Data, privacy & security

The plugin has no keys to your world.

A fair question to ask before installing anything into your Claude: what can it actually see, and where does your data go? Here are the straight answers — for you, and for the person at your company you answer to. Every claim reflects how the product is actually built, including where the honest answer is “yes, but with a caveat.”

The 60-second version

  • It cannot open your email, calendar, drive, or CRM. It has no passwords or connections to any of them.
  • It rides the AI you already use. The Manage Suite runs on Claude (Anthropic) — the same assistant, and the same AI company, your Claude session already runs on. No new AI vendor.
  • Claude does the reaching, not us. When something in your inbox or calendar would sharpen the read, Claude pulls the relevant snippet and hands us that text for that one exchange. We receive only what Claude chose to send.
  • We don’t keep the raw material by default. What we keep is our own notes — a private summary of what we’re helping you with and who’s involved.
  • You can be forgotten. Delete your notes, your history, or any single person from your notes, on request.

If your company already permits Claude with work connectors, this plugin adds no new access to your data and no new AI vendor. It’s an operating-partner layer on a relationship you’ve already approved.

The one thing to understand: who holds the keys

A “plugin” sounds like something installed inside your Claude that can then rummage through everything Claude sees. That’s not how this works.

  • Claude holds the connectors. If you’ve connected Gmail, Calendar, Drive, or a CRM to Claude, those connections belong to Claude, under your authorization. They exist whether or not our plugin is installed.
  • Our plugin is a separate service Claude talks to. When you connect it, you authorize exactly one thing: access to your Manage Suite account. That grants us nothing on your Google account or CRM — we hold no credentials for them, and our software contains no code capable of calling them.
  • So the data flow is deliberate. Claude decides a bit of context is relevant and passes us that text. We can’t reach back through Claude to browse your mailbox.

The practical upshot: the right question isn’t “should we trust this plugin with our data.” It’s “do we already permit Claude with work connectors?” If yes, the access already happens — under Anthropic, whom you already evaluated — and this plugin doesn’t widen it.

What actually happens, step by step

  1. You start a session (e.g. “prep me for my 1:1”).
  2. If it helps, Claude gathers relevant context from tools you connected to it — say, recent threads with a report, or next week’s calendar.
  3. Claude sends our engine two things: your message, and that gathered text.
  4. Our engine (running on Anthropic’s API) writes the response and sends it back for Claude to relay to you.
  5. In the background, we update our private notes so your next session has continuity.

That’s the whole loop. The only content that leaves your Claude session is the snippet Claude chose to include; the only content that leaves our systems goes to Anthropic to generate the reply.

What we store — and what we don’t

“We store nothing” is the kind of claim a security team will rightly disbelieve. Here’s the real answer.

What we keep

  • Your sessions. The back-and-forth of your sessions, so history and continuity work.
  • Memory. A plain-language summary of what matters to you — goals, style, ongoing themes.
  • A private “map” of your work. Summarized notes about the people and situations you work through with it — names, roles, and where things stand. It’s why the Manage Suite remembers your context instead of starting cold. Notes, not raw quotes.

What we deliberately don’t keep

  • The raw material Claude gathers. Emails, transcripts, and calendar entries Claude pulls in are used for that exchange and then dropped. Storing them is an off-by-default setting; when on, it auto-deletes after 30 days.
  • Anything in our logs or analytics. Operational logging and usage metrics record counts, timings, and event names — never the text of your conversation, your memory, or the people you discuss.

An honest note about the “map”: because it’s how the Manage Suite stays useful, it does contain real names, roles, and situations of people you talk about. It lives only in your account, is never merged with anyone else’s, and is fully deletable — but it is real information about real people, and we’d rather tell you that plainly than pretend the product is memoryless.

Where your data goes

Only two outside services ever see session content, and both are expected. Everything else sees no session content at all.

