Legal

Privacy Policy

Effective date: 20 August 2026  ·  1Presence

1. What we collect and why

1.1 Account data

When you create an account we collect your email address and, if you sign in with Google, your Google profile name and profile picture. We use this to authenticate you, address you by name, and contact you about your account.

1.2 Conversation content

Messages you send to your agent and responses your agent generates are stored in Firestore under your user ID and synced to your personal cloud vault (Google Cloud Storage). This data belongs to you. We store it so your agent can maintain continuity across sessions. We do not use your conversation content for advertising, to build profiles of you, or to train AI models. We access it only as needed to operate your agent for you, to provide support you request, to maintain the security and integrity of the service, or where the law requires it.

1.3 Vault content

Markdown notes you write, or that your agent writes on your behalf, are stored in a GCS bucket scoped exclusively to your user ID. Access is enforced at the infrastructure level via IAM, so no other user can read your vault. We restrict employee access tightly: our staff do not access your vault in the ordinary course, and do so only where you ask us to (for example, to help with support), where it is necessary to maintain the security and integrity of the service, or where we are required to by law.

1.4 Semantic memory

Your agent maintains a vector database (ChromaDB) of semantic memories derived from your conversations. This data is stored on your dedicated agent pod's ephemeral disk and periodically synced to a private GCS bucket scoped to your user ID. It is not shared with other users, and we do not use it to train any models.

1.5 Usage and technical data

We log standard server-side metadata — timestamps, HTTP status codes, request durations — for the purpose of diagnosing errors and monitoring system health. These logs do not include message content and are retained only as long as needed for these purposes before being purged. We also use error and performance monitoring (described in section 6.1) that captures technical error reports and page-performance metrics, scrubbed of message content.

1.6 Cookies, analytics, and local storage

We use Firebase Authentication, which sets a session cookie and uses localStorage to persist your sign-in state. Your agent's display name preference is stored in localStorage on your device only.

To understand how 1Presence is used and to improve it, we use privacy-respecting, cookieless analytics. We measure things like which pages are visited, how people move from signing up to getting set up, and which features are used — never the content of your conversations, which our analytics pipeline cannot see. To understand roughly where our users are, we use your network address to estimate your country when you load a page. We use it only for that purpose, do not retain it for analytics, and derive nothing more specific than the country — which is the only location signal passed to our analytics provider. We set no advertising cookies and use no cross-site or ad-network tracking. Some of this measurement is handled by an analytics provider acting solely on our behalf under a data-processing agreement, with appropriate safeguards for any international transfers, and used only to improve the product. We never sell or share your personal information, and you can ask us to exclude your usage from analytics at any time.

2. Third-party integrations

You may optionally connect third-party services to your agent. All integrations are opt-in — you choose which services to connect and can disconnect them at any time. When you connect most services, you grant 1Presence a limited OAuth access token (a small number use an API key you provide instead). We store that credential encrypted in Google Cloud Secret Manager, scoped exclusively to your user account. Local folders are the exception — they are accessed directly through your browser and no credential is ever sent to or stored by us (see 2.18). The token is used only to act on your behalf within the connected service — to retrieve information you ask for or perform actions you explicitly request.

We do not store content retrieved from third-party services beyond what is necessary to fulfill a specific request or maintain context in your agent's memory. We do not share third-party service data with other users.

2.1 Google services (Gmail, Google Drive, Google Calendar, Google Meet)

Gmail: read access to your messages and, optionally, the ability to send email on your behalf. Google Drive: read access to your files and, optionally, the ability to create new files on your behalf. Google Calendar: read access to your events and, optionally, the ability to create or edit events on your behalf.

Google Meet: when you connect Google Calendar, you can additionally grant read-only access to the transcripts of meetings you host or attend in Google Meet, so Presence can fetch and summarise them when you ask. This is an optional addition to the Calendar connection; if you do not grant it, Presence cannot read your Meet transcripts.

These connections use Google's own OAuth system. Your Google credentials never leave Google. Google's privacy policy governs how Google handles your data.

1Presence's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. This commitment applies to every Google service we connect to, including those described in 2.2 and 2.3 below. In plain terms: we use the access you grant only to provide and improve the features you ask for inside 1Presence; we never sell your Google data; we never use it for advertising; and we do not use your Gmail, Google Drive, Google Calendar, Google Meet, Google Analytics, Google Search Console, Google Tag Manager, or YouTube content — or any other Google user data — to develop, improve, or train generalised or non-personalised artificial-intelligence or machine-learning models. No human reads this data except where you ask us to (for example, to help with a support request), where it is necessary for security or to meet a legal obligation, or where the data has been aggregated and anonymised for internal operations.

