This Privacy Policy explains how Weesp AI, Inc. (“Weesp AI,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects information in connection with Bracket, our platform for creating and managing agent-based business processes, and our website at getbracket.io.

Bracket is a business-to-business (B2B) product. Most of the data we handle belongs to our enterprise customers and is processed on their behalf and under their instructions. Section 4 of this policy describes, specifically and prominently, how Bracket handles Google user data obtained through Google APIs.

1. Who We Are

Bracket is operated by:

Weesp AI, Inc.
131 Continental Dr, Suite 305
Newark, DE 19713, United States

Privacy contact: privacy@getbracket.io

Bracket lets enterprise customers build and run agent-based business processes. Where a user connects a Google Calendar, Bracket’s agents can read availability and create, update, reschedule, or cancel meetings on that calendar, acting only on that user’s explicit instruction.

2. Scope of This Policy

This policy applies to:

Our role. Bracket is built for businesses. When we process Customer Content — calendar events, documents, and other material that our customers route into Bracket, and the outputs Bracket generates from it — we act as a processor / service provider on our customer’s documented instructions, under a data processing agreement with that customer. The customer (typically your employer or the business you interact with) is the controller of that content and decides what is connected to Bracket, why, and for how long.

For the limited data we collect for our own purposes — account registration details, billing records, website analytics, and support communications — we act as the controller.

If you are an employee or business contact of a Bracket customer and have questions about how that organization uses Bracket, please contact that organization directly. We support our customers in responding to such requests.

3. Information We Collect

Account and contact data. Name, business email address, role, organization, authentication identifiers, and billing details of the people who register for or administer a Bracket workspace, and of prospects who contact us. Authentication is handled through our identity provider (Descope).

Customer Content. Content our customers connect to or submit into Bracket so their configured agents can do their work. Depending on the customer’s configuration, this includes event details, attendees, and availability from connected Google Calendars, documents uploaded directly, and the outputs, audit trails, and notifications Bracket produces. Customer Content may incidentally contain personal data of the customer’s employees, suppliers, and other third parties; the customer controls what is connected.

Usage and telemetry data. Log data, device and browser information, IP address, feature-usage events, and diagnostic data (including error reports processed through Sentry). We use essential cookies and similar technologies for sign-in, security, and understanding product usage; we do not use advertising cookies.

Support data. Information you provide when contacting support, including the contents of your messages and any material you choose to share so we can help.

We do not collect more data than we need to operate Bracket, and we do not collect data from Google services beyond what Section 4 describes.

4. Google User Data

This section applies whenever a user connects Google Calendar to Bracket, and is intended to describe fully and prominently how Bracket accesses, uses, stores, and shares Google user data.

4.1 What we access — and the connection model

Bracket accesses only the specific calendars that the user explicitly connects through Bracket’s settings, using Google’s OAuth consent flow. Bracket never scans, browses, or accesses any other calendar, mailbox, folder, file, or Google account data, and we request only the narrowest scopes needed for the features described below.

Google Calendar events (https://www.googleapis.com/auth/calendar.events): to create, update, reschedule, cancel, and RSVP to events on calendars the user connects, acting only on that user’s explicit instruction.

Google Calendar list (https://www.googleapis.com/auth/calendar.calendarlist.readonly): to show a user their calendars by name so they can choose which calendar an agent may act on.

Google Calendar availability (https://www.googleapis.com/auth/calendar.events.freebusy): to find times when attendees are free before a meeting is proposed.

4.2 Why we access it

We use Google user data solely to provide user-facing features of Bracket that the customer has configured:

We do not use Google user data for any other purpose.

4.3 Limited Use — our explicit commitments

Bracket’s use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In addition, Bracket’s use of information received from Google Workspace APIs will adhere to the Google Workspace API User Data and Developer Policy, including its Limited Use requirements.

Specifically, with respect to Google user data, we:

4.4 Storage and retention of Google user data

Google user data ingested into Bracket is encrypted in transit (TLS 1.2+) and at rest (AES-256), protected by role-based access controls, and retained only as long as needed to provide the service and as described in Section 10. When a user disconnects a calendar, Bracket’s access ends immediately and previously ingested data is deleted in accordance with Section 10.

4.5 Revoking access

A user or customer administrator can disconnect any calendar in Bracket’s settings at any time. Access can also be revoked directly from Google at myaccount.google.com/permissions (or, for Workspace administrators, via the Google Admin console). Revocation takes effect immediately for future access.

