Privacy Policy
This Privacy Policy describes how Teamlocus AI Studio (“we,” “us,” or “our”), operated by Deep Foods Inc., collects, uses, stores, and shares information when you use our websites, applications, and related services (collectively, the “Service”). By using the Service, you acknowledge this policy.
Google API Limited Use disclosure. Teamlocus AI Studio's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
1. Who we are and what the Service does
Teamlocus AI Studio is an organization-scoped AI workspace. After you sign in with your Teamlocus account, you can chat with AI models, work with documents, generate images and video, schedule workflows, and optionally connect workplace apps such as Gmail, Google Drive, Google Calendar, Google Meet, and TLChat. The AI can then help you search, summarize, draft, and take actions you approve.
The Service is intended for business users of Teamlocus organizations. It is not a consumer social network and is not directed at children.
2. Information we collect
We collect the following categories of information, depending on how you and your organization use the Service:
- Account and authentication data. Identifiers supplied by Teamlocus sign-in (for example username, display name, user ID, organization ID, and session or JWT tokens we issue after a successful login). We do not receive your Teamlocus password after authentication completes.
- Chat and AI interaction data. Prompts, attachments, AI responses, conversation titles, selected provider/model, custom agent instructions, timestamps, and related metadata.
- Files and media. Documents, images, and other files you upload, plus images and videos generated in the Service.
- Connected Google account data (only if you choose to connect Google). See Section 6.
- TLChat data (only if you connect TLChat). Conversation lists, messages, and related metadata needed to fulfill your requests.
- Technical and usage data. IP address, browser or device type, timestamps, diagnostic logs, and security events.
- Audit records. Server-side logs of important events such as sign-in, tool use, uploads, approvals, and app connect/disconnect, for security and organizational compliance.
- Support communications. Information you send when you contact us.
3. How we collect information
- Directly from you when you sign in, send messages, upload files, configure agents or workflows, or connect an app.
- Automatically when you use the Service (server logs, reliability monitoring, and security monitoring).
- From Teamlocus identity services when you authenticate.
- From Google APIs after you grant OAuth consent, and only for the scopes you authorize.
- From TLChat when you connect that integration.
4. How we use information
We use the information above to:
- Provide, operate, and maintain the Service, including routing requests to the AI model you select.
- Store, retrieve, and display your conversations, projects, agents, workflows, and media.
- Connect optional Google and TLChat integrations and run tools you request, including actions that require your explicit in-app approval.
- Authenticate you, protect accounts, detect abuse, and enforce our terms.
- Troubleshoot errors, monitor performance, and improve reliability and security.
- Comply with legal obligations and respond to lawful requests.
- Communicate with you about the Service or support requests.
We do not sell your personal information. We do not use Google user data or chat content to train our own foundation models. We do not use Google user data for advertising, retargeting, or credit decisions.
5. Third-party AI providers
When you send a message, we transmit the content needed to fulfill that request to the third-party provider that operates the model you selected. Without that transmission, the model cannot respond.
5.1 What may be sent
- Your current prompt, including attachments you include.
- Prior messages in the same conversation that are needed as context.
- Google or TLChat content that a tool retrieved because you asked the AI to use it (for example, an email thread you asked to summarize).
- Technical parameters such as model name and token limits.
Do not submit government ID numbers, payment card numbers, health information, or other highly sensitive data unless you accept that it may be processed by the provider you selected.
5.2 Who may receive it
- OpenAI, LLC (OpenAI API models)
- Google LLC (Gemini and related Google AI services)
- Amazon Web Services, Inc. (Amazon Bedrock, which may host Anthropic Claude and other foundation models according to your organization's configuration)
- ElevenLabs (only if you use the optional voice agent feature)
Each provider processes data under its own privacy policy and terms. Their use may include generating the response, safety filtering, fraud prevention, and legal compliance. Review your organization's enterprise agreements if you require zero-retention or data-processing addenda.
5.3 When sharing happens
Personal data, including Google user data, is sent to an AI provider only when you (or a workflow/agent you configured) take a deliberate action that requires it — for example sending a chat message, running an agent, or allowing a scheduled task to run. If you do not connect Google apps, we do not access your Gmail, Drive, Calendar, or Meet data.
6. Google user data (OAuth integrations)
Connecting Gmail, Google Drive, Google Calendar, or Google Meet is optional. Teamlocus AI Studio uses a single Google OAuth client so you can grant access from the in-app Apps screen. We request only the scopes required for the features described below. We do not request Google passwords. Access tokens and refresh tokens are stored encrypted at rest, scoped to your user and organization, and used only to call Google APIs on your behalf.
