Privacy Policy

Last updated: July 2026

What we collect

When you sign in with Google OAuth, we receive your email address, display name, and profile picture. We store this to identify your account. We do not access your Google contacts, calendar, or any other data.

We store the content you create in your workspace: leads, accounts, contacts, companies, pipelines, tasks, calendar events, logged communications, notes, and form submissions. This is your business data and it belongs to you.

How we use it

Your account data is used to authenticate you and display your profile. Your workspace data is used to provide the PI6 service — storing, serving, and searching your records.

Workspace data is isolated per workspace and enforced at the database level. Members of a workspace can see its data according to their role; nobody outside it can.

If you publish an intake form, the form itself is reachable by anyone with its link — that is the point of it. Submissions to that form are private to your workspace.

AI features

If you use in-app AI features, the relevant workspace records are sent to third-party AI providers (e.g. Anthropic, OpenAI) to process that specific request. We do not use your data to train AI models, and we do not share it with AI providers for any other purpose.

If you connect your own AI client over MCP, it authenticates as you via OAuth and acts with your permissions. The conversation itself happens between you and your AI provider under your own subscription — PI6 is not a party to it and does not store your prompts or your assistant's replies.

We do record what an AI client did. Every tool call made over MCP writes an entry to your workspace audit log: who acted, which action, which record, and when — the same trail as a change made in the web app. This is a deliberate control, so a workspace owner can always see what an assistant changed. Owners can view it under Audit Log, and revoke any client's access under Connections.

Data storage

Your data is stored in PostgreSQL databases. File uploads are stored on Cloudflare R2. Sessions are managed via Redis. All data is encrypted in transit (HTTPS). Database backups are encrypted at rest.

Data export and deletion

Your data is readable at any time through the API or your connected AI client, so you can export it without asking us.

A workspace owner can delete a workspace from Settings. This immediately makes it and all its records inaccessible, and revokes every connected AI client's access to it.

To permanently erase a workspace, or to delete your user account entirely, contact us using the details below and we will action it. Permanent erasure is irreversible.

Cookies

We use httpOnly session cookies for authentication and CSRF protection. We do not use tracking cookies, analytics pixels, or third-party advertising cookies.

Third parties

We use Google for OAuth sign-in, Cloudflare for CDN and file storage, and AI providers as described above. If we introduce paid plans we will use a payment processor and name it here first. We do not sell, share, or monetize your data in any way.

Contact

For privacy questions or data deletion requests, reach out via Discord.