HomieDeskEspañol

Privacy Policy

Last updated: 2026-08-03

This document explains what data HomieDesk uses, what for, who it is shared with, and how you can remove it. It is written to be understood, not to cover ourselves.

1. Who we are

HomieDesk is a CRM operated by HomieDesk, which acts as the data controller.

For any privacy question, or to request access to, correction of, or deletion of your data, write to hello@homiedesk.com.

2. What Google data we use, and why

Connecting your Google account is optional. Without it, the CRM works minus the email and meeting features. When you connect it, we request these permissions and use them only for this:

Read your email (gmail.readonly): to show, on each customer's record, the messages exchanged with them, to detect when someone replies to you, and to build the timeline of the relationship.

Send email (gmail.send): to send, from your own address, the messages you approve inside the CRM. We never send anything you have not approved.

Modify your email (gmail.modify): so that actions you take in the CRM (mark as read, archive, save a draft) are reflected in your Gmail.

Your email address (userinfo.email): to know which account is connected and show it to you.

Read your calendar (calendar.readonly) and create events (calendar.events): to list your upcoming meetings and to schedule meetings with a Meet link from the CRM.

Read Meet spaces (meetings.space.readonly): to match a meeting transcript with its corresponding calendar event.

We do not use your Google data for advertising, we do not sell it, and we do not use it to train artificial intelligence models.

3. Limited Use of Google data

HomieDesk's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically: we do not transfer Google data to third parties except as necessary to provide or improve the features you requested, to comply with applicable law, or as part of a merger or acquisition with your consent; no humans read your Google data unless you give explicit permission for support purposes, for security, or where required by law; and we do not use that data for advertising or to train generalized artificial intelligence models.

4. What we store, and for how long

So the CRM does not have to ask Google for everything on every screen, we store copies in our database:

Email messages related to your customers: sender, recipients, subject, date and the BODY of the message, in plain text and HTML. We store the full body, not just a summary.

Calendar events associated with customer meetings.

Meeting transcripts, plus the summary, key points and tasks that artificial intelligence extracts from them.

The access tokens Google issues for your account, which are what make the connection possible.

We keep this data while your account is active. If you disconnect Google from the CRM, we stop syncing and delete the tokens. If you request account deletion, we delete your data within 30 days, except what the law requires us to retain.

5. Who we share data with

We do not sell data. We share it only with the providers required to run the service, each with access only to what it needs:

Supabase: database and file storage.

Vercel: application hosting.

Anthropic: the artificial intelligence model that drafts messages, summarizes meetings and answers in chat. It receives the text needed for that task. Anthropic does not use this data to train its models.

Recall.ai: only if you enable meeting recording. Its bot joins the call and produces the transcript.

Apollo.io: only if you use prospecting. It receives search criteria, not your email.

Stripe: payments. It receives billing data; we do not store card numbers.

The content of your email and meetings is never shared with other organizations using the CRM. Each organization sees only its own data.

6. How to revoke access and delete your data

You can cut off access at any time, through two independent paths:

From the CRM: Settings → Email → Disconnect Google. Tokens are deleted and syncing stops.

From your Google account: go to myaccount.google.com/permissions, find HomieDesk and remove its access. This invalidates the tokens immediately, without going through us.

To delete data already stored (email, transcripts, summaries), write to hello@homiedesk.com and we will do it within 30 days.

7. Security

Data access is restricted per organization: each account can only read its own organization's data, and this is enforced in the database, not just in the interface. Communication with the application is always encrypted in transit (HTTPS).

No system is infallible. If we detect a breach affecting your data, we will notify you.

8. Changes

If we change this policy, we update the date above. If the change affects how we handle your Google data, we will notify you inside the application before it takes effect.