Privacy Policy
Last updated: September 9, 2026
This policy describes what Podclave LLC, a Florida limited liability company (“Podclave,” “we”), collects when you use podclave.com, why, and what we do with it.
We keep account information, connected credentials, and configuration to run the service. We also store Workspace files, setup, and agent history so your work can return between Sessions, plus the current content of World Shared files and My files. Private work is restricted to its owner through Podclave; shared content follows the access rules of the feature you use.
When you ask an agent to use connected Google Drive or Slack content, that content passes through Podclave. Requested Google Doc and Slack message text is screened by Google Cloud before it reaches the agent. Results can then reach your selected agent provider and remain in your Workspace’s history or saved files. We do not independently archive the source channels or documents. Content included in a saved conversation follows that conversation’s retention rules.
Our product analytics are server-side and use no cookies. We do not sell your personal data. Optional voice dictation sends mic audio to ElevenLabs, which can retain audio and transcripts. Nothing is sent to ElevenLabs if you do not use the mic.
Questions or requests: hello@podclave.com.
1. What we collect and store
Account data. Your email address, your role, organization memberships and invitations, and timestamps of account activity. Sign-in uses one-time codes sent to your email. If you register a passkey, we store the information needed to verify it. We do not receive or store your biometric data; that check happens on your device.
Credentials you connect. We store the agent and service credentials you choose to connect, including Anthropic (Claude), OpenAI (Codex) sign-in or API access, SpaceXAI (Grok), and personal GitHub access. We use them to authenticate the sessions you launch and refresh access where the provider supports it.
We keep these credentials encrypted while stored in the account service and exclude them from product analytics and application logs. Credentials needed by a tool can be made available to that tool in your Workspace. You can disconnect each provider in the product and revoke its authorization at the provider independently of us.
World repository access. A World can connect a GitHub App installation. We store the installation and selected repository information and use the access granted to prepare repositories and support requested GitHub operations. This is separate from each member’s personal agent credentials.
Google Drive connection credentials. A World Google Drive connection works differently. Podclave creates a dedicated Google service account for that connection. A World Admin adds its email address to one Shared Drive and chooses its Google role. We keep the connection credential encrypted while stored and use it only for the Drive requests described in this policy. We do not send it to a Workspace, agent, or model provider, or include it in analytics or logs.
Configuration you store. World settings, selected repositories, tools, member grants, Workspace and Session names and state, and Public URL settings. For connected services, we store the connection settings, access level, and state. We also keep limited operation records to prevent duplicate creates or posts and support troubleshooting. These records do not contain a separate copy of Drive files or Slack message text.
Workspace work. We store your repository and other Workspace files, configuration, and agent history with our compute provider, including saved state needed to return after compute parks or is replaced. Other World members and World Admins cannot inspect your personal Workspace or its chat titles and contents through Podclave. Content you place in Shared files or send to a connected service follows that feature’s access rules.
Supervisor Sessions and saved conversations. In Worlds where this feature is enabled, we keep a readable copy of your conversations and retained attachments so you can review them while compute is parked. This copy excludes thinking panels and raw tool output. We also keep assignments, questions, delivery records, agent profiles, team definitions, and files or conversation entries you select for a handoff. Your permitted agents can use this information to coordinate your work within the same World. Other members and World Admins do not gain access to your private work. A profile or team definition is shared with World members only when you explicitly publish it.
World Shared files and My files. If you use these folders in a World, Cloudflare R2 stores their current content and paths. Shared files are available to all members of that World. My files are private to one person in one World; other World members, including World Admins, cannot open them through Podclave. You can use these files from your Workspace or from browser file pages without a running Session. Podclave does not keep prior file versions. An overwrite or delete can remove the prior content.
Billing data. Stripe handles payments and acts as merchant of record for standard Worlds plan sales. Card numbers go directly to Stripe and never touch our servers. We store the billing and usage records needed to manage your service.
