Smart Manager
PrivacyTerms

Legal

Privacy Policy

Last updated July 23, 2026

Scope and OperatorNotice at CollectionInformation We CollectSources of InformationGoogle and YouTube DataHow We Use InformationAI Processing and Model TrainingHow We Disclose InformationNo Sale or Behavioral Advertising SharingData RetentionSecurityYour Rights and ChoicesAccount Deletion and ExportChildrenInternational Data TransfersChanges to This PolicyContact Us
01

Scope and Operator

This Privacy Policy explains how SmartManager LLC ("we," "our," or "us") collects, uses, discloses, and retains personal information when you use the Smart Manager websites, desktop and mobile applications, AI features, and related services (collectively, the "Service").

SmartManager LLC is the service operator. Legal notices may be sent to legal@smartmanager.ai or to 480 Boynton Ave, San Jose, California 95117, United States. This policy does not govern third-party services that you choose to connect; their policies govern their own processing.

02

Notice at Collection

At or before collection, we collect the following categories of personal information for the purposes summarized below:

  • Identifiers and account details, such as name, email, user and organization identifiers, authentication records, and contact details, to create, secure, and support your account
  • Commercial and billing information, such as plan, subscription status, transaction identifiers, and payment-related records received from Stripe, to provide subscriptions, prevent fraud, and maintain financial records
  • User Content and connected-service data, such as prompts, AI conversations, files, documents, emails, calendars, contacts, tasks, messages, photos, audio, and instructions, to provide the features you request
  • Internet, device, and usage information, such as IP-derived information, browser, device, operating system, diagnostics, feature activity, and security logs, to operate, secure, debug, and improve the Service
  • Inferences and generated information, such as AI classifications, summaries, recommendations, embeddings, and Outputs, to provide search, organization, automation, and assistant features
  • Sensitive personal information that may appear in content you choose to provide, connected-account credentials or tokens, precise location when enabled, communications contents, and visual matching data when photo features are used, solely to provide and secure the requested feature

We do not sell personal information or share it for cross-context behavioral advertising. We retain each category only for as long as reasonably necessary for the purposes described here, including the life of the account, user-directed deletion, security needs, legal obligations, and ordinary backup expiration. More detail appears in Data Retention.

Providing account and authentication information is necessary to use an account. Other information is optional, but a feature may not work if you do not provide or connect the information it needs.

03

Information We Collect

3.1 Account and Profile Information

We collect information such as your name, email address, phone number if provided, profile details, organization, role, account dates, settings, authentication events, and legal-consent receipts.

3.2 User Content and AI Activity

We process prompts, conversations, instructions, uploaded or generated files, documents, images, audio, transcripts, feedback, Outputs, and actions you request. Content may contain personal information about you or others.

3.3 Connected Services

When you authorize an integration, we receive the data and permissions needed for that connection. Depending on your choices, this can include email, calendars, contacts, files, cloud storage, tasks, messages, social content, meeting data, activity archives, and provider account metadata. OAuth tokens or similar credentials are used to maintain the connection.

3.4 Device, Usage, and Diagnostics

We collect device and browser type, operating system, IP address, approximate location derived from IP, login and activity times, referring pages, feature interactions, API events, crash reports, performance data, and security signals.

3.5 Payment Information

Stripe processes payment-card details. We receive subscription, customer and transaction identifiers, billing status, plan, amount, currency, invoices, and limited payment-method details. We do not store full payment-card numbers.

3.6 Photos, Audio, and Location

If you enable relevant features, we process microphone recordings, transcripts, photos, visual or face-matching representations, and device location. Visual matching is used to organize or link user-selected photos, not to authenticate identity, unless we provide separate notice and obtain any consent required by law.

