Effective Date: August 5, 2026 · Last Updated: August 5, 2026
BINOM AI, Inc. (“Binom AI,” “we,” “us,” or “our“) operates a marketplace of AI agents (Sales, Support, HR, Recruiting, Marketing, SMM, Legal Assistance, and other business roles), accessible through binomai.com and app.binomai.com (the “Service“).
This Privacy Policy explains what personal data we collect, from what sources, how we use, store, share, and protect it, and what rights you have — including where data is obtained through third-party APIs (Google, Meta) or through AI agents operating on behalf of our customers.
We distinguish between two roles: where you (the “Customer“) register and pay for the Service, we act as Data Controller. Where your AI agent processes documents, integrations, or conversations involving your own End Users, we act as a Data Processor, and you remain the Controller responsible for the lawful basis of that data.
If you do not agree with this Policy, please do not use the Service.
Account data. Name, email, billing details, and company information provided directly by the Customer at signup.
Technical & log data. IP address, browser type, ISP, timestamps, and referring/exit pages, collected automatically for security, analytics, and site administration.
Cookies. Used for session authentication and preferences. Non-essential cookies (analytics, marketing) are only set after opt-in consent via our cookie banner.
Documents uploaded directly by the Customer. Files (PDF, Word, Excel, PowerPoint, TXT, CSV) or links added manually to an agent’s knowledge base.
Google API data (YouTube, Google Drive, Google Docs, Google Calendar, Google Sheets, Gmail). See Section 4.1.
Notion API. See Section 4.2.
Meta API data (Facebook, Instagram). See Section 4.3.
CRM and other third-party integrations. Data the Customer connects via API, webhooks, or connectors, in the scope the Customer configures.
End User data & conversation history. Content of conversations between an AI agent and the Customer’s End Users, and any contact details an End User voluntarily provides during a chat. See Section 4.4.
We use collected data to:
We do not use data obtained via third-party APIs (Google, Meta), or provided by Customers or End Users, to train generalized machine-learning models serving other customers, and we do not use it for advertising, retargeting, or sale to third parties.
Some agents (notably HR/Recruiting) may analyze candidate data and produce recommendations affecting hiring decisions. We do not make decisions producing legal or similarly significant effects on individuals (within the meaning of GDPR Art. 22) without human involvement on the Customer’s side — the final decision (e.g., to hire) is made by the Customer, not by the Service. Where a Customer’s use case falls under high-risk AI system categories of the EU AI Act (e.g., employment and worker management, Annex III), the Customer acts as the deployer and is responsible for informing affected individuals; Binom AI provides the technical means to support the transparency obligation under AI Act Art. 50 (disclosure that a user is interacting with an AI system) in the agent’s interface.
We share data with a limited set of third parties, only to the extent necessary to provide the Service: cloud hosting providers, AI model providers (under contracts prohibiting use of Customer data to train the provider’s own models), payment processors, and analytics tools (aggregated/anonymized data). We disclose data to government authorities only where legally required. We do not sell personal data. A current list of subprocessors is available on request at support@binomai.com.
We use Google APIs only to provide functionality the Customer explicitly selects and enables by connecting their own Google account via OAuth 2.0.
Binom AI’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We confirm that:
Scopes used:
https://www.googleapis.com/auth/youtube.force-ssl
https://www.googleapis.com/auth/drive.readonly
YouTube API Services. By connecting YouTube, you agree to the YouTube Terms of Service and Google Privacy Policy. We access video metadata, transcripts, comments, and public commenter information to let the agent analyze discussions and prepare or publish replies on the Customer’s behalf. Data is encrypted and deleted within 30 days of disconnection or account deletion; cached copies are not retained longer than permitted by YouTube API cache headers. Access can be revoked anytime via the Binom AI dashboard or myaccount.google.com/permissions.
Google Drive, Google Docs, Google Sheets API. Access is limited to the specific folder/files the Customer selects — never the entire Drive. Content is used solely as the knowledge base for that Customer’s agent. Indexed content is encrypted and deleted within 30 days of disconnection or account deletion. Access can be revoked anytime via the Binom AI dashboard or myaccount.google.com/permissions.
Google Calendar API. We create a separate calendar in the Customer’s Google account for appointments booked through the agent and work only inside it — the calendar.app.created scope gives us no access to the Customer’s other calendars. To prevent double-booking we additionally read free/busy intervals through calendar.freebusy, which returns only the periods marked busy and never event titles, descriptions, guests, or any other content of those events. For each appointment we store the start and end time, the calendar and event identifiers, and the details the End User provides when booking: name, email, phone, and any comment they add. Disconnecting the integration deletes the stored credentials and revokes our access to the Google account. The calendar itself and the appointments in it remain in the Customer’s Google account — they are real meetings with real clients, and removing them would erase somebody’s schedule; the Customer can view, share, or delete that calendar in Google at any time. Booking records held on our side are retained while the Customer’s account exists and are deleted on request at support@binomai.com.
Gmail API. Access is limited to the single mailbox the Customer connects — one mailbox per organization, and never other mailboxes on the Google account. We read messages that arrive in that mailbox’s inbox, including subject, body, sender and recipient headers, and attachments, so that the agent can analyze incoming inquiries; we send replies in the same thread on the Customer’s behalf; and we mark answered messages as read. The gmail.modify scope is required because the feature both reads incoming mail and sends replies and updates message state; a read-only scope cannot deliver it.
