Privacy Policy
Last updated: August 24, 2026
Introduction
Team0 ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI operations platform and services. We are proud to be CASA Tier 2 certified, demonstrating our commitment to enterprise-grade security and data protection standards.
Information We Collect
Personal Information
- •Name and email address (via Clerk authentication)
- •Business information you provide during onboarding
- •Payment information (processed securely by LemonSqueezy)
- •Communication preferences
Business Data
- •Business descriptions and website URLs
- •Documents and knowledge base content you upload
- •Calendar events and email data (with your explicit permission)
- •Communication channel messages (Slack, Telegram, WhatsApp)
- •Task schedules and automation preferences
WhatsApp Integration Data
When you connect WhatsApp to communicate with your Team0 agents:
- •Your WhatsApp phone number used for agent communication
- •Messages exchanged between you and your Team0 agents only
- •Message timestamps and delivery status
- •Activation codes used to connect your WhatsApp to your agents
Privacy Notice: Team0 provides a dedicated WhatsApp Business number (+1 430-200-0006) that enables secure communication exclusively between you and your AI agents. Through this Business-number bridge we do NOT access, store, or process any of your other WhatsApp conversations, contacts, or personal WhatsApp data — the connection is limited solely to agent interactions. (Separately, our optional Chrome extension can capture specific WhatsApp Web chats that you explicitly opt in to; that is a distinct, user-controlled feature described under "Chrome Extension & Privacy" below.)
Google Services Data
When you authorize Team0 to access Google services, we may collect:
- •Gmail: Email metadata, partial message content for processing (read/compose/send)
- •Google Calendar: Event details, attendees, and scheduling information
- •Google Drive: File metadata and content you explicitly share
- •Google Workspace: User profile information (name, email)
All Google data access follows Google's API Services User Data Policy and requires your explicit consent. You can revoke access at any time through your Google Account settings.
Team0's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use this data only to provide and improve the user-facing features you see; we never sell it, never share it with third parties for advertising, and never use it to train generalized AI models.
Slack Integration Data
When a workspace administrator connects Team0 to Slack:
- •Installation: We store the Slack workspace ID and name, installer Slack user ID, bot user ID, granted scopes, channel preferences, and an encrypted bot token for as long as the integration remains connected.
- •Messages to Team0: Direct messages, mentions, and replies addressed to Team0 are processed to generate a response and may be retained in your Team0 workspace conversation history.
- •Optional channel sync: Background sync is off by default. If you enable it, Team0 reads only channels you explicitly select and only while the app remains a member. Recent messages may produce structured facts with a short supporting excerpt, speaker, channel, and timestamp.
- •AI processing: Slack content is processed primarily by models hosted through Amazon Bedrock in Team0's AWS account in the United States. Direct Anthropic access is a service fallback, and short passages may be embedded by OpenAI for a standby search index. These services receive only the content needed for the requested feature.
- •No training or advertising: We do not sell Slack data, use it for advertising, or use it to train generalized AI models.
- •Disconnect and deletion: Disconnecting or uninstalling removes the Slack credential and stops new access. Learned facts are not automatically deleted on disconnect; you may delete them individually or request account data deletion.
See the Team0 for Slack page for a plain-language explanation of every requested permission.
Usage Data
- •Log data including IP addresses and browser information
- •Feature usage and interaction patterns
- •AI agent execution history
- •Credit usage and subscription data
How We Use Your Information
- •To provide and maintain our AI operations services
- •To personalize AI agents with your business context
- •To process transactions and manage subscriptions
- •To send service updates and important notifications
- •To improve our services through analytics
- •To detect and prevent fraud or abuse
- •To comply with legal obligations
- •To enable secure WhatsApp communication between you and your Team0 agents
- •To authenticate and route messages to the correct agent assigned to you
Data Security
We implement industry-standard security measures to protect your data:
- •Encryption in transit (TLS 1.2+) and at rest (AES-256)
- •Each account's data held in its own database schema, not filtered by the application
- •Regular security audits and monitoring
- •Access controls and JWT authentication via Clerk
- •Secure API endpoints with rate limiting
- •OWASP-compliant security headers and CSRF protection
- •CASA Tier 2 certified (Cloud Application Security Assessment) - independently assessed, renewed annually
- •Field-level encryption for OAuth tokens and connected-tool credentials
- •Vulnerability scanning and dependency management
If There Is a Breach
If we become aware of a breach affecting your data, we will tell you within 72 hours of confirming it, by email to the account owner. That message will say what we know, what we do not yet know, and what we are doing about it. We will follow up as the picture becomes clearer rather than waiting for certainty before contacting you.
You do not have to take our word for it: your own Google audit log shows what our application accessed, independently of us, and you can withdraw our access from your Google account at any time without asking us first.
What We Process vs. What We Store
We believe in transparency about how your data flows through our system.
💬 Conversations with AI Agents
Slack Integration
📧 Email Intelligence (Gmail Integration)
📅 Calendar Events & Tasks
🔐 Integration Credentials (OAuth Tokens, API Keys)
Why Not Encrypt Everything?
AI agents need to read your conversations and context to assist you effectively. Encrypting this content would break core functionality (search, context understanding, proactive insights). Instead, we protect your data through:
- •Per-tenant schema isolation - Your people, facts, transcripts and documents are held apart from other workspaces
- •Access controls - Only authorized workspace members can access conversations
- •Encryption at rest - All databases use AES-256 encryption (AWS RDS)
- •Selective field encryption - Credentials and secrets always encrypted with per-tenant keys
- •Data retention policies - Automatic cleanup of old data (soon to be configurable)
No Human Access: Your conversations and integrated data are processed exclusively by AI models and automated systems. Team0 staff do not proactively view or access your content. Access is only granted for critical debugging purposes.
