Privacy Policy

Effective date: August 20, 2026 Last updated: September 5, 2026

This Privacy Policy explains how Spej Corp ("Spej", "Plooms", "we", "us", or "our") collects, uses, discloses, and protects information in connection with the Plooms websites at plooms.ai (including per-customer subdomains such as yourcompany.plooms.ai and me.plooms.ai), our applications, and our services (together, the "Services").

Plooms is a private, single-tenant AI workspace: chat, document and application creation, connectors to your own accounts, and a personal or organizational knowledge graph, all grounded in what you and your organization actually know. Privacy is a core design goal of the product, and this policy describes how that works in practice.

If you use Plooms through an organization (your employer or another entity that provides you access), that organization is the controller of your workspace data and its own privacy policies and agreements also apply. For questions about how your organization uses Plooms, contact your administrator.

1. A note on how Plooms is built

Two design facts shape everything below:

2. Information we collect

a. Information you provide.

b. Information from accounts you connect (connectors). If you choose to connect a third-party account — such as Google Workspace, Microsoft 365, Box, Slack, or Microsoft Teams — Plooms reads only the specific mailboxes, labels, folders, files, sites, or channels you select. Connections are per-user and opt-in, the access you grant is revocable at any time, and stored access tokens are encrypted at rest. We ingest only what you choose; we do not access anything you have not authorized.

c. Information we collect automatically. When you use the Services we collect standard technical and usage data such as IP address, device and browser type, log and diagnostic data, and events needed to operate, secure, and meter the Services (for example, to enforce prepaid usage limits). We use strictly necessary cookies and similar technologies to keep you signed in and secure.

We do not knowingly collect information from anyone under 18. The Services are not directed to children.

3. How we use information

We use information to:

AI processing. To answer you or create an artifact, relevant content is sent to our model-serving provider to generate the result and returned to you. As stated above, that content is not retained by the provider after the request and is not used to train models, and we do not use your content to train models. When you enable web search for a chat, your query (not your private data, unless you include it) is sent to a search provider to retrieve results.

We do not sell your personal information, and we do not use your content or connected-account data for advertising.

4. How we share information

We share information only as follows:

5. Data retention and deletion

We retain your information for as long as your account is active and as needed to provide the Services, then delete or de-identify it within a commercially reasonable period, unless a longer period is required by law or to resolve disputes and enforce agreements. Security and audit logs are retained on a rolling window (currently up to 90 days for detailed security event records). You can delete individual content within the product, and you can request deletion of your account and associated data as described in Section 7.

Deleting connected-account data. When you disconnect a connector you choose what happens to what was already brought in. If you ask us to delete it, we remove it everywhere it was stored — the extracted text and its search index, the stored copies of any files, and the entries derived from it in your knowledge graph. It stops appearing in answers immediately, and the underlying records are erased shortly afterwards. If you would rather keep it — for example because you are reconnecting an account whose sign-in expired — we keep it and only the connection is removed.

6. Security

We use administrative, technical, and physical safeguards designed to protect information, including single-tenant isolation, encryption of data in transit and of stored credentials/secrets at rest, hashed passwords, mandatory two-factor authentication, least-privilege access, network hardening, and continuous automated threat monitoring and response. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, restrict or object to certain processing of, or port your personal information, and to withdraw consent. You can exercise many of these directly in the product (edit your profile, delete content, disconnect connectors) or by contacting us at [email protected]. We will not discriminate against you for exercising your rights.

California residents (CCPA/CPRA). You have the right to know what personal information we collect and how we use and disclose it, to request access and deletion, and to correct inaccurate information. We do not sell or "share" (as defined for cross-context behavioral advertising) your personal information. You may exercise these rights, including through an authorized agent, by emailing [email protected].

EEA/UK residents (GDPR/UK GDPR). Where applicable, our legal bases for processing are performance of our contract with you, our legitimate interests in operating and securing the Services, your consent (for example, to connect an account or enable web search), and compliance with law. You have the rights described above and may lodge a complaint with your local supervisory authority. Where we act as a processor for a business customer, we process personal data on that customer's documented instructions under a data processing agreement.

8. International data transfers

We are based in the United States and may process information in the United States and other countries where we or our service providers operate. Where required for transfers of personal data from the EEA, the United Kingdom, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

9. Third-party services

The Services let you connect and interact with third-party services (for example, Google, Microsoft, Box, Slack). Your use of those services is governed by their own terms and privacy policies, and their handling of your data is their responsibility. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements: we use Google user data only to provide and improve the features you connect, we do not transfer or sell it except as needed to provide those features or as required by law, and we do not use it for advertising or to train generalized AI models.

10. Google user data

This section describes, specifically, what Plooms does with data from a connected Google account. It supplements the rest of this policy; nothing here overrides Sections 5 or 7.

Limited Use. Plooms' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically:

Humans do not read your Google data. No Spej employee accesses Google user data except with your explicit permission (for example, if you ask for support on a specific problem), where required for a documented security investigation, or where required by law.

What we request, and why. Connecting Google is optional and per-user. You choose which mailbox labels, Drive folders, and transcripts to include, and you can change or remove that selection at any time.

Google scopeWhat it lets Plooms doWhere the data is storedHow long
openid, email, profileConfirm which Google account you are connecting, and check it matches your Plooms accountAccount record only (your email address)While connected
calendar.readonlyAnswer questions about your scheduleRead on demand; not storedNot retained
gmail.sendSend an email on your behalf, when you ask an agent toNot storedNot retained
calendar.eventsCreate, update, or delete a calendar event, when you askNot storedNot retained
meetings.space.readonlyBring your Google Meet transcripts into your knowledge baseYour workspace database and knowledge graphUntil you delete it
gmail.readonlyBring the content of the mail labels you select into your knowledge base, so answers can cite itYour workspace database (text + search index) and knowledge graphUntil you delete it
drive.readonlyBring the content of the Drive folders you select into your knowledge base, so answers can cite itYour workspace database, your workspace file storage, and knowledge graphUntil you delete it

We request gmail.readonly and drive.readonly — rather than a narrower scope — because Plooms ingests the content of the labels and folders you select as a background sync, on your behalf and without you picking each file individually. Google's narrower alternatives do not support that: drive.file covers only files chosen one at a time in a Google file picker, and gmail.metadata returns headers without the message content that answers are grounded in. We do not request any broader scope: Plooms never asks for permission to modify or delete your mail, or for access to your full Drive.

Deleting it. You can disconnect Google at any time, from Connectors in the product. Disconnecting revokes Plooms' access token at Google. You are then asked, separately, whether to delete everything already brought in; choosing to delete removes the extracted text, the search index entries, any stored file copies, and the knowledge-graph entries derived from them. You can also delete individual items at any time, or email [email protected] to request deletion of your account and all associated data.

11. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by prominent notice in the Services and update the "Last updated" date. Your continued use of the Services after the effective date constitutes acceptance of the updated policy.

12. Contact us

Spej Corp 230 West Ohio Street, Chicago, Illinois 60654 Email: [email protected]