Draft โ pending legal review
Privacy policy
This page explains, in plain English, what data Gentoo Logic collects when you use our products (Cairn, Pebble, the Researcher, the App Builder), how we use it, who we share it with, and what choices you have. If anything below is unclear, email pdauderis@rookeryventuresllc.com and we will walk you through it.
1. What we collect
Account information
When you sign up, we collect your name, email address, and the venture or organization you represent. If you pay us, our payment processor handles your card details โ we never see the full card number.
Email content (when you connect Gmail)
Pebble โ our inbox agent โ needs to read your email to triage it and draft replies. When you connect a Google account, we read message contents, subject lines, sender and recipient addresses, attachments, and labels. We only act inside the account you connected. We do not look at messages outside the connected account.
Calendar events (when you connect Google Calendar)
Pebble reads your calendar to schedule meetings and surface conflicts. We see event titles, times, attendees, and locations for the connected account.
Contacts (when you connect Google Contacts)
With your permission, we read your contacts to build a working address book for your venture. We see names, email addresses, phone numbers, and any notes you have written into the contact record.
Files (when you connect Google Drive)
Pebble can organize files it creates on your behalf โ proposals, briefs, meeting notes. We do not scan your full Drive unless you have explicitly enabled a Drive-scan feature; if you have, that scan is read-only and is described in the feature's consent screen.
OAuth tokens
When you connect a Google account we receive an access token and a refresh token. We store these encrypted at rest and use them only to perform the actions you have authorized. You can revoke them at any time at myaccount.google.com/permissions or by clicking Disconnect in the app.
Usage data
We collect basic logs about how the product is used โ pages visited, features clicked, errors hit. These logs help us fix bugs and improve the product. They contain device and browser information but not the contents of your messages or files.
Penn project-plan requests
You can generate a Penn starter plan without giving us contact details. If you ask for a review, we collect the pain point and choices you submitted, your generated starter plan, your name, email address, company if supplied, and your permission for Gentoo Logic to contact you about that request. We use this information only to evaluate and follow up on the project you asked us to review.
Prompts and research questions (Conny)
When you use Conny, we collect the email address you verify, the prompts and research questions you submit, the enhanced prompts and briefs we produce for you, and โ for paid briefs โ the delivery record. With the consent you give on the form, we keep these prompt-and-result records and analyze them in aggregate, anonymized form to improve Conny's prompt templates and model picks. We do not use them to train AI models, we never sell them, and we never mix them with any other customer's data.
2. How we use it
We use the data above to run the product you signed up for โ nothing more. Specifically:
- Reading and triaging your email so Pebble can draft replies in your voice.
- Reading your calendar so Pebble can schedule meetings and surface conflicts.
- Reading your contacts so Cairn can build a working address book.
- Organizing files Pebble created so they end up in the right folder.
- Showing you fleet activity, decisions, and analytics inside the cockpit.
- Sending you product emails (onboarding, feature changes, billing receipts).
- Running your Conny prompts through the AI models that produce your answer, and delivering the result to your email.
- Reviewing and responding to Penn project-plan requests you explicitly submit.
Marketing email and the Gentoo Logic list
Some actions โ like requesting a Conny access code โ add you to the Gentoo Logic email list, and say so right next to the button before you click. We send occasional product news, never more than a few emails a month. Every marketing email includes a one-click unsubscribe link, and unsubscribing never affects the transactional email you asked for (access codes, receipts, paid briefs). We never sell or share the list.
We do not sell your data. We do not use the contents of your messages, calendar, contacts, or files to train AI models โ neither our own models nor third-party models. The only data that ever leaves your tenant in an aggregated form is anonymous "what kind of decision was made and how it was handled" telemetry, and you can turn that off in Settings โ Privacy.
3. Who we share it with
We share data only with the service providers we need to run the product:
- Google โ when Pebble reads your inbox, sends a draft, or lists a calendar, those API calls go to Google. Google's privacy policy governs the data once it is in their hands.
- Anthropic โ Pebble and Cairn use Anthropic's Claude models to draft text and reason over decisions. We send Anthropic only the content needed for the immediate task, with prompts configured so that Anthropic does not retain the data for training.
