1. Overview
Beck AI ("Beck", "we", "us", or "our") provides an AI coworker platform that helps businesses coordinate work, memory, tasks, approvals, and integrations. This Privacy Policy describes how we handle personal information when you use hirebeck.com, our dashboards, or any related services (collectively, the "Service").
By using the Service, you agree to the practices described here. If you do not agree, please do not use the Service.
2. Who we are
Beck AI is the controller of personal information collected through our public marketing pages and account systems. For information you or your organization uploads, connects, or asks Beck to process, your organization is the controller and Beck acts as a processor on your behalf.
3. Information we collect
3.1 Information you provide
- Account information: name, email, password hash, organization name, and role.
- Billing information: handled by our payment processor. We do not store full card numbers.
- Content: messages you send Beck, documents you upload, knowledge sources you configure, tasks, approvals, memories, and any files you attach.
- Support communications: messages you send to our team.
3.2 Information from connected services
When you connect a third-party service (for example Gmail, Google Drive, Google Calendar, Slack, Shopify, or others), we access only the data your permissions authorize, to perform the actions you request. Scopes are shown at the time of connection and can be revoked at any time.
3.3 Automatically collected information
- Device, browser, IP address, and general location.
- Usage events (pages viewed, actions taken, features used).
- Cookies and similar technologies used for authentication, security, and analytics.
- Log data including timestamps, request identifiers, and error diagnostics.
4. How we use information
- Provide, operate, secure, and improve the Service.
- Authenticate accounts and prevent fraud, abuse, and security incidents.
- Personalize Beck's memory, tasks, and recommendations for your organization.
- Send transactional messages (verification, password reset, billing, approvals, alerts).
- Comply with legal obligations and enforce our Terms of Service.
- Understand product usage in aggregate and improve reliability, performance, and safety.
We do not sell your personal information. We do not use your business content or connector data to train foundation models.
5. AI and model processing
Beck sends prompts and relevant context to underlying AI providers to generate responses. These providers process the content only to return an answer and do not retain it for model training under our agreements. We may cache short-term data (e.g. embeddings for search) to make Beck faster and more accurate for your organization.
AI outputs may be inaccurate, incomplete, or unsuitable for a given situation. You are responsible for reviewing outputs before acting on them, particularly for legal, financial, medical, safety, or other consequential matters.
6. Google Workspace data and AI processing
Beck's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Beck does not use or transfer raw or derived Google Workspace data to develop, improve or train generalized AI or machine learning models. Google Workspace data is processed only to provide user-requested functionality.
6.1 What Google data Beck accesses
Only with your explicit OAuth consent, and only within the scopes shown at connection time: Gmail messages, threads and drafts; Google Calendar events; and Google Drive files you point Beck at. Beck accesses this content to perform the specific action you asked for — summarizing a thread, preparing a reply for your approval, checking availability, scheduling an event, or answering a question about a document.
6.2 Provider, model and tier
Any AI processing of raw or derived Google Workspace content is routed exclusively to Google's own billing-enabled, paid AI platform — the Gemini API (or Vertex AI) operated by Google — using the gemini-2.5-flash model family. This routing is enforced in our server code: content labelled as Google Workspace data cannot be sent to any other model endpoint. We never use a free-tier Gemini endpoint for this content.
6.3 No training, no secondary use
Under Google's paid-tier terms, prompts and responses submitted through the paid Gemini API / Vertex AI are not used to train or improve Google's models. In addition, Beck does not send Google Workspace content — raw, aggregated, derived, or summarized — to any general-purpose AI gateway, third-party embedding provider, model-evaluation suite, training dataset, human-review or feedback pipeline, or product analytics system. Google Workspace content is excluded from Beck's semantic long-term memory: no embeddings are generated from it, and Beck's memory suggestions derived from Google content are never promoted into the searchable memory index.
6.4 Data-origin labelling
Every record derived from a Google API response is labelled server-side with a data-origin marker (source_provider: google_workspace). Once a request touches Google Workspace content, the entire processing run is pinned to the approved Google endpoint, and every export path to a non-approved destination is blocked at the code level rather than by policy alone.
6.5 Retention and deletion
Beck does not maintain a mirror copy of your mailbox, calendar, or Drive. Google content is fetched on demand for the action you requested. Message excerpts that appear in a conversation you had with Beck are retained as part of that conversation's history for as long as you keep it, and are deleted when you delete the conversation, disconnect the connector, or delete your organization — normally within 30 days, subject to routine encrypted backup cycles. Prepared email drafts are retained until sent, discarded, or deleted. Access tokens are deleted immediately on disconnect and access is revoked with Google at the same time.
6.6 Logging
Our application and usage logs record metadata only — timestamps, request identifiers, tool names, token counts, cost, status codes, and error codes. They do not contain Gmail, Calendar, or Drive message content. Errors are recorded without message bodies.
6.7 Encryption and access control
Google OAuth refresh and access tokens are encrypted at rest with AES-256-GCM and are never exposed to browser code. All traffic is encrypted in transit with TLS. Access is restricted by row-level security scoped to your organization and role, and privileged operations are recorded in an audit log.
6.8 Your control
You can disconnect Google at any time from the dashboard, which revokes Beck's access with Google and deletes stored tokens, or revoke access directly at myaccount.google.com/permissions.
7. Third-party connectors
When you connect a third-party service, that service's privacy policy also applies. We access only the scopes you approve. You can disconnect a connector at any time from the dashboard, which revokes Beck's access on our side. You may also need to revoke access directly with the provider.
Access tokens for connectors are stored encrypted at rest.
9. Retention and deletion
We retain personal information for as long as your account is active and as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. When you delete data or your account, we remove or anonymize it within a commercially reasonable timeframe, subject to backup and legal retention requirements.
10. Security
We use industry-standard technical and organizational measures, including encryption in transit (TLS), encryption at rest for sensitive fields (AES-256-GCM for connector tokens), role-based access controls, database row-level security, audit logs, and least-privilege service credentials.
No system is perfectly secure. You are responsible for keeping your credentials confidential and notifying us of suspected unauthorized access.
11. Your rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal information, and to object to certain processing. To exercise these rights, contact us at privacy@hirebeck.com. We will verify your request and respond within the timeframe required by applicable law.
If your organization administers your Beck account, please direct rights requests to your organization first; we will assist as processor.
12. International transfers
Beck operates globally. Your information may be processed in countries other than your own. Where required, we use appropriate safeguards such as standard contractual clauses to protect international transfers.
13. Children
The Service is not directed to individuals under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us information, contact us so we can remove it.
14. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email or through the Service. Continued use after the effective date constitutes acceptance of the updated policy.
15. Contact us
Questions or requests? Email privacy@hirebeck.com.
