Privacy Policy

Last updated: February 19, 2026

Overview

U4IA ("we," "our," or "us") provides a Chrome extension and platform that helps professionals identify and act on referral opportunities within their existing business relationships. This Privacy Policy explains how we collect, use, and protect your information when you use the U4IA PartnerOS Chrome extension and related services.

The key principle: We only analyze conversations with external parties. All analysis happens server-side through the U4IA web application. Internal company emails are never analyzed or sent to our servers.

Information We Collect

Account Information

When you sign in with Google, we collect:

  • Your email address
  • Your name
  • Your profile picture (for display purposes)

Email and Calendar Data

With your permission, our web application (u4ia.ai) accesses:

  • Gmail messages — To identify conversations with external business contacts that may represent referral opportunities
  • Google Calendar events — To identify meetings with external parties and understand relationship context

The Chrome extension does not access Gmail or Calendar data. All email and calendar analysis happens server-side through the U4IA web application.

What we DO NOT access:

  • Internal company emails (emails between you and coworkers at the same domain)
  • Personal emails to family or friends
  • Email attachments
  • Draft emails
  • Deleted emails

Slack Data (Optional)

If you choose to connect a Slack workspace, we access the following via OAuth (read-only):

  • Channel history — Messages in channels you belong to, to identify conversations with external contacts that may represent referral opportunities
  • Direct message history — DMs and group DMs, for the same purpose
  • User information — Names and email addresses of Slack workspace members, to distinguish internal from external participants

Slack access is entirely optional. The web application functions fully with Gmail alone. You can disconnect Slack at any time from the web application settings.

How We Determine "External" vs "Internal"

When you sign up, you specify your company's email domain(s). Any email conversation involving only people at your company domain is considered "internal" and is never sent to our servers. Only conversations with participants from external domains are analyzed.

How We Use Your Information

Data Type How We Use It
Account info To identify you and manage your account
External email content To identify companies that match your partner's ideal customer profile and detect buying signals
Calendar meetings To understand relationship context (prospect vs. customer vs. vendor)
Company enrichment data To score how well a contact's company matches your partner's target market

Third-Party Services

We use the following third-party services to provide our functionality:

Service Purpose Data Shared
Anthropic (Claude AI) Analyze conversation content for buying signals and generate intro drafts External email snippets, company context
The Companies API Enrich company data (industry, size, tech stack) Company domain names only
Google APIs Authentication and email/calendar access OAuth tokens (encrypted at rest)
PostHog Product analytics and error tracking (web application only — not used in the Chrome extension) Email address, company name, organization domains, feature usage events, scan result summaries (opportunity counts and fit categories — no email content), onboarding progress, error details

We use PostHog for product analytics to understand how users interact with the extension. This includes your email address and company name (for user identification), feature interaction events, scan result summaries (aggregate counts and categories only), onboarding step durations, and error tracking. No email content, conversation text, or personal communications are sent to PostHog.

Data Storage and Security

  • Encryption: All OAuth tokens are encrypted at rest using Fernet symmetric encryption
  • Database: Your data is stored in a PostgreSQL database hosted on Railway (US region)
  • Transmission: All data is transmitted over HTTPS/TLS
  • Access: Only you can access your opportunities and drafts. Workspace administrators can see aggregate metrics but not individual email content.

Data Retention

  • Account data: Retained while your account is active
  • Opportunity records: Retained for 2 years for commission tracking purposes
  • Email content: We store only snippets and extracted signals, not full email bodies. Snippets are retained for 90 days.
  • Deletion: You can request complete deletion of your data at any time by emailing [email protected]

Your Rights

You have the right to:

  • Access — Request a copy of all data we have about you
  • Delete — Request deletion of your account and all associated data
  • Revoke — Disconnect your Gmail/Calendar access at any time from the extension settings
  • Export — Request an export of your opportunities and commission history

Chrome Extension Permissions

Our Chrome extension requests the following permissions:

Permission Why We Need It
identity To sign you in with Google OAuth
storage To cache your preferences and opportunities locally
alarms To periodically sync new opportunities in the background
notifications To alert you when high-value opportunities are detected
sidePanel To display your opportunity dashboard in a Chrome side panel

The Chrome extension only communicates with https://api.u4ia.ai. It does not access Gmail, Calendar, Slack, or any other website content.

Children's Privacy

U4IA is designed for business professionals. We do not knowingly collect information from anyone under the age of 18. If you believe we have inadvertently collected such information, please contact us immediately.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of the extension after changes constitutes acceptance of the updated policy.

Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

  • Email: [email protected]
  • Website: u4ia.ai

For data deletion requests: Email [email protected] with the subject line "Data Deletion Request" and we will process your request within 30 days.