- Multi-model AI providers (Conny) โ Conny's whole point is running your question through several independent models. Depending on the product you buy, your prompt goes to Anthropic, OpenAI, Google, and Perplexity (which also hosts the NVIDIA model we use). Each receives only your prompt for the immediate task โ never your account details.
- Resend โ our transactional email provider. Resend sees the recipient address and the content of the emails we send you (access codes, receipts, briefs) in order to deliver them.
- Google Cloud / Firebase โ our database and runtime live on Google Cloud. Your data is encrypted at rest in Firestore.
- Stripe (if you pay us) โ billing only. Stripe sees your card details; we see a receipt.
We do not share your data with advertisers, data brokers, or third-party analytics platforms. If we are ever required by law to disclose data (court order, subpoena), we will notify you unless the legal order prohibits notice.
4. How long we keep it
- Email, calendar, contact, and file data: kept as long as your account is connected. If you disconnect a Google account, we delete the cached copies within 90 days.
- OAuth tokens: deleted immediately when you disconnect or revoke access at myaccount.google.com/permissions.
- Account information: kept until you close your account. When you close, we delete personal data within 30 days and keep only the minimum records we are required to keep by law (invoices, tax records).
- Anonymized telemetry: kept indefinitely. Because it contains no tenant identifier, name, or content, we cannot link it back to you to delete it โ but it cannot identify you either.
- Logs: 30 days for application logs, 90 days for security logs.
- Conny prompts and briefs: kept while you have an account so your history keeps working. Email pdauderis@rookeryventuresllc.com to have your prompt history deleted; we delete it within 30 days.
- Email list membership: kept until you unsubscribe. Unsubscribes take effect immediately.
5. Your rights and choices
You have rights over your data. We honor these rights for everyone โ not only people in jurisdictions where the law requires it.
- Access โ download a copy of your tenant data from Settings โ Privacy โ Download my data.
- Correction โ edit your account profile from Settings โ Account.
- Deletion โ close your account from Settings โ Account โ Close, or email us at pdauderis@rookeryventuresllc.com.
- Portability โ the Download my data export is a JSON bundle you can take elsewhere.
- Disconnect Google โ click Disconnect in the app, or revoke access at myaccount.google.com/permissions. Either path stops Pebble from reading your account.
- Opt out of telemetry โ Settings โ Privacy โ "Help us improve" toggle.
- Object / restrict processing (GDPR) โ email us and we will pause processing of your data while we work it out.
- Do-not-sell / share (CCPA) โ we do not sell or share your personal information, so this is always on by default.
- Complain to a regulator โ if we have not handled your request well, you can complain to your local data protection authority. In the EU, that is your national DPA; in California, that is the CPPA.
To exercise any of these, email pdauderis@rookeryventuresllc.com. We will respond within 30 days.
6. Security
We do the basics carefully. OAuth tokens are encrypted at rest. Data in transit is encrypted with TLS. Database access is limited to the service accounts that need it, and every access is logged. Tenant data lives in tenant-scoped collections that the database rules prevent from being read across tenants โ the isolation is enforced in code, not just policy.
We are a small team and we do not pretend to be SOC 2 certified โ we are not. We will tell you what we are and are not. If a breach happens that affects your data, we will notify you within 72 hours of discovering it, with what happened, what data was involved, and what we are doing about it.
7. Children
Gentoo Logic is a B2B product. It is not designed for, marketed to, or intended for use by anyone under 16. We do not knowingly collect personal information from anyone under 16. If you believe we have, email us and we will delete it.
8. Changes to this policy
We update this policy as the product changes. When we make a material change โ anything that affects what we collect, how we use it, or who we share it with โ we will email everyone with an active account and update the "last updated" date at the top of this page. You will see the change in your dashboard before it takes effect.
9. Contact
Gentoo Logic is operated by Rookery Ventures LLC. For any privacy question, data request, or complaint, email pdauderis@rookeryventuresllc.com. For everything else, see gentoologic.com.