04

Sources of Information

We collect information:

  • Directly from you, including information you enter, upload, say, approve, or generate
  • Automatically from your device and use of the Service
  • From services you connect, such as Google, Microsoft, iCloud, messaging, storage, social, and meeting providers
  • From identity, payment, security, analytics, hosting, and AI service providers
  • From an organization that invites you to or administers a Smart Manager workspace
  • From other users when they share content or collaborate with you
05

Google and YouTube Data

YouTube API Services

Smart Manager uses YouTube API Services when you connect YouTube. The ordinary YouTube connection can collect your subscriptions, liked and disliked videos, playlists and playlist items, and related video, playlist, channel, and account metadata that the YouTube Data API makes available. It does not provide Smart Manager with YouTube watch history, search history, Watch Later, or a complete history of comments you authored.

Google Data Portability

If you separately enable YouTube History Import, Smart Manager uses the Google Data Portability API to request the YouTube resource groups you select. The import requests the available history for those groups and can include YouTube watch and search activity, YouTube ad interactions, related image, audio, or CSV attachments, comments, subscriptions, private, public, and unlisted playlists, and associated metadata. Data Portability authorization is separate from the ordinary YouTube connection. After a successful capture, Smart Manager asks Google to reset the import authorization rather than retaining an ongoing Data Portability grant. Smart Manager does not use scraping to obtain unavailable YouTube data.

Use and AI Processing

We use connected YouTube data to provide the synchronization, import, search, and organization features you authorize. The ordinary YouTube Data API connection temporarily queues factual records for synchronization and does not create derived metrics or preference memories or send those records to AI providers for interest inference. YouTube History Import stores factual imported records by default. If you separately select Reviewable preference evidence, Smart Manager creates a deterministic, source-attributed evidence summary for you to inspect. That summary is not sent to an AI provider and is not promoted into assistant memory or treated as an accepted statement about your preferences. A view is not treated as endorsement, missing activity is not treated as a dislike, and no sensitive identity traits are inferred.

Storage, Disclosure, and Retention

We store OAuth tokens in protected form and keep YouTube records in your private Smart Manager data silo. We do not persist Google's temporary signed archive download links. We disclose Google user data only to service providers acting on our behalf when necessary to provide or secure the feature you requested, as described in How We Disclose Information. We do not sell Google user data, use it for behavioral advertising, or permit humans to read it except with your affirmative agreement for a specific item, when necessary for security or abuse investigation, or when required by law. Completed ordinary YouTube Data API queue records are deleted after synchronization; a delayed deletion backstop removes an abandoned queue generation within 29 days. Smart Manager periodically reconfirms ordinary YouTube authorization and deletes the corresponding Authorized Data if Google reports that access was revoked. Data Portability records and any optional reviewable evidence summary are retained only as long as needed for the user-facing import purpose you authorized.

Disconnecting and Deletion

YouTube is an exception to the Service's general provider-retention behavior because YouTube policy requires Authorized Data deletion following revocation. When a YouTube disconnect completes, Smart Manager asks Google to revoke or reset the selected authorization and deletes records and review artifacts obtained under that YouTube authorization. If deletion cannot be completed, the Service reports the failure and preserves enough connection state to retry instead of falsely reporting success. Other YouTube accounts that remain connected are not deleted. See [Manage and delete YouTube data](/help/youtube-data) for step-by-step controls. You can also revoke Smart Manager from Google's third-party access settings, request deletion through the Service, or delete your Smart Manager account.

Your use of the YouTube connection is also governed by the YouTube Terms of Service and Google Privacy Policy. Smart Manager's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Smart Manager's use and transfer of information received from the Google Data Portability API also adheres to the Data Portability API Additional Requirements.

06

How We Use Information

We use personal information to:

  • Provide, personalize, and maintain the Service
  • Authenticate users, provision accounts and data silos, and enforce permissions
  • Process prompts, generate Outputs, search content, and perform approved actions
  • Synchronize and maintain connected services
  • Process subscriptions, send transaction notices, and provide billing support
  • Detect abuse, prevent fraud, protect users, and secure the Service
  • Diagnose errors, measure performance, and improve features
  • Communicate about the Service, legal updates, security, and support
  • Enforce our agreements and comply with legal obligations

We may create aggregated or de-identified information and use it for analytics, security, and product improvement. We do not attempt to re-identify information that has been de-identified except to test whether de-identification is effective.

