Privacy Policy
Last updated 13 July 2026
This policy explains what personal data Pilota (“Pilota”, “we”, “us”) collects, how we use it, and the choices and rights you have. Pilota is a calm, AI-assisted task cockpit that scores your tasks, plans your day against your calendar, and helps you triage messages from the tools you connect. Pilota is operated by Pilota ApS, Danneskiold-Samsøes Allé 41, 1434 Copenhagen, Denmark. If you are in the EU/EEA or UK, we act as the data controller for the data described here.
Pilota is currently in an invite-only beta with a limited number of users. During the beta, accounts you connect (particularly Google) may need to be reconnected periodically.
1. Information we collect
Information you give us
- Account details — your email address (used to sign in via a magic link or Google) and your display name.
- Your content — the tasks, goals, notes/captures, tags, and preferences you create, and your saved assistant conversations (currently the focus copilot; Ask Pilota panel chats are not stored).
Information from services you connect
When you connect Gmail, Google Calendar, Microsoft (Outlook mail, calendar and Teams), or Slack, Pilota reads a limited, read-only slice of your data to power the relevant screen. A crucial distinction:
- We display this content live and do not store it. Email headers (sender, subject, date), a short mail preview line, calendar events, Slack direct messages and messages that @-mention you, and your Teams chats are fetched from the provider each time you open the screen and are shown in your browser — they are not written to our database.
- The one exception is what you choose to save. If you turn an email or message into a task, the task title and any details you keep are stored as your own task content — because you asked us to create it.
- Connection credentials.To fetch on your behalf we store the connected account’s address/label, the read-only permissions you granted, and the access/refresh tokens — which are encrypted at restand only ever used on our servers (see “How we protect your data”).
Information we collect automatically
We keep minimal server and security logs (such as timestamps and error events) needed to run the service reliably and safely. We do not use third-party advertising or cross-site tracking.
2. The permissions we request
We ask only for read-only access, and only for the tools you choose to connect:
- Google Calendar —
calendar.readonly(view your events). - Gmail —
gmail.metadata(message headers only: sender, subject, date and labels — never the body of your emails). - Microsoft —
Mail.Read,Calendars.ReadandChat.Read(one Microsoft consent covers Outlook mail, calendar and Teams chats). - Slack — reading your direct messages and messages that mention you, so we can surface what needs your attention.
3. How we use your data
- To provide the service: store your tasks and preferences, score and prioritise your work, lay out your day, and surface messages that need you.
- To generate AI assistance (“Pilota’s read” and Ask Pilota) — see the next section.
- To secure the service, prevent abuse, debug problems, and communicate with you about your account.
Our legal bases (EU/UK GDPR) are: performance of our contract with you (running the app you signed up for), your consent (each integration you connect, which you can withdraw at any time), and our legitimate interests in keeping the service secure and functioning.
4. AI processing
To power “Pilota’s read” and the Ask Pilota assistant, we send the relevant details of your tasks (such as title, goal, deadline and importance) and the messages you type to the assistant to our AI provider, Anthropic(Claude). “Pilota’s read” is generated automatically when you open your cockpit (and cached for the session); the assistant only runs when you message it. OpenAI is a registered secondary provider that may be enabled after the beta. We do notsend the raw contents of your email, calendar, Slack or Teams to AI providers — except where you choose to save an item as a task, in which case that task’s details are processed like any other task you create. We use these providers under their commercial API terms, which state that content submitted through the API is not used to train their models. AI output can be wrong — you stay in control, and Pilota asks you to confirm before it acts on your data.
5. Google user data — Limited Use
Pilota’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically: we only use your Google data to provide the calendar and mail features you connect; we do not sell it; we do not use it for advertising; and we do not use it to train generalised AI models. Google data is fetched live and shown to you — it is not stored on our servers beyond the connection tokens needed to fetch it.
6. How we protect your data
- EU data residency — your account data is stored in the European Union (our database runs in Frankfurt, Germany).
- Isolation — row-level security scopes every record to your account, so one user can never read another’s data.
- Token encryption — the access tokens for your connected accounts are encrypted at rest (AES-256-GCM) with a key held only in our application environment, never in the database, and are used only on the server. Tokens never reach your browser.
- Transport security — all traffic is served over HTTPS.
7. Who we share data with
We do not sell your personal data. We share it only with the service providers (“subprocessors”) that help us run Pilota, under contract and only as needed:
- Supabase — database, authentication and storage (EU region, Frankfurt).
- Vercel — application hosting.
- Anthropic — AI processing; OpenAI — secondary AI provider (may be enabled after the beta).
The Google, Microsoft and Slack services are the sources you connect, governed by their own privacy policies. We may also disclose data if required by law or to protect the rights and safety of our users.
8. International transfers
Your account data is stored in the EU. Some of the providers listed above — our AI providers and our application host — operate in the United States, so the limited data described in section 4 (your task details and assistant messages) is transferred outside the EEA. We rely on the data-protection terms and transfer safeguards those providers offer, including Standard Contractual Clauses. If you would like details of the safeguards that apply to a specific provider, contact us at privacy@usepilota.com.
9. Data retention
We keep your account data for as long as your account is active. Content fetched live from your connected tools is not retained. When you delete your account, or disconnect an integration, the related data is removed as described below.
10. Your rights and choices
- Disconnect a tool — in Settings → Connections, at any time. We delete that account’s stored tokens immediately, and revoke Pilota’s access at the provider where the provider supports it (Google, Slack). Microsoft does not offer a revocation endpoint, so although we delete our tokens and can no longer read anything, the authorisation remains listed in your Microsoft account until you remove Pilota there (Microsoft account → Privacy → App permissions).
- Delete your account — in Settings → Account. This permanently erases your account and all associated data (tasks, tags, notes, conversations and connections).
- Export your data — email us and we will provide a copy of your Pilota data (data portability).
If you are in the EU/EEA or UK you also have the rights to access, correct, restrict or object to processing, and to withdraw consent — exercisable via the controls above or by contacting us. You may lodge a complaint with your local data protection authority.
11. Children
Pilota is not directed to children under 16 and we do not knowingly collect their data.
12. Changes to this policy
We may update this policy as Pilota evolves. We will change the “last updated” date above and, for material changes, notify you in the app or by email.
13. Contact
Questions or requests about your data: privacy@usepilota.com (data controller: Pilota ApS, Danneskiold-Samsøes Allé 41, 1434 Copenhagen, Denmark).