2.2 Google Analytics, Search Console, and Tag Manager

If you manage websites, you can connect these Google tools so Presence can report on and help you work with your own properties. Google Analytics: read-only access to the analytics properties in your account — traffic, engagement, and conversion reporting. Google Search Console: access to your verified sites' search-performance data and, where you ask, the ability to submit sitemaps or request indexing on your behalf. Google Tag Manager: access to your containers and, where you ask, the ability to create or edit tags, triggers, and variables on your behalf.

These connections use Google's own OAuth system and are covered by the Google API Services User Data Policy, including the Limited Use commitments described in 2.1. We never use this data for advertising or to train models. Google's privacy policy governs how Google handles your data.

2.3 YouTube

If you connect YouTube, Presence can access your YouTube channel and content and, where you ask, manage your videos, playlists, and channel details on your behalf. This connection uses Google's OAuth system and is covered by the Google API Services User Data Policy, including the Limited Use commitments described in 2.1. Your use of the YouTube integration is also subject to the YouTube Terms of Service, and Google's privacy policy explains how Google handles your data.

2.4 Microsoft 365 (Outlook mail, calendar, OneDrive)

You can connect a Microsoft 365 or Outlook.com account, which covers your Outlook mail, calendar, OneDrive files, contacts, notes, and tasks in a single connection. Presence reads these to help you and, only where you explicitly ask, can send mail, create or edit calendar events, and create or update files and tasks on your behalf. Where your account has Microsoft Teams meetings, Presence can also read the transcripts and recordings of meetings you attended. This connection uses Microsoft's own OAuth system; Microsoft's privacy statement governs how Microsoft handles your data.

2.5 GitHub

Public mode: access to your public repositories, profile, and notifications. Full mode: access to all repositories including private ones, your profile, and notifications. GitHub's privacy policy governs how GitHub handles your data.

2.6 Slack

Read mode: access to channel history, private group history, and direct message history in workspaces you belong to. Read + send mode: the above plus the ability to send messages on your behalf. Slack's privacy policy governs how Slack handles your data.

2.7 LinkedIn

Profile mode: access to your LinkedIn profile and email address. Post mode: the above plus the ability to create posts on your behalf. LinkedIn's privacy policy governs how LinkedIn handles your data.

2.8 Notion

Access to pages and databases you explicitly share with the 1Presence integration. Notion's privacy policy governs how Notion handles your data.

2.9 X (Twitter)

Profile mode: read access to your X profile — name, username, bio, and follower and following counts. Post mode: the above plus the ability to post on your behalf. X's privacy policy governs how X handles your data.

2.10 Motion

Read access to your tasks, projects, and workspaces and, optionally, the ability to create and update tasks on your behalf. Motion connects via an API key you provide, which we store encrypted in the same way as an OAuth token. Motion's privacy policy governs how Motion handles your data.

2.11 monday.com

Read access to your boards, items, and updates and, optionally, the ability to create and update items on your behalf. monday.com's privacy policy governs how monday.com handles your data.

2.12 HubSpot

Read access to your CRM records — contacts, companies, deals, and their associated activity — and, optionally, the ability to create or update records on your behalf. HubSpot's privacy policy governs how HubSpot handles your data.

2.13 Twilio

Read-only access to your own Twilio account's call logs, message (SMS/MMS) history, call recordings, and recording transcripts, so Presence can review and reference your communications. This connection is read-only — Presence cannot send messages or place calls through it. Twilio connects via API credentials you provide, which we store encrypted in the same way as an OAuth token. Twilio's privacy notice governs how Twilio handles your data.

2.14 Strava

Read-only access to your own Strava data — profile, aggregate stats, and individual activities (including splits, heart rate, power, and route detail). Presence only ever reads your own activity, never anyone else's, and we never use it to train any models. Strava's privacy policy governs how Strava handles your data.

2.15 Meeting recording

You can ask Presence to join a video meeting — Google Meet, Zoom, or Microsoft Teams — as a recorder, to capture the audio and produce a transcript and summary saved to your vault. The recorder joins the meeting under the name "1Presence" so that other participants can see it is present. The capture is performed by a specialist meeting-recording provider acting on our behalf (see 6.1); the audio and resulting transcript are processed only to produce your recording and summary, and are stored in your account. Neither we nor that provider may use them to train models, under the contract described in 6.1.