07

AI Processing and Model Training

We send prompts and relevant content to AI providers when needed to perform the feature you request. The provider, model, and processing location may vary based on feature availability, reliability, safety, and configured routing.

SmartManager LLC does not use User Content to train its own general-purpose AI models unless we provide separate notice and obtain consent where required. We require service providers to process data for authorized service purposes, subject to their contracts and our configuration. Provider retention and training commitments can differ, so we select business or API services and data-control settings appropriate to the feature.

You should not submit information that you are not authorized to process. Avoid including highly sensitive information unless it is necessary for the feature and you understand the applicable controls.

08

How We Disclose Information

We disclose information only as needed for the purposes described in this policy:

7.1 Service Providers and Subprocessors

Our providers may include:

  • WorkOS for identity and authentication
  • Stripe for subscription billing and payment processing
  • Amazon Web Services for storage, email delivery, and infrastructure
  • Elastic and Convex for search, databases, isolated user data silos, and application data
  • Vercel for application hosting, delivery, and performance services
  • OpenAI, Groq, OpenRouter, and other configured AI-model providers for AI inference
  • Trigger.dev for durable background tasks and workflows
  • Axiom and Vercel runtime telemetry for privacy-safe operational diagnostics, plus PostHog for consented product analytics when enabled
  • ElevenLabs and other configured speech providers for voice features
  • Stream for video or communication features
  • Google, Microsoft, Apple/iCloud, and other providers you choose to connect

Provider use varies by feature and deployment. Providers may change when we replace a service or add a materially equivalent provider. We require providers to protect information and process it only for authorized purposes.

7.2 Your Organization and Other Users

Workspace administrators may manage memberships, access shared workspace information, and control organization settings. We disclose content to other users when you direct us to share or send it.

7.3 Legal, Safety, and Corporate Events

We may disclose information when reasonably necessary to comply with law, protect rights or safety, investigate fraud or abuse, or respond to lawful process. Information may be transferred in a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality protections.

09

No Sale or Behavioral Advertising Sharing

We do not sell personal information for money or other valuable consideration, and we do not share personal information for cross-context behavioral advertising as those terms are defined by California law.

We do not disclose mobile phone numbers, messaging consent, or messaging-originator data to third parties or affiliates for their own marketing or promotional purposes. Service providers may process this data only to deliver and support the messaging feature.

We honor legally required opt-out preference signals, such as Global Privacy Control, when applicable to the processing at issue.

10

Data Retention

We use the following retention criteria:

  • Account and profile information is retained while your account is active and as needed to administer closure, resolve disputes, prevent fraud, or meet legal obligations
  • User Content is retained until you delete it, disconnect the source where deletion applies, or delete your account, subject to shared content, legal holds, and ordinary backup expiration
  • Connected-service tokens are retained while the integration is connected and are removed or invalidated when the connection or account is deleted, subject to provider behavior and security records
  • Temporary processing files and caches are retained only for the period needed to complete, recover, or secure the applicable job and are then scheduled for deletion
  • Billing, transaction, tax, and legal-consent records are retained for the period required to document the transaction, comply with financial and consumer-protection law, and establish or defend legal claims
  • Security, audit, diagnostic, and usage logs are retained for the shortest period reasonably necessary for security, reliability, fraud prevention, troubleshooting, and legal compliance
  • Backup copies are isolated from ordinary use and expire through our normal backup lifecycle unless preservation is required by law

Retention can vary based on the sensitivity and volume of information, the purpose of processing, contractual requirements, risk of harm, and applicable law. When retention ends, we delete or de-identify the information.

11

Security

We use administrative, technical, and physical safeguards designed to protect personal information. Measures include encrypted transport, encryption at rest where supported, access controls, isolated user data silos, authentication controls, monitoring, secret management, and security review.

No system is perfectly secure. You are responsible for protecting your devices and authentication methods and for promptly reporting suspected unauthorized access to support@smartmanager.ai.

