This Privacy Policy explains how AnyReach Inc. ("AnyReach," "we," "us," "our") collects, uses, and shares information in connection with Oz, our AI teammate product. Oz is part of the AnyReach platform; this policy supplements the general AnyReach Privacy Policy and, for Oz specifically, controls where it differs. By using Oz, you agree to this policy.
1. Scope
This policy covers information processed through Oz, including information from messaging channels (Slack, Microsoft Teams, email), information from services you connect, the conversations and instructions you give Oz, and the persistent memory Oz maintains to assist you. It also explains how we handle information about people who are not Oz users but whose data Oz processes at a customer's direction (Section 9).
2. Our Role: Controller and Processor
Oz is primarily a business product, and our role depends on the data:
- As a processor. For Customer Content and the data Oz accesses from your Connected Services—including conversations, connected-account content, memory derived from your use, and Third-Party Data—we act as a processor (or service provider) that processes data on behalf of, and under the instructions of, our customer (the organization), who is the controller. Our processing of that data is governed by the Oz Terms and any Data Processing Addendum.
- As a controller. For account, authentication, billing, security, and product-usage information we collect to operate and improve Oz and manage our relationship with you, we act as a controller.
If you are an individual user within a customer organization and want to exercise rights over data we process as a processor, please contact your organization; we will support the controller in responding (Section 12).
3. Information We Collect
a. Account and identity information. Because Oz uses single sign-on, when you sign in through Google, Microsoft/Outlook, Microsoft Teams, or Slack, we receive identity information from that provider, such as your name, email address, profile image, locale, and organization/workspace identifiers. We do not create or store passwords for Oz.
b. Connected-service data. When you authorize Oz to connect to a service (such as email, calendar, CRM, file storage, or a messaging platform), Oz accesses data from that service as needed to perform your requested tasks—for example, messages, calendar events, contacts, files, and records. The scope depends on the permissions you grant and can be changed or revoked by you.
c. Conversations and instructions. The messages, prompts, instructions, uploads, and approvals you provide to Oz across channels.
d. Memory and derived data. To personalize its assistance, Oz maintains a persistent memory and may derive profiles, preferences, summaries, and "skills" from your use. This data is isolated to your organization and used to serve you (Section 6).
e. Usage and device data. Automatically collected information such as IP address, browser/device type, pages and features used, timestamps, and diagnostic logs.
f. Payment information. When you purchase a plan or credits, our payment processor collects and processes your payment details. We do not store full payment-card numbers; we retain limited information such as card brand, last four digits, and billing status.
g. Third-party data. Personal data about individuals who are not Oz users but who appear in your Connected Services or conversations, or whom you engage with Oz (Section 9).
h. Cookies and similar technologies. We use cookies and similar technologies for authentication, preferences, security, and analytics. You can manage cookies through your browser settings; some features may not work without them.
4. How We Use Information
We use information to:
- provide, operate, maintain, secure, and improve Oz;
- perform the tasks and actions you direct Oz to carry out, including accessing Connected Services and generating outputs;
- personalize your experience through Oz's memory and learned skills;
- authenticate users and manage organizations, roles, and access;
- process transactions, billing, credits, and usage metering;
- communicate with you about your account, security, and—where permitted—product updates and marketing (you can opt out of marketing);
- monitor usage and trends, and detect, prevent, and address security incidents, fraud, and abuse; and
- comply with legal obligations and enforce our terms.
Where required, our legal bases include performance of a contract, your consent, our legitimate interests in operating and securing the Service, and compliance with law.
5. Connected Services
Oz accesses Connected Services only at your direction and only to the extent needed to provide the features you use. We do not access Connected Services for purposes unrelated to providing Oz. You control which services are connected and the scopes granted, and you can disconnect at any time, which stops further access (data already processed may persist as described in Section 10). Your use of each Connected Service remains subject to that provider's own privacy policy.
