What we collect, what we read, and what we do with it.
Written from what the product actually does, in the order a person would ask. Last updated 2026-09-01. If something here stops being true, this page changes first.
Who is responsible
OnDuty is operated by Unbound Operators, based in Bogotá, Colombia. For anything on this page, write to the address at the bottom and a person answers.
What we collect from you directly
| Data | Why | Kept |
|---|---|---|
| Your name, email address and password hash | To sign you in and address you. | While your account exists. |
| Your Google account identity, if you sign in with Google | To sign you in without a password. | While the link exists. You can sign in with a password instead. |
| Workspace name, members, roles and invitations | To run the workspace you belong to. | While the workspace exists. |
| Billing identity and subscription state | To charge the plan you chose. Card numbers never reach us; Stripe holds them. | While the subscription exists, plus what tax law requires of invoices. |
| Sessions and sign-in events | To keep you signed in and to let you revoke a device. | Until you sign out or revoke; expired sessions are purged. |
| Activity and audit records | To show who did what in the workspace, and to keep the decision trail verifiable. | While the workspace exists. The decision trail is append-only by design. |
What we read from the systems you connect
Only when a workspace owner or admin connects a source, and only the scopes that source was granted. Every connector is read-only.
Gmail
threads, participants, timing
Subjects, participants and dates of threads, and message text where the Brain needs it to conclude something. Google classes this scope as restricted; until Google's verification completes, access is limited to a small number of test users.
Google Drive
documents, revisions, authors
File names, revision history, authors and document text, so an answer can cite the file it came from. Same restricted-scope limitation as Gmail.
Google Calendar
events, attendees
Event titles, times and attendees.
HubSpot
contacts, companies, deals
Contact and company records and deal state. No write scope is requested.
WhatsApp and webchat
conversations
Messages exchanged with your customers on channels you connect, and the phone number or visitor identity they arrive with.
Anything you did not connect
Nothing. A source that is not connected is not read, and there is no discovery of systems you did not name.
What is read becomes entities, memories, signals and insights in your workspace, each marked with the source it came from. Credentials for connected sources are encrypted at rest with a key held outside the database; without that key configured, connecting is refused.
Who processes it on our behalf
| Provider | What for | Where |
|---|---|---|
| Supabase | Hosting the database. | United States (us-east-2). |
| Vercel | Hosting the application and running scheduled jobs. | United States, with edge delivery worldwide. |
| OpenAI, and Groq for workspaces created before the switch | Composing replies and answers. Conversation and record content the Brain needs for an answer is sent to the model provider on our account and is not used by us to train shared models. | United States. |
| Stripe | Payments, invoices, and the subscription record. | Stripe's own infrastructure. |
| Resend | Transactional email: verification, invitations, password reset, billing notices. | United States. |
| Selah (api.selahcore.com) | Evaluating proposed actions against your workspace's policies. It receives the proposed action and its context, returns a verdict, and holds no connector credentials. | Selah's own infrastructure. |
| Google and HubSpot | Only as the systems you connect, through their own APIs and consent screens. | Their infrastructure. |
What you can do
See it
Everything the Brain holds about a person or company is on that entity's page, with the source of each record.
Disconnect a source
Deletes the credential and the sync state at once. Knowledge already derived stays attributed to that source, marked as no longer connected, so a conclusion never loses its provenance.
Leave a workspace, or delete one
A member can be removed by an owner or admin. An owner can delete the workspace, which removes its records.
Revoke a session
From your sessions list, any device, at any time.
Ask us
For a copy, a correction or a deletion of anything about you, write to us. We answer within thirty days and usually much sooner.
Things we do not do
Sell data
We do not sell or rent personal data to anyone.
Train shared models on your data
Content from your workspace is used to answer within your workspace.
Track you across other sites
The site sets no advertising cookies and loads no third-party trackers. The product uses a session cookie to keep you signed in.
Serve children
OnDuty is a business tool and is not directed at anyone under eighteen.
Changes
When this page changes, the date at the top changes with it, and material changes are announced to workspace owners by email. Questions, requests and complaints go to the address below.
A person answers.
Write to daniel@alwaysonduty.io for anything about your data.
On duty ·