Summay Privacy Policy
Last updated: July 22, 2025
Overview
The privacy of your data — and it is your data, not ours! — is a big deal to us. At Summay, Inc., we believe your data belongs to you. This Privacy Policy explains how we collect, use, and protect your personal information when you use Sunsama and our related services. We're committed to transparency about our data practices and your privacy rights.
Our promise: We never sell your data. Never have, never will.
This policy applies to all products and services provided by Summay, Inc. ("Summay," "we," "us," or "our"), including our website at sunsama.com, our applications, and any related services (collectively, the "Services").
Last Updated: [DATE]
Table of Contents
- What Information We Collect
- How We Use Your Information
- How We Share Your Information
- Your Rights and Choices
- Data Security
- Data Retention
- International Transfers
- Cookies and Tracking
- AI Features and Data Processing
- Third-Party Services
- Children's Privacy
- Changes to This Policy
- Contact Us
What Information We Collect
We collect only the information necessary to provide and improve our Services. Here's what that includes:
Information You Provide to Us
Account Information: When you create an account, we collect your name, email address, and any other information you choose to provide during registration.
Profile Information: You may choose to add profile details like your photo, time zone, and work preferences to personalize your experience.
Payment Information: If you subscribe to a paid plan, our payment processor (Stripe) handles your payment details. We store only the information necessary for billing, such as your billing email address and the last four digits of your payment method.
Content You Create: This includes your tasks, notes, calendar events, and any other content you add to Sunsama. We access this information only to provide the Services you've requested.
Communications: When you contact our support team or communicate with us, we keep records of those interactions to help provide better service.
Information We Collect Automatically
Usage Data: We collect detailed information about how you use Sunsama, including:
- Which features you access and how frequently
- Time spent in different areas of the app
- User flows and navigation patterns through the Services
- Onboarding completion and feature adoption rates
- Interaction patterns and engagement metrics
Device and Technical Information: We collect information about the devices and technology you use:
- IP address, browser type, operating system, and device identifiers
- Screen resolution, device model, and hardware specifications
- Network information and connection quality
- App version and build information
Performance and Reliability Data: To ensure our Services work properly, we collect:
- Page load times and app performance metrics
- Error messages, crash reports, and diagnostic information
- System performance and resource usage data
- API response times and service availability metrics
Session and Activity Data: We track information about your sessions:
- Session duration and frequency of use
- Pages visited, features used, and user flows
- Referral sources (how you found our website or were directed to specific pages)
- Time zone information (automatically detected and user-configured)
- Login patterns and authentication events
Email and Communication Tracking: When we send you emails:
- Whether you open our emails and when
- Which links you click in our communications
- Email delivery status and bounce information
Integration Usage Analytics: We collect information about your use of integrations:
- Which third-party services you connect to Sunsama
- Frequency and patterns of integration usage
- Integration setup and configuration choices
Mobile App Specific Data: For our mobile applications:
- Push notification tokens and notification interaction data
- Mobile-specific usage patterns and gestures
- Offline usage data that syncs when you reconnect
- Mobile device orientation and accessibility settings
Testing and Feature Data: To improve our Services:
- A/B testing participation and interaction data
- Beta feature usage and feedback
- Feature flag configurations and experiment results
Security and Fraud Prevention: For security purposes:
- Login attempts and authentication patterns
- Suspicious activity detection data
- Security event logs and access patterns
- Account security status and verification information
- Bot protection data collected through Cloudflare Turnstile to prevent automated abuse
Location Information: We may collect general location information (such as country, region, or city) based on your IP address to optimize performance, comply with local laws, and provide region-appropriate features.
Information from Third Parties
Connected Services: When you connect third-party services to Sunsama, we access only the information necessary to provide the integration you've requested. Our authentication methods vary by service:
- OAuth integrations (Google Calendar, Slack, etc.): We never access your passwords - OAuth provides secure authorization without password sharing
- App-specific passwords (Apple Calendar): We store encrypted app-specific passwords that you generate specifically for Sunsama
- API tokens (Monday.com and similar services): We store API tokens that you provide for service integration
Third-Party API Compliance: Our integrations with major service providers follow their respective data usage policies:
- Google Services: Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements
- Microsoft Services: Our integration with Microsoft services follows Microsoft's API terms and data protection requirements
- Other Services: All integrations comply with the respective service providers' terms and data usage policies
Other Sunsama Users: When you join a workspace or accept an invitation:
- We may receive information about you from the person who invited you (name, email address)
- Other team members may share information about you through collaborative features
- You may receive information from other team members through shared workspace content
What We Do NOT Collect
We want to be clear about what we don't collect to protect your privacy:
Protected Characteristics: We do not collect characteristics of protected classifications including age, race, gender, religion, sexual orientation, gender identity, gender expression, or physical and mental abilities or disabilities. You may voluntarily provide some of this information (such as pronouns in your profile), but we do not actively collect it.
Biometric Data: We do not collect fingerprints, face recognition data, or other biometric identifiers.
Profile Picture Analysis: While you can add a profile picture, we do not extract any information from it or analyze its contents. It's solely for your use.
