ClosioClosio

Privacy Policy

Last updated: July 7, 2026

This policy explains what personal data Closio collects, how we use it, and what rights you have. Data controller: Emiko (Poland). Contact: support@emiko.io.

1. What we collect

  • Account info: name, email, the Google or Microsoft account ID you sign in with, profile photo, company name.
  • Mailbox data: emails sent and received on your behalf, through Gmail or Outlook. By default we read only messages relevant to your sales pipeline; you can widen or narrow that in Settings.
  • Calendar data: event titles, times, attendees for meeting detection.
  • Meeting transcripts: when you enable the Emiko Notetaker bot, we store the full transcript of that meeting.
  • Lead data: contact details, notes, activity history you import or generate.
  • LinkedIn data: if you connect LinkedIn, the invites and messages sent on your behalf and the replies to them.
  • Usage data: which pages you visit, actions taken, errors encountered. Used only to improve the product.

2. Why we collect it

  • Provide the Closio service (legitimate interest + contract).
  • Authenticate you and secure your account.
  • Send you operational emails (billing, incidents, changes).
  • Improve the product in aggregated, non-identifiable form.

We do NOT sell your data, do NOT use it to train third-party AI models, and do NOT share it for advertising.

2a. Google user data (Limited Use disclosure)

Closio's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, for data obtained through the Gmail and Google Calendar APIs:

  • We only use Gmail and Calendar data to provide the sales-pipeline features you see in the app: sending emails you approve, syncing replies into your pipeline, and detecting meetings with your leads.
  • We do not use Google user data for advertising, do not sell it, and do not use it to train generalized AI or machine-learning models.
  • Humans do not read your Google data except with your explicit permission (e.g. a support request), where required for security or legal compliance, or on aggregated, de-identified data for internal operations.
  • We only transfer Google user data to the processors listed below as necessary to provide the service, never to data brokers or advertisers.

3. Third parties

Closio uses these processors to deliver the service:

  • Anthropic — AI models for drafting emails and analyzing meetings. Data sent to Anthropic is processed under their enterprise no-training terms.
  • Railway — application + database hosting (EU region).
  • Google and Microsoft — authentication, and the mailbox and calendar APIs you connect.
  • A business contact-data provider — the source of the prospects we find for you from licensed business data.
  • A mailbox and domain provider — where we set up a sending address for you on a domain we own.
  • A LinkedIn integration provider — where you connect LinkedIn, to send invites and messages on your behalf.
  • Sentry — error monitoring.

We name the categories here rather than the vendors. Write to support@emiko.io for the current named list, which we will also send you before we add anyone to it.

3a. People we contact on your behalf

Closio also holds data about people who never signed up to Closio: the prospects our customers reach out to. For that data the customer is the controller and we act on their instructions. We hold business contact details — name, role, company, work email, public professional profile — obtained from licensed business databases and public sources, and we use them only to send that customer's outreach and to match the replies.

Every email we send carries a one-click unsubscribe. Anyone who unsubscribes, or replies asking to stop, is suppressed permanently for that customer and is not contacted again. If you have been contacted through Closio and want your data removed, email support@emiko.io and we will act on it directly, and pass it to the customer who contacted you.

4. Where we store data

Your data is stored in the European Union. We do not transfer personal data outside the EEA except to processors listed above under appropriate safeguards (SCCs or adequacy decisions).

5. Retention

We keep your data while your account is active, plus 30 days after you cancel. You can request earlier deletion at any time.

6. Your rights (GDPR)

  • Access: request a copy of the data we have about you.
  • Rectification: correct inaccurate data.
  • Erasure: delete your account and data.
  • Portability: export your data in a machine-readable format.
  • Objection: opt out of any data processing based on legitimate interest.
  • Complaint: lodge a complaint with your local data-protection authority.

Email support@emiko.io for any of the above, we respond within 30 days.

7. Security

We use encryption in transit (TLS) and at rest, scoped OAuth tokens, row-level workspace isolation, and short-lived session tokens. We never log full transcripts to third parties outside the processors above.

8. Cookies

Closio uses one session cookie (closio_session) to keep you logged in. It is httpOnly, secure, and sameSite=lax. We do not use tracking or advertising cookies.

9. Changes

Material changes to this policy will be notified at least 14 days before taking effect by email.