Legal
Privacy Policy
Last updated: July 27, 2026
This Privacy Policy explains how Umbrella (“we,” “us,” or “our”) handles personal information when you use our websites, applications, and related services (the “Service”), including AI-powered features such as Violet and connected third-party integrations. We operate primarily from the United States. If you do not agree with this Policy, please do not use the Service. Capitalized terms not defined here have the meanings in our Terms of Service.
1. Scope
This Policy covers personal information we process in connection with the Service. It does not cover third-party websites or services that we do not control. When you connect a third-party account, that provider’s privacy policy also applies to data it holds.
2. Information we collect
Information you provide
- Account and profile: name, email address, authentication credentials or tokens via our auth provider, phone number if you provide one, profile fields, and similar account data.
- Workspace and operations data: programs and related records; signals, artifacts, and resources; notes, preferences, playbook or onboarding inputs; and other content you enter into the Service.
- Uploads: images or files you upload where upload features are offered (for example, profile or resource images).
- Communications: support requests, feedback, and other messages you send us.
- Payment and billing data: when you purchase or subscribe to paid features, or use booking/payout features where offered, we and our payment processor (Stripe, and any similar processors we use) may process billing contact details, payment method identifiers, transaction amounts, subscription status, invoices, payouts, and related metadata. Full payment card numbers are handled by Stripe (or the applicable processor) under their policies; we do not store full card numbers.
Information from integrations you connect
If you connect third-party services (such as email, calendar, CRM, or event platforms), we receive information those services make available under the permissions you grant, for example message metadata and selected excerpts, calendar event details, deal or opportunity fields, or event listings. We use integration infrastructure (such as OAuth connection providers) to authorize and maintain those connections.
When you connect Google Calendar, we use calendar read access to obtain event title, time, attendees, and location so you can match holds and load-in windows to a program and review them in Signals. When you connect Gmail, we use read access to view message subject, participants, timestamps, and short excerpts so you can review commitments (such as venue holds, client confirmations, and vendor handoffs) in Signals and attach them to a program. Unless a feature you enable expressly permits a limited write action (such as creating a draft), we do not send, modify, or delete your mail or calendar events.
Information collected automatically
- Device and logs: IP address, browser and device information, approximate location derived from IP, pages or features used, referrers, and timestamps.
- Cookies and similar technologies: we use cookies, local storage, and similar technologies as needed to operate sessions, keep you signed in, remember preferences, maintain security, and understand how the Service is used. See Section 7.
Information from other sources
- Authentication and identity providers (for example, Google sign-in);
- Payment and risk vendors when payment features are used;
- Public or commercial sources where reasonably needed to operate directory features (for example, network or directory data we maintain), consistent with applicable law.
3. How we use information
We use personal information to:
- Provide, operate, secure, and improve the Service;
- Authenticate users, maintain sessions, and prevent fraud and abuse;
- Power workspace features such as programs, signals, artifacts, resources, and operational views;
- Run AI-powered features (including Violet), for example recommendations, summaries, draft preparation, ranking, and related assistance, as described in Section 6;
- Sync and process data from integrations you connect, and perform limited write actions you authorize (such as creating a draft) when enabled;
- Communicate with you about the Service, security, and (where permitted) product updates;
- Analyze usage in aggregate or de-identified form to improve reliability and product quality;
- Process payments, subscriptions, invoices, and related accounting or tax records where paid features are used;
- Comply with law and enforce our Terms.
4. Legal bases (EEA and UK)
If you are in the European Economic Area or United Kingdom, we rely on one or more of: performing our contract with you; legitimate interests (such as securing and improving the Service) where your rights do not override those interests; consent where required; and legal obligations. You may withdraw consent where processing is consent-based, without affecting prior processing.
5. How we share information
Service providers
We share information with vendors that process it on our behalf, which may include:
- Cloud, database, and authentication providers that host accounts and Service data;
- Integration platforms that facilitate OAuth connections and API access to services you connect;
- AI model providers (currently including Anthropic, and other providers we may use) to generate AI Output when those features are enabled (see Section 6);
- Stripe and affiliates (and any other payment processors we use) for subscriptions, invoices, checkout, payouts, fraud prevention, tax-related processing, and similar payment operations. Stripe’s privacy policy applies to payment data you submit in their flows;
- Communications providers (for example, email delivery, or SMS/WhatsApp providers where those messaging features are enabled);
- Logging, security, and support tools we configure from time to time.
Within your workspace
Information in your workspace is available to your account and, if we offer multi-user access later, to users you authorize.
Legal and safety
We may disclose information to comply with law, regulation, legal process, or governmental requests; to enforce our policies; or to protect Umbrella, users, or the public.
