Legal

Privacy Policy

This Privacy Policy explains how Sylvie ("Sylvie", "we", "us" or "our") collects, uses, shares and protects information when you use our website, create an account, or use our platform and related services (the "Service"). By using the Service, you accept the practices described here.

1. Who we are

Sylvie provides a second brain for marketing teams: a living, permission-aware memory for every brand, and AI agents that run operational marketing work on top of it. Sylvie acts as a data processor for the content you connect and store in your brains, and as a data controller for your account and billing information.

2. Information we collect

We collect the following categories of information:

Information you provide

Information from the tools you connect

Information collected automatically

3. Connected accounts and permissions

Sylvie reads from a tool only after you connect it and approve access. Connections use OAuth: we receive a token limited to the permissions you approve, and we never see or store your password for that tool.

We request the narrowest set of permissions that makes the feature work, and the provider shows you exactly what is being requested before you approve it. Depending on the agents you set up, Sylvie may hold read and write permissions. Read access builds and keeps your brand brain current. Write access lets an agent you configured act in that tool on your behalf, for example drafting an email, creating a document or posting an update. Sylvie writes only when an agent you configured does so, and every action is recorded in your workspace.

Sylvie honours the permissions of the source tool. If a member of your team cannot see a file, channel or record in the original tool, Sylvie does not surface it to them.

You can disconnect a tool at any time from your Sylvie workspace, or revoke access directly with the provider: Google at myaccount.google.com/permissions, Microsoft at myaccount.microsoft.com, Slack and other providers in their connected apps settings. Revoking stops all further access immediately. Content already structured into a brain remains until you delete it, and you can delete it at any time.

Support for Microsoft 365 services, including Outlook and Microsoft Graph, follows the same rules described in this section. Where a provider imposes additional requirements on how their user data may be handled, those requirements apply in addition to this Policy.

4. Google user data

When you connect a Google service such as Gmail, Google Drive or Google Ads, Sylvie accesses that data only to provide the features you have enabled in your workspace.

Sylvie's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In practice, this means:

5. How we use your information

We use information to provide and operate the Service; to build and maintain your brand and project brains; to run the AI agents and features you request; to authenticate users and secure accounts; to process billing; to provide support; to send service and, where permitted, product communications; and to comply with legal obligations. We only process brain and integration content to deliver the Service to you.

6. Legal bases for processing

Where the GDPR or similar laws apply, we rely on: performance of our contract with you; your consent (which you can withdraw at any time); our legitimate interests in operating and securing the Service; and compliance with legal obligations.

7. Our role and yours

For the account and billing information you provide directly, Sylvie acts as a data controller. For the content Sylvie reads from the tools you connect and structures into a brand or project brain, your organisation is the controller and Sylvie acts as a processor, handling that content only on your documented instructions. We make a Data Processing Agreement available to customers who need one, including standard contractual clauses where relevant. Write to [email protected] to request it.

8. How we share information

We do not sell your personal information or your brain content. We share information only with:

9. AI models and your data

Sylvie uses AI models to structure memory and power agents. The model providers we currently use are Anthropic, OpenAI and Google, under commercial terms that prohibit them from using your content to train their models. Your brain content and integration data are never used to train foundation models, and are never shared with model providers for their own training. Each brand or project brain is isolated, so content from one account is never visible to another.

10. Research, development and training

We work continuously to improve Sylvie, and we are specific about what that involves.

11. Data retention

We keep account and billing information while your account is active and for as long as we are required to by law, for example for tax and accounting purposes. Brain content and integration data are kept while the relevant brain exists. When you delete a brain, disconnect a tool or close your account, the associated content is removed from the Service within 30 days, except where we are legally required to keep it for longer. Encrypted backups are rotated on a rolling basis and are purged within the same window. You can delete content at any time from your workspace, and you can ask us to delete it by writing to [email protected].

12. Data security

We protect your data with encryption in transit and at rest, access controls, isolation between brains, and ongoing monitoring. Sylvie respects the access permissions of every tool it connects. No method of transmission or storage is perfectly secure, but we work to protect your information using industry-standard measures.

13. International data transfers

Sylvie stores and processes customer data in the United States and the European Union. Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on appropriate safeguards, including the European Commission's standard contractual clauses, and we apply additional technical measures such as encryption in transit and at rest. Contact us if you need details of the safeguards that apply to your account.

14. Your rights

Depending on your location, you may have the right to access, correct, export, restrict or delete your personal information, to object to certain processing, and to withdraw consent. You can exercise most of these in the product or by contacting us, and we will respond in accordance with applicable law.

15. Cookies

We use essential cookies to keep you signed in and to operate the Service. Where required, we ask for your consent before using non-essential analytics cookies, and you can decline them without losing core functionality.

16. Children's privacy

The Service is intended for businesses and is not directed to children under 16. We do not knowingly collect personal information from children.

17. Changes to this policy

We may update this Policy from time to time. When we make material changes, we will update the date above and, where appropriate, notify you. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.

18. Contact us

For privacy questions or to exercise your rights, contact us at [email protected].