Information you provide
We process account details, profile preferences, conversations, files, tasks, support reports, and other content you choose to place in Cyperion. Payment card information is handled by Stripe and is not stored by Cyperion.
Connected services
Connections are optional and use provider OAuth authorization. Depending on the features you enable, Cyperion may read Gmail, Google Calendar, Google Drive metadata, Outlook mail, Microsoft calendars, OneDrive, SharePoint, Teams, invited Slack channels, or Salesforce CRM records. Cyperion requests read-only access by default and does not sell connected-service data.
Access tokens are encrypted at rest. Connected content is used to answer your requests, populate your workspace, and create summaries or daily briefs. Provider data may be sent to an AI service only when needed to perform the feature you requested.
Google API data
Cyperion’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is not used to train general-purpose AI models, sold, or used for advertising.
How information is used
- Provide, secure, support, and improve Cyperion.
- Authenticate users, enforce plan limits, and process subscriptions.
- Generate user-requested answers, summaries, plans, and workspace context.
- Detect abuse, diagnose failures, and meet legal obligations.
Service providers
Cyperion uses infrastructure and service providers that may include Supabase, Vercel, OpenAI, Stripe, Resend, Sentry, Upstash, and the integration provider you authorize. They process information only to provide their contracted services and under their own applicable terms.
Retention and control
We retain account information while your account is active and as needed for security, billing, dispute resolution, and legal compliance. You may disconnect an integration at any time, delete individual workspace content, or delete your Cyperion account. Disconnecting deletes Cyperion’s stored authorization for that provider; provider-side data remains under your provider account.
Security and international processing
We use encryption in transit, encrypted integration credentials, access controls, audit records, and least-privilege permissions. No system is completely secure. Information may be processed in the United States and other locations where our providers operate.
Your requests
To request access, correction, export, or deletion, use account settings or follow the data deletion instructions. Privacy questions can be submitted through the Cyperion Support Center.