5. How We Use Information

We use the information described in Section 3 to:

We do not use any information we process — including Customer Content and Google user data — for advertising, and we do not build advertising profiles.

No sale of personal data. We do not sell personal information, and we have not sold personal information in the preceding 12 months. We do not “share” personal information for cross-context behavioral advertising (as those terms are defined in the California Consumer Privacy Act, as amended).

No training of generalized models. Customer data — including Customer Content and Google user data — is not used to train or fine-tune generalized AI/ML models, whether ours or a third party’s.

6. AI Processing Disclosure

Bracket’s agents use large language models to perform the tasks customers configure (for example, interpreting a scheduling request and drafting the resulting calendar invitation). Specifically:

In both cases, processing occurs at inference time only, under enterprise agreements with these providers that prohibit the use of our customers’ data to train or improve their models. Model outputs (such as scheduled events and notifications) become part of the customer’s Customer Content. We do not permit any AI provider to retain customer data for training, and we do not use customer data to train generalized models ourselves (see Sections 4.3 and 5).

7. How We Share Information

We share information only as described below. We never sell it.

Subprocessors. We use the following service providers to run Bracket. Each processes data only to provide its service to us, under contracts requiring confidentiality, security, and use limitations consistent with this policy (and, for Google user data, with the Limited Use requirements):

SubprocessorRole
Google LLCCloud infrastructure (Google Cloud Platform), Gemini model inference, and Google Calendar API connectivity
Anthropic PBCClaude model inference (only where the customer elects Claude)
Twilio Inc. (SendGrid)Transactional email delivery
Neon Inc.Managed database hosting
Functional Software, Inc. (Sentry)Application error and performance monitoring (diagnostic data)
Descope Inc.Authentication and identity management

Within the customer’s organization. Customer Content, including calendar events and notifications Bracket creates, is shared with the users and recipients the customer designates.

Legal requirements. We may disclose information where required by law, regulation, legal process, or enforceable governmental request, or where necessary to protect the rights, safety, or property of our customers, the public, or Weesp AI. Where lawful, we will notify the affected customer before disclosing Customer Content.

Corporate transactions. If Weesp AI is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction; we will provide notice to affected customers, and any transfer of Google user data will remain subject to Google’s policies, including any required consent.

8. International Data Transfers

Weesp AI processes data in Israel, the United States, and the European Economic Area (EEA). Where personal data is transferred across borders, we rely on appropriate safeguards, which may include European Commission adequacy decisions (including the adequacy decision covering Israel), Standard Contractual Clauses, and equivalent mechanisms under the UK GDPR and Israeli Protection of Privacy Law, together with the technical and organizational measures described in Section 9. Details of transfer mechanisms applicable to a specific customer are set out in that customer’s data processing agreement.

9. Security

We maintain a security program appropriate to the sensitivity of the data we process, including:

No system is perfectly secure, but we review and improve these measures on an ongoing basis.

10. Data Retention and Deletion

11. Your Rights and Choices

If you are an employee, supplier, or other individual whose data appears in a customer’s content: the Bracket customer is the controller. Please direct requests to that organization; we will assist it in honoring your rights. If you contact us directly, we will refer your request to the relevant customer where appropriate.

If you are a business contact or Bracket account holder, you may have rights under applicable law — including the Israeli Protection of Privacy Law, the EU/UK GDPR, and the California Consumer Privacy Act (CCPA/CPRA), in each case to the extent applicable — to:

To exercise these rights, contact privacy@getbracket.io. We will verify your request and respond within the timelines required by applicable law.

Google account choices. You or your administrator can review and revoke Bracket’s access to Google data at any time at myaccount.google.com/permissions, or by disconnecting the calendar in Bracket’s settings.

12. Children’s Privacy

Bracket is a business product. It is not directed at anyone under 18, and certainly not at children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.

13. Changes to This Policy

We may update this policy from time to time. We will post the updated version at this URL with a revised “Last updated” date, and for material changes we will provide reasonable advance notice to customer administrators (for example, by email or in-product notice). Changes to how we handle Google user data will remain consistent with Google’s policies, and where Google’s policies require it, we will seek renewed consent.

14. Contact Us

Weesp AI, Inc.
131 Continental Dr, Suite 305
Newark, DE 19713, United States

Privacy inquiries: privacy@getbracket.io

If you have unresolved concerns, you may also have the right to complain to your local data protection authority.