to children under the age of 16. We do not knowingly collect personal information from children under 16. If we learn that we have collected personal information from a child under 16, we will take steps to delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the effective date. We encourage you to review this page periodically.
14. Contact Us
If you have questions or concerns about this Privacy Policy, please contact us at privacy@encelade.ai.