6.1 Google data we access and why
| Google service | Scopes | Data accessed | How we use it |
|---|---|---|---|
| Sign-in identity | openid, userinfo.email, userinfo.profile |
Google account email and basic profile | Show which Google account is connected and keep the connection associated with your Teamlocus user. |
| Gmail | https://www.googleapis.com/auth/gmail.modify |
Email threads, messages, labels, and drafts that you ask the AI to work with | Search and summarize mail, read a thread you specify, create drafts for you to review, and apply or remove labels. The app does not send email automatically. Sensitive send/write-style actions require your explicit in-app approval where the product exposes them. |
| Google Drive | drive.readonly, drive.file |
File names, metadata, permissions, and file content you ask to read; files the app creates | Search and read files so the AI can answer questions from your documents; create or copy files you request, with approval for write actions. |
| Google Calendar | https://www.googleapis.com/auth/calendar |
Calendars, events, and availability | List upcoming events, check free/busy time, and create, update, delete, or respond to events you request, with approval for changes. |
| Google Meet | meetings.space.created, meetings.space.readonly |
Meet spaces, conference records, and participants | Create Meet spaces, schedule meetings with Meet links (via Calendar), and look up conference records you request. We do not join meetings on your behalf. |
Gmail gmail.modify is requested because the product both reads mail and writes drafts/labels. We do not use this scope to export your mailbox, mine it for advertising, or grant unrelated third parties access to it.
6.2 How Google user data is stored
- OAuth tokens (access token, refresh token, expiry, granted scopes) are encrypted and stored so the Service can call Google APIs until you disconnect.
- Connected account email is stored so the UI can show which Google account is linked.
- Google content (email bodies, Drive file contents, calendar event details, Meet records) is fetched on demand when you ask the AI to use it. We do not bulk-sync or permanently archive your entire mailbox, Drive, or calendar.
- Snippets of Google content that appear in a chat, agent run, or workflow result become part of that conversation record, which is stored so you can reopen it later. Those records are scoped to your user and organization.
6.3 How Google user data is shared
Google user data is shared only as needed to operate the feature you requested:
- Third-party AI providers listed in Section 5, solely to generate the response or take the tool action you initiated. This is a transfer to provide user-facing features in the application UI, not a sale of data.
- Infrastructure processors that host the Service (for example our database and cloud hosting), under confidentiality and security obligations.
- Your organization administrators, to the extent audit logs or organizational policy require it.
- Law enforcement or regulators when we believe disclosure is required by law.
We do not transfer Google user data to advertising platforms, data brokers, or information resellers. We do not use Google user data to serve ads.
6.4 Limited Use commitments
In addition to the disclosure at the top of this policy, we commit that:
- We use Google user data only to provide or improve user-facing features that are prominent in Teamlocus AI Studio (chat, agents, workflows, and the Apps integrations listed above).
- We do not allow humans to read Google user data unless: (a) you give affirmative agreement to view specific messages, files, or other data (for example a support request you initiate); (b) it is necessary for security, debugging, or abuse investigation; (c) it is necessary to comply with law; or (d) the data is aggregated and used for internal operations in accordance with law.
- We require employees, contractors, and successors to comply with these restrictions.
- We do not use Google user data for serving advertisements, determining credit-worthiness, or lending.
6.5 Disconnecting Google and deleting Google user data
You may revoke Teamlocus AI Studio's access at any time:
- In the Service, open App, select the connected Google app, and disconnect. We revoke the Google token when possible and delete the stored encrypted credentials for that app.
- Independently, visit Google Account → Third-party access and remove Teamlocus AI Studio / the OAuth client.
To request deletion of conversation records that contain Google user data, delete the relevant chats in the product or email support@teamlocus.com. We will delete or anonymize retained copies except where we must keep records for legal, security, or backup purposes for a limited period.
7. Sharing beyond AI and Google processors
We may share information with service providers that help us host, secure, or operate the Service; with authorities when required by law or to protect rights and safety; and in a merger, acquisition, or sale of assets, subject to notices where required.
8. Retention
- Account and workspace data is retained for as long as your Teamlocus organization uses the Service.
- Conversations, uploads, agents, workflows, and media are retained until you or your organization delete them, plus a limited backup window.
- Google OAuth credentials are retained until you disconnect the app or your account is removed.
- Audit logs may be retained longer as required for security and compliance.
9. Security
We use administrative, technical, and organizational measures designed to protect personal data, including TLS in transit, encrypted storage of Google OAuth tokens, organization- and user-scoped access controls, and approval gates for side-effecting tool actions. No method of transmission or storage is completely secure.
10. International transfers
We and our providers may process data in the United States and other countries where we or they operate. Those countries may have different data protection laws than your country of residence.
11. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or export personal data, or to object to or restrict certain processing. You may also have the right to lodge a complaint with a supervisory authority. To exercise rights, contact support@teamlocus.com. Organization-managed accounts may need to go through your Teamlocus administrator.
You can also: sign out; disconnect Google or TLChat; delete conversations; and choose not to send sensitive content to AI models.
12. Children
The Service is not directed to children under 13 (or the age of digital consent in your region). We do not knowingly collect personal information from children in violation of applicable law, including COPPA. Child-directed use of Google Sign-In / Google API Services is not permitted.
13. Changes to this policy
We may update this policy from time to time. We will post the revised policy on this page and update the “Last updated” date. For material changes to how we use Google user data, we will provide additional notice and, where required, prompt you to consent before using that data in a new way.
14. Contact
Questions about this policy, Google user data, or deletion requests:
- Email: support@teamlocus.com
- Operator: Deep Foods Inc., 1090 Springfield Road, Union, NJ 07083, United States