Privacy Policy

Your privacy is important to us. This policy explains how Summoner Corp. collects, uses, and protects your information in our decentralized agent communication platform.

Summoner Corp. (“Summoner,” “we,” “us,” or “our”) provides a platform for people, organizations, software tools, and AI agents to coordinate work across systems and organizational boundaries. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you use our websites, applications, software development kits, APIs, integrations, and related services (collectively, the “Services”).

If you use the Services through an employer, customer, or other organization, that organization may control your account and the information processed through it. In those circumstances, Summoner generally processes Customer Content on the organization’s behalf and according to its instructions. Please contact that organization if you have questions about its privacy practices.

Last Updated: August 5, 2026

1. Information We Collect

Account and contact information

We may collect your name, email address, username, organization, job title, profile information, authentication identifiers, account preferences, and communications preferences.

Customer Content

We process information that users and organizations submit to or make available through the Services. Depending on the features used, Customer Content may include:

  • Messages, prompts, instructions, responses, and attachments.
  • Files, documents, spreadsheets, emails, drafts, calendar events, tasks, and other business records.
  • Agent definitions, configurations, capabilities, credentials references, and tool instructions.
  • Information exchanged within Spaces or between participating users, organizations, tools, and agents.
  • Proposals, approvals, rejections, overrides, action plans, and workflow outcomes.
  • Voice notes, support communications, and other content users choose to provide.

Customer Content may include personal information relating to people other than the account holder. Customers are responsible for ensuring that they have the authority to provide this information to Summoner and to direct its processing through the Services.

Connected-service information

When you connect a third-party service, such as Google Workspace or Microsoft 365, we may receive:

  • Your connected account identifier and basic profile information.
  • OAuth permissions, authorization status, and connection metadata.
  • Access and refresh tokens or equivalent authorization credentials.
  • Files, messages, events, tasks, records, metadata, and other information that you direct Summoner to access.
  • Results returned by actions performed through a connected service.

The information available to Summoner depends on the permissions you grant, the features you enable, and the instructions or approvals provided through the Services.

Depending on the permissions granted and the workflow configured, Summoner may read, retrieve, create, modify, move, share, transmit, overwrite, or delete information in a connected service on the user’s or customer’s behalf. These operations may be initiated by an authorized user, performed by an Agent or workflow within a Space, triggered automatically by configured conditions, or completed following a configured approval. Customers are responsible for configuring their connections, permissions, Space access, Agent access, workflows, and approval requirements.

Agent and coordination information

We collect information needed to coordinate and audit activity, including:

  • Human, agent, organization, and Space identifiers.
  • Space membership and participant relationships.
  • Capabilities and resources requested or authorized.
  • Tool and agent activity.
  • Approval, denial, revocation, and access-control events.
  • Action status, timestamps, errors, latency, and outcomes.
  • Audit and decision-trail records.

Payment and Billing Information

When you purchase or subscribe to the Services, we collect billing information such as your name, email address, company name, billing address, subscription or plan details, transaction history, invoice information, tax information, and limited payment-method information, such as the payment method type, card brand, expiration date, and last four digits.

We use Stripe to process payments, manage subscriptions, issue invoices and refunds, prevent fraud, authenticate transactions, and perform related billing services. Payment-card and bank-account details entered during checkout are submitted directly to Stripe. Summoner does not receive or store complete payment-card numbers.

Stripe may collect and process transaction information, payment-method information, contact and billing information, IP addresses, device identifiers, and information used for fraud prevention, authentication, analytics, and regulatory compliance. Stripe processes this information according to its Privacy Policy.

We receive transaction status, subscription status, payment-method metadata, invoice information, and other billing records from Stripe. We use this information to provide paid Services, administer accounts and subscriptions, respond to billing requests, maintain financial records, prevent fraud, and comply with legal and tax obligations.

We retain billing and transaction records for as long as reasonably necessary to administer the Services, meet accounting and tax requirements, resolve disputes, enforce our agreements, and comply with applicable law.

Usage and technical information

We may automatically collect IP address, browser and device type, operating system, referring pages, timestamps, feature usage, API activity, diagnostic information, crash reports, performance data, and security events.

Cookies and similar technologies

We use cookies and similar technologies to operate the Services, remember preferences, maintain sessions, protect accounts, and understand how the Services are used. Where required, we obtain consent before using non-essential analytics technologies.

