Privacy Policy

Effective September 5, 2026. Last updated September 5, 2026.

This policy explains what data Keysoft collects, how it is used, where it is stored, and how to remove it. It covers our website and Keysoft Chief of Staff, our scheduled assistant for executive search firms.

Keysoft is operated by Keysoft LLC, 210 Trilith Pkwy, Ste 100, Fayetteville, GA 30214. Questions about this policy go to privacy@keysoft.tech.

Limited Use disclosure

Keysoft Chief of Staff's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, we do not transfer Google user data to third parties except as necessary to provide or improve the application, comply with applicable law, or as part of a merger or acquisition. We do not use Google user data for advertising. We do not allow humans to read Google user data except with your explicit consent for specific messages, to comply with applicable law, for security purposes such as investigating abuse, or where the data has been aggregated and anonymised. We do not use Google user data to develop, improve, or train generalised artificial intelligence or machine learning models.

Google user data we access

Keysoft Chief of Staff requests the narrowest permissions that allow it to do its job. Each is listed below with what it is used for.

ScopeWhat we accessWhat we do with it
gmail.readonly Metadata and content of messages in your mailbox, primarily sent mail. Identify contacts who have gone quiet and follow-up commitments you made in writing. Message content is processed at run time to produce draft text and task descriptions.
gmail.compose The ability to create draft messages in your mailbox. Save suggested outreach as drafts for your review. This scope does not permit sending, and we never request a scope that does.
calendar.events Events on your calendar. Determine your availability and propose meeting times. Events with attendees outside your organisation are never created without your explicit approval.

What we store, and for how long

Message bodies and calendar event contents are read during a scheduled run and are not retained after that run completes. We do not build a copy of your mailbox.

We do store the following:

  • Your Google refresh token, encrypted at rest, so scheduled runs can operate without asking you to sign in each time.
  • Activity records: that a message was drafted to a named contact on a given date, and whether you sent it. These support your reporting and are written to your own applicant tracking system, which remains your system of record.
  • Run history: when each scheduled run started, finished, and what it produced, for support and billing.
  • Your configuration: schedule, timezone, target criteria, and writing style preferences.

Activity records and run history are retained for the life of your subscription and for 90 days after it ends, then deleted. Your Google refresh token is deleted as soon as you disconnect the account or cancel, whichever comes first.

Billing and tax records are kept separately for as long as the law requires. These contain your account and payment details only. They never contain mailbox content.

Third parties that process data on our behalf

We use the following service providers, each bound by contract to process data only on our instructions:

  • Amazon Web Services, for application hosting and email delivery, in the United States.
  • Supabase, for database hosting and encrypted credential storage.
  • Anthropic, for the language model that generates draft text.
  • Stripe, for subscription billing. Stripe receives billing details, never mailbox content.

We do not sell your data, and we do not share it with advertisers or data brokers.

How data is protected

  • All data is encrypted in transit using TLS and encrypted at rest.
  • Provider credentials, including Google refresh tokens, are stored encrypted in a dedicated secrets store and decrypted only at the moment of use.
  • Access to systems holding customer data is limited to personnel who need it, and is logged.
  • Each customer's data is isolated from every other customer's.

Withdrawing access and deleting your data

You can revoke the application's access at any time at myaccount.google.com/permissions. Access stops immediately and all scheduled runs stop with it.

To have your stored data deleted, email privacy@keysoft.tech. We delete it within 30 days and confirm when it is done. Deleting your Keysoft account also deletes your stored refresh tokens, configuration, and run history. Data already written to your own applicant tracking system stays there, under your control.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete personal data we hold about you, and to object to or restrict certain processing. Write to privacy@keysoft.tech and we will respond within the period the applicable law requires.

Website visitors

Our website collects standard server logs and, where you submit a contact form, the details you provide. We use these to respond to enquiries and to keep the site running.

We do not use analytics or advertising cookies, and we do not track visitors across sites. The site loads fonts and scripts from Google Fonts and from a content delivery network, which means those providers receive your IP address and browser details as part of serving those files. We do not receive that information and do not use it.

Children

Keysoft Chief of Staff is a business product and is not directed to anyone under 16. We do not knowingly collect personal data from children.

Changes to this policy

If we change how the application uses Google user data, we will notify affected customers and ask them to consent to the updated policy before the new use begins. Other changes will be posted here with an updated effective date.

Contact

Keysoft LLC
210 Trilith Pkwy, Ste 100, Fayetteville, GA 30214
privacy@keysoft.tech