Privacy Policy for VirgoFlow AI and MemoKit
Last Updated: September 30, 2026
VirgoFlow AI (VirgoFlow) provides a customizable business management and customer relationship management (CRM) service. This Privacy Policy explains how we collect, use, and protect your information, including when you connect Google Calendar or Google Contacts to VirgoFlow and when you use MemoKit, our companion application for existing VirgoFlow subscribers. MemoKit is operated by Yair Shiloach. Sections 1–6 describe Google integrations; the additional MemoKit information is set out in sections 7–9. Google-derived information processed in MemoKit remains subject to the Google-data restrictions above.
1. Google Connections and Data Accessed
When you authorize a Google connection, VirgoFlow requests permissions for that integration. These connections use Google Calendar, Google Contacts, and account email permissions. The information involved depends on the connection and the records being synchronized:
- Connected account: We obtain your Google account email address to identify the account connected to the integration. We also receive OAuth access and refresh tokens so the connection can continue to work, including background synchronization, without asking you to authorize every request.
- Calendar selection: We read the list of calendars you can edit or own, including their identifiers, names, primary-calendar status, and colors, so you can select a calendar to synchronize.
- Calendar events: For the selected calendar, synchronization processes event titles, descriptions, start and end dates and times, all-day status, locations, colors, and event identifiers. It also processes attendee names and email addresses, invitation responses, and organizer and optional-attendee indicators when present. Imported event information is stored in your VirgoFlow calendar together with identifiers needed to keep the two systems synchronized.
- Contacts sent to Google: When you sync a CRM contact, VirgoFlow sends contact information from that CRM record to Google. Depending on the fields present, this can include the name, phone numbers, email address, company, address, and notes. Creating a Google contact can also include a birthday and tax or external identifiers when these are present in the CRM record.
- Contact information received from Google: When updating a linked contact, VirgoFlow reads its name, email addresses, phone numbers, company, addresses, and notes or biography, together with its record version, to carry out the update. We use Google contact identifiers to associate it with the CRM record. The returned field values are not imported into the CRM contact, and this integration does not import your entire Google address book into VirgoFlow.
- Synchronization records: We store linked Google record identifiers, synchronization times, status, and error or activity logs to track synchronization and troubleshoot failures. Operational logs may also contain event information, such as an event title and start time.
2. How the Integrations Use Your Data
We use this information to provide the connected features:
- Identify the connected Google account and maintain the connection you authorized.
- Synchronize events between your selected Google Calendar and VirgoFlow. This includes creating, updating, and deleting events in Google when corresponding changes are made in VirgoFlow, and importing changes from Google into VirgoFlow. An event canceled in Google is marked as deleted in VirgoFlow.
- Process background calendar changes through Google change notifications and synchronization requests while the connection is active.
- Create or update a Google contact from a CRM contact when you use the contact synchronization action or run an automation configured to do so.
- Use synchronized calendar records in workflows you configure, such as including event details in a message or sending them to a service you select through a webhook.
Event guests: When VirgoFlow creates, updates, or deletes a Google Calendar event, it requests that Google notify the event's guests. Google may send invitations, updates, or cancellation notices to those guests, sharing the relevant event information with them.
AI processing: If you provide Google-derived information in an AI conversation or another AI feature, that content is processed to respond to your request. The processing may involve AI service providers, and conversation history may store the content and related tool inputs and outputs.
No model training: We do not use Google user data to train, retrain, or improve machine learning or AI models. We do not use data obtained through Google Workspace APIs to develop, improve, or train generalized or non-personalized AI or machine learning models. Any AI processing of Google-derived information remains subject to the Limited Use restrictions below.
3. Data Sharing
We do not sell, trade, or rent your Google user data to third parties. We use service providers for hosting, database storage, integration processing, and background synchronization. These providers process the information needed to operate those features, which can include event content as well as connection and synchronization records. AI service providers process content when you supply it to an AI feature as described above.
Information is also shared with Google to perform the contact and calendar actions you enable, with event guests through Google's notifications, and with recipients or services selected in workflows you configure. These transfers are limited to providing the features you request and remain subject to the Google API Services User Data Policy and its Limited Use requirements. Google user data is not used or transferred for advertising, data brokerage, or creditworthiness or lending decisions.
