ClosioClosio

Privacy Policy

Last updated: July 7, 2026

This policy explains what personal data Closio collects, how we use it, and what rights you have. Data controller: Emiko (Poland). Contact: support@emiko.io.

1. What we collect

  • Account info: name, email, Google account ID, company name.
  • Gmail data: sent + received emails on your behalf. Only messages relevant to your sales pipeline.
  • Calendar data: event titles, times, attendees for meeting detection.
  • Meeting transcripts: when you enable the Emiko Notetaker bot, we store the full transcript of that meeting.
  • Lead data: contact details, notes, activity history you import or generate.
  • Usage data: which pages you visit, actions taken, errors encountered. Used only to improve the product.

2. Why we collect it

  • Provide the Closio service (legitimate interest + contract).
  • Authenticate you and secure your account.
  • Send you operational emails (billing, incidents, changes).
  • Improve the product in aggregated, non-identifiable form.

We do NOT sell your data, do NOT use it to train third-party AI models, and do NOT share it for advertising.

2a. Google user data (Limited Use disclosure)

Closio's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, for data obtained through the Gmail and Google Calendar APIs:

  • We only use Gmail and Calendar data to provide the sales-pipeline features you see in the app: sending emails you approve, syncing replies into your pipeline, and detecting meetings with your leads.
  • We do not use Google user data for advertising, do not sell it, and do not use it to train generalized AI or machine-learning models.
  • Humans do not read your Google data except with your explicit permission (e.g. a support request), where required for security or legal compliance, or on aggregated, de-identified data for internal operations.
  • We only transfer Google user data to the processors listed below as necessary to provide the service, never to data brokers or advertisers.

3. Third parties

Closio uses these processors to deliver the service:

  • Anthropic — AI models for drafting emails and analyzing meetings. Data sent to Anthropic is processed under their enterprise no-training terms.
  • Railway — application + database hosting (EU region).
  • Recall.ai — meeting bot + transcription (only when you use the feature; EU region).
  • Google — authentication, Gmail, Calendar APIs.
  • Sentry — error monitoring.

4. Where we store data

Your data is stored in the European Union. We do not transfer personal data outside the EEA except to processors listed above under appropriate safeguards (SCCs or adequacy decisions).

5. Retention

We keep your data while your account is active, plus 30 days after you cancel. You can request earlier deletion at any time.

6. Your rights (GDPR)

  • Access: request a copy of the data we have about you.
  • Rectification: correct inaccurate data.
  • Erasure: delete your account and data.
  • Portability: export your data in a machine-readable format.
  • Objection: opt out of any data processing based on legitimate interest.
  • Complaint: lodge a complaint with your local data-protection authority.

Email support@emiko.io for any of the above — we respond within 30 days.

7. Security

We use encryption in transit (TLS) and at rest, scoped OAuth tokens, row-level workspace isolation, and short-lived session tokens. We never log full transcripts to third parties outside the processors above.

8. Cookies

Closio uses one session cookie (closio_session) to keep you logged in. It is httpOnly, secure, and sameSite=lax. We do not use tracking or advertising cookies.

9. Changes

Material changes to this policy will be notified at least 14 days before taking effect by email.