Privacy Policy
Company draft for attorney review. Version: launch-draft-1. Effective date: September 11, 2026. Operator: [LEGAL OPERATOR NAME], operating under the Pineform Labs brand, 1550 Wilson Blvd, Ste 700 PMB264, Arlington, VA 22209. Contact: [email protected]. The legal operator and jurisdiction-specific disclosures must be finalized before public launch.
Scope
This policy describes Soren's handling of information for its AI-assisted productivity service. Current hosted functionality is private staging. Organizational workspaces can contain shared tenant data; conversations and the Google connection are organization-owned, not a guarantee of a separate private vault for each member. Your organization's own policies and any separate agreement may also apply. We will clarify controller and processor responsibilities in applicable organizational agreements before offering deployments that require them.
Information we process
- Account information: name and email supplied by verified Google sign-in, account identifiers, authentication-related information, session metadata, and organization and membership information. Google login tokens are not persistently stored by the login flow; Soren stores its own session credential digests.
- Conversation information: prompts, messages, instructions, model responses, conversation identifiers, timestamps, and related metadata. Content you submit and generated responses may contain personal or sensitive information about you or others.
- Google Workspace information: authorized Gmail message metadata and content, Calendar lists and events, and Drive file metadata and supported content. We also store encrypted Workspace OAuth access and refresh credentials and connection/account metadata.
- Technical information: network IP addresses processed for connections and rate limits, browser/device information supplied with requests, timestamps, diagnostics, and application/security logs. Not all technical information received by the hosting stack is stored in Soren's application logs. Current application logging uses bounded operational fields rather than intentionally logging message bodies or credentials.
Google Workspace access and use
Sign in with Google verifies identity. Connecting Google Workspace is a separate, explicit authorization. Current Workspace scopes provide READ access only to supported Gmail, Google Calendar, and Google Drive information. They do not grant Gmail sending, Calendar modification, or Drive writing. Access depends on your authorization and the permissions of the connected account.
We use Google Workspace information to provide requested Soren functionality, such as showing relevant messages, events, documents, and context. Bounded excerpts may be sent to OpenAI as context when needed to answer a supported AI request. We do not sell Google Workspace data, use it for advertising, or use it to develop or train generalized AI models. Our intended use and transfer of information received from Google APIs is limited to the Google API Services User Data Policy, including its Limited Use requirements; this draft is not a claim of completed Google verification or a security assessment.
You can disconnect using Disconnect in the Google Workspace section of the signed-in service. A successful local disconnect removes stored credential ciphertext from the live connection record and blocks future reads through that connection. Soren also attempts provider revocation, which may fail if Google is unavailable. You can separately remove access in your Google Account's third-party connections controls. Disconnection does not automatically delete previously saved prompts, responses, connection metadata, audit records, or backups. Responses may retain information drawn from retrieved content. Contact [email protected] for deletion requests.
AI processing
OpenAI may process the prompts, relevant conversation history, bounded evidence excerpts, and pseudonymous safety identifiers needed to fulfill AI requests. Soren stores conversation responses and separate request/usage metadata. Soren requests disabled response storage through the API's store setting, but that setting is not a promise of zero provider retention. Provider handling remains subject to the applicable service terms, data controls, and legal obligations. We do not claim that OpenAI never retains data. Provider account settings, contracts, and processing locations must be confirmed before public launch.
Voice and audio
The current commercial server does not provide raw audio transcription or synthesis; those endpoints are unavailable. A separate local development voice feature processes microphone audio for transcription and text for synthesized playback using local speech software. Transcripts submitted as messages are stored as conversation data. That local implementation uses temporary audio processing; it does not implement speaker identification or voiceprints. We do not use voice for biometric identification. If hosted audio processing is introduced, we will disclose its processing, providers, and retention before making it available. Obtain any legally required consent before recording others.
Purposes and sharing
We process information to authenticate users, operate requested features, maintain tenant and permission boundaries, support users, diagnose errors, prevent abuse, and meet legal obligations. Where applicable law requires a legal basis, we will rely on an appropriate basis such as performing our contract, legitimate interests in security and operation, legal obligations, or consent where required. Particular bases and local disclosures must be reviewed for the launch jurisdictions.
We share information with service providers needed to operate Soren, including the providers described on our Service Providers & Subprocessors page. Other authorized members may access organization-owned information through available workspace features. We may disclose information when legally required, to protect lawful rights or safety, or during a merger, acquisition, financing, or business transfer with appropriate safeguards and notice as required. We do not sell personal information or use it for cross-site behavioral advertising in the current service.
Cookies and browser storage
We use necessary authentication, session, OAuth browser-binding, and security mechanisms. CSRF proofs protect authenticated changes. The local development UI also keeps essential app-state and voice preferences in browser storage. Current application source includes no third-party advertising or cross-site behavioral tracking scripts. Our Cookie & Tracking Notice explains the inventory. Adding nonessential tracking would require renewed policy and consent review.
Retention
We retain information for as long as needed for the purposes described, account and service operation, dispute resolution, security, and applicable obligations. We consider sensitivity, purpose, legal requirements, and technical deletion constraints. Session expiry stops authentication but does not itself delete stored session records. Current staging does not automatically purge historical conversations, connection metadata, usage records, or audit/security logs on a fixed schedule. We are establishing and validating retention controls before public launch; no exact automatic deletion period is promised here.
Workspace reads are processed as bounded request context, rather than a background copy of your entire Workspace. Retrieved information can nevertheless appear in saved conversations, outputs, and browser memory. Backups may retain earlier records until managed expiry; deleting live records does not instantly erase backups or third-party copies. We may retain necessary records under a lawful preservation obligation, with access restricted to that purpose.
Security
We use reasonable technical and organizational safeguards appropriate to the service. The code includes authenticated tenant boundaries, CSRF protections, encrypted stored Workspace credentials, and bounded logging. Security also depends on deployment configuration and operating practices. No system is absolutely secure. We do not claim security certifications, HIPAA compliance, or guaranteed confidentiality against every threat. Report concerns to [email protected]; avoid including passwords or tokens in a report.
Choices, deletion, and privacy rights
You may stop using Soren, disconnect Google Workspace, and request access, correction, export, restriction, or deletion through [email protected]. Depending on your jurisdiction, you may also have rights to object, withdraw consent without affecting prior lawful processing, appeal a decision, or complain to a supervisory authority. We will verify requests proportionately, consider organizational authority and the rights of others, and respond as applicable law requires. We will not unlawfully discriminate against you for exercising privacy rights.
There is currently no self-service account deletion interface or complete automated account erasure workflow. The email above is the intended interim request channel and must be monitored before launch. An existing conversation-deletion endpoint is not full account deletion. Organization-owned records, linked jobs, and legally necessary records require separate assessment. We will explain applicable limitations rather than promise immediate or universal deletion.
International processing
Information may be processed where Soren and its providers operate. Exact processing locations, transfer mechanisms, and contractual safeguards are to be confirmed before public launch. We will provide required regional information and use safeguards required by applicable law; this draft does not assert a specific data-residency arrangement or certification.
Adults only and changes
Soren is intended only for users aged 18 or older and is not intended for children. If you believe a person under 18 has provided information, contact [email protected] so we can investigate and address it. We may update this policy and will identify the effective version and provide notice of material changes as required. A privacy acknowledgment is not blanket consent for unrelated future processing.
Contact
Privacy requests: [email protected]. Support: [email protected]. Security: [email protected]. Postal contact: Pineform Labs / [LEGAL OPERATOR NAME], 1550 Wilson Blvd, Ste 700 PMB264, Arlington, VA 22209.