Privacy Policy for VirgoFlow AI and MemoKit

Last Updated: September 30, 2026

VirgoFlow AI (VirgoFlow) provides a customizable business management and customer relationship management (CRM) service. This Privacy Policy explains how we collect, use, and protect your information, including when you connect Google Calendar or Google Contacts to VirgoFlow and when you use MemoKit, our companion application for existing VirgoFlow subscribers. MemoKit is operated by Yair Shiloach. Sections 1–6 describe Google integrations; the additional MemoKit information is set out in sections 7–9. Google-derived information processed in MemoKit remains subject to the Google-data restrictions above.

1. Google Connections and Data Accessed

When you authorize a Google connection, VirgoFlow requests permissions for that integration. These connections use Google Calendar, Google Contacts, and account email permissions. The information involved depends on the connection and the records being synchronized:

2. How the Integrations Use Your Data

We use this information to provide the connected features:

Event guests: When VirgoFlow creates, updates, or deletes a Google Calendar event, it requests that Google notify the event's guests. Google may send invitations, updates, or cancellation notices to those guests, sharing the relevant event information with them.

AI processing: If you provide Google-derived information in an AI conversation or another AI feature, that content is processed to respond to your request. The processing may involve AI service providers, and conversation history may store the content and related tool inputs and outputs.

No model training: We do not use Google user data to train, retrain, or improve machine learning or AI models. We do not use data obtained through Google Workspace APIs to develop, improve, or train generalized or non-personalized AI or machine learning models. Any AI processing of Google-derived information remains subject to the Limited Use restrictions below.

3. Data Sharing

We do not sell, trade, or rent your Google user data to third parties. We use service providers for hosting, database storage, integration processing, and background synchronization. These providers process the information needed to operate those features, which can include event content as well as connection and synchronization records. AI service providers process content when you supply it to an AI feature as described above.

Information is also shared with Google to perform the contact and calendar actions you enable, with event guests through Google's notifications, and with recipients or services selected in workflows you configure. These transfers are limited to providing the features you request and remain subject to the Google API Services User Data Policy and its Limited Use requirements. Google user data is not used or transferred for advertising, data brokerage, or creditworthiness or lending decisions.

4. Data Storage & Protection

We store synchronized CRM records and integration information in our application database. OAuth access and refresh tokens are kept separately in a secrets vault for use by the integration services. We use HTTPS to communicate with Google APIs and access controls to restrict access to application data. Background processing services handle synchronization jobs, and operational logs help diagnose errors. These measures are intended to protect against unauthorized access, alteration, or destruction of your information.

5. Data Retention & Deletion

We retain your Google user data only for as long as necessary to provide you with our services.

Disconnecting an integration: You can disconnect Google Calendar or Google Contacts in VirgoFlow's integration settings. Disconnecting the integration is separate from deleting records that have already been synchronized or revoking access in your Google account. In particular, disconnecting does not delete events or contacts already copied to Google, or imported calendar records already stored in VirgoFlow.

Revoking Google access: You can review and remove VirgoFlow's access through your Google Account connections. Revoking access prevents further authorized access through that connection; it does not itself delete previously stored copies of your information.

Deletion: You may request the deletion of your data at any time by contacting us at support@virgoflow.ai.

Upon request, we will delete all associated user data from our active databases within 30 days.

6. Compliance with Google Policies

VirgoFlow AI's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

7. MemoKit: Information and Purposes

MemoKit connects your existing VirgoFlow account to the workspaces and AI agents available to you. Access depends on your account and workspace permissions. We process the following information to provide these features:

8. MemoKit: AI Processing and Device Access

MemoKit uses our application and agent services, together with providers of authentication, hosting, storage and AI processing. Relevant messages, conversation context, attached content and information returned by tools may be sent to AI providers to answer requests or perform supporting tasks such as creating conversation titles and routing requests. Recorded audio is sent for transcription when you use that feature. The provider used for a supporting task can differ from the model selected for the conversation. Processing takes place on servers, not solely on your device.

This policy describes processing; accepting general terms is not a substitute for any separate permission required to share personal information with third-party AI services. The Google-data restrictions in sections 2, 3 and 6 also apply when that information is included in a MemoKit request.

Microphone access is used for recordings you initiate. File and image pickers let you select attachments. You can change device permissions in your device settings and type a message without using the microphone. The native application stores session information using secure device storage so you can remain signed in; display preferences are stored locally. Server-side access checks restrict access to conversations and files by user and workspace.

9. MemoKit: Stored Information and Privacy Requests

Conversations and attachments are stored on our servers to support conversation history and continued use. Signing out or uninstalling MemoKit does not delete that history or your VirgoFlow account. Ending access to a subscription and requesting deletion of stored information are separate matters.

For questions about MemoKit, requests to access or correct your information, deletion requests, or requests concerning permission to process your information with AI, contact me@yair.ai. Please identify the account and describe your request without including your password or verification codes. We may need to verify your identity and authority over the information. Requests involving an organization's shared workspace may require coordination with its authorized administrator. Removing information needed by a feature can affect your ability to continue using that feature.

For Google integration privacy and deletion requests, the contact channel and commitments in section 5 continue to apply. Contact us if you need help identifying which service holds the information concerned.