1. Introduction
This Privacy Policy describes how Oxiom ("we", "us", "our") collects, uses, and protects information when you use our mobile application (the "App"). By using the App, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Information You Provide
- Account Information: name, email address, phone number, and profile details you provide when registering or signing in.
- Authentication Data: credentials used to sign in via email/password or third-party providers such as Google Sign-In.
- User Content:any information, documents, or data you submit through the App as part of your organization's workflow.
2.2 Information Collected Automatically
- Device Information: device type, operating system, unique device identifiers, and browser type.
- Usage Data: pages viewed, features used, timestamps, and interactions within the App.
- Log Data: IP address, access times, and diagnostic information.
2.3 Google Account Data
When you sign in with Google and explicitly authorize additional Google integrations in the App, we receive basic profile information (name, email address, profile picture, and Google account ID) and access the specific Google APIs listed in Section 3. We do not access any Google services or data unless you explicitly authorize them through the Google OAuth consent screen inside the App.
3. Google User Data & Limited Use
Affirmative Limited Use statement. Oxiom's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Raw and derived Google user data is not transferred to third-party services for training AI or ML models, is not used for advertising, and is not sold. Where AI features are invoked by the user, requests are sent only to OpenAI's REST API, whose terms prohibit training on API customer data.
3.1 Google Scopes We Request and How We Use Them
We request each Google scope solely to deliver a specific, user-facing feature inside the App. We do not use Google user data for any other purpose.
- userinfo.profile, userinfo.email — used only to identify your Google account and link it to your Oxiom user profile at sign-in.
- https://www.googleapis.com/auth/calendar.events — used only to display your upcoming meetings in the App and to create or reschedule events when you explicitly request it (including via voice commands).
- https://www.googleapis.com/auth/tasks — used only to display your tasks inside the App and to create or mark tasks as completed when you request it.
Email inside the App is handled exclusively via user-configured IMAP/SMTP accounts (see Section 4). We do not request Gmail scopes and never access Gmail data through Google APIs.
3.2 Limited Use Commitments
With respect to data obtained from Google APIs, we commit to the following:
- We use Google user data only to provide or improve the user-facing features that are visible in the App and described in Section 3.1.
- We do not transfer Google user data to third parties except (a) as necessary to provide or improve the user-facing features described above, (b) to comply with applicable law, or (c) as part of a merger, acquisition, or sale of assets with your explicit prior consent.
- We do not use Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
- We do not sell Google user data to third parties or data brokers under any circumstances.
- We do not use Google user data to train, fine-tune, or otherwise develop generalized or foundational AI or machine-learning models — whether our own or those of any third party. Google Calendar events and Google Tasks may be sent to the OpenAI REST API only when you explicitly invoke an in-App action that requires it (for example, a voice command such as "what's my next meeting"). Per OpenAI's Enterprise Privacy commitments and API data-usage policy, data submitted to the OpenAI API is not used to train OpenAI's models unless the customer explicitly opts in. We have never opted in.
- We do not allow humans to read Google user data, except: (a) with your explicit consent for the specific data being read, (b) when necessary for security purposes such as investigating abuse, (c) when required by law, or (d) when the data has been aggregated and anonymized and is used for internal operations.
3.3 Revoking Access
You can revoke the App's access to your Google account at any time — either from within the App (Settings → "Disconnect Google") or at myaccount.google.com/permissions.
4. How We Use Your Information
We use the collected information (other than Google user data, which is governed exclusively by Section 3) to:
- Provide, operate, and maintain the App;
- Authenticate users and secure access to your account;
- Enable multi-tenant functionality within your organization;
- Communicate with you regarding your account, updates, and support;
- Improve, personalize, and expand the App's features;
- Detect, prevent, and address technical issues or security threats;
- Comply with legal obligations.
5. Legal Basis for Processing (GDPR)
We process personal data based on:
- Consent — when you explicitly agree to processing;
- Contract — to provide the services you requested;
- Legitimate interests — to secure and improve the App;
- Legal obligation — to comply with applicable laws.
6. Sharing of Information
We do not sell your personal information. Sharing of Google user data is governed exclusively by Section 3.2. For other data collected by the App, we may share it only with:
- Service providers (e.g., cloud hosting, authentication providers) acting on our behalf under confidentiality obligations;
- Your organization's administrators, if the App is used as part of an organizational account;
- Legal authorities, when required by law or to protect our rights;
- Business transfers, in connection with a merger, acquisition, or sale of assets.
7. Data Retention
We retain personal data only as long as necessary for the purposes described in this policy, to comply with legal obligations, resolve disputes, and enforce our agreements. When data is no longer needed, it is securely deleted or anonymized.
8. Data Security
We implement appropriate technical and organizational measures to protect your data, including encrypted transmission (HTTPS/TLS), secure industry-standard authentication, encrypted storage of OAuth tokens, and access controls. However, no method of transmission over the internet is 100% secure.
9. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access, correct, or delete your personal data;
- Object to or restrict processing;
- Data portability;
- Withdraw consent at any time;
- File a complaint with a supervisory authority.
To exercise these rights, contact us at [email protected].
10. Children's Privacy
The App is not directed to children under the age of 13 (or 16 in the EU). We do not knowingly collect personal information from children. If you believe we have collected such information, please contact us and we will delete it.
11. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place in accordance with applicable data protection laws.
12. Third-Party Services
The App relies on the following third-party services:
12.1 Google APIs
Google Sign-In, Gmail, Google Calendar, and Google Tasks — subject to Google's Privacy Policy. Scopes and purposes are listed in Section 3.1.
12.2 OpenAI (AI provider)
- Provider: OpenAI, Inc., San Francisco, California, USA.
- Plan / tier: pay-as-you-go OpenAI API (project-scoped API key). No aggregator, gateway, or model hub is used — the App connects directly to
api.openai.com. - Models used:
gpt-4o,gpt-4o-mini,gpt-4.1-mini(chat completions),whisper-1(speech-to-text),tts-1(text-to-speech). - What is sent: only content necessary to fulfill a user-initiated action (e.g., a voice transcript for classification, an email body for summarization, a text prompt for chat). No bulk or background transfer of Google user data ever occurs.
- Training: OpenAI does not train on API customer data by default, per its Enterprise Privacy commitments. We have not enabled the opt-in data-sharing setting, so no data submitted from Oxiom to OpenAI is used to train, fine-tune, or otherwise develop any AI or ML model.
- Retention at OpenAI:up to 30 days for abuse-and-misuse monitoring, then deleted, per OpenAI's API data-usage policy.
- No other AI providers: Oxiom does not use Anthropic, Google Gemini, Cohere, Groq, Perplexity, Mistral, Replicate, Azure OpenAI, AWS Bedrock, OpenRouter, Together AI, Fireworks, or any self-hosted or offline AI model.
12.3 Other infrastructure providers
- Amazon Web Services — application hosting, database, and identity/authentication infrastructure (EU region).
- Analytics providers — used for aggregated, non-personally-identifiable product analytics only.
We are not responsible for the privacy practices of these third parties.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes will be posted with an updated "Last updated" date. Continued use of the App after changes constitutes acceptance of the updated policy.
14. Contact Us
If you have any questions or concerns about this Privacy Policy, please contact us:
- Email: [email protected]
- Company: Oxiom
- Website: https://www.oxiom.me
