This Privacy Policy explains how Weesp AI, Inc. (“Weesp AI,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects information in connection with Bracket, our platform for creating and managing agent-based business processes, and our website at getbracket.io.
Bracket is a business-to-business (B2B) product. Most of the data we handle belongs to our enterprise customers and is processed on their behalf and under their instructions. Section 4 of this policy describes, specifically and prominently, how Bracket handles Google user data obtained through Google APIs.
1. Who We Are
Bracket is operated by:
Weesp AI, Inc.
131 Continental Dr, Suite 305
Newark, DE 19713, United States
Privacy contact: privacy@getbracket.io
Bracket lets enterprise customers build and run agent-based business processes. Where a user connects a Google Calendar, Bracket’s agents can read availability and create, update, reschedule, or cancel meetings on that calendar, acting only on that user’s explicit instruction.
2. Scope of This Policy
This policy applies to:
- the getbracket.io website; and
- the Bracket platform, including all Bracket features that connect to a customer’s systems (such as Google Calendar calendars).
Our role. Bracket is built for businesses. When we process Customer Content — calendar events, documents, and other material that our customers route into Bracket, and the outputs Bracket generates from it — we act as a processor / service provider on our customer’s documented instructions, under a data processing agreement with that customer. The customer (typically your employer or the business you interact with) is the controller of that content and decides what is connected to Bracket, why, and for how long.
For the limited data we collect for our own purposes — account registration details, billing records, website analytics, and support communications — we act as the controller.
If you are an employee or business contact of a Bracket customer and have questions about how that organization uses Bracket, please contact that organization directly. We support our customers in responding to such requests.
3. Information We Collect
Account and contact data. Name, business email address, role, organization, authentication identifiers, and billing details of the people who register for or administer a Bracket workspace, and of prospects who contact us. Authentication is handled through our identity provider (Descope).
Customer Content. Content our customers connect to or submit into Bracket so their configured agents can do their work. Depending on the customer’s configuration, this includes event details, attendees, and availability from connected Google Calendars, documents uploaded directly, and the outputs, audit trails, and notifications Bracket produces. Customer Content may incidentally contain personal data of the customer’s employees, suppliers, and other third parties; the customer controls what is connected.
Usage and telemetry data. Log data, device and browser information, IP address, feature-usage events, and diagnostic data (including error reports processed through Sentry). We use essential cookies and similar technologies for sign-in, security, and understanding product usage; we do not use advertising cookies.
Support data. Information you provide when contacting support, including the contents of your messages and any material you choose to share so we can help.
We do not collect more data than we need to operate Bracket, and we do not collect data from Google services beyond what Section 4 describes.
4. Google User Data
This section applies whenever a user connects Google Calendar to Bracket, and is intended to describe fully and prominently how Bracket accesses, uses, stores, and shares Google user data.
4.1 What we access — and the connection model
Bracket accesses only the specific calendars that the user explicitly connects through Bracket’s settings, using Google’s OAuth consent flow. Bracket never scans, browses, or accesses any other calendar, mailbox, folder, file, or Google account data, and we request only the narrowest scopes needed for the features described below.
Google Calendar events (
https://www.googleapis.com/auth/calendar.events): to create, update, reschedule, cancel, and RSVP to events on calendars the user connects, acting only on that user’s explicit instruction.Google Calendar list (
https://www.googleapis.com/auth/calendar.calendarlist.readonly): to show a user their calendars by name so they can choose which calendar an agent may act on.Google Calendar availability (
https://www.googleapis.com/auth/calendar.events.freebusy): to find times when attendees are free before a meeting is proposed.
4.2 Why we access it
We use Google user data solely to provide user-facing features of Bracket that the customer has configured:
- Scheduling: reading availability and creating, updating, or cancelling events on connected calendars when a user asks an agent to schedule, reschedule, or cancel a meeting.
We do not use Google user data for any other purpose.
4.3 Limited Use — our explicit commitments
Bracket’s use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In addition, Bracket’s use of information received from Google Workspace APIs will adhere to the Google Workspace API User Data and Developer Policy, including its Limited Use requirements.
