Last updated: August 23, 2026
Privacy Policy
At Fastyr, we take your privacy seriously. This Privacy Policy describes how Fastyr, Inc. ("Fastyr", "we", "us", or "our") collects, uses, and protects your information when you use the Fastyr platform at app.fastyr.ai and our related services.
1. Information We Collect
We collect information to provide and improve the Service. The types of information we collect include:
Account Information
- Name, email address, and authentication credentials
- Organization name and configuration
- Billing information (processed and stored by Stripe)
- Profile and workspace preferences
- Mobile phone numbers, SMS consent choices, and consent records when you choose to receive text messages
Usage Data
- Platform interaction data (features used, pages visited, actions taken)
- Agent configuration and workflow data
- Subscription and billing events
- Device information, browser type, and IP address
Agent Interaction Data
- Messages and instructions sent to AI agents
- Agent outputs, tool calls, and execution logs
- Files and documents processed by agents within your workspace
- Integration data flowing through connected third-party services
2. How We Use Information
We use the information we collect to:
- Provide, maintain, and improve the Fastyr platform
- Process AI agent tasks and deliver results within your workspace
- Process payments and manage your subscription
- Send transactional communications (account verification, billing notifications, security alerts)
- Send recurring SMS account, AI-agent, approval, and support updates only after you separately opt in
- Analyze usage patterns to improve platform performance and reliability
- Detect, prevent, and respond to security incidents, fraud, and abuse
- Comply with legal obligations
We do not use Google Workspace API data to develop, improve, or train generalized or non-personalized artificial intelligence or machine-learning models. For data that does not come from Google Workspace APIs, we do not use your data or agent interactions to train our own models unless you explicitly opt in.
SMS Messaging Privacy
We do not share, sell, or provide your mobile phone number or messaging consent data to third parties or affiliates for marketing or promotional purposes.
If you separately opt in to the Fastyr SMS program, we collect your mobile phone number, SMS consent choice, consent record, and message delivery and support records. We use this information only to send the recurring account activity, AI-agent, approval, integration, and support updates you requested; manage your messaging preferences; provide support; and maintain compliance records.
Message frequency varies. Message and data rates may apply. Consent to receive SMS messages is optional and is not a condition of purchase or use of Fastyr. You may reply STOP to opt out or HELP for help at any time.
We never rent or sell mobile phone numbers, SMS opt-in data, or messaging consent data. The non-sharing restriction above applies notwithstanding every other data-sharing provision in this Privacy Policy.
We disclose mobile information only to service providers, including Twilio and telecommunications carriers, when strictly necessary to operate, deliver, secure, and support the SMS program. Those providers may not use the information for their own marketing or promotional purposes. For the complete consent, help, and opt-out flow, see our SMS Messaging Program.
3. Google Workspace API Data
When a Google Workspace administrator connects Fastyr, Fastyr accesses Google user data only to provide the administrator-directed mailbox and account automation described in the product. This section applies specifically to data received from Google Workspace APIs.
Data We Access
- The connecting administrator's email address and OAuth authorization credentials
- Verified Workspace domain names and Directory user information needed to create, validate, update, and delete organization-owned agent accounts, including names, email addresses, organizational-unit paths, and account status
- Gmail messages, threads, headers, bodies, attachments, labels, and mailbox state for organization-owned agent inboxes
- Gmail vacation-response and forwarding settings used during administrator-configured agent offboarding
How We Use Google Workspace Data
Fastyr uses this data only to provide visible, user-facing features:
- Show verified domains and let the administrator select the domain for agent accounts
- Automatically create an organization-owned Workspace user and Gmail inbox when an agent is hired, validate its health, rotate its unpublished password when offboarding begins, and delete the disposable user after the configured grace period
- Synchronize, display, search, send, reply to, and organize messages and attachments in the agent's Fastyr inbox, including read/unread, archive, trash, restore, and label state
- Configure an automatic response and forward new mail during the offboarding grace period to the agent's hiring principal, falling back to the connected Workspace administrator
- Copy retained mailbox messages before final deletion to the connected Workspace administrator, falling back to the resolved forwarding destination
Storage, Security, Sharing, and Retention
- OAuth credentials are encrypted and stored separately from application data. Google message data and attachments are encrypted in transit and at rest and are isolated by organization and access-controlled role.
- We disclose Google Workspace data only to infrastructure and model-processing providers acting for Fastyr when strictly necessary to deliver these user-facing features, under contracts that prohibit independent use and model training; for security or abuse investigation; when required by law; or as part of a business transfer after obtaining any consent required by Google's policies. We do not sell Google Workspace data or use it for advertising, retargeting, data-broker services, credit decisions, or lending.
- Fastyr personnel do not read Google message content unless the customer gives affirmative permission for specific data, access is necessary to investigate a security or service issue, access is required by law, or the data is aggregated for permitted internal operations.