2. How We Use Your Information

We use information to:

  • Create, authenticate, and administer accounts.
  • Provide and operate Spaces, agents, tools, integrations, APIs, and workflows.
  • Retrieve, organize, analyze, transform, or transmit information as directed by users.
  • Allow authorized users and agents to coordinate across connected systems and organizations.
  • Generate recommendations, proposed actions, summaries, and workflow outputs.
  • Enforce permissions, resource restrictions, approval requirements, and organizational boundaries.
  • Create audit records and decision trails.
  • Execute approved actions through connected services.
  • Maintain, troubleshoot, secure, and improve the Services.
  • Detect fraud, abuse, unauthorized access, and security threats.
  • Provide support and respond to requests.
  • Send service, security, billing, and administrative communications.
  • Develop aggregated operational insights, provided that such use is consistent with applicable agreements and restrictions.
  • Comply with law and enforce our agreements.

3. Google Workspace Data

If you connect Google Workspace, Summoner may, depending on the features and permissions you enable:

  • Access, search, retrieve, organize, and process Gmail messages, threads, attachments, and metadata.
  • Create, update, or send email drafts and messages at your direction.
  • Access, search, retrieve, export, create, or update Google Drive files and Google Docs.
  • Access calendars and events and create or update events.
  • Use relevant information to provide visible user-facing coordination, automation, agent, and workflow features.

Summoner accesses Google Workspace data only after authorization and only to provide or improve user-facing features requested or enabled by the user.

Summoner does not sell Google Workspace data, use it for advertising, use it to determine creditworthiness, or transfer it to data brokers or information resellers.

Summoner does not use information received from Google Workspace APIs to create, train, or improve a generalized or non-personalized artificial intelligence or machine-learning model. Google Workspace data may only be used for a specific user’s personalized feature when permitted by Google policy and with the required consent.

Summoner personnel will not access Google Workspace data except:

  • When the user has affirmatively authorized access to specific information for support or another disclosed purpose.
  • When necessary to investigate security incidents, abuse, or technical problems.
  • When required by applicable law.
  • When information has been aggregated and anonymized for permitted internal operations.

Summoner’s use and transfer of information received from Google Workspace APIs will adhere to the Google Workspace User Data and Developer Policy, including its Limited Use requirements.

4. Microsoft 365 Data

If you connect Microsoft 365, Summoner may, depending on the features and permissions you enable:

  • Access, search, download, create, or update files in OneDrive or SharePoint.
  • Retrieve or update supported Excel workbooks.
  • Access Outlook messages or create reply drafts.
  • Access Microsoft To Do tasks.
  • Access supported Teams channels or messages.
  • Retrieve limited organizational information needed to provide the selected feature.

Summoner uses Microsoft 365 information only to provide the connected functionality requested by the user or customer and according to the permissions granted through Microsoft.

You may revoke Summoner’s Microsoft authorization through Summoner, your Microsoft account, or your organization’s Microsoft administrator.

5. AI Processing

Some Services use artificial intelligence models to interpret instructions, analyze authorized information, generate recommendations, coordinate workflows, or produce other user-facing results.

Where an AI provider processes Customer Content for Summoner, the provider acts as a service provider or subprocessor and may use that information only as permitted by its agreement with Summoner.

Summoner does not use Customer Content to train generalized AI models unless this is expressly authorized by the applicable customer agreement and any legally required consent is obtained. Regardless of any other authorization, Google Workspace data is subject to the additional restrictions described in Section 3.

AI-generated results may be incomplete or inaccurate. Customers are responsible for configuring appropriate access controls and human approvals before allowing agents to take consequential actions.

6. Cross-Organizational Spaces and Authorized Sharing

Spaces may allow users, tools, and agents from different organizations to work together. Information placed in a shared Space may become available to other authorized participants according to the Space’s configuration, permissions, and user instructions.We retain information only as long as necessary to provide our services and comply with legal obligations. Account information is deleted upon request, subject to legal requirements.

When you invite another participant, authorize a resource, approve an action, or direct an agent to share information, you instruct Summoner to make the relevant information or output available for that purpose.We retain information only as long as necessary to provide our services and comply with legal obligations. Account information is deleted upon request, subject to legal requirements.

Before sharing information from a connected service with another organization or participant, users must ensure that they are authorized to do so. Summoner may present contextual disclosures or approval requests before executing certain disclosures or actions.We retain information only as long as necessary to provide our services and comply with legal obligations. Account information is deleted upon request, subject to legal requirements.

