Data use and AI

The data we handle, the data sent to AI, and the limits on its use.

01

What data can Graph One hold?

We can hold account data, connected work data, professional profile data, and results made from it.

  • Account and sign-in data, such as name, email, and account IDs.
  • Email headers and labels, calendar events, contacts, and connected account details.
  • Professional profile, employer, role, and social connection data.
  • User-made lists, notes, searches, sharing rules, and app settings.
  • Results such as merged identities, relationship strength, paths, and suggested matches.
  • Support, security, and service logs.
02

Does Graph One read email content?

By default, we read email headers and labels, not the body. A user can grant wider access for a feature that needs content.

The default Google scope is gmail.metadata. The default Microsoft scope is Mail.ReadBasic. Both exclude the email body.

We also support clear, feature-led permission upgrades. A wider read scope can let a feature read and store body text. The user sees the added permission in the provider consent step.

03

What calendar data can Graph One read?

By default, we can read calendar events but cannot change them.

Event data can include the title, times, attendees, organizer, location, status, and event text supplied by Google or Microsoft. We use it to find people and relationship signals.

04

Does Graph One add data from other sources?

Yes. We can add professional data from public or paid sources when a feature needs it.

A lookup may send a name, work email, company, domain, or profile clue to an enrichment or search provider. We use the result to fill gaps or improve a match.

The providers page lists the services used for this work.

05

Which AI providers process customer data, and when?

AI search uses OpenAI and Google Gemini. For identity matching, OpenRouter processes names and email addresses from connected accounts.

We do not send any other email metadata or body content, or any calendar event metadata or text, to AI providers.

Current AI provider data handling

Provider
When used
Data that may be sent
Retention and logging
Training or improvement
OpenAI API Search query parsing and company discovery User query and fixed instructions; one company search request can use OpenAI web search Abuse-monitoring logs may hold content for up to 30 days. No other response state is stored. Not used for training or service improvement.
Google Gemini API Person and company result ranking User query and search criteria Google logs paid-service prompts and responses for a limited period for abuse checks. Not used for training or service improvement.
OpenRouter Identity matching. OpenRouter routes requests to approved providers only where they offer zero data retention (ZDR) and do not use prompts or responses for training. These include OpenAI models running on Microsoft Azure or Amazon Bedrock, as well as models from xAI or Z.ai Names and email addresses from connected accounts OpenRouter and the model endpoint do not retain prompts or responses. OpenRouter stores request metadata. Its DPA says it deletes other customer data from datastores and backups within 30 business days of a request. Not used for training or service improvement.
06

Is customer data used for AI training or improvement?

AI providers do not use customer data for training or service improvement. Graph One may use some names and email addresses from connected accounts to test and improve its own identity-matching system.

OpenAI, Google Gemini, OpenRouter, and the model endpoints used through OpenRouter do not use the customer data we send them for training or service improvement.

We may use some names and email addresses from connected accounts to test and improve our own identity-matching system. This does not train or improve a provider's model.

08

What product and website analytics run?

We use Google Analytics on the website and PostHog's EU cloud in the product.

Product events can include account and use details such as email, name, connected account count, and setup state. Cookie choices and the public cookie policy govern website tracking.