ServiceWhat it’s forWhat it receives
Anthropic (Claude API)Generating the response itselfYour message, the notes we’ve built, and the context Claude gathered for that turn. The same AI provider your Claude session already uses.
Supabase (our database)Storing your account, history, and notesEverything we keep, described above. US-hosted PostgreSQL, isolated per user.
StripeBillingYour email, name, and a subscription record. No session content.
ResendSending transactional/marketing emailYour email address and the rendered message. No session content.
VercelHostingOperational logs only (counts/timings). No content.

How your data is kept separate and secure

Per-user isolation, enforced structurally

Every piece of your data is keyed to your account. If you discuss a colleague, those notes live only in your map — never surfaced to another user, and there is no path in the system that would join your notes to anyone else’s.

Server-only database access

The app’s screens and browser code never query this data directly. All reads and writes go through authenticated server code that checks ownership on every request.

Row-Level Security as a backstop

Every table additionally has database-level Row-Level Security in a deny-by-default posture. To be precise: today the primary enforcement is application-level (server code filters every query by your user ID), with RLS underneath as a safety net — written so it becomes active per-row enforcement if we later adopt per-user database credentials. Defense-in-depth, described accurately.

Encrypted in transit

All connections use TLS. The plugin authenticates with modern OAuth 2.1 (PKCE), and access is a short-lived token scoped only to your Manage Suite account.

Your controls: retention and deletion

  • Raw gathered context: off by default; when on, auto-deletes after 30 days.
  • Notes, memory, and history: retained so the Manage Suite stays useful, until you ask us to delete them.
  • Deletion, on request (handled by us today rather than a self-serve button, a deliberate choice while the product is early): forget one person, delete the whole map, or a full erasure of your Manage Suite data. Billing and account-login records are retained even on a full delete — those aren’t session content, and we’re generally required to keep the financial ones.

Straight answers for a security team

Can this plugin read our email / CRM / drive?

No. It has no connection or credential to any of them, and no code that could call them. It only receives text that Claude — under your own connector authorization — chooses to pass it.

Does our data go to a new AI vendor?

No. Responses are generated by Anthropic’s API — the same provider as your Claude session. No additional model provider is introduced.

What does Anthropic do with the data you send their API?

That’s governed by Anthropic’s commercial API terms, which state they do not train on API traffic and offer limited-retention and zero-retention options. We can provide a Data Processing Agreement (DPA) covering this — we’d rather point you to the contract than ask you to take a paraphrase.

Where is data stored, and for how long?

In our US-hosted PostgreSQL database (Supabase). Raw gathered context: 30 days when enabled (off by default). Notes, memory, and history: retained until you request deletion.

How is one customer’s data isolated from another’s?

Every row is keyed to a user ID; server code filters every query by owner; there is no join path between users’ data; and Row-Level Security is enabled as a deny-by-default backstop.

Can we get our data deleted?

Yes — one person, the whole relationship map, or a full erasure of your Manage Suite data (transcripts, memory, model, commitments, decisions). Billing records are retained as generally required.

Are you SOC 2 / ISO 27001 certified?

Not today — we’re early-stage and would rather say so than imply a certification we don’t hold. The architecture follows the defense-in-depth lines an audit looks for. If a certification is a hard requirement for you, tell us — it helps us prioritize.

What we don’t claim

To keep this trustworthy, here’s what we’re careful not to say:

  • We don’t say “we store nothing” — we store notes, memory, and history, and we’ve described exactly what that includes.
  • We don’t say the database enforces per-user isolation today — that’s application-enforced, with RLS as a deny-by-default backstop.
  • We don’t assert Anthropic’s retention/training terms as if they were ours — they’re Anthropic’s, under our API agreement, and worth confirming at the source.
  • We don’t claim a compliance certification we don’t hold.

Being able to say all of the above, plainly, is the point. A privacy story only helps if it survives a careful reader.

Questions, or a security review to work through?

Talk to us →