An organization may administer its users, agents, integrations, Spaces, and permissions. Administrators may be able to access account information, audit activity, shared resources, and Customer Content associated with their organization.We retain information only as long as necessary to provide our services and comply with legal obligations. Account information is deleted upon request, subject to legal requirements.

7. How We Disclose Information

We may disclose information in the following circumstances:

At your or your organization’s direction

We disclose information to participants, organizations, tools, agents, and connected services when authorized through a Space, workflow, integration, or approval.

Service providers and subprocessors

We may use service providers for cloud infrastructure, authentication, database hosting, security, monitoring, customer support, analytics, payment processing, AI processing, and third-party integrations. They may process information only to provide contracted services to Summoner and are subject to confidentiality and data-protection obligations.

Summoner’s current service providers and subprocessors are listed below.

Arrow
Provider Services provided Data potentially processed Role Processing location
Amazon Web Services, Inc. (AWS) Cloud infrastructure, application hosting, managed PostgreSQL database services—including Amazon Aurora and RDS Proxy—storage, networking, backups, logging, error monitoring, and security monitoring through CloudWatch Account information; Customer Content; connected-service data; OAuth credentials and tokens; prompts and outputs; workflow, approval, decision, and audit records; application, database, access, and security logs Subprocessor US East (N. Virginia)
OpenAI, applicable contracting entity AI-model inference, generation, analysis, and related API services Prompts, instructions, authorized Customer Content, files or extracts submitted to the model, generated outputs, and request metadata Subprocessor United States and other locations used by OpenAI, depending on Summoner's API project, endpoint, and data-residency configuration
Anthropic, PBC AI-model inference, generation, analysis, and related Claude API services Prompts, instructions, authorized Customer Content, files or extracts submitted to the model, generated outputs, and request metadata Subprocessor Data stored in the United States; processing may occur in the United States, Europe, Asia, and Australia unless different routing is configured
Okta, Inc. (Auth0) User registration, authentication, account verification, identity management, authorization, and account security Names, email addresses, user and organization identifiers, authentication information, verification status, login and security events, and IP, device, and browser information Subprocessor US West (Oregon, USA)
PostHog, Inc. Product analytics, feature-usage measurement, diagnostics, performance monitoring, and—if enabled—session replay User or account identifiers, analytics events, feature activity, URLs, IP addresses, device and browser information, and session content if session replay is enabled Subprocessor PostHog Cloud US
Webflow, Inc. Website hosting, design, content management, forms, waitlist or contact collection, and supported data storage Website-visitor information, form submissions, names, email addresses, company information, waitlist or contact records, and other information intentionally stored through Webflow Subprocessor for information processed on Summoner's behalf Primarily United States, with additional processing by Webflow's disclosed subprocessors
Stripe, LLC and applicable affiliates Payment processing, subscriptions, invoicing, tax calculation, refunds, authentication, and fraud prevention Billing contacts, billing addresses, transaction and subscription records, invoices, tax information, payment status, payment-method metadata, IP and device information, and fraud-prevention information Processor for certain merchant-directed services; independent controller for certain regulated, fraud-prevention, and compliance activities United States and other locations used by Stripe and its disclosed service providers
Brex Inc. and applicable affiliates Banking and financial services and, if enabled, customer invoicing and payment collection Customer billing contacts, invoices, payment status, bank-transfer information, vendor information, and related financial records Financial-service provider; role depends on the Brex service used United States and other locations described in Brex's privacy disclosures

Organizational administrators

If your account is associated with an organization, its authorized administrators may manage your account and access information associated with organizational use of the Services.

Legal and security purposes

We may disclose information when reasonably necessary to comply with law, legal process, or enforceable governmental requests; enforce agreements; protect rights and safety; or investigate fraud, abuse, or security incidents.

Business transactions

Information may be transferred in connection with a financing, merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to applicable law and contractual restrictions. Google Workspace data will not be transferred as part of such a transaction without any consent required by Google’s Limited Use requirements.

Summoner does not sell personal information. We do not share personal information for cross-context behavioral advertising.

