Introduction
This Privacy Policy explains how Draz collects, uses, stores, shares, and protects information when you use our website, workspace, AI agents, workflow automation, chat, integrations, connectors, APIs, and related services.
Draz is built to connect the tools you choose, such as email, calendars, documents, messaging apps, customer systems, developer tools, AI model providers, and other business applications. Because teams may connect many different services over time, this policy describes both our current practices and the categories of connectors we may support in the future. We only request access to a third-party service when you or your workspace administrator chooses to connect that service or enables a feature that requires it.
Information We Collect
We may collect and process the following categories of information:
- Account information:name, email address, profile image, authentication identifiers, workspace membership, role, settings, and login activity.
- Workspace information:workspace name, team members, permissions, projects, agents, workflows, automations, knowledge sources, configuration, and usage history.
- Customer content:prompts, messages, chat transcripts, documents, files, URLs, knowledge-base content, workflow inputs and outputs, metadata, and other content you submit to or generate through Draz.
- Connector information:account identifiers, OAuth tokens, refresh tokens, scopes, authorization status, provider metadata, synced records, message metadata, files, events, comments, tasks, tickets, contacts, calendar entries, emails, or other data made available by a connected third-party service.
- Connected provider data:if you connect a third-party service, we may access the specific provider data allowed by the permissions you approve, such as profile information, account identifiers, email messages, drafts, labels, attachments, metadata, calendar data, documents, files, records, tasks, tickets, comments, or other content, depending on the connector and feature you enable.
- AI provider data:prompts, instructions, context, files, connector data, model outputs, evaluation data, and metadata needed to generate or improve responses within your workspace.
- Billing and commercial information:plan, subscription status, billing contact, invoices, payment status, and related transaction metadata. Payment card details may be processed by our payment provider rather than stored directly by Draz.
- Technical and usage information:IP address, device and browser information, log data, error reports, cookie identifiers, pages viewed, feature usage, API usage, and performance information.
- Support and communications:messages you send us, support tickets, feedback, demo requests, call notes, and email communications.
How We Use Information
We use information to provide, secure, maintain, and improve Draz. This includes:
- Creating and managing accounts, workspaces, authentication, access control, roles, and permissions.
- Connecting third-party services that you authorize and using connector data to power workflows, agents, search, summaries, drafts, actions, notifications, and automations.
- Reading, creating, updating, sending, routing, or organizing data only as needed for the connector feature or workflow you configure.
- Processing prompts, connector context, and workspace content with selected AI model providers so Draz can generate responses, summaries, classifications, drafts, actions, and workflow outputs.
- Operating APIs, MCP servers, connectors, webhooks, background jobs, and integrations.
- Providing support, debugging, incident response, abuse prevention, audit logs, and service reliability.
- Communicating with you about product updates, security, billing, account notices, and support.
- Complying with legal obligations and enforcing our Terms.
We do not sell personal information, connected provider data, connector data, workspace content, or customer content.
Third-Party Integrations and Connectors
Draz may let you connect third-party services, including email, calendar, storage, documents, CRM, support, messaging, developer, analytics, database, payment, AI model, and other business services.
When you connect a third-party service:
- Draz requests only the permissions needed for the feature or workflow you enable.
- The connector provider may show its own consent screen, terms, and privacy notices.
- You can disconnect a connector from your workspace settings or by revoking access with the provider.
- Removing a connector stops future access, but previously processed workflow records, logs, or outputs may remain until deleted under our retention practices or your workspace settings.
- Workspace administrators may control which connectors are enabled and which users can configure or use them.
Third-party services are governed by their own terms and privacy policies. Draz is not responsible for the privacy or security practices of third-party services that you choose to connect.
Connected Service and Email Data
If you connect an external service, Draz accesses provider user data only after you authorize access through the provider's consent flow, OAuth flow, API key, token, webhook, admin configuration, or another supported authorization method. The exact data depends on the permissions or scopes shown by the provider and the Draz feature you enable.