4. Data Storage & Protection
We store synchronized CRM records and integration information in our application database. OAuth access and refresh tokens are kept separately in a secrets vault for use by the integration services. We use HTTPS to communicate with Google APIs and access controls to restrict access to application data. Background processing services handle synchronization jobs, and operational logs help diagnose errors. These measures are intended to protect against unauthorized access, alteration, or destruction of your information.
5. Data Retention & Deletion
We retain your Google user data only for as long as necessary to provide you with our services.
Disconnecting an integration: You can disconnect Google Calendar or Google Contacts in VirgoFlow's integration settings. Disconnecting the integration is separate from deleting records that have already been synchronized or revoking access in your Google account. In particular, disconnecting does not delete events or contacts already copied to Google, or imported calendar records already stored in VirgoFlow.
Revoking Google access: You can review and remove VirgoFlow's access through your Google Account connections. Revoking access prevents further authorized access through that connection; it does not itself delete previously stored copies of your information.
Deletion: You may request the deletion of your data at any time by contacting us at support@virgoflow.ai.
Upon request, we will delete all associated user data from our active databases within 30 days.
6. Compliance with Google Policies
VirgoFlow AI's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
7. MemoKit: Information and Purposes
MemoKit connects your existing VirgoFlow account to the workspaces and AI agents available to you. Access depends on your account and workspace permissions. We process the following information to provide these features:
- Account and access information: Your email address, user identifier, available profile information, workspace membership and permissions are used to authenticate you and determine what you can access. Sign-in credentials and verification codes are processed by the VirgoFlow authentication service.
- Conversations: Messages, agent responses, conversation titles, tool results, requests for approval and your decisions are processed and stored to provide answers, carry out requested actions and continue conversations.
- Files you attach: Selected images and PDF documents are uploaded and stored with the conversation. Their contents may be processed as part of your request.
- Audio and transcription: When you record audio for transcription, the recording is sent through our service to a transcription provider. The returned text is presented as a draft for you to review and edit. The conversation history does not include the original recording merely because it was transcribed; text you send is stored as a message.
- Workspace information: Agents may retrieve and process business information, such as tasks, leads or inventory, within the permissions of your account and the available tools. Information returned by tools can become part of the conversation and its context.
- Preferences and operational information: Display preferences, model selections and working preferences you ask the service to remember support your use of the application. Request and conversation identifiers, errors, response times and model usage information support operation and troubleshooting.
8. MemoKit: AI Processing and Device Access
MemoKit uses our application and agent services, together with providers of authentication, hosting, storage and AI processing. Relevant messages, conversation context, attached content and information returned by tools may be sent to AI providers to answer requests or perform supporting tasks such as creating conversation titles and routing requests. Recorded audio is sent for transcription when you use that feature. The provider used for a supporting task can differ from the model selected for the conversation. Processing takes place on servers, not solely on your device.
This policy describes processing; accepting general terms is not a substitute for any separate permission required to share personal information with third-party AI services. The Google-data restrictions in sections 2, 3 and 6 also apply when that information is included in a MemoKit request.
Microphone access is used for recordings you initiate. File and image pickers let you select attachments. You can change device permissions in your device settings and type a message without using the microphone. The native application stores session information using secure device storage so you can remain signed in; display preferences are stored locally. Server-side access checks restrict access to conversations and files by user and workspace.
9. MemoKit: Stored Information and Privacy Requests
Conversations and attachments are stored on our servers to support conversation history and continued use. Signing out or uninstalling MemoKit does not delete that history or your VirgoFlow account. Ending access to a subscription and requesting deletion of stored information are separate matters.
For questions about MemoKit, requests to access or correct your information, deletion requests, or requests concerning permission to process your information with AI, contact me@yair.ai. Please identify the account and describe your request without including your password or verification codes. We may need to verify your identity and authority over the information. Requests involving an organization's shared workspace may require coordination with its authorized administrator. Removing information needed by a feature can affect your ability to continue using that feature.
For Google integration privacy and deletion requests, the contact channel and commitments in section 5 continue to apply. Contact us if you need help identifying which service holds the information concerned.