Operational logs. Standard server logs for security and debugging, which can include IP addresses and request paths. We don’t build profiles from them.
2. How content moves through the service
When you browse, upload, or download files, use a terminal, or chat with an agent, we and our hosting providers process the content needed to deliver that feature. Workspace files and agent history are stored as described in section 1. Upload staging files are removed after transfer. We do not keep a separate service archive of terminal output or file listings.
Because we supply the hosting, authorized service operators can technically access stored work. We limit access to what is needed to operate the features you request, investigate security or abuse, meet legal duties, or provide support with your permission. Private Workspace access restrictions apply to other customers and World Admins; they do not mean the hosting provider cannot process the data.
Agent providers. Prompts, responses, and content supplied to Claude, Codex, or Grok are processed by Anthropic, OpenAI, or SpaceXAI under the account access you select. Podclave and its hosting providers handle the credentials and traffic needed to deliver those sessions. The agent provider’s own retention and data-use settings apply to its copy. Agent history can also remain in your Workspace. When you authorize supervision, selected context and files can reach the providers used by your permitted child Sessions. Downloaded conversation files contain private content and attachments; anyone you give the file to can read those copies.
Connected Google Drive data passes through Podclave and Google Cloud. When a World member asks an agent to use a connected Shared Drive, Podclave sends the requested search, read, create, or edit operation to the Google Workspace APIs. File and Drive ids, names, metadata, search terms, requested Google Doc text, and content supplied for a create or edit can pass through our service to complete that operation.
For a Google Doc read, we send the requested text to Google Cloud Model Armor in the United States to check for prompt injection before we return it to the agent. Google Cloud does not retain a copy of the text sent for this screening. We do not store Drive search results or file content in our service records or application logs.
The screened text and other tool results are returned to the requesting agent. They can be sent to that member’s selected agent provider and can remain in the agent session’s runtime transcript. When a member asks an agent to create or edit Drive content, Google stores the resulting file or change in the connected Shared Drive. Every World member can use the tools that the World Admin enabled by the Google role.
The selected agent provider’s own retention and data-use settings apply to the copy it receives. A member must use Drive tools only with a provider plan that excludes general model training or after the member turns training off for that provider. The member must not send provider feedback about a conversation that contains Drive data if that feedback can be used for model training.
Connected Slack discussion passes through Podclave. A World member can ask an agent to list the connected bot’s public channels and read their messages and threads. We retrieve the requested channel information, message text, author references, timestamps, and source links under that bot’s access. We send requested message text to Google Cloud Model Armor in the United States for screening before returning it to the agent. The results can reach the member’s selected agent provider and remain in Session transcripts or saved work under that provider’s retention and data-use settings. We do not keep a separate message archive or log message text in the control service.
Every World member can use this access, even if that person is not a member of the Slack workspace. Add the bot only to public channels intended for that World. When a World Admin enables posting, members can ask agents to send messages and thread replies as that bot. We send the requested text to Slack, where channel members and connected apps can access it. Slack controls those messages under the workspace’s agreement and settings. This pilot does not read private channels or direct messages, search the full Slack workspace, or reply automatically to incoming messages.
We store the bot name and any icon you choose or upload so World members can identify the connection. Saved icons remain with the connection and are deleted when you remove an unfinished setup or delete the World. If you upload the icon to Slack, Slack controls that copy under its own settings.
Optional voice dictation goes directly to ElevenLabs. The first time you tap the mic in an agent chat, Podclave shows a separate consent notice. If you choose Use voice dictation, your browser stores that choice locally. When you tap the mic, your browser sends mic audio directly to ElevenLabs and receives the transcript directly from ElevenLabs. Podclave does not keep a copy of the mic audio. If you send the transcript as a chat message, it becomes part of your agent conversation and is stored with that history.