12

Your Rights and Choices

Depending on your location, you may have the right to:

  • Know or access the personal information we process
  • Correct inaccurate information
  • Delete personal information
  • Receive a portable copy of information you provided
  • Restrict or object to certain processing
  • Opt out of sale, behavioral-advertising sharing, or certain automated processing where applicable
  • Limit certain uses of sensitive personal information where applicable
  • Withdraw consent for consent-based processing
  • Appeal a denied privacy request

You may update profile information, disconnect integrations, manage subscription billing, export data, or request account deletion through the Service. You may also email legal@smartmanager.ai. We may verify your identity and authority before completing a request. Authorized agents must provide proof of authority. We will not discriminate against you for exercising a privacy right.

California residents may request the categories, sources, purposes, recipients, and specific pieces of personal information covered by applicable law. Because we do not sell or share personal information for behavioral advertising, there is no sale or advertising-sharing activity to opt out of.

13

Account Deletion and Export

Account settings provide an account deletion flow. The Service attempts to create an export before deleting active account data and fails closed if that export cannot be created. If deletion only partially completes, we preserve the export and direct you to support rather than reporting a false success.

Account deletion does not require deletion of records we must retain for billing, fraud prevention, security, legal compliance, or the establishment or defense of legal claims. It may not remove content that another user lawfully retains in a shared workspace. Backup copies expire through the normal protected backup lifecycle.

14

Children

The Service is intended for adults and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact legal@smartmanager.ai so we can investigate and take appropriate action.

15

International Data Transfers

We and our providers may process information in the United States and other countries where privacy laws differ from those in your location. Where required, we use contractual or other approved safeguards for international transfers.

16

Changes to This Policy

We may update this policy to reflect changes in the Service, providers, law, or our practices. We will post the revised policy and update the date above. If a change materially affects your privacy rights or how we use previously collected information, we will provide additional notice and obtain consent when required by law.

17

Contact Us

Privacy questions and requests may be sent to legal@smartmanager.ai.

Postal address:

SmartManager LLC

480 Boynton Ave

San Jose, California 95117

United States

© 2026 SmartManager LLC
PrivacyTermsContact
Smart Manager
PrivacyTerms

Legal

Privacy Policy

Last updated July 23, 2026

Scope and OperatorNotice at CollectionInformation We CollectSources of InformationGoogle and YouTube DataHow We Use InformationAI Processing and Model TrainingHow We Disclose InformationNo Sale or Behavioral Advertising SharingData RetentionSecurityYour Rights and ChoicesAccount Deletion and ExportChildrenInternational Data TransfersChanges to This PolicyContact Us
01

Scope and Operator

This Privacy Policy explains how SmartManager LLC ("we," "our," or "us") collects, uses, discloses, and retains personal information when you use the Smart Manager websites, desktop and mobile applications, AI features, and related services (collectively, the "Service").

SmartManager LLC is the service operator. Legal notices may be sent to legal@smartmanager.ai or to 480 Boynton Ave, San Jose, California 95117, United States. This policy does not govern third-party services that you choose to connect; their policies govern their own processing.

02

Notice at Collection

At or before collection, we collect the following categories of personal information for the purposes summarized below:

  • Identifiers and account details, such as name, email, user and organization identifiers, authentication records, and contact details, to create, secure, and support your account
  • Commercial and billing information, such as plan, subscription status, transaction identifiers, and payment-related records received from Stripe, to provide subscriptions, prevent fraud, and maintain financial records
  • User Content and connected-service data, such as prompts, AI conversations, files, documents, emails, calendars, contacts, tasks, messages, photos, audio, and instructions, to provide the features you request
  • Internet, device, and usage information, such as IP-derived information, browser, device, operating system, diagnostics, feature activity, and security logs, to operate, secure, debug, and improve the Service
  • Inferences and generated information, such as AI classifications, summaries, recommendations, embeddings, and Outputs, to provide search, organization, automation, and assistant features
  • Sensitive personal information that may appear in content you choose to provide, connected-account credentials or tokens, precise location when enabled, communications contents, and visual matching data when photo features are used, solely to provide and secure the requested feature

We do not sell personal information or share it for cross-context behavioral advertising. We retain each category only for as long as reasonably necessary for the purposes described here, including the life of the account, user-directed deletion, security needs, legal obligations, and ordinary backup expiration. More detail appears in Data Retention.

