Trust & data
Privacy policy
This policy explains what BrokerAI handles, why it is needed, and the specific data flows behind Google Sheets and Google Meet.
Last updated: September 7, 2026
Information we handle
BrokerAI handles the information you provide when you create and use an account, including:
- Account and profile information, such as your email address, first and last name, phone number, professional title, description, profile photo and banner.
- CRM content you enter or import, including contact names, phone numbers, email addresses, countries, notes, photos, cases, budgets, tasks, comments and feedback.
- Files, images, spreadsheet details and voice recordings you intentionally submit to an import or AI-assisted feature.
- Technical and pilot-usage information needed to operate and test the service, such as session data, pages opened, controls used, form submissions, record changes, display preferences, push-notification subscriptions and diagnostic logs. Pilot telemetry records action labels and changed field names, but not passwords, phone numbers, comments or the values typed into forms.
How we use information
We use this information only to provide, secure and improve BrokerAI: to authenticate you, maintain your CRM workspace, import contacts, create meetings, deliver reminders, power the features you request, understand pilot usage, prepare restricted daily activity reports for the operator, prevent abuse and troubleshoot the service.
BrokerAI does not sell personal information and does not use it to serve advertising.
Google Sheets import
When you paste a Google Sheets URL and choose to connect Google, BrokerAI requests read-only access to spreadsheets. We use that access for the import you initiated, to read the spreadsheet identified by the URL and prepare a contact preview.
- The Google Sheets access token is used during the one-time import and is not persisted in BrokerAI's database.
- The prepared preview is private to your account and access to it expires after 30 minutes. Contact records are created only from the rows you confirm.
- To identify columns, BrokerAI may send column headings and non-content structural descriptions to OpenAI. These requests use store: false; spreadsheet row values are not sent for this column-mapping step.
Google Calendar and Google Meet
When you choose Google Meet for a contact action, BrokerAI requests permission to create and manage events. It reads the connected Google account email, creates a 30-minute event in the primary calendar and asks Google Calendar to attach a Meet link. BrokerAI does not list or browse your other calendar events.
To keep the connection available, BrokerAI stores the connected account email, granted scope, expiry information and OAuth access or refresh tokens in Supabase. Tokens are encrypted before database storage and are used only to perform meeting actions you request. You can revoke access at any time from your Google Account permissions.
BrokerAI's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. Read Google's policy.
AI-assisted processing
Some optional features use OpenAI to interpret information you submit, such as mapping import columns, extracting contacts from an image, transcribing a voice recording or structuring a case request. BrokerAI sends these API requests with store: false. Only use these features with information you are authorized to process.
Service providers and data locations
BrokerAI relies on Supabase for authentication, database and file storage; Vercel for hosting, runtime delivery and operational logs; Resend for restricted operator activity emails; OpenAI for the optional AI-assisted processing described above; and Google only when you initiate a Google integration. These providers process information under their own security and privacy commitments, potentially in countries other than your own.
We may also disclose information when required by law, or when reasonably necessary to protect users, the service or the public.
Retention and security
CRM and profile information is retained while your account uses the service, or until it is deleted or no longer needed for the purposes described here. Google Sheets authorization tokens are not retained. Google meeting credentials remain encrypted while the connection is active. Operational records may be kept for a limited period for security, reliability and legal obligations.
We use access controls, account-scoped database rules and encryption for stored integration tokens. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.
Your choices and rights
You can review and update profile and CRM information in BrokerAI, choose whether to enable notifications, decline an optional integration, and revoke Google access from your Google Account. To request access, correction or deletion of information associated with your BrokerAI account, contact us from the email address linked to that account.
Updates and contact
We may update this policy as BrokerAI changes. The date shown above identifies the latest version. Material changes will be communicated through the service when appropriate.
Questions or privacy requests: kalled.abdelmajid@gmail.com