ElevenLabs uses default retention for this feature. It can retain the mic audio and transcript to provide and improve its service, troubleshoot, moderate content, and keep its systems secure. Do not use voice dictation for passwords, API keys, health data, financial data, or other sensitive information. There is no local speech-recognition fallback: if you use the mic, this ElevenLabs processing applies. If you type instead and do not use the mic, it does not apply.
3. Product analytics
We run server-side product analytics (PostHog, US Cloud) with no browser tracking and no cookies, against a fixed allowlist of events:
- Events are things like “user signed up” and “session opened” — business moments, identified by a pseudonymous account id, never your email.
- We never send: email addresses, code or file contents, file names or paths, repository names or URLs, credentials, shell input, agent prompt text, or IP addresses.
We use Sentry for operational monitoring. It receives error and performance data needed to diagnose service problems. We configure it to exclude customer content, credentials, contact data, and network addresses. Request paths can contain pseudonymous record ids or organization slugs. Sentry stores this data in the United States.
4. How we use data
To operate the service (everything in sections 1–2 exists to make a feature work, including transcribing mic audio when you choose voice dictation); to send transactional email (sign-in codes and team invites); to bill for service usage; to understand product usage in aggregate and fix errors; to secure the service and enforce our Terms; and to comply with law. We do not sell or rent personal data, and we do not use your content or your data to train machine-learning models.
Podclave’s use of information received from Google Workspace APIs adheres to the Google User Data Policy, including its Limited Use requirements. We use this information only to provide the Drive tools that a World member requests. We do not use raw or derived Google Workspace data for advertising, credit decisions, sale, or to create, train, or improve a general machine-learning or artificial-intelligence model.
5. Who we share data with
Only the vendors it takes to run the service, listed with their roles on the Subprocessors page — service hosting and compute (Fly.io, Vercel, and Hetzner), database (Neon), email (Resend), payments (Stripe), analytics (PostHog), operational monitoring (Sentry), and bot protection, Public URL access and traffic, DNS, and World file storage (Cloudflare). Google Cloud supplies the dedicated Drive service accounts and screens requested Google Doc and Slack message text with Model Armor. ElevenLabs provides optional voice dictation only after the mic-specific consent described in section 2. Each receives only what its function needs.
Separately, when you connect Anthropic, OpenAI, SpaceXAI, GitHub, Google Drive, or Slack, we interact with those providers under the authority you or your World Admin supplied — that is the feature. Your relationship with each provider is also governed by its privacy policy and terms. Requested Drive and Slack tool results can be sent to the agent provider selected for that session.
We will disclose data if validly compelled by law. Unless legally prohibited, we will tell you before handing over anything about you. If Podclave LLC is ever acquired or its assets sold, this policy continues to apply to data collected under it, and we will notify you before any change.
6. Where data lives
We are a US company. Our service data and hosted compute (listed on the Subprocessors page) are US-based. Vercel runs World Workspaces in the United States. World Shared files and My files use a US-jurisdiction Cloudflare R2 bucket, which stores and processes those objects in the United States. Retained conversation attachments, selected handoff files, and temporary conversation downloads use the same storage location. Cloudflare’s global network also handles bot protection, DNS, and traffic for apps exposed through Public URLs. Monitoring data sent to Sentry is stored in the US. Google Cloud Model Armor screens requested Google Doc and Slack message text in the United States. Your Google Workspace agreement and settings govern where Google stores the source Shared Drive. Slack and the agent providers process their copies under their own service terms and regional settings. ElevenLabs states that it has service locations in the United States, the Netherlands, and Singapore, and that personal data is transferred to the United States for storage. If you use Podclave from outside the United States, your service data is processed in the US and optional mic data can also be processed in those ElevenLabs locations. For users in the EEA/UK: we rely on our subprocessors’ standard contractual protections for applicable transfers, and the rights in section 8 are available to you regardless of where you live.
7. Retention and deletion
We keep account data, configuration, and credentials while needed to supply your service, subject to deletion requests and required billing or legal records. Disconnecting a personal credential deletes our stored account copy. Revoke access at the provider as well if you need to invalidate credentials already supplied to a tool.