8. Human Access to Customer Content

Access to Customer Content by Summoner personnel is limited to personnel with a business need and appropriate authorization. Our services are not intended for children under 13. We do not knowingly collect personal information from children. If we learn we have collected such information, we will delete it promptly.We strive to maintain high availability of our Service, but we cannot guarantee:

Summoner personnel may access Customer Content when:Access to Customer Content by Summoner personnel is limited to personnel with a business need and appropriate authorization.Our services are not intended for children under 13. We do not knowingly collect personal information from children. If we learn we have collected such information, we will delete it promptly. We strive to maintain high availability of our Service, but we cannot guarantee:

  • A user or customer requests support and authorizes access to the relevant content.
  • Access is necessary to investigate a security incident, abuse, outage, or technical problem.
  • Access is required by law.
  • The information has been aggregated and deidentified for permitted internal operations.

Our personnel and contractors are subject to confidentiality and data-handling obligations.

9. Data Retention and Deletion

We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including providing the Services, complying with contractual commitments, resolving disputes, maintaining security, and meeting legal obligations.

Unless otherwise specified in an applicable customer agreement, our standard retention periods are:

  • Account information: retained while the account is active and deleted from active systems within 30 days after account closure. Limited billing, transaction, fraud-prevention, security, and legal-compliance records may be retained separately as described below. Closing an individual account does not automatically delete Customer Content owned or controlled by an organization or shared with other authorized participants.
  • OAuth credentials: access is discontinued when a connected service is disconnected or authorization is withdrawn. Where technically supported, the applicable authorization is revoked, and active copies of the credentials are deleted or rendered unusable within 24 hours. Residual encrypted copies may remain in backups until those backups are overwritten, but they are not used or restored for operational access.
  • Customer Content: retained for the duration of the customer relationship or according to customer-configured retention settings, then deleted from active systems within 30 days after termination or an authorized and verified deletion request, unless a different period is specified in an applicable agreement. When an organization controls the account or Customer Content, deletion may be subject to that organization’s instructions and retention requirements.
  • Coordination and decision records: workflow history, approvals, decisions, action records, and customer-facing audit trails are treated as Customer Content and follow the customer’s applicable retention period.
  • Security and technical records: authentication, access, and security-event records are generally retained for 12 months. High-volume application, diagnostic, and performance logs are generally retained for up to 90 days.
  • Backups: residual information in backups is deleted or overwritten within 90 days after deletion from active systems. Backups are isolated from ordinary use and retained only for disaster-recovery, security, and business-continuity purposes. If a backup is restored, applicable deletion requests and credential revocations will be reapplied before the restored information is returned to operational use.
  • Support records: retained for three years after a request is resolved, unless a shorter period is appropriate or longer retention is necessary for a dispute, security investigation, or legal obligation.
  • Billing and transaction records: retained for seven years after the relevant transaction or termination of the customer relationship, or longer when required by applicable accounting, tax, or legal obligations.
  • Analytics: identifiable product-analytics information is generally retained for up to 90 days, after which it is deleted or converted into aggregated or deidentified information.

Disconnecting an integration stops future access to the connected service but may not automatically delete information previously imported into the Services or incorporated into a workflow. Users may request deletion as described in Section 10.

We may retain information beyond these periods when required by law, necessary to establish or defend legal claims, subject to a valid legal hold or preservation request, or required by an applicable customer agreement. When immediate deletion is not possible, we will restrict the information from further operational use where appropriate.

To request deletion, email legal@summoner.org. If you use the Services through an employer or another organization, you may need to direct your request to that organization.

10. Your Rights and Choices

Depending on your location and relationship with Summoner, you may have the right to:

  • Access personal information we hold about you.
  • Correct inaccurate information.
  • Request deletion.
  • Obtain a portable copy of certain information.
  • Object to or restrict certain processing.
  • Withdraw consent where processing is based on consent.
  • Appeal the denial of a privacy request.
  • Lodge a complaint with an applicable data-protection authority.

You may disconnect Google or Microsoft through your Summoner settings and may also revoke access through the applicable Google or Microsoft account controls.

If Summoner processes your information on behalf of your employer or another customer, submit your request to that organization first. We will assist the organization as required by applicable law and contract.

To submit a request directly to Summoner, email legal@summoner.org. We may need to verify your identity and authority before fulfilling a request. We will not discriminate against you for exercising applicable privacy rights.

16. Contact Us

For questions, requests, or concerns about this Privacy Policy or Summoner’s privacy practices, contact:

Summoner Corp.
Email: privacy@summoner.org
General inquiries: info@summoner.org
Website:  https://summoner.org/contact
Mailing address:

Summoner Corp.
8 The Green
Ste 8297
Dover, DE 19901

For security reports: support@summoner.org

For privacy questions, data-rights requests, or other data-protection inquiries, contact legal@summoner.org.