Privacy policy

This policy explains how SigVelo ("SigVelo," "we," "us," or "our") handles information when you visit sigvelo.com, contact us, use a SigVelo provisioning flow, or use Rook. Last updated .

Information we collect

Information you provide. We collect contact details and message content when you submit a contact or waitlist form or correspond with us.

Provisioning information. If you use a self-service setup flow, we process the account and deployment details needed to perform the actions you request. Depending on the flow, this may include Cloudflare account identifiers, resource names and identifiers, Worker URLs, deployment metadata, GitHub App installation metadata, status information, and error details. Authentication credentials and access tokens used during provisioning are short-lived.

Information collected automatically. Our hosting, security, analytics, and error-monitoring providers may process IP address, browser and device information, referring URLs, pages viewed, approximate location derived from IP, request logs, performance measurements, and diagnostic error data. If you allow optional analytics, Sentry may also collect masked session replay showing page interactions and technical state so we can reproduce errors.

Google Workspace data and Rook

What Rook accesses. Rook is a browser extension that can connect, at your direction, to Google Workspace services. When you approve the Google permissions, Rook may access the Google User Data needed for the services and task you select: Gmail message content, headers, labels, threads, and drafts; Google Calendar event details; Google Chat spaces and messages; Google Drive files, folders, metadata, and content; Google Contacts and Google Workspace Directory profile information; and basic Google Account profile information. It may create, modify, or delete Google Workspace data only when your requested task calls for an action and the connected Google service permits it.

Why Rook uses it. Rook uses this data only to authenticate and maintain the Google Workspace connection, retrieve and present information you ask it to work with, execute the specific task you give it, and provide the resulting response or requested Google Workspace action. The data Rook accesses depends on the Google services you connect and the task you request.

Where it is processed and retained. Google access tokens are used to authenticate Rook’s connection to Google-hosted MCP services and are refreshed while the connection remains active. Connection configuration is retained in Rook’s upstream MCP runtime so the connection can continue to work; you can remove it by disconnecting the service or revoking Rook’s Google access. Google User Data is otherwise processed for the active task. If you ask Rook to keep information in a conversation or workspace file, that information remains there until you delete it, subject to the operational retention described below.

Model processing and transfers. Rook may send the task-specific Google User Data needed to understand or complete a task to the AI model endpoint you choose. Its ChatGPT connection requests disabled provider-side response storage (store: false). If you configure a custom model endpoint, you direct that transfer and that provider’s terms apply. Rook also sends the information necessary to Google’s APIs and hosted MCP services to perform the requested Google Workspace operation, and uses Cloudflare as the infrastructure provider for the Rook runtime. We do not sell Google User Data, use it for advertising, or use it to develop, train, or improve generalized AI or machine-learning models. We do not permit providers that process Google User Data for Rook to use it for those purposes.

Google API Limited Use. Rook’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How and why we use information

  • Provide the site, respond to messages, and deliver requested services.
  • Complete and troubleshoot provisioning actions you authorize.
  • Operate, secure, maintain, and improve our systems.
  • Measure site reliability and understand aggregate use.
  • Send communications you request and manage waitlist participation.
  • Comply with law, enforce our terms, and protect people and services.

Where applicable law requires a legal basis, we rely on performance of a contract or steps requested before entering one, our legitimate interests in operating and securing the service, consent, and compliance with legal obligations.

Cookies and similar technologies

We do not use advertising cookies. Essential session technology may be used during a provisioning flow to maintain security and continuity. The site also uses limited session storage to restore navigation state. Cloudflare Web Analytics processes technical usage data without using cookies. Sentry performance monitoring and masked session replay remain off until you select “Allow optional analytics.” You can change that choice at any time through “Privacy choices” in the footer. Where your browser exposes Global Privacy Control, we treat an enabled signal as a denial of optional analytics.

When we share information

We share information only as needed with service providers that process it for us, including Cloudflare for hosting, storage, security, email delivery, and analytics, and Sentry for error and performance monitoring. During a provisioning action, Cloudflare and GitHub may receive information as necessary to complete the action you authorize. Their own privacy terms also apply to their services.

We may also disclose information if required by law; to protect rights, safety, and security; or in connection with a merger, financing, acquisition, or transfer of all or part of our business, subject to appropriate protections.

We do not exchange personal information for money or use it for targeted advertising. Some privacy laws may define a disclosure for analytics as a “sale” or “sharing” even when no money changes hands. Optional Sentry disclosures occur only after consent and can be stopped through “Privacy choices” in the footer.

Retention

We keep information only as long as reasonably necessary for the purposes described here, including security, dispute resolution, and legal obligations. Provisioning session data is generally configured to expire within one week; OAuth state and temporary credentials generally expire within minutes or hours. Contact records and operational logs may be retained longer when needed to respond to you, maintain business records, prevent abuse, or satisfy legal requirements. We delete or de-identify information when it is no longer needed.

Your privacy rights

Depending on where you live, you may have rights to request access to, correction of, deletion of, restriction of, or portability of your personal information; to object to certain processing; and to withdraw consent. You may also have the right to appeal a decision or complain to a data-protection authority.

California residents may request to know, correct, or delete personal information and may exercise applicable opt-out rights without discriminatory treatment. Selecting “Essential only,” or sending Global Privacy Control in a browser that exposes the signal, prevents optional analytics disclosures.

To make a request, email hello@sigvelo.com. We may need to verify your identity before completing it.

International transfers and security

SigVelo and its providers operate in the United States and other countries. When required, we use recognized safeguards for international transfers. We use administrative, technical, and organizational measures designed to protect information, including encrypted transport, restricted access, and short-lived provisioning credentials. No system can guarantee absolute security.

Children

The service is intended for businesses and developers and is not directed to children under 13. We do not knowingly collect personal information from children. If local law sets a higher age for consent to online services, we do not knowingly collect information from children below that age without appropriate authorization.

Changes and contact

We may update this policy as our services or legal obligations change. We will post the revised policy here and update the date above. If a change materially affects how we use personal information, we will provide additional notice where required.

Questions or privacy requests can be sent to hello@sigvelo.com.