PrendoAI

Prendo AI — Privacy Policy

Last updated: Oct 10, 2026

1. Who we are

Prendo AI, Inc., a Delaware corporation, 205 De Anza Boulevard #71, San Mateo, CA 94402, United States ("Prendo", "we", "us").

Prendo is an intelligence layer for firms that sell and deliver technology — sales agencies, VARs and MSPs. Our customer is the firm.

Questions or requests: privacy@getprendo.ai.

2. Who this policy covers

RoleWho they are
CustomerThe firm that subscribes to Prendo, and the people it invites into its workspace
Connected-account holderThe individual who authorises a data source
Third parties in that contentPeople who appear in connected material — the customer's own customers, vendors and colleagues
VisitorAnyone using our website without an account

Where our customer determines why data is processed, they are the controller and we act as processor on their instructions under our agreement with them. This policy describes our practices; it does not replace that agreement.

3. What we collect

Account data. Name, work email, workspace and role, and authentication factors. Sign-in is passwordless — Google sign-in, one-time email sign-in links, passkeys, and authenticator-based two-step verification. We do not store passwords.

Content from the tools you connect. We connect to email, file storage, chat, meeting and CRM tools; the tools available are shown in the product when you add a source. When a user connects one, we read only what that connection grants — email messages, files and documents, chat messages, meeting transcripts and summaries, CRM records, and the contact entries used to identify the people in a conversation.

Content you upload. A user can upload a file directly into a workspace. We extract the text and store that.

Derived data. Summaries, deal state and recommendations generated from your content by a third-party AI model (see section 7).

Connected content necessarily contains information about third parties who did not authorise the connection — our customer's own customers, vendors and colleagues. We process it on our customer's instruction and behalf.

Operational records. Server logs from our hosting provider, an audit record of activity in a workspace, and — where a customer connects an external AI agent — a record of the requests that agent makes.

Waitlist. If you join our waitlist on getprendo.ai, we collect your email address and the kind of firm you work for, and store them with the date you joined. We use them to contact you about Prendo.

Website data. Our website sets no cookies and loads no advertising, analytics or tracking scripts. Our application sets only strictly necessary cookies and loads no advertising or tracking scripts.

4. How connections work

Connections use OAuth. You authorise on the provider's own consent screen, which shows you the permissions before you approve; we never see or store your password. We receive a revocable access token, and you can disconnect at any time — from Prendo, or from the tool's own connected-apps settings, which we recommend.

We request read-only access wherever the provider offers it, and we do not write, edit, move or delete anything in a connected system. Salesforce is the one exception at the protocol level, where access is bounded by the permissions of the user you connect; we recommend connecting a read-only user.

Some connections require an administrator's approval in your own organisation before they can be made.

5. Why we process it

  • To provide the service our customer asked for
  • To authenticate users and operate workspaces
  • To secure the service, investigate abuse, and fix faults
  • To meet legal obligations

We do not sell personal information, and we do not use connected content for advertising or transfer it to data brokers.

6. Google user data — Limited Use

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

What we access, and why. We access your Google data only to provide the features of the service, and only for the account you connect:

  • Gmail — we search your mailbox for the messages you ask for, and read the ones you choose to import, so that their content can be organised, searched and summarised within your workspace. We do not send, modify or delete mail.
  • Google Drive — we search your Drive, including shared drives, for the documents you ask for, and read the text of the Google Docs, Sheets and Slides you choose to import, so that their content can be organised, searched and summarised. This includes the transcripts that Google Meet saves to your Drive as documents — Meet material reaches us through this connection rather than a separate one. We do not read recordings, images or other uploaded files, and we do not create, modify, move or delete files.
  • Google Chat — we read the messages in the conversations you search and choose to import. To show who wrote each message, we look up the people in those conversations in your Google contacts: those you have saved, and those Google keeps automatically for people you have emailed or chatted with. We use the name to label their messages, and the email address to suggest which of your customers the conversation belongs to; when you confirm, we remember that address for that customer. We do not read or copy the rest of your contacts.

How we use it. The content is stored in your workspace and processed to produce the summaries, answers and recommendations described in section 7. It is visible only to your workspace, as described in section 9.

