Privacy Policy
Last Updated: September 8, 2026 • Effective Date: September 8, 2026
1. Introduction
NousHub Technologies ("NousHub", "we", "us", or "our") provides an autonomous inbound email operations, lead qualification, and response drafting platform. We respect your privacy and are committed to protecting personal data collected through our website (noushub.vercel.app), applications, APIs, and connected integrations.
This Privacy Policy explains what information we collect, how we process and protect it, and your rights under applicable privacy regulations including GDPR, CCPA, and Google API Services User Data Policies.
2. Google API Services User Data & Limited Use Disclosure
NousHub integrates with Google APIs to allow operators to connect their corporate Gmail or Google Workspace mailboxes for autonomous lead inquiry triage and response drafting.
Google API Limited Use Statement:
NousHub's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, when you connect your Google Account:
- Data Accessed: We request access to
userinfo.email,userinfo.profile, and Gmail scopes (gmail.readonly,gmail.modify,gmail.send) strictly when you explicitly configure an inbound mailbox in Agent Hub. - Strict Purpose: We use Gmail data solely to identify unread inbound lead inquiries, perform intent analysis against your organization's verified Knowledge Base collateral, and generate draft responses in your Review Queue.
- No Advertising / Data Brokering: We never sell, transfer, or use your Gmail data, email bodies, or contact lists to serve advertisements, build consumer profiles, or broker to third parties.
- No Human Reading Without Consent: Humans do not read your email messages unless: (a) you have provided explicit affirmative consent for technical troubleshooting, (b) it is required for security investigations, or (c) required by applicable law.
- No AI Model Training on Private Data: Customer email content and uploaded Knowledge Base files are never used to train generalized foundation AI models.
3. Information We Collect
A. Account and Profile Data
When you register or sign in via Google OAuth or credentials, we collect your full name, email address, workspace/organization name, and encrypted authentication tokens.
B. Knowledge Base Collateral
PDF documents, pricing sheets, agreements, and operational policies that you upload are chunked and converted into vector embeddings stored in your isolated tenant partition in PostgreSQL (pgvector) to ground AI responses.
C. Inbound Email Data
Metadata (sender email, subject, timestamps) and message text processed from connected mailboxes are stored to maintain thread context, audit trails, and review queues.
4. How We Use Information
- To provide, operate, and maintain the NousHub autonomous triage platform.
- To extract intent, calculate priority scores, and synthesize grounded reply drafts.
- To enforce automation rules, safety hold gates, and review queues.
- To notify you of high-priority leads, draft approvals, and system events via Server-Sent Events (SSE).
- To ensure compliance, prevent security incidents, and maintain immutable audit logs.
5. Data Security & Encryption
We implement enterprise-grade security standards designed to protect customer data:
- Encryption at Rest: All database storage, vector embeddings, OAuth tokens, and refresh tokens are encrypted using AES-256 GCM.
- Encryption in Transit: All communications between your browser, our servers, and third-party APIs use TLS 1.3 encryption.
- Multi-Tenant Isolation: Data is strictly scoped by organization UUID. Queries enforce tenant boundaries to prevent cross-tenant leakage.
- Fail-Closed Safety Holds: AI drafts exceeding risk thresholds are held in your Review Queue for operator approval before dispatch.
6. Data Retention and Erasure
You maintain full control over your data:
- Disconnecting Mailboxes: When you disconnect a Gmail account in Agent Hub, access and refresh tokens are immediately revoked and deleted from our database.
- Document Deletion: Deleting a document from your Knowledge Base purges its source file, text chunks, and vector embeddings immediately.
- Account Deletion: You can request complete erasure of your workspace and all associated leads, messages, and vector records by contacting privacy@noushub.io.
7. Third-Party Service Providers
We utilize select vetted subprocessors to provide our services:
- Google Cloud / Gemini API: For AI text embeddings and response draft synthesis (data is processed ephemerally and not retained for model training).
- Neon / PostgreSQL: Cloud PostgreSQL database hosting with pgvector extension.
- Vercel & Render: Secure application hosting and serverless edge delivery.
8. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our Google API data practices, please contact our Data Protection team at:
NousHub Technologies Inc.
Email: privacy@noushub.io
Support: support@noushub.io
Website: https://noushub.vercel.app