Legal

Privacy Policy

Last updated: July 26, 2026

Gunimi (“we”, “our”, “us”) operates an AI-first workspace operating system for business teams. This Privacy Policy explains what data we collect, how we use it, and your rights as a user. By creating an account you agree to the practices described here.

Gunimi is currently in Open Alpha. Access is controlled — each workspace is personally reviewed and approved. Features, data practices, and this policy may evolve. We will notify registered users of material changes by email.

1. Data We Collect

Account Information

When you register, we collect your email address, full name, and any profile information you choose to provide (job title, avatar).

Workspace Data

All content you create inside Gunimi — companies, contacts, deals, notes, tasks, and activity records — is stored in your workspace and associated with your account.

Usage Activity

We record workspace activity events (e.g. “deal created”, “task completed”) to power your activity feed and workspace analytics.

Technical Data

Standard server logs including IP addresses, browser type, and request timestamps for security and debugging purposes.

2. How We Use Your Data

  • To provide and operate the Gunimi platform
  • To authenticate your identity and secure your workspace
  • To power AI features: note content may be sent to AI model providers to generate summaries and insights (see Section 4)
  • To send transactional emails (workspace invites, verification) via Postmark
  • To improve the product during the alpha period based on usage patterns
  • We do not sell your data. We do not use your data for advertising.

3. Data Storage & Security

Your data is stored in Supabase, a managed PostgreSQL platform. Data may be stored in the EU depending on your region. We enforce row-level security (RLS) so that workspace data is only accessible to authenticated members of that workspace.

Authentication is handled by Supabase Auth using email and password. Passwords are never stored in plain text. All connections are encrypted via TLS 1.3.

Alpha note: During Open Alpha, workspace data may be reset, migrated, or deleted without advance notice as we iterate on the product. We recommend not storing business-critical information in Gunimi during this phase.

4. AI & Third-Party Services

AI Model Providers

When you use AI features, the relevant content is sent to third-party AI model APIs for processing. We have data processing agreements that prohibit use of your data for model training. We do not send credentials or payment information to AI providers.

Supabase

Database, authentication, and real-time features are provided by Supabase, Inc.

Postmark

Transactional emails are sent via Postmark. Email addresses are shared with Postmark only for delivery purposes.

Upstash Redis

User IDs are stored temporarily in Upstash Redis for rate limiting purposes. No personal data beyond user ID is stored.

5. Your Rights

Depending on your jurisdiction, you may have rights including:

  • Access to the personal data we hold about you
  • Correction of inaccurate data
  • Deletion of your account and associated data
  • Export of your workspace data

To exercise any of these rights, email support@gunimi.com. We will respond within 30 days.

6. Data Retention

We retain your account and workspace data for as long as your account is active. If you request account deletion, we will remove your personal data within 30 days, except where we are required to retain it by law.

7. Cookies

Gunimi uses session cookies provided by Supabase Auth to keep you logged in. These are strictly necessary for the service to function and do not track you across third-party websites. See our Cookie Policy for full details.

8. Google API Services

Limited Use Disclosure

Gunimi’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

When you connect a Google account to Gunimi, we may access the following data depending on the integrations you enable:

  • Gmail: read email headers and message content to surface communication context within your workspace
  • Google Calendar: read and create calendar events to support scheduling and meeting preparation features
  • Google profile: your name and email address for authentication and workspace identity

Google user data is used exclusively to provide the features you request within your workspace. We do not:

  • Transfer Google user data to third parties except as necessary to operate and improve our service
  • Use Google user data for advertising purposes
  • Allow humans to read your Google data unless you have given explicit consent, or it is required for security purposes
  • Use Google user data to train AI or machine learning models

9. Contact

For privacy questions, data requests, or concerns, contact us at support@gunimi.com.