Third-Party Services
We integrate with trusted third-party services to provide our platform:
- •Clerk: User authentication and management
- •LemonSqueezy: Payment processing
- •Amazon Bedrock: Hosts the Claude models that read and write on your behalf, and the Cohere model that powers search, inside our own AWS account
- •OpenAI: Receives short passages of your text to maintain a standby copy of the search index while we complete a migration away from it. API data, not used to train models
- •Anthropic: Direct model access, used only as a fallback if our primary hosting is unavailable
- •Meeting recording and transcription providers: Join the meetings you choose to record and transcribe the audio. Named on request as part of a security review
- •Google APIs: Calendar, Gmail integration (with your consent)
- •Meta/WhatsApp Business API: Secure messaging infrastructure for agent communication
- •AWS: Infrastructure and encrypted data storage
Data Retention
We retain data while your account is active for the feature that created it. Conversation records and some historical operational data are retained for up to 90 days by default. Durable facts your Chief learns, user-created artifacts, and active integration settings remain until you delete them or close the account. Upon account deletion, we delete personal information within 30 days, except where retention is required by law.
GDPR Compliance & Your Rights
For users in the European Economic Area (EEA), we process data under the following legal bases:
- •Your consent for optional features (including WhatsApp integration)
- •Legitimate interests for service improvement
- •Legal obligations for compliance
- •Contract performance for providing our services
Your Data Rights
Under GDPR and applicable privacy laws, you have the right to:
- •Access: Request a copy of your personal data
- •Rectification: Correct inaccurate or incomplete data
- •Erasure: Request deletion of your personal data
- •Portability: Export your data in a machine-readable format
- •Object: Opt-out of certain data processing activities
- •Restrict: Limit how we process your data
- •Withdraw consent: Revoke consent at any time (including WhatsApp connection)
To exercise these rights, contact us at hey@team0.ai or use the data management tools in your account settings.
WhatsApp Integration & Privacy
Our WhatsApp integration is designed with privacy at its core:
- •Limited Scope: You connect to Team0's WhatsApp number to chat exclusively with your AI agents
- •No Access to Your Personal WhatsApp (Business number): Through the WhatsApp Business-number bridge, we cannot see your personal contacts, groups, or other conversations. (The optional Chrome extension's opt-in, per-chat WhatsApp Web capture is separate and described under "Chrome Extension & Privacy.")
- •End-to-End Encryption: All messages remain encrypted per WhatsApp's security standards
- •Opt-in Only: You must actively send an activation code to connect
- •Easy Disconnection: Remove the integration anytime from your Team0 dashboard
- •Compliance: We follow Meta's WhatsApp Business API Terms and Privacy Policy
Chrome Extension & Privacy
Our Chrome extension ("Chief of Staff Everywhere") provides a browser side panel to chat with your AI Chief of Staff. Here is how it handles your data:
- •Authentication: The extension reads your existing Clerk authentication token from the team0.ai web app to authenticate API requests. No additional login is required. Tokens are stored locally in Chrome storage and refreshed automatically.
- •Page Context (User-Initiated Only): The extension reads the current page title, URL, selected text, or captures a screenshot ONLY when you explicitly click a quick action button or use the right-click context menu. It never monitors or tracks your browsing automatically.
- •WhatsApp Web Capture (Opt-In, Per-Chat): The extension can turn selected WhatsApp Web conversations into structured notes ("facts") for your Chief. This is strictly opt-in and per-chat: every chat starts as "Skip," and a chat is read only after you explicitly choose "Capture while viewed" on it — and only while you have that chat open in WhatsApp Web. There is no background or bulk reading, and chats you never opt in to are never read. From captured chats we extract only distilled facts (people, decisions, requests) plus a short supporting quote; the full conversation is never stored. Captured text is processed by our AI provider (Anthropic) solely to perform this extraction. You can switch any chat back to "Skip" at any time.
- •No Browsing History: The extension does not track, store, or transmit your browsing history, visited URLs, or any browsing patterns.
- •Local Storage Only: Authentication credentials and session preferences are stored locally on your device using Chrome's storage API. No data is stored on external servers beyond what is sent through normal chat interactions.
- •Host Access: The extension runs on team0.ai (to read your Team0 auth token), connects to api.team0.ai (for chat, briefings, and agent data), and — only when you use WhatsApp capture — on web.whatsapp.com. It does not access or inject content into any other websites.
- •Same Data Pipeline: All chat messages and page context shared through the extension flow through the same secure API as the web app, with identical encryption, access controls, and data retention policies.
Data Sharing and Consent
We share your data only in the following circumstances:
- •With your explicit consent
- •To comply with legal obligations or respond to lawful requests
- •With trusted service providers who help operate our platform (under strict confidentiality)
- •In connection with a merger, acquisition, or sale of assets (with prior notice)
- •To protect rights, property, or safety of Team0, our users, or the public
We never sell your personal information to third parties or use it for advertising.
Children's Privacy
Our services are not intended for children under 18. We do not knowingly collect personal information from children.
Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of significant changes via email or platform notification.
Contact Us
If you have questions about this Privacy Policy or your data, please contact us at:
Team0 Privacy Team
Email: hey@team0.ai
Your Privacy Matters
We never sell your personal information. Your business data is yours, and you can export or delete it at any time.