You are responsible for complying with the laws and participant-consent requirements that apply where you and the other participants are located. Some jurisdictions require that everyone in a meeting is informed of, or consents to, recording before it begins.

2.16 Read AI

Access to meeting transcripts, summaries, and action items for meetings you attended, retrieved through Read AI's own integration. Read AI's privacy policy governs how Read AI handles your data.

2.17 Plaud

Read-only access to your own Plaud recordings and their transcripts and summaries, retrieved through Plaud's own integration, so Presence can reference them. Presence only ever reads your own recordings, and we never use them to train any models. Plaud's privacy policy governs how Plaud handles your data.

2.18 Local folders

You can connect a folder on your computer directly from your browser (Chrome or Edge) using the browser's permission-gated file access. This connection is different from the others: no files are uploaded or copied to our servers, and no access token is stored by us. Your browser grants Presence read access to the folder you choose, for as long as you allow it, and the files never leave your machine. You can revoke access by closing the browser, removing the folder, or revoking the permission in your browser settings.

You can disconnect any integration at any time from within 1Presence. Disconnecting revokes our stored access token immediately. We also recommend revoking access directly from the third-party service's settings page to ensure complete revocation.

3. How we use your data

  • To authenticate you and route requests to your agent pod.
  • To operate, maintain, and improve the 1Presence service.
  • To send you transactional emails — account confirmation, password reset, service notices. We do not send marketing email without your explicit consent.
  • To comply with legal obligations.

We do not sell your data. We do not use your conversation content, vault, or memories to train AI models. Your data is used to provide the service to you, and is not shared except as described in this policy.

We may disclose personal data where we are required to by law, regulation, legal process, or an enforceable governmental request; where reasonably necessary to detect, prevent, or address fraud, security, or technical issues, or violations of our Terms; to protect the rights, property, or safety of our users, the public, or us; or in connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honour this policy or give you notice of any change. In each case we disclose only the data reasonably necessary, and we do not sell your personal data.

4. AI model providers

Your agent is powered by one or more third-party AI model providers. The messages you send are transmitted to the provider that generates your agent's response, solely to produce that response. We only work with providers that are contractually prohibited from using your inputs or outputs to train their models. We may change providers, or route between them, over time to deliver the best quality, reliability, and value — the specific provider or providers we currently use are available on request at support@1presence.com.

If you use creative media generation (image, video, or audio), the prompt — together with any reference image or voice sample you provide — is sent to the specialist media-generation provider that produces that content, solely to fulfil that specific request. These providers act on your behalf for the generation only; they do not receive your conversations, vault, or memories, and they are not permitted to use your data to train their models. Aside from the providers described here, no other third-party AI providers receive your data.

5. Data storage and security

All data is stored within Google Cloud Platform infrastructure. Where your data is processed, and the safeguards that apply when it crosses borders, are described in section 6. We use the following security measures:

  • All data in transit is encrypted via TLS 1.2 or higher.
  • All data at rest is encrypted by GCS and Firestore default encryption.
  • Per-user GCS buckets are access-controlled via IAM — each agent pod can only access its own user's data via Workload Identity.
  • Firebase Authentication tokens are short-lived and verified on every request.
  • Agent pods are isolated Kubernetes deployments — no shared processes or filesystems between users.

6. International data transfers

1Presence is operated from the United Kingdom and serves users worldwide. Your data is hosted on Google Cloud Platform and is processed principally in the United States, and it may also be processed in the United Kingdom, the European Economic Area (EEA), and other countries where we and our service providers operate. This means your data may be transferred to, and processed in, a country other than the one you live in — including a country whose data-protection laws differ from your own.

Whenever we transfer personal data out of the UK or EEA to a country that has not been judged to provide an equivalent level of protection, we rely on appropriate safeguards recognised under data-protection law — principally the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum, and/or a provider's certification under a recognised framework such as the EU–US and UK–US Data Privacy Framework. You can request a copy of the relevant safeguard by emailing support@1presence.com.