Business transfers
In a merger, financing, reorganization, bankruptcy, or asset sale, information may transfer as part of that transaction, subject to confidentiality and applicable law.
6. AI processing (including Violet)
When you use AI-powered features, we may send prompts, questions, and relevant context from your workspace (for example, structured operational summaries, program details, or signal context) to model providers and our systems to generate a response. Some AI features may be disabled in your environment; when disabled, the Service may still provide non-model or deterministic assistance.
We do not use Customer Content to train foundation models of our AI providers unless we obtain your appropriate consent or provide clear notice and a choice required by law. Providers may process prompts and outputs to deliver the service to us under their terms and our agreements with them. Avoid pasting sensitive categories of data into AI features unless we request them through a dedicated flow.
We may log AI interactions as reasonably needed for security, abuse prevention, debugging, and quality evaluation, consistent with Section 8 (retention).
7. Cookies and similar technologies
We use essential cookies and similar technologies to authenticate users, maintain sessions, and operate core features. We may also use technologies that help us understand product usage and reliability. You can control many cookies through your browser settings; disabling essential cookies may prevent sign-in or core functionality.
We do not currently operate a third-party advertising pixel network in the Service. If we later use advertising or analytics technologies that require additional notices or choices, we will update this Policy and provide those choices where required.
8. Retention
We retain personal information for as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Some records (for example, security logs or payment records where applicable) may be kept longer. Soft-archived programs or conversations may retain underlying data until deleted in accordance with our practices or your valid request.
Self-serve account deletion and export tools may not be available in all environments. You may request deletion or a copy of personal information as described in Section 10.
9. Security
We use administrative, technical, and organizational measures designed to protect personal information, such as authenticated access controls, encrypted transport in transit to the Service, and safeguards around sensitive actions (for example, limiting certain writebacks to connected accounts). No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Your rights and choices
Depending on where you live, you may have the right to request access, correction, deletion, or a portable copy of certain personal information; to object to or restrict certain processing; to opt out of certain sharing for cross-context behavioral advertising where applicable; and to appeal our decision on a privacy request where the law provides that right.
To exercise rights, email info@umbrellalive.com. We will verify requests as required by law. Authorized agents may submit requests with valid authorization. If you are in the EEA or UK, you may lodge a complaint with your supervisory authority.
You may disconnect integrations in the Service where that control is offered. Disconnecting may stop future sync from that source; it may not delete data already imported unless you request deletion or we provide an in-product purge.
11. California privacy notice
We do not sell personal information for money. If we engage in “sharing” for cross-context behavioral advertising as defined by California law, we will provide required notices and opt-out methods (which may include a “Do Not Sell or Share My Personal Information” link and recognition of certain opt-out signals) and update this Policy accordingly.
California residents may exercise the rights in Section 10 by contacting us at the email below.
12. International transfers
We are based in the United States. If you use the Service from another country, your information may be processed in the United States and in other countries where our vendors operate. Those countries may have different data-protection laws. Where required, we use appropriate safeguards for cross-border transfers.
13. Children
The Service is not directed to children under 13 (or under 16 where a higher age applies), and we do not knowingly collect their personal information. If you believe we have, contact us and we will take appropriate steps to delete it.
14. Third-party services
Links to or integrations with third-party services are governed by those parties’ policies, not this one. We are not responsible for their privacy practices.
15. Google user data (Limited Use)
Umbrella’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular:
- We use Google user data only to provide or improve user-facing features that are prominent in the Service (for example, reviewing calendar and email items in Signals and attaching them to programs), and for related security, abuse prevention, and troubleshooting.
- We do not use Google user data to serve advertisements, including personalized, retargeted, or interest-based ads.
- We do not sell Google user data.
- We do not transfer Google user data to third parties except: (a) as necessary to provide or improve user-facing features with your consent or as part of providing the Service (for example, our hosting, integration, and AI processors acting on our behalf); (b) for security purposes (for example, investigating abuse); (c) to comply with applicable laws; or (d) as part of a merger, acquisition, or sale of assets with notice to users where required.
- Human access to Google user data is limited to cases needed to provide the Service, secure it, comply with law, or with your explicit request/consent (for example, support you initiate).
You may disconnect Google integrations in the Service where that control is offered. Disconnecting stops future sync; previously imported items may remain until you delete them or request deletion as described in Section 10.
16. Messaging features
Where SMS, WhatsApp, or similar messaging features are enabled, we or our providers may process phone numbers and message content to deliver those messages. Message and data rates may apply. Opt-out instructions for marketing messages will be provided where required; transactional or security-related messages may continue where permitted by law.
17. Updates
We may revise this Policy by posting an updated version and changing the “Last updated” date. For material changes, we will provide additional notice when appropriate.
18. Contact
Privacy questions and requests: info@umbrellalive.com.