Draz may use connected email, calendar, file, message, record, or workflow data to provide user-facing features such as:
- Listing, searching, reading, and summarizing connected content.
- Creating drafts, replies, tasks, records, tickets, events, or other workspace outputs.
- Sending messages or taking actions when instructed by a user or configured workflow.
- Applying labels, statuses, assignments, comments, tags, archive state, read state, or other record updates when a workflow requires it.
- Triggering automations based on connected content, metadata, labels, senders, recipients, owners, assignees, timestamps, status, or other workflow conditions.
- Displaying connected-account status and workspace-level integration metadata.
Draz uses and transfers connected provider data only to provide, secure, maintain, troubleshoot, or improve user-facing Draz features, and only as described in this Privacy Policy or as permitted by the provider's applicable policies. We do not use connected provider data for advertising, retargeting, credit eligibility, lending decisions, sale to data brokers, sale to information resellers, or training generalized AI models.
We do not allow human access to connected provider data except when necessary to provide or secure the service, comply with law, investigate abuse, resolve a support request you initiate, or when you explicitly authorize access.
AI Providers
Draz may send prompts, instructions, files, workspace context, connector data, and generated outputs to AI model providers selected by Draz, your workspace, or your configuration.
We use AI providers to deliver product features such as chat, automation, classification, summarization, drafting, retrieval, workflow planning, and tool execution. We do not use connected provider data to train generalized AI models.
How We Share Information
We may share information only as needed to operate Draz and provide the services you request:
- Service providers:hosting, infrastructure, databases, analytics, observability, email delivery, billing, security, support, and other vendors that help us operate Draz.
- Connector providers:when you use a connector, we may send instructions, requests, metadata, or content back to that provider to perform the action you requested.
- AI model providers:when required to generate responses or workflow outputs for your workspace.
- Workspace members and administrators:content and connector outputs may be visible to other authorized users in your workspace according to permissions.
- Legal, safety, and compliance:when required by law, legal process, security investigation, rights enforcement, fraud prevention, or protection of users and the public.
- Business transfers:in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to appropriate confidentiality protections.
We do not share connected provider data or connector data with third parties for advertising, sale, surveillance, credit eligibility, lending, or unrelated data brokerage purposes.
Security
We use administrative, technical, and organizational safeguards designed to protect information, including access controls, encryption in transit, encryption or protected storage for sensitive credentials where appropriate, logging, monitoring, and least-privilege access practices.
OAuth access tokens and refresh tokens are used to operate authorized connectors. We store connector credentials in protected systems and limit access to people and systems with a need to operate or secure the service.
No internet service is completely secure. You are responsible for protecting your account credentials, configuring appropriate workspace permissions, and promptly notifying us of unauthorized use.
Data Retention and Deletion
We retain information for as long as needed to provide Draz, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and support legitimate business purposes.
Retention periods vary by data type:
- Account and workspace records are generally retained while your account or workspace remains active.
- Connector credentials are retained while the connector remains connected and are deleted or disabled after disconnection according to our operational retention practices.
- Workflow logs, messages, outputs, and audit records may be retained to provide history, debugging, compliance, and security.
- Backups may retain deleted information for a limited period before being overwritten.
You may request deletion of your account, workspace data, or connector data by contacting us. Workspace administrators may also delete users, connectors, workflows, and content inside the product. Some information may be retained where required by law, security, fraud prevention, billing, dispute resolution, or backup processes.
Cookies and Similar Technologies
We may use cookies, local storage, and similar technologies to keep you signed in, remember preferences, understand product usage, improve performance, and protect the service. You can control cookies through your browser settings, but some features may not work correctly without them.
International Transfers
We may process and store information in countries other than where you live. When we transfer information internationally, we use safeguards designed to protect information in accordance with applicable law.
Children
Draz is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes to how we use connected provider data, connector data, or customer content, we will provide notice as required and, where necessary, request renewed consent before using data for a materially different purpose.
Contact Us
If you have questions about this Privacy Policy, privacy requests, connector data, or connected provider data, contact us at [email protected].