Specifically, with respect to Google user data, we:
- do NOT sell it — to anyone, ever, including to data brokers or information resellers;
- do NOT use it for advertising — we do not use Google user data for advertising of any kind, including ad targeting, retargeting, personalized or interest-based advertising, or serving ads. We do not use data obtained from any Google service to target, serve, or measure advertising directed at any individual, and we do not combine Google user data across services or customers for advertising purposes;
- do NOT use it to determine creditworthiness or for lending purposes;
- do NOT use it to create, train, or improve generalized AI or machine-learning models. Google user data is processed by AI models only to perform the customer’s configured task at inference time (see Section 6); it is never used — by us or by our AI providers — to train or improve generalized models, and we do not build models of any kind from Google Workspace user data beyond what the Google Workspace API policy permits;
- do NOT allow humans to read it, except in these limited cases: (a) with the customer’s (or the affected user’s) explicit consent to view specific content — for example, when the customer asks our support team to troubleshoot a specific document; (b) where necessary for security purposes, such as investigating abuse or a suspected bug; (c) where necessary to comply with applicable law; or (d) where the data has been aggregated and anonymized and is used only for internal operations;
- transfer it only to the subprocessors listed in Section 7 that are needed to provide or improve Bracket’s user-facing features (under contracts that bind them to protections consistent with this policy), or where necessary for security purposes, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to affected customers and any consent Google’s policies require.
4.4 Storage and retention of Google user data
Google user data ingested into Bracket is encrypted in transit (TLS 1.2+) and at rest (AES-256), protected by role-based access controls, and retained only as long as needed to provide the service and as described in Section 10. When a user disconnects a calendar, Bracket’s access ends immediately and previously ingested data is deleted in accordance with Section 10.
4.5 Revoking access
A user or customer administrator can disconnect any calendar in Bracket’s settings at any time. Access can also be revoked directly from Google at myaccount.google.com/permissions (or, for Workspace administrators, via the Google Admin console). Revocation takes effect immediately for future access.
5. How We Use Information
We use the information described in Section 3 to:
- provide and operate Bracket, including running the agent processes our customers configure;
- secure the service — authenticate users, prevent abuse and fraud, and investigate security incidents;
- support customers and respond to requests;
- bill for and administer customer accounts;
- improve the reliability and performance of the service, using telemetry and aggregated, anonymized usage data;
- comply with legal obligations.
We do not use any information we process — including Customer Content and Google user data — for advertising, and we do not build advertising profiles.
No sale of personal data. We do not sell personal information, and we have not sold personal information in the preceding 12 months. We do not “share” personal information for cross-context behavioral advertising (as those terms are defined in the California Consumer Privacy Act, as amended).
No training of generalized models. Customer data — including Customer Content and Google user data — is not used to train or fine-tune generalized AI/ML models, whether ours or a third party’s.
6. AI Processing Disclosure
Bracket’s agents use large language models to perform the tasks customers configure (for example, interpreting a scheduling request and drafting the resulting calendar invitation). Specifically:
- Content is processed using Google Gemini models on Google Cloud Platform; and
- where the customer elects, Anthropic Claude models.
In both cases, processing occurs at inference time only, under enterprise agreements with these providers that prohibit the use of our customers’ data to train or improve their models. Model outputs (such as scheduled events and notifications) become part of the customer’s Customer Content. We do not permit any AI provider to retain customer data for training, and we do not use customer data to train generalized models ourselves (see Sections 4.3 and 5).
7. How We Share Information
We share information only as described below. We never sell it.
Subprocessors. We use the following service providers to run Bracket. Each processes data only to provide its service to us, under contracts requiring confidentiality, security, and use limitations consistent with this policy (and, for Google user data, with the Limited Use requirements):
| Subprocessor | Role |
|---|---|
| Google LLC | Cloud infrastructure (Google Cloud Platform), Gemini model inference, and Google Calendar API connectivity |
| Anthropic PBC | Claude model inference (only where the customer elects Claude) |
| Twilio Inc. (SendGrid) | Transactional email delivery |
| Neon Inc. | Managed database hosting |
| Functional Software, Inc. (Sentry) | Application error and performance monitoring (diagnostic data) |
| Descope Inc. | Authentication and identity management |
Within the customer’s organization. Customer Content, including calendar events and notifications Bracket creates, is shared with the users and recipients the customer designates.