### Google Calendar conferencing add-on
When you install and use Oz Meeting for Google Calendar, the add-on processes a Google-signed user identifier and verified email address to connect you to an active Oz workspace. It reads Calendar identifiers, event identifiers and version markers, title and description, start and end times, time zone, and conference status for the events needed to create an Oz meeting and keep that meeting aligned with event changes or cancellation. A bounded Calendar synchronization can inspect nearby event changes locally in Apps Script, but only events already bound to an Oz conference are sent to the Oz service for update or cancellation. Event titles and descriptions for those bound events may be used as room context and included in an AI-generated pre-call brief when that Oz meeting starts.
Apps Script User Properties store per-user synchronization tokens and event-to-conference binding identifiers. The Oz service stores the Google subject-to-Oz-workspace binding and the event, occurrence, and conference metadata needed to provide a stable, revocable joining link. A short-lived account-link handoff is deleted as soon as it is used, and expired handoffs are purged. Google identity bearer tokens are verified for each request and are not logged or stored. We use this Google user data only to authenticate the user, provision and synchronize the requested Oz conference, secure the service, and provide support. We do not sell it, use it for advertising, or use it to train public or shared foundation models. It is shared only with Google at your direction and with the service providers described in Sections 6–8 under their contractual protections.
Uninstalling the add-on or revoking its Google permissions stops future Calendar access and synchronization. An authenticated user can also manage or disconnect Google Calendar. Disconnecting removes the Google-to-Oz binding, cancels active conferences in the selected workspace, and strips Calendar identifiers, titles, descriptions, and timing metadata from the retained revocation records. Separate Oz meeting records and recaps follow the account and Customer Content retention rules in Section 10. You or your organization can also request access or deletion at support@anyreach.ai.
AnyReach's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
6. AI Processing & Third-Party Services
AI Service Provider. Oz is developed and operated by AnyReach Inc. ("Anyreach"). When you use Oz, the following data is transmitted to Anyreach's servers to generate responses and complete tasks on your behalf:
- Messages you send to Oz and conversations you have with Oz
- Files, images, and documents you upload or share with Oz
- Your account information (name, email address, workspace membership)
- Contact and conversation metadata Oz accesses to work on your behalf (email threads, Slack messages, call transcripts)
How Anyreach uses your data:
- To generate AI responses, drafts, summaries, and completed work
- To personalize Oz's understanding of your preferences, voice, and priorities
- To improve the Oz service (e.g., reliability, feature development)
What Anyreach does NOT do:
- Your data is never sold to third parties
- Your data is never used to train public AI models
- Your data is never shared with other Anyreach customers
All data is encrypted in transit (TLS) and at rest. You can request deletion of your data at any time by contacting support@anyreach.ai.
Consent. Before Oz sends any data to Anyreach's AI service, the app presents a one-time consent screen that explains what data is shared and requires your explicit approval. You can withdraw consent at any time by signing out of Oz.
AI Model Processing. To generate outputs, relevant Customer Content and conversation data are transmitted to Anyreach's AI model provider for processing:
- No training of foundation models on your content. We do not use Customer Content to train foundation AI models, and our AI model provider does not use content transmitted through its commercial interface to train its foundation models.
- Per-customer learning is isolated. Oz's memory and skills learning improves Oz's assistance to you and your organization only. It is logically isolated to your organization and is not used to benefit other customers or to train shared or foundation models.
- De-identified, aggregated data. We may use de-identified and aggregated data (which cannot reasonably be used to identify you, your organization, or any individual) to operate, analyze, and improve the Service.
You can view and delete items from Oz's memory through the product (Section 12).
7. How We Share Information
We share information only as described here:
- Subprocessors. With vendors who process data on our behalf to provide Oz, under contracts requiring appropriate protection (Section 11).
- At your direction. With Connected Services and recipients when you instruct Oz to act (for example, sending an email or updating a record).