What we do not do. We do not use Google user data for advertising or marketing. We do not sell it. We do not transfer it to third parties except to the service providers described in section 8, who process it on our behalf to deliver these features, for security, to comply with law, or in connection with a merger or acquisition with your consent.

We do not use Google user data to develop, improve, or train generalised AI or machine-learning models.

7. AI processing

Prendo uses large language models from third-party AI providers to produce the answers, summaries and recommendations in the service. We send them only what each task needs:

When you search a connected source: the words you type, so they can be turned into a search of that source.

When you ask a question: your question and the relevant content from your workspace.

When you generate or refresh summaries, deal analyses or suggested findings: the relevant content from your workspace.

If your workspace turns on automatic refresh: that same content, on a daily schedule and without a user present, to keep summaries current. Automatic refresh is off by default.

Our AI providers process this content to return results to us and to detect misuse of their services. They may not use it to train their models, and we do not train or fine-tune AI models on customer content.

8. Who we share it with

We do not sell data. We share it only with service providers who process it on our behalf under contract — for hosting and our database, AI processing, credential storage, scheduled processing, and transactional email.

If a customer connects an external AI agent to their workspace, that agent receives the content it requests. The customer chooses whether to connect one and can revoke it at any time. An agent connected this way is governed by its own terms, not ours.

We also disclose data where legally compelled, and will tell the affected customer unless prohibited.

9. Tenancy and who can see your material

Each customer's workspace is isolated, and imported content is never exposed to another customer. Within a workspace, access is scoped by role. Where a vendor is given a seat, their material sits in a separate space and their queries are answered only from their own material.

Source permissions are not replicated. The access permissions that applied to content in its original system — who in your organisation could open a given file, folder, channel or mailbox — are not carried across when that content is imported. Imported material becomes part of your workspace and is readable by the people in that workspace whose role permits it, which may be a wider group than could see it in the source system. A user who connects their own mailbox is making its contents available to their workspace, not only to themselves. Deciding who to admit to a workspace, and which sources to connect, is the customer's responsibility.

Within Prendo, only authorised personnel have access to customer workspaces, and only to operate, support, secure and debug the service, to comply with law, or with the customer's agreement.

10. Retention and deletion

Content stays in your workspace until it is deleted. Nothing expires on its own.

Disconnecting a source deletes the credentials we hold for it and stops further collection. It does not remove content already imported, and deleting content in the source system does not delete the copy we hold — an imported item is a point-in-time copy, and material that should no longer be held must be deleted in Prendo as well.

Deleting an item removes it from your workspace. Summaries and claims already generated from it are stored separately and are not removed with it; they can be regenerated, or removed by deleting the workspace. Contact us at privacy@getprendo.ai if you need derived content removed directly.

Deleting a workspace removes the workspace and everything in it. Workspace deletion is currently performed by Prendo on request.

When a customer leaves, we make their content available for retrieval for 30 days and then delete it. Deleted content may remain in routine backups for a period before aging out.

You can revoke Prendo's access to a Google account at any time from your Google Account's third-party access settings, in addition to disconnecting within Prendo.

11. Security

We use industry-standard technical and organisational measures to protect your data. Traffic between you and the service, and between the service and the providers we use, is encrypted in transit, and stored data is encrypted at rest. Sign-in is passwordless, with passkeys and authenticator-based two-step verification available. Access within a workspace is scoped by role and enforced centrally. We keep an audit trail of activity in a workspace, and we review the codebase for security issues on a regular, automated basis.

No system is perfectly secure. If we become aware of a security incident affecting your data, we will notify you without undue delay.

12. International transfers

Your data is stored in the United States. We do not currently offer a non-US storage option. Where data is transferred out of the European Economic Area or the United Kingdom, we rely on appropriate safeguards such as the Standard Contractual Clauses published by the European Commission.

13. Your rights

Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal information, and to object to it. Where we process data on a customer's behalf, we will route your request to that customer and support them in answering it.

To exercise a right, contact privacy@getprendo.ai. We will not discriminate against you for exercising one.

14. Children

The service is not directed to anyone under 16 and we do not knowingly collect their information.

15. Changes

We will post any change here and update the date above. For material changes affecting connected data, we will notify customers before the change takes effect.

16. Contact

Prendo AI, Inc. 205 De Anza Boulevard #71, San Mateo, CA 94402, United States privacy@getprendo.ai