Unnecessary Personal Data: We limit data collection to what's essential for providing our Services. We don't collect personal information for the sake of having more data.
How We Use Your Information
We use your information to provide, improve, and protect our Services:
To Provide Our Services
- Create and manage your account
- Sync and display your tasks, calendar events, and notes
- Enable integrations with third-party services you choose to connect
- Process payments and manage subscriptions
- Provide customer support
To Improve Our Services
- Analyze usage patterns to identify areas for improvement
- Develop new features and functionality
- Conduct research to better understand user needs
- Test and optimize the performance of our Services
To Provide AI-Enhanced Features
- AI Summaries: Generate intelligent summaries of your daily activities and accomplishments
- AI Predictions: Provide suggestions for task planning, including estimated completion times and appropriate categories (channels)
Our Commitment: We Never Train Models on Your Data. Your personal tasks, calendar information, notes, and usage patterns are never used to train AI models - not ours, not third-party providers', not anyone's. Your data is used solely to provide the AI features you've requested for your own account.
To Communicate With You
- Send important updates about your account or our Services
- Respond to your questions and support requests
- Share product updates and new features (you can opt out anytime)
To Ensure Security and Compliance
- Detect and prevent fraud or unauthorized access
- Comply with legal obligations
- Enforce our Terms of Service
- Protect the security and integrity of our Services
We process your information only when we have a lawful basis to do so, such as:
- Contract performance: To provide the Services you've signed up for
- Legitimate interests: To improve our Services and communicate with you
- Consent: When you've given explicit permission
- Legal compliance: To meet our legal obligations
How We Share Your Information
We believe in data minimization. We don't sell your personal information and never will. Here's when we might share it:
With Service Providers
We work with trusted third-party companies that help us provide our Services:
- Cloud hosting: Google Cloud Platform (GCP) and Amazon Web Services (AWS)
- Payment processing: Stripe for handling payments
- Analytics: HyperDX and other analytics providers to understand product usage
- Customer support: Intercom for providing help when you need it
- Email delivery: Various providers for sending transactional and marketing emails
- AI services: Third-party LLMs and inference providers for powering our AI features (such as summaries and predictions)
- Security and bot protection: Cloudflare for DDoS protection, performance optimization, and bot prevention
All service providers are contractually required to protect your information and use it only for the purposes we specify. For AI services specifically: We require that AI service providers do not use your data to train their general models and that they process your information solely to provide the AI features you've requested.
For Legal Reasons
We may disclose information when required by law or when we believe in good faith that disclosure is necessary to:
- Comply with legal process or government requests
- Protect against fraud or other illegal activity
- Investigate security incidents
- Protect the rights, property, or safety of Summay, our users, or others
Law Enforcement Transparency: We are committed to protecting your data from unnecessary government access. If law enforcement approaches us:
- We require proper legal process (warrants, subpoenas, court orders) before sharing any data
- We will notify affected users unless legally prohibited from doing so
- We review all requests and may challenge those we believe are overly broad or improper
- Transparency note: We have never received a National Security Letter or FISA order
In Business Transfers
If Summay is involved in a merger, acquisition, or sale of assets, your information may be transferred. We'll notify you before your information becomes subject to a different privacy policy.
With Your Consent
We may share information in other circumstances when you've given us explicit permission to do so.
Your Rights and Choices
You have control over your personal information. At Summay, we apply the same data rights to all customers, regardless of their location. Currently, some of the most privacy-forward regulations are the EU's GDPR and California's CCPA. We recognize all rights granted in these regulations for all our users. Depending on where you're located, you may have some or all of these rights:
Access and Portability
- Access: Request a copy of the personal information we have about you
- Portability: Get your data in a machine-readable format to transfer to another service
Correction and Deletion
- Correction: Update or correct inaccurate information
- Deletion: Request that we delete your personal information (subject to certain limitations)
Control and Restriction
- Opt-out: Unsubscribe from marketing communications
- Restriction: Limit how we process your information
- Objection: Object to certain types of processing
- AI Features: Disable or limit AI-powered features in your account settings
Account Management
You can manage many of these preferences directly in your account settings at sunsama.com/settings. For other requests, contact us at support@sunsama.com.
Response Time: We aim to respond to all privacy requests within 30 days.
Verification: We may need to verify your identity before processing certain requests to protect your information.
Data Security
Security is fundamental to everything we do. We implement industry-standard safeguards to protect your information:
Technical Safeguards
- Encryption: All data is encrypted in transit and at rest
- Access controls: Strict limits on who can access your information
- Monitoring: Continuous monitoring for security threats
- Regular updates: Systems are kept up-to-date with security patches
Organizational Safeguards
- Employee training: All team members receive security training
- Background checks: Appropriate screening for personnel with data access
- Incident response: Clear procedures for handling security incidents
- Regular audits: Periodic reviews of our security practices
Your Role in Security
- Use strong, unique passwords
- Keep your devices and apps updated
- Report any suspicious activity immediately
No system is 100% secure. While we implement strong protections, we cannot guarantee absolute security. If you believe your account has been compromised, contact us immediately.