Providing account and authentication information is necessary to use an account. Other information is optional, but a feature may not work if you do not provide or connect the information it needs.

03

Information We Collect

3.1 Account and Profile Information

We collect information such as your name, email address, phone number if provided, profile details, organization, role, account dates, settings, authentication events, and legal-consent receipts.

3.2 User Content and AI Activity

We process prompts, conversations, instructions, uploaded or generated files, documents, images, audio, transcripts, feedback, Outputs, and actions you request. Content may contain personal information about you or others.

3.3 Connected Services

When you authorize an integration, we receive the data and permissions needed for that connection. Depending on your choices, this can include email, calendars, contacts, files, cloud storage, tasks, messages, social content, meeting data, activity archives, and provider account metadata. OAuth tokens or similar credentials are used to maintain the connection.

3.4 Device, Usage, and Diagnostics

We collect device and browser type, operating system, IP address, approximate location derived from IP, login and activity times, referring pages, feature interactions, API events, crash reports, performance data, and security signals.

3.5 Payment Information

Stripe processes payment-card details. We receive subscription, customer and transaction identifiers, billing status, plan, amount, currency, invoices, and limited payment-method details. We do not store full payment-card numbers.

3.6 Photos, Audio, and Location

If you enable relevant features, we process microphone recordings, transcripts, photos, visual or face-matching representations, and device location. Visual matching is used to organize or link user-selected photos, not to authenticate identity, unless we provide separate notice and obtain any consent required by law.

04

Sources of Information

We collect information:

  • Directly from you, including information you enter, upload, say, approve, or generate
  • Automatically from your device and use of the Service
  • From services you connect, such as Google, Microsoft, iCloud, messaging, storage, social, and meeting providers
  • From identity, payment, security, analytics, hosting, and AI service providers
  • From an organization that invites you to or administers a Smart Manager workspace
  • From other users when they share content or collaborate with you
05

Google and YouTube Data

YouTube API Services

Smart Manager uses YouTube API Services when you connect YouTube. The ordinary YouTube connection can collect your subscriptions, liked and disliked videos, playlists and playlist items, and related video, playlist, channel, and account metadata that the YouTube Data API makes available. It does not provide Smart Manager with YouTube watch history, search history, Watch Later, or a complete history of comments you authored.

Google Data Portability

If you separately enable YouTube History Import, Smart Manager uses the Google Data Portability API to request the YouTube resource groups you select. The import requests the available history for those groups and can include YouTube watch and search activity, YouTube ad interactions, related image, audio, or CSV attachments, comments, subscriptions, private, public, and unlisted playlists, and associated metadata. Data Portability authorization is separate from the ordinary YouTube connection. After a successful capture, Smart Manager asks Google to reset the import authorization rather than retaining an ongoing Data Portability grant. Smart Manager does not use scraping to obtain unavailable YouTube data.

Use and AI Processing

We use connected YouTube data to provide the synchronization, import, search, and organization features you authorize. The ordinary YouTube Data API connection temporarily queues factual records for synchronization and does not create derived metrics or preference memories or send those records to AI providers for interest inference. YouTube History Import stores factual imported records by default. If you separately select Reviewable preference evidence, Smart Manager creates a deterministic, source-attributed evidence summary for you to inspect. That summary is not sent to an AI provider and is not promoted into assistant memory or treated as an accepted statement about your preferences. A view is not treated as endorsement, missing activity is not treated as a dislike, and no sensitive identity traits are inferred.

