Data use and AI

The data we handle, the data sent to AI, and the limits on its use.

01

What data can Graph One hold?

We can hold account data, connected work data, professional profile data, and results made from it.

  • Account and sign-in data, such as name, email, and account IDs.
  • Email headers and labels, calendar events, contacts, and connected account details.
  • Professional profile, employer, role, and social connection data.
  • User-made lists, notes, searches, sharing rules, and app settings.
  • Results such as merged identities, relationship strength, paths, and suggested matches.
  • Support, security, and service logs.
02

Does Graph One read email content?

By default, we read email headers and labels, not the body. A user can grant wider access for a feature that needs content.

The default Google scope is gmail.metadata. The default Microsoft scope is Mail.ReadBasic. Both exclude the email body.

We also support clear, feature-led permission upgrades. A wider read scope can let a feature read and store body text. The user sees the added permission in the provider consent step.

03

What calendar data can Graph One read?

By default, we can read calendar events but cannot change them.

Event data can include the title, times, attendees, organizer, location, status, and event text supplied by Google or Microsoft. We use it to find people and relationship signals.

04

Does Graph One add data from other sources?

Yes. We can add professional data from public or paid sources when a feature needs it.

A lookup may send a name, work email, company, domain, or profile clue to an enrichment or search provider. We use the result to fill gaps or improve a match.

The providers page lists the services used for this work.

05

What data does Graph One send to AI services?

Our AI search sends the user's query and selected professional profile or company fields.

OpenAI or Google Gemini can use those inputs to turn a plain-language request into search terms and to rank the result. The user decides what to do with the result.

The current AI search path does not send email bodies or calendar events.

AI services used by current search code

Provider
Use
Data sent
OpenAI Search and result checks Query and selected profile or company context
Google Gemini Search and result checks Query and selected profile or company context
06

Is connected data used to train public AI models?

No. We do not use connected user data to develop, improve, or train public AI models.

We send only the inputs needed for the feature to the named AI provider. We do not use Google user data to develop, improve, or train AI or machine-learning models.

Our DPA and the provider terms set the rules for each provider's use and retention of that data.

07

What product and website analytics run?

We use Google Analytics on the website and PostHog's EU cloud in the product.

Product events can include account and use details such as email, name, connected account count, and setup state. Cookie choices and the public cookie policy govern website tracking.