6.1 Service providers who process data on our behalf

We share personal data with a small number of sub-processors strictly so they can provide infrastructure and services to us, under contracts that require them to protect it and use it only on our instructions:

  • Cloud infrastructure — Google Cloud Platform and Firebase provide our hosting, storage, database, and authentication.
  • AI model providers — one or more third-party AI providers process the messages needed to generate your agent's responses (see section 4).
  • Media generation — when you generate images, video, or audio, specialist providers process that specific request (see section 4).
  • Meeting recording — when you ask Presence to record a meeting, a specialist meeting-recording provider dispatches the recorder and processes the resulting audio and transcript on our behalf, solely to produce your recording and summary (see section 2.15). It does not use your data to train models.
  • Payments — our payment provider processes your subscription and usage billing; we do not store your full card details.
  • Email — our transactional email provider delivers account and service messages.
  • Analytics — our privacy-respecting, cookieless analytics provider acts solely on our behalf (see section 1.6).
  • Error and performance monitoring — a monitoring provider receives technical error reports and page-performance metrics so we can detect and fix problems and keep the service fast. These are scrubbed of message content and never include your conversations, vault, or memories.

In addition, any third-party services you choose to connect (section 2) receive only the data needed to perform the actions you request. We do not sell your personal data to anyone, and we do not share it for advertising.

7. Data retention

We retain your personal data for as long as your account is active and as long as needed to provide the service. When you delete your account, we remove your conversation history, vault contents, and semantic memories from our active systems within 30 days. Residual copies in backups and in our cloud storage's deletion-protection window are purged within 90 days. We keep diagnostic server logs for 30 days. Where the law requires us to retain certain data for longer, we keep it only for that period and then delete it.

8. Your rights

Depending on where you live, you may have rights including:

  • Access — request a copy of the personal data we hold about you.
  • Correction — ask us to correct inaccurate data.
  • Deletion — ask us to delete your data (right to erasure).
  • Portability — request your vault contents and conversation history in a machine-readable format.
  • Objection — object to processing where we rely on legitimate interests.
  • Restriction — ask us to restrict processing while a dispute is resolved.
  • Withdraw consent — where we rely on your consent, withdraw it at any time without affecting processing already carried out.

To exercise any of these rights, email support@1presence.com. We will respond within the time required by applicable law — generally within 30 to 45 days — and may extend this where the law permits for complex requests. We will not discriminate against you for exercising your rights.

8.1 UK and EEA users

If you are in the UK or EEA, the UK GDPR and EU GDPR apply to our processing of your personal data. The legal bases we rely on are: performance of a contract (to provide the service you sign up for), your consent (for optional integrations and analytics), legitimate interests (to keep the service secure and to improve it, balanced against your rights), and legal obligation (where the law requires it).

You have the right to lodge a complaint with your local supervisory authority — the Information Commissioner's Office (ICO) in the UK, or the data protection authority in your EEA country of residence.

8.2 Rest of the world

Many countries — including Brazil, Canada, Australia, and others — give you comparable rights over your personal data. Wherever you live, you are welcome to make any of the requests above by emailing us, and we will honour the rights available to you under your local law.

9. Your California privacy rights

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), gives you specific rights over your personal information:

  • Right to know — the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and any parties we disclose it to.
  • Right to delete — request deletion of personal information we have collected from you, subject to legal exceptions.
  • Right to correct — request correction of inaccurate personal information.
  • Right to opt out of sale or sharing — direct us not to sell or "share" (for cross-context behavioural advertising) your personal information.
  • Right to limit use of sensitive personal information — restrict our use of sensitive personal information to what is necessary to provide the service.
  • Right to non-discrimination — we will not deny you service, charge you a different price, or provide a different quality of service for exercising your rights.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising — so there is nothing for you to opt out of in that respect. We also do not use your sensitive personal information for any purpose other than providing and securing the service. To exercise your right to know, delete, or correct, email support@1presence.com; we may need to verify your identity before acting on your request, and you may use an authorised agent.

10. Children and young people

1Presence is for adults. You must be at least 18 to hold an account, and the Service is not directed at children or young people under 18. We do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has created an account, please contact us at support@1presence.com and we will delete the account promptly.

11. Changes to this policy

We may update this policy from time to time. We will notify you of material changes by email or by displaying a notice in the application at least 14 days before the change takes effect. Your continued use of the service after the effective date constitutes acceptance of the updated policy.

12. Contact

Questions, requests, or concerns about this policy: support@1presence.com.

13. Who we are

1Presence is operated by Float Frequency Ltd ("we", "us", "our"), a company registered in England and Wales under company number 14986635, with its registered office at 128 City Road, London, England, EC1V 2NX.

1Presence is available to people around the world. We are the data controller responsible for your personal data, and we apply the protections described in this policy to all of our users wherever they live. If you have any privacy question, or wish to exercise your rights, you can reach us at support@1presence.com.

We built 1Presence to give individuals a private, personal AI agent — not to harvest data, serve advertising, or sell your information to third parties. This policy explains exactly what we collect, why, and what you can do about it.