Storage, Disclosure, and Retention

We store OAuth tokens in protected form and keep YouTube records in your private Smart Manager data silo. We do not persist Google's temporary signed archive download links. We disclose Google user data only to service providers acting on our behalf when necessary to provide or secure the feature you requested, as described in How We Disclose Information. We do not sell Google user data, use it for behavioral advertising, or permit humans to read it except with your affirmative agreement for a specific item, when necessary for security or abuse investigation, or when required by law. Completed ordinary YouTube Data API queue records are deleted after synchronization; a delayed deletion backstop removes an abandoned queue generation within 29 days. Smart Manager periodically reconfirms ordinary YouTube authorization and deletes the corresponding Authorized Data if Google reports that access was revoked. Data Portability records and any optional reviewable evidence summary are retained only as long as needed for the user-facing import purpose you authorized.

Disconnecting and Deletion

YouTube is an exception to the Service's general provider-retention behavior because YouTube policy requires Authorized Data deletion following revocation. When a YouTube disconnect completes, Smart Manager asks Google to revoke or reset the selected authorization and deletes records and review artifacts obtained under that YouTube authorization. If deletion cannot be completed, the Service reports the failure and preserves enough connection state to retry instead of falsely reporting success. Other YouTube accounts that remain connected are not deleted. See [Manage and delete YouTube data](/help/youtube-data) for step-by-step controls. You can also revoke Smart Manager from Google's third-party access settings, request deletion through the Service, or delete your Smart Manager account.

Your use of the YouTube connection is also governed by the YouTube Terms of Service and Google Privacy Policy. Smart Manager's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Smart Manager's use and transfer of information received from the Google Data Portability API also adheres to the Data Portability API Additional Requirements.

06

How We Use Information

We use personal information to:

  • Provide, personalize, and maintain the Service
  • Authenticate users, provision accounts and data silos, and enforce permissions
  • Process prompts, generate Outputs, search content, and perform approved actions
  • Synchronize and maintain connected services
  • Process subscriptions, send transaction notices, and provide billing support
  • Detect abuse, prevent fraud, protect users, and secure the Service
  • Diagnose errors, measure performance, and improve features
  • Communicate about the Service, legal updates, security, and support
  • Enforce our agreements and comply with legal obligations

We may create aggregated or de-identified information and use it for analytics, security, and product improvement. We do not attempt to re-identify information that has been de-identified except to test whether de-identification is effective.

07

AI Processing and Model Training

We send prompts and relevant content to AI providers when needed to perform the feature you request. The provider, model, and processing location may vary based on feature availability, reliability, safety, and configured routing.

SmartManager LLC does not use User Content to train its own general-purpose AI models unless we provide separate notice and obtain consent where required. We require service providers to process data for authorized service purposes, subject to their contracts and our configuration. Provider retention and training commitments can differ, so we select business or API services and data-control settings appropriate to the feature.

You should not submit information that you are not authorized to process. Avoid including highly sensitive information unless it is necessary for the feature and you understand the applicable controls.

08

How We Disclose Information

We disclose information only as needed for the purposes described in this policy:

7.1 Service Providers and Subprocessors

Our providers may include:

  • WorkOS for identity and authentication
  • Stripe for subscription billing and payment processing
  • Amazon Web Services for storage, email delivery, and infrastructure
  • Elastic and Convex for search, databases, isolated user data silos, and application data
  • Vercel for application hosting, delivery, and performance services
  • OpenAI, Groq, OpenRouter, and other configured AI-model providers for AI inference
  • Trigger.dev for durable background tasks and workflows
  • Axiom and Vercel runtime telemetry for privacy-safe operational diagnostics, plus PostHog for consented product analytics when enabled
  • ElevenLabs and other configured speech providers for voice features
  • Stream for video or communication features
  • Google, Microsoft, Apple/iCloud, and other providers you choose to connect

Provider use varies by feature and deployment. Providers may change when we replace a service or add a materially equivalent provider. We require providers to protect information and process it only for authorized purposes.

7.2 Your Organization and Other Users

Workspace administrators may manage memberships, access shared workspace information, and control organization settings. We disclose content to other users when you direct us to share or send it.

7.3 Legal, Safety, and Corporate Events

We may disclose information when reasonably necessary to comply with law, protect rights or safety, investigate fraud or abuse, or respond to lawful process. Information may be transferred in a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality protections.