Message subject and body, together with text extracted from attachments, are stored as conversation records in the Customer’s own account so that the agent can keep context across an email thread. Attachment files themselves are not retained — only the text extracted from them. This content is used solely to operate that Customer’s own agent. Disconnecting the mailbox deletes those conversations along with the stored credentials and revokes our access to the Google account; the same content is deleted on account deletion. Gmail data is never used for advertising or retargeting, never used to train generalized AI/ML models beyond the requesting Customer’s own agent, and never sold or transferred to data brokers. Access can be revoked at any time via the Binom AI dashboard or myaccount.google.com/permissions.
Where a Customer connects a Notion workspace, access is granted through Notion’s own OAuth screen, on which the Customer selects which pages and databases we may read. Within that grant the Customer then chooses in Binom AI the specific pages or databases to import.
We read the content, structure, and titles of the selected pages, databases, and their child blocks, together with the identity of the connected workspace, and store the rendered content as documents in that Customer’s knowledge base so the agent can answer from it. We subscribe to Notion’s change notifications, verified by signature, so that edits made in Notion are reflected in the knowledge base; the notifications themselves carry no page content.
Notion content is used solely as the knowledge base for that Customer’s own agent. It is never used for advertising, never used to train generalized AI/ML models beyond the requesting Customer’s own agent, and never sold or transferred to data brokers. Disconnecting the workspace deletes the imported documents and revokes our access token; the pages in Notion itself are not modified or deleted.
Where a Customer connects a Facebook Page, Instagram account, or Meta Business account, we access data through the Meta Graph API only after explicit authorization and within the scope the Customer approves on Meta’s permission screen.
Our use and transfer of information received via Meta APIs adheres to the Meta Platform Terms and Meta Developer Policies.
We access posts and their metadata, comments and Messenger/Instagram Direct messages, public commenter/sender information, and basic page statistics, within approved permissions, to let the agent analyze inquiries and prepare or publish replies on the Customer’s behalf. We never use Meta data for third-party advertising, to train generalized AI models beyond the requesting Customer’s own agent, or to transfer data to data brokers. Data is encrypted and deleted within 30 days of disconnection. Access can be revoked anytime via the Binom AI dashboard or the Business Integrations settings of the Customer’s Facebook/Instagram account.
For data provided by a Customer’s End Users during a chat with an AI agent, Binom AI acts as Processor and the Customer as Controller. The Customer is responsible for its own lawful basis to collect this data and for disclosing to End Users that they are interacting with an AI agent, where required by applicable law (see Section 3.1).
Conversation data is used only to fulfill the End User’s request, maintain conversational context, display history to the Customer in the dashboard, and improve that specific Customer’s agent — never to train models serving other customers.
Conversation history is retained for the life of the Customer’s account and up to 12 months after closure, unless a longer period is legally required. Customers may request export or deletion via the dashboard or support@binomai.com.
Data received through CRM or other connected integrations follows the same Processor/Controller framework described above.
We retain personal data only as long as necessary for the purposes described in this Policy, or as required by law, to resolve disputes, and to enforce our agreements. Retention periods for specific data categories are set out in Section 4.
Security. We apply technical and organizational measures including encryption in transit (TLS/HTTPS) and at rest, role-based access controls, and access logging for sensitive data. In the event of a security incident affecting personal data, we will notify affected Customers without undue delay and within the timeframe required by applicable law (generally no later than 72 hours after becoming aware of the incident, where GDPR applies), and support Customers in meeting their own controller obligations.
International transfers. BINOM AI, Inc. is incorporated in the United States. Where we transfer personal data of individuals in the EEA, UK, or Switzerland outside those jurisdictions, we rely on recognized transfer mechanisms, including Standard Contractual Clauses (SCCs) approved by the European Commission or another applicable adequacy mechanism. A copy of applicable contractual terms is available on request at support@binomai.com.
EU Representative (GDPR Art. 27):
Digital Forest OÜ
Registry code: 14207360
Kaupmehe tn 7-120, Kesklinna linnaosa, Tallinn, Harju maakond, 10114, Estonia
Email: support+dfOU@binomai.com
Digital Forest OÜ has been designated as BINOM AI, Inc.’s representative in the European Union for matters relating to the processing of personal data of individuals located in the EU, pursuant to GDPR Art. 27, under a separate written mandate between the parties.
Data Processing Agreement. Processing where the Customer acts as Controller and Binom AI as Processor (End User data, integration content, conversation history) is governed by a separate Data Processing Agreement (DPA), available on request at support@binomai.com, covering subprocessors, incident notification, deletion upon termination, and audit rights.
Cookie & children’s data. The Service is not directed at individuals under 16 (or the applicable age of digital consent in your country, but never below 13). We do not knowingly collect personal data from such individuals; contact support@binomai.com if you believe this has occurred.
You have the right to access, rectify, erase, restrict, or port your data; to object to processing; to withdraw consent at any time; and to lodge a complaint with your local data protection supervisory authority.
You have the right to know what categories of personal information we collect, use, and disclose; to request deletion; to opt out of the sale or sharing of personal information (Binom AI does not sell or share personal information as defined by CCPA/CPRA); and to equal service regardless of exercising these rights.
We may update this Policy as the Service evolves or as law requires. If a change affects how previously collected Google/Meta API data or other End User data is used, we will notify the Customer and, where applicable, request renewed consent before using the data for a new purpose.
BINOM AI, Inc.
1111B S Governors Ave STE 20321, Dover, DE 19904, USA
Email: support@binomai.com