- Within your organization. Consistent with the roles and sharing settings configured by your organization.
- Legal and safety. When required by law or legal process, or to protect rights, safety, and the integrity of the Service.
- Business transfers. In connection with a merger, acquisition, financing, or sale of assets, with notice as required by law.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not sell or share mobile numbers or messaging opt-in status.
8. Subprocessors
We use a limited set of subprocessors to provide Oz, which may include providers for: AI model processing, third-party integration/connectivity, identity and authentication, payment processing, cloud hosting and infrastructure, email and messaging delivery, and analytics and error monitoring. We maintain a current list of subprocessors available on request (and, for business customers, as part of the DPA), and we require subprocessors to provide appropriate data protection.
9. Third-Party (Non-User) Data
Oz may process personal data about individuals who are not Oz users—for example, people you email, people copied on a thread Oz participates in, contacts in a connected CRM, or participants in a conversation Oz is part of.
- Source and basis. We process this data on behalf of, and at the instruction of, our customer (the controller), who is responsible for having a lawful basis and any required notices or consents. We process it only to provide Oz's features in that context.
- Engaged participants. Where a customer's Oz interacts with someone the customer has engaged (such as a person copied on an email or a participant in a thread), that interaction is limited to the relevant conversation and the information the customer has shared into it. It does not grant that person access to the customer's other data, and we apply controls to keep organizations' data separated.
- Requests from non-users. If you are a non-user and want to access or delete personal data Oz processes about you, contact us at the address below; because we typically act as a processor for such data, we will refer your request to the relevant controller and assist them in responding.
10. Data Retention
We retain personal data only as long as necessary for the purposes described here or as required by law. In general: account and memory data are retained while your account is active; upon account closure or contract termination, we make Customer Content available for export for a limited period and then delete or de-identify it, subject to legal retention requirements and backup cycles. Connected-service data is retained only as needed to provide the relevant features. Where applicable, SMS/messaging consent logs are retained for two (2) years.
11. Security and Data Isolation
We implement reasonable administrative, technical, and organizational safeguards designed to protect information, including encryption in transit, access controls, single sign-on authentication, and logical isolation of each organization's data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Your Rights and Choices
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, or object to processing of your personal data, to data portability, and to withdraw consent. You also may have the right not to be discriminated against for exercising these rights.
- Account holders: you can manage your profile, preferences, connected services, and memory directly in Oz, and opt out of marketing communications.
- To exercise statutory rights as a controller's data subject, contact your organization; we will assist the controller. For data we control, contact us at support@anyreach.ai.
- We will verify requests as required and respond within the timeframes required by applicable law. You may also have the right to lodge a complaint with a supervisory authority.
13. International Data Transfers
We may process and store information in countries other than your own, including the United States, which may have different data-protection laws. Where required, we use appropriate safeguards (such as Standard Contractual Clauses) for international transfers.
14. Messaging and SMS
If you provide a mobile number and opt in, you consent to receive text messages from AnyReach; message frequency varies and carrier message/data rates may apply. The opt-in workflow is documented at anyreach.ai/sms-optin. You may revoke consent at any time by replying STOP; reply HELP or email support@anyreach.ai for assistance. We do not sell or share your mobile number or opt-in status with third parties for their own marketing.
15. Children's Privacy
Oz is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their personal information. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.
16. Third-Party Links and Services
Oz may reference or link to third-party sites and services, including Connected Services. We are not responsible for their privacy practices. Review their policies before providing information.
17. Changes to This Policy
We may update this Privacy Policy from time to time. We will post material changes in the product or notify you by email or other reasonable means, and update the "Last Updated" date. Continued use of Oz after changes take effect constitutes acceptance.
18. Contact Us and Data Processing Addendum
Privacy questions, requests, or to request our Data Processing Addendum or subprocessor list: support@anyreach.ai · AnyReach Inc. · 11596 Southwood Dr, Saratoga, CA 95070.

