Privacy Policy
Last updated Jul 17, 2026
Lowkey Privacy Policy
Effective Date: July 17, 2026
This Privacy Policy explains how Lowkey Technologies Inc ("Lowkey," "we," "our," or "us") collects, uses, discloses, and protects personal data when you use our websites, applications, APIs, assistants, automations, and related services (collectively, the "Service").
By using the Service, you acknowledge this Privacy Policy.
1. Scope
This Privacy Policy applies to personal data processed by Lowkey in connection with the Service, including when you:
- visit https://lowkey.money,
- create or use a Lowkey account,
- connect third-party tools to Lowkey,
- run assistant workflows and automations, or
- contact us for support or business inquiries.
This Privacy Policy does not apply to third-party services that you connect to Lowkey. Those services are governed by their own privacy policies.
2. Personal Data We Collect
2.1 Data You Provide Directly
We collect personal data you provide to us, such as:
- account data, including name, email address, organization name, and authentication details,
- profile or workspace settings,
- prompts, instructions, uploaded files, and other content you submit,
- communication data when you contact us, including support requests and feedback,
- billing contact details if you purchase paid features.
2.2 Data From Connected Integrations
If you connect a third-party service, you authorize Lowkey to access and process data from that service in accordance with the permissions you grant and the workflows, automations, or assistant actions you request or configure.
Connected services may include:
- Google Workspace services, such as Gmail, Google Calendar, Google Drive, Google Docs, Google Sheets, and Google Tasks;
- Google Cloud, developer, analytics, and distribution services, such as BigQuery, Firebase, Google Cloud Logging, Google Analytics, and Google Play Console;
- communication, collaboration, project-management, developer, and design services, such as Slack, Microsoft Teams, GitHub, Notion, Linear, and Figma;
- product analytics and social services, such as Mixpanel and X; and
- identity, payments, and financial services, such as Persona, Stripe, PayPal, and Bridge.
Depending on the service and the permissions you grant, integration data may include:
- account and profile identifiers, workspace or organization details, connection status, granted permissions, and authentication tokens;
- emails, attachments, contacts, calendar events, attendees, messages, channels, tasks, comments, and related communication metadata;
- files, documents, spreadsheets, databases, designs, pages, source code, repositories, issues, pull requests, and related content, metadata, and permissions;
- product analytics, application, release, crash, log, cloud-resource, and operational data; and
- identity-verification, payment, transaction, wallet, or other financial data when you choose to use an integration that provides those functions.
Lowkey may read, search, organize, summarize, analyze, create, update, send, or otherwise act on integration data only as needed to provide the user-facing features you request or configure. Some integrations allow actions that change data in the connected service. We perform those actions when you request them, approve them where approval is required, or configure an automation that authorizes them.
We may store connection credentials, configuration, selected source data, and outputs or metadata derived from connected services when needed to maintain the connection, provide conversation history and assistant memory, run automations, preserve workflow state, maintain audit records, support reliability, and secure the Service. We do not necessarily store a complete copy of the connected service.
You control which integrations are connected and can revoke access through your integration settings and/or the third-party provider settings.
Disconnecting or revoking an integration stops new access through that connection, but it may not automatically delete data previously stored in Lowkey. You can request deletion as described in Section 10.
2.3 Google Workspace API Data
When you connect Google Workspace, Lowkey may access Google account identifiers and the Gmail, Calendar, Drive, Docs, Sheets, and Tasks data covered by the permissions you grant. We use this data only to provide and improve the user-facing productivity features you request, such as email assistance, calendar and meeting workflows, document and file workflows, spreadsheet operations, task synchronization, search, summaries, and automations.
Lowkey may store Google authorization credentials, connection metadata, workflow state, and the limited Google Workspace content or derived outputs needed to provide those features, maintain user-requested history or memory, preserve audit records, support reliability, and protect the Service. We retain Google Workspace data only for as long as necessary for those purposes, subject to your settings and applicable legal requirements. We may share Google Workspace data with service providers, including AI processing providers, only when necessary to provide or secure the user-facing features you request, comply with law, or complete another transfer permitted by the Google User Data Policy. We do not sell Google Workspace user data or use it for advertising, retargeting, personalized or interest-based advertising, determining creditworthiness, or lending.
We do not use Google Workspace data to create, train, or improve generalized artificial intelligence or machine learning models. Human access to Google Workspace data is prohibited except with your explicit consent for specific data, when the data is aggregated and anonymized for permitted internal operations, when necessary for security or abuse investigation, or when required by law.
The use of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
For more information, see the Google Workspace User Data and Developer Policy and the Google API Services User Data Policy.
2.4 Usage and Device Data
We automatically collect technical and usage data about how the Service is used, such as:
- IP address and approximate location,
- device and browser type,
- operating system,
- referring pages,
- page views and interaction events,
- timestamps and diagnostic logs.
2.5 Cookies and Similar Technologies
We use cookies and similar technologies to operate the Service and understand product usage.
