TGOI
Privacy Policy
Last updated: July 25, 2026
Information we collect and process
- Account and workspace information, including name, email address, role, organization, team, invite, and membership details.
- Authentication information handled through Supabase Auth, including Google OAuth profile details such as name and email when a user signs in with Google.
- Company files and business documents uploaded or connected by users, plus extracted text, document chunks, metadata, visibility settings, and generated artifacts.
- Chat, query, prompt, image, and answer content submitted to Ask, projects, document generation, spreadsheet generation, memory, and related AI features.
- Workspace memory, canonical facts, project records, people/roster information, mentions, audit logs, and user actions created inside the product.
- Usage, billing, wallet, credit, model-routing, token, cost, refill, trial, and payment-status records needed to operate credits, trials, subscriptions, and support.
- Technical information such as device/browser signals, IP-derived request metadata available to hosting infrastructure, logs, errors, cookies, and session data needed for security and reliability.
How we use information
We use information to create accounts, authenticate users, operate organization-scoped workspaces, answer questions, retrieve company context, generate documents and spreadsheets, maintain audit trails, meter usage, show spend, prevent abuse, debug failures, provide support, and improve reliability and safety.
Google Calendar integration
When a user chooses to connect Google Calendar, TGOI accesses only the Google account and Calendar data needed to provide user-requested scheduling. This includes the connected account's email address; the primary calendar's time zone and supported conferencing options; free and busy time ranges for availability checks; and the event details the user asks TGOI to create, such as the title, start and end time, time zone, attendee email addresses, and Google Meet conference information. TGOI does not use free and busy access to read event titles, descriptions, or other event content.
To keep the connection available between sessions, TGOI stores the user's Google OAuth refresh token encrypted at rest, together with the connected account identifier and the permissions the user granted. Short-lived access tokens are used only to communicate with Google Calendar and are not included in AI prompts or logs. TGOI does not send Google OAuth tokens or Google Calendar free and busy data to AI model providers.
TGOI prepares a structured meeting proposal for the user to review. TGOI creates a Google Calendar event and sends attendee invitations only after the user explicitly confirms that proposal. TGOI does not automatically create events directly from a natural-language request.
A user can disconnect Google Calendar from TGOI Settings at any time. On disconnect, TGOI disables Calendar access, revokes the Google authorization, and deletes the stored refresh token, access tokens, and cached Google Calendar connection data. Events already created in Google Calendar remain in the user's Google Calendar and can be managed or deleted there. TGOI may retain a minimal security record that a connection or disconnection occurred, but that record does not contain Calendar event content or OAuth tokens.
TGOI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. TGOI does not use Google Calendar data for advertising or to train or improve generalized, foundation, or frontier AI models.
Google Drive integration
When a user chooses to connect Google Drive, TGOI requests selected-file access using Google's drive.file permission. The user chooses files through Google Picker. TGOI cannot browse, list, or read files the user has not selected for TGOI. TGOI also receives the connected Google account's verified email address so the user can identify which account is connected.
A selected file is imported into TGOI as durable workspace content under the visibility the user chooses: Private, Organization, or Project. Google Docs, Sheets, Slides, and Drawings may be exported into supported document formats for parsing. Imported content may be embedded, retrieved, and sent to TGOI's disclosed AI processors when needed to answer a user's request, subject to that TGOI visibility. OAuth tokens are encrypted at rest, short-lived access tokens are not logged or included in AI prompts, and file access is not used for advertising or training generalized AI models.
Disconnecting Google Drive disables access, revokes the Google authorization, and deletes stored Google credentials. Files deliberately imported into TGOI remain in the Files library until an authorized user deletes them; disconnecting is not represented as deleting those workspace copies. Account deletion also disables and revokes the connection as part of deletion processing.
TGOI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Third-party processors and AI providers
TGOI sends user content to third-party providers when needed to provide the requested feature. This includes prompts, retrieved company context, uploaded content excerpts, generated outputs, and metadata needed to complete the request.
- OpenRouter processes model calls and may route those calls to AI model providers such as OpenAI, Anthropic, Google, Meta, DeepSeek, and Perplexity depending on the selected or auto-routed model.
- Cohere processes text embeddings used for retrieval and document search.
- Tavily processes live web-search queries when web search is enabled or needed for current information.
- Supabase provides authentication, Postgres database, and storage services. The current production database deployment is configured in the ap-south-1 region, Mumbai, India.
- Vercel hosts the web application and may process request logs and deployment/runtime metadata.
- Razorpay or another payment processor may process payment details when paid subscriptions or credit purchases are enabled. TGOI should not store full card, UPI, or bank credentials directly.
Third-party providers may process data according to their own service terms and data processing practices. TGOI uses them only to provide the product features requested by the user or workspace.
Organization, team, and user scoping
TGOI is designed so each company's workspace data is scoped to that organization. Access checks use organization, user, role, team, project, and visibility rules. We do not sell one company's data or intentionally share one company's private workspace data with another company.
Retention and deletion
Workspace data is generally kept for as long as the workspace or account remains active and as needed to provide the service, maintain auditability, meet legal obligations, resolve disputes, prevent abuse, and support billing records.
Users can request access, correction, export, or deletion by contacting their workspace administrator or support@tgoi.work. Account deletion is available in Settings where configured. Deleting an account or workspace may remove or anonymize personal data, but some records may be retained where legally required or necessary for security, billing, audit, or dispute resolution.
Security
TGOI uses authentication, organization scoping, role-based access, visibility controls, server-side authorization checks, database constraints, and operational logging to help protect data. No online service can guarantee absolute security.
International processing
TGOI and its processors may process data in India and other countries where our service providers operate. By using the service, you understand that data may be transferred to and processed by these providers for the purposes described in this policy.
Changes to this policy
We may update this Privacy Policy as the product, providers, legal requirements, or payment flows change. The latest version will remain available at /privacy.
Related policies
Please also review our Terms of Service and Refund and Cancellation Policy.
Operator and contact
TGOI is an office AI workspace for companies and teams. The service is operated by Vyom Sachinkumar Singh, Cielo B 2603 Lodha Splendora, Ghodbunder Road, Thane, Maharashtra, India 400615.
Privacy contact: support@tgoi.work. This support email is the current placeholder and should be confirmed before submission to Google OAuth or Razorpay.