Last updated: May 2026 · VisionAI Workspace Beta
Your Orbit content lives in your Google Drive, which is the system of record. VisionAI Workspace reads and writes to it while you're using the platform, keeping only a short-lived cache (auto-cleared within 24 hours) plus account/usage data to run the service. Your actual content stays in your Drive, under your control.
VisionAI Workspace is designed so that you own your data. We collect the minimum necessary to provide the service:
We use the data we collect solely to operate the VisionAI Workspace platform:
When you sign in, VisionAI Workspace requests OAuth permission to access Google Sheets, Google Drive (file creation only), and Google Docs on your behalf. This access is used exclusively to:
Important: If you revoke VisionAI Workspace's Google Drive access at any time, the platform will be unable to reach your workspace and will stop functioning until access is restored. Your data in Google Drive remains yours and is unaffected.
VisionAI Workspace uses a multi-provider AI architecture designed to expand over time. When you submit a task, your prompt content is temporarily processed by one of the following AI providers to generate a response — exactly which one varies by request:
VisionAI Workspace does not retain copies of your prompts or AI outputs outside of your Google Sheet. However, each third-party AI provider may temporarily log or process your inputs according to their own privacy policies. We recommend reviewing the individual privacy policies of these providers if you have concerns about how they handle data.
To send transactional and account emails (such as waitlist confirmations, notifications, and invitations), VisionAI Workspace uses Brevo, a third-party email delivery provider. When we send you email, your email address and the message content are processed by Brevo solely to deliver that email. Brevo processes this data according to its own privacy policy. We do not use Brevo for advertising.
How it is protected. All traffic between your browser, this platform and Google's APIs runs over HTTPS/TLS. Your Google OAuth tokens are stored in our Supabase Postgres database, encrypted at rest, and are read only by server-side code — they are never sent to your browser and never appear in client-side JavaScript. Account records are protected by row-level security so one account cannot read another's, and the elevated key used for server-side work exists only in server environment variables, never in the app bundle.
The narrowest scopes that work. Drive access is drive.file, which reaches only files this application itself created for you — not the rest of your Drive. Calendar access is calendar.app.created, which reaches only a secondary calendar this application itself created; it cannot see your primary calendar or any event this app did not write. Either can be revoked at any time from your Google Account settings.
Limited Use. VisionAI Workspace's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
We do not train models on your data. We do not use Google user data — raw, aggregated, anonymized or derived — to create, train, or improve any machine learning or artificial intelligence model of our own, and we never sell it or transfer it for advertising.
One open question, stated plainly rather than left out. Content is processed by third-party AI providers to carry out your requests, and those providers set their own terms. Google's Gemini API states that on its free tier, submitted content may be used to improve Google's products and models. We have asked Google directly whether routing content that originated in your Google Sheet through their own Gemini API falls within the Limited Use requirements, and we will update this policy with their answer. If it does not, we will either move that integration to a paid tier — where Google states it does not use submitted content to improve its products — or remove it.
Which AI services see your content, and when. Content is sent to an AI provider only to carry out something you asked for — running a worker on a task, generating an image, summarizing or drafting an email — and only for as long as that request takes. The providers currently used are Groq, Google Gemini, Mistral AI, OpenRouter (a gateway that routes to other providers), Cloudflare Workers AI and Hugging Face. We do not operate self-hosted or offline models; each of these is reached over an API. The Gmail integration is presently limited to the platform owner's own account and is not available to other users.
Authentication is handled via Google OAuth and managed by Supabase, our auth infrastructure provider. Supabase stores your OAuth tokens securely to maintain session continuity. VisionAI Workspace does not have access to your Google password or any credentials beyond the OAuth tokens required to operate your workspace. Sessions are tied to your active use of the platform.
Cookies: VisionAI Workspace uses essential session cookies only. These cookies are required for authentication and to keep you logged in during your session. We do not use advertising cookies, tracking pixels, or any third-party analytics cookies. Essential cookies cannot be disabled without breaking core platform functionality.
The current beta version of VisionAI Workspace is free to use and does not require any payment information. When paid Pro features are introduced, all billing will be handled by a secure third-party payment processor. VisionAI Workspace will never store your credit card number, bank details, or any payment credentials directly. The identity of the payment processor will be disclosed at the time paid features are launched.
Because your workspace data lives in your own Google Drive, it persists as long as you choose to keep it there. Beyond your account info (name, email, OAuth tokens via Supabase), we also retain operational data needed to run the platform — usage and reliability logs, scheduling and notification records, payment history for any pack purchases, and short-lived performance caches of your workspace content (auto-cleared within 24 hours). If you request account deletion, we remove this data from Supabase. Your Google Sheet and any files in your Drive are yours and must be deleted by you directly.
You have the right to:
VisionAI Workspace is intended for adults and is not directed at anyone under the age of 18. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us with personal data, please contact us and we will take steps to remove it.
As VisionAI Workspace grows beyond beta, this privacy policy will be updated to reflect new features, providers, and legal requirements. We will notify active users of material changes via email or an in-app notice. Continued use of the platform after changes constitutes acceptance of the updated policy.
Whose Drive shared content is written to. A workspace can have more than one person in it: an owner, and the crew they invite. The owner’s Google Drive is the system of record for the whole workspace. When a crew member uploads a file or an image to a conversation, or an AI worker produces an artifact for one of the workspace’s orbits, that content is written to the owner’s Drive under the owner’s Google account — never to the crew member’s own Drive. One consequence is worth stating plainly rather than leaving to be discovered: because attachments are stored in the owner’s Drive, a workspace owner may be able to see a file that was attached to a conversation they are not a member of, even though the conversation itself is not readable by them.
What we store for messaging. Conversation membership, message text, attachment references, emoji reactions, read state and your per-conversation notification preference are stored in our Supabase Postgres database rather than in Google Drive. Row-level security restricts reads to the members of a conversation. Typing indicators and who is currently viewing a conversation are broadcast live between connected clients and are not stored at all.
Who can see a message. An orbit’s crew room is readable by everyone the owner has granted that orbit to, and its membership is kept in step with that grant automatically. A direct message is readable only by its participants, and can only be started between people who share at least one orbit — with the exception of the workspace owner, who is reachable by anyone in their workspace and may group any of their crew together.
Notifications carry part of the message. When a message needs to reach somebody who is not looking at the app, the notification contains the sender’s name, the orbit’s name or an indication that it is a direct message, and the first 90 characters of the message body. Depending on your settings that is delivered in-app, by email through Brevo, and as a web push notification through your browser or operating system’s push service. If you would rather message content did not leave the app that way, set a conversation to Quiet or Muted using the bell in its header.
Messages are not sent to AI providers. Conversations between people in a workspace are not routed to any AI model. Content reaches an AI provider only when somebody explicitly runs a worker on a task, as described in Section 4.
Deleting, and leaving a workspace. Deleting a message clears its text and its attachment references from our database; the underlying file already written to the workspace owner’s Drive is not removed by that action and has to be deleted from Drive by its owner. If an owner withdraws your access to the last orbit you hold in their workspace — including by archiving that orbit — your membership ends and you lose access to that workspace’s orbits, rooms and message history. Messages you sent and files you uploaded stay with the workspace. Deleting your own VisionAI Workspace account removes your account data from our systems; it does not retract content you contributed to somebody else’s workspace.
If you have questions about this privacy policy, your data, or how VisionAI Workspace handles your information, reach out directly:
Submit a Privacy Request