- Essential cookies are used to run core site functionality.
- Analytics technologies are used only where allowed under applicable law and, where required, after you provide consent.
On our website, Google Analytics and Mixpanel tracking are enabled only after cookie consent is accepted.
3. How We Use Personal Data
We use personal data to:
- provide, maintain, and improve the Service,
- authenticate users and secure accounts,
- execute assistant workflows and automations you request,
- support integrations you enable,
- search, summarize, organize, and act on information in connected services as you direct,
- process payments and manage subscriptions,
- detect, investigate, and prevent fraud, abuse, and security incidents,
- provide customer support and respond to inquiries,
- measure performance and understand usage trends,
- comply with legal obligations and enforce our Terms of Service.
4. Legal Bases for Processing (EEA/UK and Similar Jurisdictions)
Where required by law, we process personal data under one or more of these legal bases:
- Performance of a contract, including providing the Service you request.
- Legitimate interests, such as improving security, preventing abuse, and enhancing product performance.
- Consent, including analytics and other optional processing where consent is required.
- Legal obligations, including compliance with applicable laws and lawful requests.
5. AI and Automation Processing
Lowkey provides AI-powered assistants and automation features. To provide these features, we process your prompts, instructions, connected-service data, and related workflow data. We may transmit the content reasonably necessary to complete your request to AI model and processing providers acting on our behalf.
We use connected-service data to provide the user-facing features you request or configure. Any use of Google Workspace data is additionally subject to Section 2.3.
You are responsible for:
- reviewing generated outputs before relying on them,
- configuring appropriate human oversight for high-impact workflows, and
- ensuring that your use of the Service complies with applicable law and your internal policies.
6. How We Share Personal Data
We may share personal data with the following categories of recipients:
- Service providers that help us operate the Service, such as cloud hosting, AI model and processing, analytics, customer support, authentication, security, and payment processing vendors.
- Integration providers and partners you authorize, when needed to read from or write to connected tools and perform the workflows you request.
- Professional advisors, such as auditors, lawyers, and insurers, where necessary.
- Law enforcement, regulators, courts, or other parties when required by law or to protect rights, safety, and security.
- Buyers or successors in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets.
We do not disclose your personal data to data brokers for their independent marketing databases.
We require service providers to process personal data on our behalf and for the purposes for which we disclose it, subject to contractual and legal obligations. The specific providers involved may depend on the features and integrations you use.
The restrictions in Section 2.3 apply to all sharing and transfers of Google Workspace data. In particular, any transfer of Google Workspace data in connection with a merger, acquisition, or sale of assets will occur only after obtaining the explicit prior consent required by the Google User Data Policy.
7. International Data Transfers
Your personal data may be processed in countries other than your own. Where required, we use appropriate safeguards for cross-border transfers, such as contractual protections and equivalent legal mechanisms.
8. Data Retention
We retain personal data for as long as needed to:
- provide the Service,
- maintain account functionality,
- comply with legal obligations,
- resolve disputes, and
- enforce our agreements.
Retention periods vary by data type, product usage, account status, and legal requirements.
For connected services, we may retain authorization credentials while the integration remains connected and retain selected content, derived outputs, workflow history, memory, and audit records for the periods needed for the purposes described above. Disconnecting an integration prevents new access through that connection. To request deletion of previously retained data, contact us as described in Section 10.
When data is no longer needed, we delete or de-identify it in accordance with our retention processes and applicable law.
9. Security
We use technical and organizational safeguards designed to protect personal data, including measures intended to reduce the risk of unauthorized access, disclosure, alteration, or destruction.
No internet-based system is completely secure, and we cannot guarantee absolute security.
10. Your Privacy Rights and Choices
Depending on where you live, you may have rights to:
- access personal data we hold about you,
- request correction of inaccurate data,
- request deletion of your data,
- object to or restrict certain processing,
- request portability of certain data,
- withdraw consent where processing relies on consent.
You may also:
- update certain account data in your settings,
- disconnect integrations or revoke their permissions through the connected provider,
- request deletion of personal data retained from connected services,
- control cookie preferences via our cookie banner,
- opt out of promotional emails by using unsubscribe links.
To exercise privacy rights, contact us at hi@lowkey.money. We may need to verify your identity before fulfilling certain requests.
11. Children's Privacy
The Service is not directed to children under 18, and we do not knowingly collect personal data from children under 18.
If you believe a child has provided personal data, contact us and we will take appropriate action.
12. Third-Party Sites and Services
The Service may contain links to or integrations with third-party sites and services. Your use of those third-party services remains subject to their own terms and privacy policies. We are not responsible for their independent privacy practices, and you should review their policies directly.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the Effective Date and provide additional notice when appropriate.
Your continued use of the Service after an updated Privacy Policy becomes effective indicates your acknowledgment of the updated policy.
14. Contact Us
Lowkey Technologies Inc
Email: hi@lowkey.money
Website: https://lowkey.money