- We retain synchronized Google Workspace data only while needed to provide the connected service and according to the organization's retention settings. Disconnecting or revoking Google Workspace access stops new access. Customers can delete a managed Google mailbox through Fastyr offboarding, delete source Gmail content in Google, request deletion of Fastyr-held synchronized content under Section 8, revoke the administrator OAuth grant from their Google Account, and revoke delegated mailbox access from the Workspace Admin Console. Retained Fastyr copies follow the retention and deletion periods in Section 6 unless law requires a longer period.
Google API Services User Data Policy
Fastyr's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google Workspace API data is never used to develop, improve, or train generalized or non-personalized AI or machine-learning models. Fastyr may process that data with AI models only to perform the customer-directed, user-facing features described above, and our providers may not use the data to train their models.
4. AI Agent Data Processing
AI agents on the Fastyr platform process data in unique ways compared to traditional SaaS applications. Here is how we handle agent data:
- Sandboxed execution: Each agent operates in an isolated sandbox environment. Data processed by one agent cannot be accessed by another agent or organization
- Integration data flows: When agents interact with third-party services through connected integrations, data flows between those services and the agent's sandbox. This data is governed by both our Privacy Policy and the third-party service's privacy policy
- LLM processing: Agent reasoning involves sending prompts and context to large language model providers. We select providers with strict data processing agreements and do not allow them to use your data for model training
- Execution logs: Agent actions, tool calls, and outputs are logged for auditability and are accessible through your Command Center
5. Data Sharing & Third Parties
We do not sell your personal information. The sharing described in this section excludes mobile phone numbers, SMS opt-in data, and messaging consent data. We do not share those categories with third parties or affiliates for marketing or promotional purposes. Other data is shared only in the following circumstances:
- Connected integrations: When you connect third-party services (via OAuth or API keys), non-SMS application data is shared with those services as directed by you and your configured agents
- LLM providers: Agent reasoning requires processing non-SMS prompt and agent context through large language model providers under strict data processing agreements
- Infrastructure providers: We use cloud hosting, database, and sandbox providers to operate non-SMS portions of the Service, all under data processing agreements. SMS data is disclosed only to the delivery providers identified in SMS Messaging Privacy above
- Payment processing: Billing information is shared with Stripe for payment processing
- Legal requirements: We may disclose information if required by law, regulation, legal process, or governmental request
- Business transfers: In connection with a merger, acquisition, or sale of assets, non-SMS information may be transferred as part of that transaction. This does not authorize any use or sharing of mobile information or messaging consent for marketing or promotional purposes
6. Data Retention
We retain your information for as long as your account is active or as needed to provide the Service. Specifically:
- Account data is retained for the duration of your account and for 30 days after account deletion
- Agent execution logs are retained based on your organization's configured retention policy
- Usage and analytics data is retained in aggregated, anonymized form for up to 24 months
- Billing records are retained as required by applicable tax and financial regulations
You may request deletion of your data at any time (see Section 8 — Your Rights).
7. Data Security
We implement industry-standard security measures to protect your data:
- Encryption: Data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption
- Sandbox isolation: Each AI agent runs in an isolated execution environment, preventing cross-agent or cross-organization data access
- Access control: Role-based access control and granular permissions govern who can access data within your organization
- Credential storage: Integration credentials are encrypted and stored separately from application data
- Monitoring: We maintain comprehensive logging and monitoring to detect and respond to security incidents
For more details about our security practices, please visit our Security page.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
GDPR Rights (EEA Residents)
- Right of access: Request a copy of the personal data we hold about you
- Right to rectification: Request correction of inaccurate personal data
- Right to erasure: Request deletion of your personal data
- Right to data portability: Request your data in a structured, machine-readable format
- Right to restrict processing: Request limitation on how we process your data
- Right to object: Object to our processing of your personal data
CCPA Rights (California Residents)
- Right to know what personal information is collected, used, and shared
- Right to delete personal information
- Right to opt out of the sale of personal information (we do not sell your data)
- Right to non-discrimination for exercising your privacy rights
To exercise any of these rights, contact us at support@fastyr.ai. We will respond to your request within 30 days.
9. Cookies & Tracking
We use cookies and similar technologies to:
- Essential cookies: Maintain your session, authenticate your identity, and ensure the platform functions correctly
- Analytics cookies: Understand how you use the platform so we can improve performance and features
- Preference cookies: Remember your settings and preferences across sessions
You can manage cookie preferences through your browser settings. Disabling essential cookies may affect the functionality of the Service.
10. Children's Privacy
The Service is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16, we will take steps to delete that information promptly.
If you believe that a child under 16 has provided us with personal information, please contact us at support@fastyr.ai.
11. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws.
When we transfer data internationally, we implement appropriate safeguards including Standard Contractual Clauses (SCCs) approved by the European Commission, data processing agreements with all service providers, and technical measures such as encryption to protect your data regardless of where it is processed.
12. Changes to This Policy
We may update this Privacy Policy periodically. When we make material changes, we will notify you by email or through an in-app notification and update the "Last updated" date at the top of this page.
We encourage you to review this Privacy Policy regularly to stay informed about how we protect your data.
13. Contact
If you have any questions about this Privacy Policy or our data practices, please contact us: