Effective: April 2026
Privacy Policy
Social Capital ("we," "our," or "us") operates socialcapitalcrm.com and the Attache AI assistant. This Privacy Policy explains how we collect, use, and protect your information.
1. Information We Collect
We collect the following types of information:
- Name, email address, and phone number you provide during registration
- Professional contact data you store in Social Capital, including names, companies, job titles, emails, and phone numbers
- Gmail data, with your permission, including email metadata for relationship tracking and draft creation
- Google Calendar data, with your permission, for meeting context and preparation
- SMS message content when you communicate with the Attache assistant
- Business card photos you send to Attache for contact capture
- Relationship notes, commitments, and context you provide about your connections
2. How We Use Your Information
We use your information to:
- Provide the Attache AI assistant and relationship intelligence features
- Send SMS briefings, relationship reminders, and follow-up suggestions
- Generate personalized email drafts in your Gmail account
- Surface relationship insights, meeting context, and networking opportunities
- Track commitments and help you follow through on your promises
- Improve and develop our services
3. SMS Messaging
When you register for Social Capital and provide your phone number, you consent to receive SMS messages from Attache, our AI assistant. Important information about SMS:
- Message frequency varies based on your activity and preferences
- Message and data rates may apply depending on your wireless carrier
- Reply STOP at any time to unsubscribe from SMS messages
- Reply HELP to receive support information
4. Data Sharing
We do not sell your personal data.
We share data only with service providers necessary to operate the platform:
- Anthropic - AI processing for Attache conversations and analysis
- Twilio - SMS messaging infrastructure
- Supabase - Database and authentication (hosted on AWS)
- Google - Gmail and Calendar API integration with your explicit permission
These providers are contractually bound to protect your data and use it only to provide services on our behalf.
5. Data Security
We implement industry-standard security practices to protect your information:
- All data transmission is encrypted using TLS/SSL
- User data is isolated and never accessible by other users
- Row-level security policies ensure you can only access your own data
- Regular security audits and updates
- Secure cloud storage for business card images
6. Google User Data
Social Capital requests access to the following Google services with your explicit permission:
- gmail.readonly: To read email history and extract commitments you made to contacts (e.g., "I'll send you that article"), track interaction frequency, and build relationship context
- gmail.compose: To create AI-generated draft emails in your Gmail Drafts folder for follow-ups and introductions, which you review and send yourself
- calendar.readonly: To display upcoming meetings and provide meeting preparation context including attendee relationship history
- drive.readonly: To access meeting transcripts created by Google Meet or third-party notetakers (such as Otter.ai or Fireflies.ai) and extract action items and commitments from your meetings
We do NOT use Google user data for:
- Advertising, marketing, or promotional purposes
- Training artificial intelligence or machine learning models
- Selling or providing to data brokers or information resellers
- Credit determinations, lending decisions, or insurance underwriting
- Any purpose other than providing Social Capital's relationship management features
AI/ML Compliance Statement:
Social Capital uses AI (Anthropic's Claude API) to provide personalized features such as commitment extraction, email draft generation, and meeting note summarization. This AI processing is performed solely to provide personalized features for your individual use - not to train any AI models.
We do not use, transfer, or sell Google user data to create, train, or improve any generalized machine learning or artificial intelligence model. Per Anthropic's API Terms of Service, data sent through their API is not used to train their models. Your Google data is processed in real-time to deliver the requested feature and is not retained by the AI provider for model training or any other purpose.
We do not transfer Google user data to any third parties except as necessary to provide the service (such as AI processing). We never transfer Google user data for advertising, data brokering, or any purpose unrelated to providing Social Capital's features.
Limited Use Disclosure:
Social Capital's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use Google data to provide and improve user-facing features of Social Capital
- We do not transfer Google data to third parties except as necessary to provide the service, with user consent, or as required by law
- We do not use Google data for serving advertisements
- We do not allow humans to read Google user data except with user consent for support, for security purposes, or to comply with law
You can revoke Social Capital's access to your Google account at any time from your Google Account settings at myaccount.google.com/permissions, or by removing linked accounts within the Social Capital app.
7. Data Retention
We retain your data for as long as your account is active and as needed to provide our services:
- Contact data and relationship notes: Retained while your account is active
- SMS conversation history with Attache: Retained for 12 months
- Business card images: Retained while the associated contact exists in your account
- Email drafts created via Social Capital: Retained until sent or deleted by you
Google User Data Retention:
- Email metadata (sender, recipient, date, subject): Stored for up to 90 days to calculate relationship metrics
- Email body content: Processed in real-time for commitment extraction, not permanently stored
- Calendar event data: Processed in real-time for meeting prep, not permanently stored
- Meeting transcript content: Processed in real-time for commitment extraction, not permanently stored
- Extracted commitments and action items: Stored as user data until marked complete or deleted
When you revoke Social Capital's access to your Google account (via myaccount.google.com/permissions or within the app), we immediately stop accessing your Google data. Any stored metadata derived from Google services is deleted within 30 days. Commitments and relationship notes you created remain unless you explicitly delete them.
When you delete your Social Capital account entirely, all associated data is permanently removed from our systems within 30 days, including contacts, notes, commitments, SMS history, stored images, and any Google-derived metadata.
8. Your Rights
You have the right to access, correct, or delete your personal data. To request deletion of your account and all associated data, contact us at:
hello@socialcapitalcrm.com
Upon receiving a deletion request, we will remove your account, contact data, relationship notes, SMS history, and stored images within 30 days.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email or SMS before the changes take effect. The "Effective" date at the top of this page indicates when the policy was last updated.
Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
hello@socialcapitalcrm.com