At OpenAssistant, we build AI that users and enterprises can trust. Protecting customer data, maintaining strong security controls, and operating transparently are fundamental to how our platform is designed. This policy explains how OpenAssistant works, what data it accesses, how that data is used, and how it is protected.
1. What OpenAssistant Does
OpenAssistant is an AI assistant platform that helps users automate scheduling, communications, research, reminders, and other productivity tasks across email, messaging platforms, calendars, and connected applications.
Depending on the permissions you grant, OpenAssistant can:
Coordinate meetings and scheduling
Read calendar availability
Create, update, or cancel calendar events
Draft and send emails or messages
Summarize conversations, documents, and files
Search connected applications for information
Create reminders and recurring workflows
Complete other tasks you explicitly request
OpenAssistant only performs actions that you authorize or explicitly instruct it to perform.
2. Data Access & Use
a. Calendar & Contacts
OpenAssistant connects to supported calendar and contact providers (including Google Workspace and Microsoft 365) using secure OAuth authentication.
We access only the information required to:
View calendar availability
Create, update, or cancel meetings
Send calendar invitations
Store contact-level scheduling preferences
Complete scheduling-related tasks you request
Calendar and contact data is accessed only when necessary to provide the requested functionality.
b. Messages & Communications
When inbox permissions are not granted, OpenAssistant processes only the conversations in which it is explicitly included (such as email threads, SMS, Slack, or Microsoft Teams conversations).
This information may be used to:
Interpret requests
Coordinate scheduling
Respond within the conversation
Update user preferences
Complete additional tasks you explicitly request
c. Inbox Access
If you grant inbox permissions, OpenAssistant may read, draft, and send emails on your behalf.
Inbox access may be used to:
Draft emails
Send emails
Summarize email threads
Organize or clean up inboxes
Search for relevant information
Complete other email-related tasks you explicitly request
Inbox access is optional and only available when explicitly authorized.
d. Third-Party Integrations
If you connect OpenAssistant to third-party applications or services (such as cloud storage, collaboration platforms, CRM systems, project management tools, or other supported integrations), OpenAssistant may access the data necessary to complete the tasks you request.
Examples include:
Searching for information
Reading or summarizing documents
Creating or updating files, records, or tasks
Performing actions within connected applications
OpenAssistant only accesses services you have explicitly connected and only within the permissions you have granted.
e. User Memory & Preferences
OpenAssistant may retain user preferences, saved instructions, contacts, and workflow settings to provide a more personalized experience.
This information is used only to improve the functionality you have requested and may be updated or removed by the user at any time.
f. Data Storage & Retention
Customer data is stored using secure, encrypted cloud infrastructure operated by OpenAssistant and its approved service providers.
We implement industry-standard protections including:
Encryption in transit
Encryption at rest
Secure authentication and access controls
Customer data is retained only as long as necessary to provide requested functionality, support active workflows, comply with legal obligations, or maintain platform security. Where applicable, customer data is automatically deleted in accordance with our retention policies.
3. AI Models & Providers
OpenAssistant uses large language models from trusted providers, including OpenAI, Anthropic, and other approved AI providers, to understand natural language and perform requested tasks.
Customer data is never used to train foundation AI models.
Our agreements with AI providers prohibit the use of OpenAssistant customer data for model training.
Customer data is processed solely to deliver the functionality requested by the user.
4. Security & Compliance
Security is built into every layer of the OpenAssistant platform.
Our security program includes:
SOC 2 Type II compliance
Encryption of customer data in transit and at rest
Least-privilege access controls
Continuous security monitoring
Incident response procedures
Regular security reviews and risk assessments
Security reviews of approved sub-processors
Access to customer data is restricted to authorized personnel and permitted only when necessary for customer support, troubleshooting, security, or legal compliance.
OpenAssistant supports customer privacy requirements, including GDPR and CCPA rights related to data access, correction, export, and deletion where applicable.
5. Customer Control & Transparency
You remain in control of your data and OpenAssistant's access.
OpenAssistant only accesses systems and data that you explicitly authorize.
You may revoke permissions or disconnect integrations at any time.
OpenAssistant performs actions only when explicitly requested by you or through workflows and automations you have configured.
Data access and deletion requests are handled in accordance with applicable privacy laws.
We are committed to transparency regarding how customer data is accessed, processed, and protected.
We design OpenAssistant to follow the principle of least privilege—accessing only the information necessary to perform the tasks you have requested while maintaining strong security and privacy protections throughout the platform.
For full details on data rights and privacy practices, please review our Privacy Policy.