Data Retention
We keep your information only as long as necessary:
Active Accounts
While your account is active, we retain your information to provide the Services.
Inactive Accounts
If you don't use Sunsama for an extended period, we may delete your account and associated data after providing reasonable notice.
Account Deletion
When you delete your account:
- We remove your personal information within 30 days
- Some information may be retained in anonymized form for analytics
- Legal or security requirements may require us to retain certain information longer
Backups
Information may persist in our backup systems for up to 90 days after deletion.
International Transfers
Summay is based in the United States, and our primary servers are located here. If you're accessing our Services from outside the US, your information will be transferred to and processed in the United States.
Safeguards for International Transfers
- Adequate protection: We implement appropriate safeguards for international data transfers
- Contractual protections: Service providers outside your country must meet our privacy standards
- Compliance: We comply with applicable data protection laws
Cookies and Tracking
We use cookies and similar technologies to improve your experience:
Types of Cookies We Use
- Essential cookies: Required for the Services to function
- Analytics cookies: Help us understand how you use our Services
- Marketing cookies: Used for advertising on other platforms (with your consent)
Your Cookie Choices
- Browser settings: Most browsers allow you to control cookie settings
- Opt-out: You can opt out of non-essential cookies in your account settings
- Third-party tools: Use tools like Privacy Badger or uBlock Origin to block tracking
AI Features and Data Processing
Sunsama includes AI-powered features designed to enhance your productivity and provide intelligent insights about your work patterns and activities.
Data Used for AI Features
We may use the following types of data to provide AI-enhanced functionality:
- Your task information, including titles and completion patterns
- Work activity data from connected integrations (meetings, task completions, project updates)
- Voice input when you use voice-enabled features
- Historical usage patterns to improve predictions and suggestions
Data Storage and Retention
Short-term Processing: Some AI features require temporary data storage to generate insights. This data is typically retained for 30 days or less and then automatically deleted.
Local Processing: Where possible, AI processing occurs within our secure infrastructure without sharing data externally.
External Processing: Some AI features may use third-party AI service providers. When this occurs, we ensure these providers process your data solely for the requested functionality.
Your AI Data Rights
Control: You can:
- Enable or disable AI features per-integration in your account settings
- Delete AI-generated content and insights
Transparency: We clearly label AI-generated content and provide options to modify or improve AI suggestions.
AI Data Protection Commitments
We Never Train Models on Your Data: Your personal tasks, calendar events, notes, and productivity data are never used to train AI models - not ours, not third-party providers', not anyone's. Your data is used solely to provide AI features for your own account.
Third-Party AI Services: When we use external AI providers:
- They process your data only to provide the specific AI functionality you've requested
- We implement contractual and technical safeguards to protect your data
- Your data is not used to train or improve their general AI models
Security: All AI data processing uses encryption and follows our standard security practices outlined in the Data Security section.
Third-Party Services
Sunsama integrates with various third-party services to enhance your productivity:
Popular Integrations
- Calendar services: Google Calendar, Outlook Calendar
- Communication tools: Slack, Microsoft Teams
- Project management: Asana, Trello, GitHub
- Note-taking: Notion, Evernote
Data Sharing
When you enable an integration:
- We access only the information necessary for the integration to work
- We follow the principle of least privilege
- You can disconnect integrations at any time
Third-Party Policies
Each integrated service has its own privacy policy. We encourage you to review these policies to understand how they handle your data.
Children's Privacy
Sunsama is not intended for children under 16. We don't knowingly collect personal information from children under 16. If we discover we've collected such information, we'll delete it promptly.
If you're a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@sunsama.com.
Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or applicable laws. When we make significant changes:
- We'll notify you via email or through the Services
- We'll provide at least 30 days' notice before changes take effect
- We'll post the updated policy on our website with a new "Last Updated" date
Continued use of our Services after changes take effect means you accept the updated policy.
Contact Us
We're here to help with any privacy questions or concerns:
Email: support@sunsama.com
Phone: +1 (703) 729-158
For EU/UK residents: If you're not satisfied with our response to a privacy request, you have the right to lodge a complaint with your local data protection authority.
Response commitment: We aim to respond to all privacy inquiries within 5 business days.
Additional Information for Specific Regions
California Residents (CCPA/CPRA)
Under the California Consumer Privacy Act, you have specific rights regarding your personal information. In the past 12 months, we may have collected the following categories of personal information:
- Identifiers: Name, email address, IP address
- Commercial information: Purchase history, subscription details
- Internet activity: Usage data, device information
- Professional information: Work-related preferences you choose to share
- AI-generated content: Summaries and predictions created by our AI features
We do not sell your personal information and never have. We may share information with service providers as described above.
European Union/UK Residents (GDPR)
Under the General Data Protection Regulation, you have comprehensive rights regarding your personal data:
- Lawful basis: We process your data based on contract performance, legitimate interests, consent, or legal compliance
- Data Protection Officer: Contact security@sunsama.com for data protection matters
- Supervisory authority: You may lodge complaints with your local data protection authority
Other Jurisdictions
We comply with applicable privacy laws in all jurisdictions where we operate. Contact us for specific information about your local privacy rights.