Legal requirements. We may disclose information where required by law, regulation, legal process, or enforceable governmental request, or where necessary to protect the rights, safety, or property of our customers, the public, or Weesp AI. Where lawful, we will notify the affected customer before disclosing Customer Content.
Corporate transactions. If Weesp AI is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction; we will provide notice to affected customers, and any transfer of Google user data will remain subject to Google’s policies, including any required consent.
8. International Data Transfers
Weesp AI processes data in Israel, the United States, and the European Economic Area (EEA). Where personal data is transferred across borders, we rely on appropriate safeguards, which may include European Commission adequacy decisions (including the adequacy decision covering Israel), Standard Contractual Clauses, and equivalent mechanisms under the UK GDPR and Israeli Protection of Privacy Law, together with the technical and organizational measures described in Section 9. Details of transfer mechanisms applicable to a specific customer are set out in that customer’s data processing agreement.
9. Security
We maintain a security program appropriate to the sensitivity of the data we process, including:
- Encryption: AES-256 encryption at rest and TLS 1.2+ in transit;
- Access control: role-based access controls and least-privilege access for our personnel; human access to Customer Content is restricted as described in Section 4.3;
- Infrastructure: hosting on hardened cloud infrastructure with logging and monitoring;
- Incident response: we notify affected customers of a personal data breach without undue delay — contractually within 72 hours of confirming a breach affecting their data — with the information they need to meet their own notification duties.
No system is perfectly secure, but we review and improve these measures on an ongoing basis.
10. Data Retention and Deletion
- Active accounts: we retain account data and Customer Content for as long as the customer’s subscription is active and as needed to provide the service, or as the customer instructs.
- Disconnection: when a user disconnects a Google Calendar, new access stops immediately, and previously ingested data from that source is deleted on the schedule below unless the customer instructs otherwise.
- Termination: upon termination of a customer agreement, we delete Customer Content within 30 days, with residual copies removed from backups through our routine backup rotation within up to 90 days.
- On request: customers may request earlier deletion of specific data at any time.
- Our own records: we retain limited business records (contracts, billing, security logs) as needed to comply with legal obligations and resolve disputes, after which they are deleted or anonymized.
11. Your Rights and Choices
If you are an employee, supplier, or other individual whose data appears in a customer’s content: the Bracket customer is the controller. Please direct requests to that organization; we will assist it in honoring your rights. If you contact us directly, we will refer your request to the relevant customer where appropriate.
If you are a business contact or Bracket account holder, you may have rights under applicable law — including the Israeli Protection of Privacy Law, the EU/UK GDPR, and the California Consumer Privacy Act (CCPA/CPRA), in each case to the extent applicable — to:
- access the personal data we hold about you and receive a copy;
- correct inaccurate data;
- delete your data;
- object to or restrict certain processing, and withdraw consent where processing is based on consent;
- data portability (where applicable);
- non-discrimination for exercising your rights; and
- lodge a complaint with your supervisory authority (for example, an EU data protection authority or the Israeli Privacy Protection Authority).
To exercise these rights, contact privacy@getbracket.io. We will verify your request and respond within the timelines required by applicable law.
Google account choices. You or your administrator can review and revoke Bracket’s access to Google data at any time at myaccount.google.com/permissions, or by disconnecting the calendar in Bracket’s settings.
12. Children’s Privacy
Bracket is a business product. It is not directed at anyone under 18, and certainly not at children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
13. Changes to This Policy
We may update this policy from time to time. We will post the updated version at this URL with a revised “Last updated” date, and for material changes we will provide reasonable advance notice to customer administrators (for example, by email or in-product notice). Changes to how we handle Google user data will remain consistent with Google’s policies, and where Google’s policies require it, we will seek renewed consent.
14. Contact Us
Weesp AI, Inc.
131 Continental Dr, Suite 305
Newark, DE 19713, United States
Privacy inquiries: privacy@getbracket.io
If you have unresolved concerns, you may also have the right to complain to your local data protection authority.
← Back to site