Privacy Policy
Last updated: July 5, 2026
What this is
Cabinet (reachable at info@getcabinet.io) is an AI decision tool for solo founders. This policy explains what data we collect when you use Cabinet, how we use it, who we share it with, and what choices you have. Plain English. No dark patterns.
Data we collect
Account info. When you sign up, we store your email address, your display name (if you set one), and a password hash handled by Supabase Auth. We do not store your password in plain text and we cannot recover it.
Decision content. When you convene a council, we store the question you asked, any context you provided, the URL you optionally pasted, the council's outputs (Frame, advisor responses, dissent, synthesis, execution tiers), and metadata like duration and search count. This is so you can re-open past councils.
Integration tokens. When you connect an app (Google, Microsoft, Slack, Notion, ClickUp, HubSpot, and others), we store the OAuth access and refresh tokens for that account in our database, encrypted at rest. We use them only to read the data that powers your daily brief and to perform the actions you initiate (creating Drive files, Gmail drafts, calendar holds, tasks, and similar). You can disconnect any app at any time in Settings, which deletes its tokens.
Billing info. Stripe handles your payment method. We never see your card number. We store your Stripe customer ID and subscription status so we can show your billing tab.
Operational logs. Standard server logs (IP, user agent, request paths, response codes, timestamps) for security and debugging. Logs are retained for 30 days and not used for analytics or sold to anyone.
How we use it
We use your data to provide the Cabinet service: run councils, generate your daily brief from the apps you connect, create artifacts in your Google Workspace when you ask, charge your subscription, and let you view your past sessions. We do not train AI models on your decision content. We do not sell your data to anyone, ever.
Google API access and Limited Use
Cabinet's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We use Google user data only to provide and improve the user-facing features described below. We do not use it for advertising, we do not sell or transfer it to third parties except as needed to run those features, and no human at Cabinet reads it except where you explicitly ask us to (for example, to help you with a support request), for security, or where required by law. For each scope we request, here is the feature it powers, the data it touches, how the data is used, and how long it is kept:
gmail.readonly(restricted). Feature: your daily brief, a dashboard summary of what needs your attention each morning. Data: the sender, subject, and a short preview of your recent inbox and sent messages. Use: read transiently to identify threads waiting on you and threads you are awaiting a reply on, and to write a plain-language summary. Retention: message content is processed in memory only and is never stored; only the generated brief summary is saved, and you can delete it at any time.gmail.compose(restricted). Feature: "Save to Gmail Drafts" on an email artifact. Data: the draft subject and body you generate. Use: create a draft in your Drafts folder for you to review and send yourself. Retention: Cabinet stores nothing from this action; the draft lives in your Gmail. Cabinet never sends mail on your behalf.calendar.events(sensitive). Feature: today's schedule in your daily brief, and calendar holds you ship from a council. Data: the title, time, and attendee count of today's events. Use: read transiently to include your schedule in the brief, and write an event when you choose to create a hold. Retention: event data is not stored beyond any mention in a brief summary you can delete.drive.file(non-sensitive). Feature: creating Docs, Sheets, Slides, and folders from a council. Data: only the files Cabinet itself creates. Use: create and populate those files. Retention: the files live in your Drive; Cabinet cannot see, list, modify, or delete files it did not create.documents,spreadsheets,presentations(sensitive). Feature: populating the Docs, Sheets, and Slides Cabinet creates. Data: only the files Cabinet created above. Use: write your council output into them. Retention: the files live in your Drive; Cabinet stores no copy.userinfo.email,userinfo.profile. Feature: showing which Google account is connected. Data: your Google account email and name. Use: display them in the Integrations tab. Retention: stored only to label the connection and deleted when you disconnect the account.
Third-party processors
Cabinet uses the following processors to operate. Each receives only the data necessary for its function:
- Supabase (US): authentication, database, file storage.
- Vercel (US): hosting and edge delivery.
- Anthropic (US): AI inference. The Claude API receives the question, context, and conversation state for each council run, and, when generating your daily brief, the transient snapshot of connected-app signals it summarizes (including the sender, subject, and preview of recent email when Gmail is connected). This is sent only to produce the summary and is not stored by Cabinet afterward. Anthropic does not train on API inputs by default.
- Tavily (US): live web search and URL extraction for the autofill and advisor research tools.
- Stripe (US): payment processing. Receives your email and payment method.
- GoHighLevel / LeadConnector (US): CRM contact sync and delivery of the product emails you can opt out of (the daily brief and deliverable-ready notifications). Receives your email, name, and the brief content being sent to you.
- Composio (US): brokers connections to marketplace apps you choose to connect, and passes the requests you initiate through to those apps.
- OpenAI (US): speech-to-text transcription for the voice input in the Cabinet browser extension. Receives the audio you record when you use voice; not used to train models.
- Deepgram (US): text-to-speech and voice streaming for the browser extension. Receives the text being read aloud.
- Browserless (US): server-side rendering used to export slide decks. Receives the council output being rendered into the file.
- Google, Microsoft: only when you explicitly connect Google Workspace or Microsoft 365.
Data retention and deletion
How long we keep each kind of data, and how to remove it:
- Google email content: never stored. It is read transiently to generate your brief and discarded as soon as the summary is produced.
- Daily brief summaries and council content: kept while your account is active so you can re-open them; deleted when you delete them or close your account.
- Calendar and other connected-app data: read transiently for the brief and not retained beyond any mention in a brief summary you control.
- OAuth tokens: encrypted at rest and deleted the moment you disconnect the app in Settings.
- Google account email and name: deleted when you disconnect the Google account.
- Account and billing records: retained while your account is active and deleted within 30 days of account deletion, except where we must keep a minimal record for legal or tax reasons.
- Server logs: 30 days.
To delete everything: disconnect your apps in Settings (this removes the stored tokens), then email info@getcabinet.io to request full account and data deletion. We complete deletion within 30 days.
Your rights
You can view and edit your name and avatar in Settings. You can disconnect Google at any time in Integrations, which deletes the stored OAuth tokens. You can soft-delete past councils from the sidebar. You can email info@getcabinet.io to request a full export of your data, full account deletion, or to ask any question about how we handle your data. We respond within 7 days.
If you are in the EU/UK, you have rights under GDPR including access, rectification, deletion, restriction, portability, and objection. Contact us at the same address to exercise any of them.
Security
All data is encrypted in transit (TLS) and at rest. Database access is restricted by Row Level Security so users can only access their own data. OAuth tokens are stored separately from your decision content. We have no plans to be careless about this.
Children
Cabinet is not intended for anyone under 18. We do not knowingly collect data from children.
Changes to this policy
When we update this policy materially, we will notify you by email before the change takes effect. The current version always lives at this URL with a "last updated" date at the top.
Contact
Questions, requests, complaints: info@getcabinet.io.