SUDHI privacy
Privacy, in plain language.
SUDHI keeps your workspace owner-scoped, asks before it sends selected context to a provider, and keeps provider credentials out of the client.
Data SUDHI collects
- Account and contact information: your Clerk account identifier and email for sign-in, owner isolation, account recovery, and support.
- Workspace content: goals, evidence, notes, work sessions, memories, plans, timeline receipts, and final reports for the workspace features you request.
- Attachments: a document, photo, video, or audio file only when you choose it as Board context or goal evidence. The selected file and any extracted content are user content.
- Voice data: voice audio, transcripts, and text you choose to submit for a goal-scoped response. Apple App Privacy calls this Audio Data and Other User Content.
- Optional connected-account data: Gmail profile, message metadata, and message content after you choose a Gmail access tier; Google Calendar event summaries only after you connect read-only Calendar access.
- Purchases and entitlements: Apple purchase and RevenueCat entitlement events used to restore access and enforce plan limits.
- Notification identifier: an Expo push token and notification preferences only after you grant notification permission. It is used to deliver the reminders you enable.
- Product and site analytics: SUDHI records a random session ID, page path without query strings, coarse device class, referrer host, and event timestamp. The same bounded events may be sent to Google Analytics 4 and PostHog. Microsoft Clarity provides web experience diagnostics; SUDHI masks the entire Workspace, Boardroom, and Mission Control body from its recordings. SUDHI does not send Board questions, files, account email, or URL query strings to these analytics tools.
Why and where data is sent
When you give current consent, SUDHI sends the minimum selected context needed for the feature through its server boundary. Clerk provides authentication; Convex stores the owner-scoped workspace; DeepSeek supports requested planning; Deepgram supports consented voice sessions; Google provides Gmail and Calendar APIs; Expo delivers requested notifications; and RevenueCat synchronizes store entitlements. SUDHI does not place these provider keys in the app.
SUDHI does not use advertising identifiers, sell personal information, or use data for cross-app tracking. Anonymous operational analytics are always active so SUDHI can measure reliability and user paths. Google Analytics 4, PostHog, and Microsoft Clarity process the bounded website telemetry under their own privacy terms; Clarity private-product surfaces are explicitly masked. Gmail and Calendar are optional. Gmail scopes are shown before authorization; Calendar is read-only; both can be revoked from Settings. Gmail actions that can send, trash, or otherwise change mail require a visible confirmation.
AI transparency and limits
The Board partners are AI personas, not people in a live meeting. Their guidance is generated from the question and context you choose to provide, and it can be wrong, incomplete, incorrect, or unsuitable for your situation. You remain responsible for checking facts, weighing trade-offs, and making every decision.
When the subject of your question needs up-to-date public facts, SUDHI automatically sends only the literal question to its public research provider and shows the resulting source links with the response. It does not send attachments, Mailroom items, Calendar entries, or other private context to that provider. SUDHI does not make decisions, send mail, alter a connected account, or take another external action without your specific confirmation. Do not use SUDHI for medical, legal, financial, emergency, diagnostic, therapeutic, or other professional advice.
Retention and deletion
SUDHI retains workspace data and operational entitlement or quota events while your account is active, or as needed for security, billing, support, and legal obligations. Provider processing and retention are also governed by the provider terms for the configured production service. You can export SUDHI data, revoke AI, Gmail, or Calendar consent, turn notifications off, and permanently delete the account from in-app Settings.
Account deletion removes owner-scoped SUDHI records, requests deletion of the authenticated account, revokes Gmail and Calendar access, and clears the local session. Apple subscription records and billing are managed by Apple separately.
Your controls
Use Settings to review consent, export data, revoke Gmail or Calendar, disable notifications, restore purchases, manage an Apple subscription, sign out, or delete the account. Use the public account-deletion page if you need the deletion steps before signing in.
Contact
For privacy questions, use the contact on the SUDHI help page. Do not send passwords, provider keys, OAuth codes, or Gmail message contents in a support request.