Workspace work. Parking compute preserves saved work. Running out of credits early does not start a storage-deletion grace period: saved Workspace work remains through the paid period. If that period ends without renewal, there is a seven-day storage grace period. After grace, we may delete stored Workspace work; continued retention is not guaranteed. This is not a promise of deletion at an exact time. Removing a Workspace permanently removes its saved work. Keep independent copies of anything you need.
Saved conversations and handoffs. Parking compute or pausing supervision does not delete saved conversations. Removing a Session removes its service conversation copy and retained handoff packages involving that Session. Removing the World removes these copies for its Sessions. Conversation download links expire after 24 hours, and their temporary service copies are then removed. Files already downloaded, imported into another Workspace, or sent to an agent provider remain with those copies under their own retention rules. Turning an experiment off stops new collection and automatic coordination; it preserves existing private work for your review and removal.
World Shared files and My files. We keep their current content while the World retains those files. Deleting a file removes its current stored content; Podclave does not keep prior file versions. Removing a World removes its Workspaces, Shared files, and every member’s My files for that World. These features are not a versioned backup service.
Disconnecting Google Drive first blocks new tool calls. Podclave then deletes the dedicated Google service account and its encrypted credential. We keep the service-account email and connection state until a World Admin removes the deleted account from the Shared Drive member list and confirms that step in Podclave. Disconnecting does not delete or change files in Google Drive. Drive content already returned to an agent can remain in that session’s runtime transcript until the session, its Workspace, or the World is removed.
For Slack, we store connection names, workspace and bot identities, access state, and encrypted app credentials and bot tokens. Disconnecting stops future reads and posts and deletes our bot token. We retain the app credentials and connection settings so a World Admin can reconnect through Slack. Deleting the World removes those records and credentials. Disconnecting does not uninstall the app from Slack or erase content already returned to a Session. Removing the bot from a Slack channel stops new reads and posts through that channel. Posts already sent remain in Slack until removed there. We keep send records with the requesting member, destination, time, and result to prevent duplicate sends and support troubleshooting. We do not store a separate copy of the posted text in these records. Deleting the World removes its send records.
There is no self-serve account deletion yet — email hello@podclave.com and we will delete your account and the service data above within 30 days, except minimal records we must keep (for example invoices, which Stripe retains for tax law). Your private Workspace work is included in that request. Retrieve anything you want to keep first. Content shared with a team or sent to another service can remain there under its access and retention rules; contact us to include that content in your request where you have the right to remove it.
ElevenLabs controls its own default retention of voice-dictation audio and transcripts. Its current policy says default Speech to Text history is retained, deletion removes database items but some debugging and moderation logs can remain, and deleted database items can remain in backups for up to 30 days. Email us if a privacy request includes voice dictation, and we will pass on or support the request as required.
8. Your rights
Email hello@podclave.com to access, correct, export, or delete your personal data, or to object to a use of it. We honor these requests for everyone, not only where a statute (GDPR, UK GDPR, CCPA) requires it, and we respond within 30 days. We will never discriminate against you for exercising them. We do not sell or “share” personal information as the CCPA defines those terms.
9. Security
We encrypt credentials and other sensitive values while stored and use encrypted connections when data moves over a network. Sign-in uses one-time email codes or passkeys. Production access is limited to people who operate the service. No system is perfectly secure; if we suffer a breach affecting your data, we will notify you promptly and tell you what we know.
10. Children
Podclave is not directed at children under 13, and we do not knowingly collect their data (where your country sets a higher minimum age for online services, that age applies instead). Users under 18 participate as invited members of an organization managed by an adult — see the Terms, section 3. If you believe a child below the minimum age has an account, email us and we will delete it.
11. Changes
We will update this policy as the product evolves. The “Last updated” date reflects the current version and the full history is preserved. For material changes we will notify you by email or in the product before they take effect.
Podclave LLC · Florida, USA · hello@podclave.com