Privacy Policy
Last updated: August 13, 2026
The short version
Cybella runs AI workers for your business, so we necessarily handle your business's data to do that work. We keep each organization's data isolated from every other, we encrypt the sensitive parts, we never sell it, and we never share it with another customer. We do not use your content to train AI models unless you switch that on yourself. When you delete your organization, we destroy its data and shred its encryption keys.
Two things we will not pretend about. Cybella is a shared service: our systems and, where necessary, our staff can access your data in the course of running it. And your workers' thinking happens on AI infrastructure we operate at a cloud provider — the sections below name every company involved.
What we hold
Account and organization. Your email address and name, who belongs to your organization and their role, your business name and logo, and your subscription status.
What you tell your workers. Your business profile, documents and website content you upload, the chats you have with your workers, the tasks they run and the transcripts of that work, approvals you grant, and the records they keep — including contacts and appointments.
Your customers' information, through you. If your workers answer calls, WhatsApp or SMS, we hold the conversation and the caller's number and name. If you connect an account like Gmail or a calendar, your workers read and write there on your instruction. You are the controller of that information; we process it for you.
Technical data. Standard request logs (IP address, browser, timestamps) at our infrastructure provider for security and performance. Our operational logs record partial phone numbers involved in call routing, so we can debug a call that went wrong. We run no advertising or third-party analytics scripts in the app.
When you ask us for help. If you escalate a conversation to our support team, that conversation is sent to our support inbox by email so a person can read it and answer you. Send us only what you want a human to see.
Where it lives, and how it is kept apart
Your organization's records live in a shared database in which each organization's rows are separated by row-level security enforced by the database itself, not only by our application code. Uploaded files are stored in per-organization object storage. Credentials for accounts you connect, and your backups, are encrypted with AES-256-GCM using keys belonging to your organization alone, held apart from the data they protect. Traffic is encrypted in transit, and our database and storage providers encrypt data at rest.
Organizations that require physically separate, single-tenant infrastructure can arrange that with us as an Enterprise deployment.
How AI processing works
Your workers' reasoning runs on open-weights models we operate ourselves on GPU infrastructure rented from RunPod. Your prompts are not sent to a commercial AI provider for that work, and nothing from it is used to improve anyone else's model.
Some specific features use other providers: speech-to-text and voice for phone calls (Deepgram and ElevenLabs, through Twilio), voice-note transcription and the public website assistant (Cloudflare Workers AI). If you connect an integration through our broker Composio, the details of those actions pass through Composio, which also holds the access token for that account.
Google Workspace data (Gmail, Calendar, Drive)
If you connect a Google account, Cybella's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms, that means the following.
We use it only to run the features you connected it for. Calendar access lets your workers see what you have on and book time. Gmail access lets them read and draft mail you asked them to handle. Drive access lets them read the files you point them at. We request read-only access wherever a feature does not need to write.
We never use it for advertising, and we never sell it or pass it to a data broker.
We never use it to train AI models — and unlike the rest of your data, this is not something you can switch on. The opt-in described below excludes any task in which a worker used your email, calendar or Drive, and that exclusion runs before the consent check, not after it. The reason is that the consent is yours to give while the contents of your inbox are largely other people's.
People do not read it. Our staff do not read your Google data except where you ask us to look at something specific while helping you, where we must to investigate abuse or a security incident, or where the law requires it.
Disconnecting a Google account in Cybella revokes our access immediately and deletes the stored token. You can also revoke it from your own Google account's permissions page at any time, and you can delete what your workers stored from it by deleting your organization.
Companies that process data for us
Cloudflare (hosting, networking, file storage, some AI features), Supabase (sign-in and database), RunPod (GPU infrastructure for our own models), Contabo (servers), Stripe (payments — card details never reach us), Twilio with Deepgram and ElevenLabs (phone calls and SMS), Meta (WhatsApp Business messaging), Resend (our emails to you), and, where you choose to connect them, Composio and Unipile plus whichever services you link (Google, Microsoft, Slack, Shopify and others). Each processes data only to deliver its part of the service.
Training AI models — off unless you turn it on
By default nothing you or your customers say is used to train AI models. In your organization's settings you can choose to contribute completed task transcripts to improve the product. If you switch it on: customer emails, phone numbers, card-like numbers, and names and addresses your workers passed to a tool are replaced with placeholders before anything leaves, and your uploaded documents are never included. That redaction is pattern-based, so personal details written in free text may not be caught — please do not switch this on if your work routinely involves sensitive personal information. Switching it off deletes what you have already contributed. Tasks in which a worker used your Gmail, Google Calendar or Google Drive are excluded entirely and cannot be contributed even with this on — see the Google Workspace section above.
Separately, and regardless of that setting, we collect counts of how work turns out — how many tasks succeeded, failed or waited for approval. That telemetry contains no message content, no names and no customer data, and it is how we find out where the product breaks in real use.
How long we keep it
You choose a retention window for your workers' task and approval history in your settings — from keeping nothing to a custom period — and we redact the content of that history once it passes. Your business profile, documents, contacts, conversations and finished work are kept until you delete them or delete your organization, because they are what your workers rely on to do their job.
We take encrypted backups of your organization's data so we can recover it after a failure. When you delete your organization we take one final encrypted backup, hold it for 30 days in case you need it back, then delete it and shred the keys — after which it cannot be read by anyone, including us.
Deleting your organization
Deleting your organization cancels your subscription, then destroys your business records, uploaded files, contacts, conversations and any contributed transcripts, and shreds your organization's encryption keys. We keep billing records — invoices and payment history — because tax and accounting law requires it. You can start deletion from your settings, or ask us at the address below.
Your rights and choices
You can export your organization's data from settings at any time, correct your business information, disconnect any integration, and delete documents, contacts and conversations individually. Depending on where you live (for example under the UK/EU GDPR) you may also have rights of access, correction, portability, restriction and objection, and the right to complain to your data protection authority. To exercise any of them, email [email protected] from your account address, and we will respond within 30 days.
If your workers handle your customers' information, you are responsible for having a lawful basis to do so and for telling those customers — including any recording or messaging consent your local law requires.
Security
Access to production systems is limited to people who need it to run the service, sensitive actions by your workers wait for your approval, and credentials you connect are encrypted so they are not readable from a database copy alone. No system is perfect: if a breach affects your data we will tell you and the relevant authority as the law requires.
Children
Cybella is a business product, is not directed at children under 16, and we do not knowingly collect their data.
Changes to this policy
If we make material changes we will update the date at the top of this page and, for significant changes, tell you by email or in the app before they take effect.
Contact
Questions about privacy, or to exercise any right above: [email protected].