09

No Sale or Behavioral Advertising Sharing

We do not sell personal information for money or other valuable consideration, and we do not share personal information for cross-context behavioral advertising as those terms are defined by California law.

We do not disclose mobile phone numbers, messaging consent, or messaging-originator data to third parties or affiliates for their own marketing or promotional purposes. Service providers may process this data only to deliver and support the messaging feature.

We honor legally required opt-out preference signals, such as Global Privacy Control, when applicable to the processing at issue.

10

Data Retention

We use the following retention criteria:

  • Account and profile information is retained while your account is active and as needed to administer closure, resolve disputes, prevent fraud, or meet legal obligations
  • User Content is retained until you delete it, disconnect the source where deletion applies, or delete your account, subject to shared content, legal holds, and ordinary backup expiration
  • Connected-service tokens are retained while the integration is connected and are removed or invalidated when the connection or account is deleted, subject to provider behavior and security records
  • Temporary processing files and caches are retained only for the period needed to complete, recover, or secure the applicable job and are then scheduled for deletion
  • Billing, transaction, tax, and legal-consent records are retained for the period required to document the transaction, comply with financial and consumer-protection law, and establish or defend legal claims
  • Security, audit, diagnostic, and usage logs are retained for the shortest period reasonably necessary for security, reliability, fraud prevention, troubleshooting, and legal compliance
  • Backup copies are isolated from ordinary use and expire through our normal backup lifecycle unless preservation is required by law

Retention can vary based on the sensitivity and volume of information, the purpose of processing, contractual requirements, risk of harm, and applicable law. When retention ends, we delete or de-identify the information.

11

Security

We use administrative, technical, and physical safeguards designed to protect personal information. Measures include encrypted transport, encryption at rest where supported, access controls, isolated user data silos, authentication controls, monitoring, secret management, and security review.

No system is perfectly secure. You are responsible for protecting your devices and authentication methods and for promptly reporting suspected unauthorized access to support@smartmanager.ai.

12

Your Rights and Choices

Depending on your location, you may have the right to:

  • Know or access the personal information we process
  • Correct inaccurate information
  • Delete personal information
  • Receive a portable copy of information you provided
  • Restrict or object to certain processing
  • Opt out of sale, behavioral-advertising sharing, or certain automated processing where applicable
  • Limit certain uses of sensitive personal information where applicable
  • Withdraw consent for consent-based processing
  • Appeal a denied privacy request

You may update profile information, disconnect integrations, manage subscription billing, export data, or request account deletion through the Service. You may also email legal@smartmanager.ai. We may verify your identity and authority before completing a request. Authorized agents must provide proof of authority. We will not discriminate against you for exercising a privacy right.

California residents may request the categories, sources, purposes, recipients, and specific pieces of personal information covered by applicable law. Because we do not sell or share personal information for behavioral advertising, there is no sale or advertising-sharing activity to opt out of.

13

Account Deletion and Export

Account settings provide an account deletion flow. The Service attempts to create an export before deleting active account data and fails closed if that export cannot be created. If deletion only partially completes, we preserve the export and direct you to support rather than reporting a false success.

Account deletion does not require deletion of records we must retain for billing, fraud prevention, security, legal compliance, or the establishment or defense of legal claims. It may not remove content that another user lawfully retains in a shared workspace. Backup copies expire through the normal protected backup lifecycle.

14

Children

The Service is intended for adults and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact legal@smartmanager.ai so we can investigate and take appropriate action.

15

International Data Transfers

We and our providers may process information in the United States and other countries where privacy laws differ from those in your location. Where required, we use contractual or other approved safeguards for international transfers.

16

Changes to This Policy

We may update this policy to reflect changes in the Service, providers, law, or our practices. We will post the revised policy and update the date above. If a change materially affects your privacy rights or how we use previously collected information, we will provide additional notice and obtain consent when required by law.

17

Contact Us

Privacy questions and requests may be sent to legal@smartmanager.ai.

Postal address:

SmartManager LLC

480 Boynton Ave

San Jose, California 95117

United States

© 2026 SmartManager LLC
PrivacyTermsContact