Privacy Policy
Last updated 17 September 2026
This policy explains what personal data Pilota (“Pilota”, “we”, “us”) collects, how we use it, and the choices and rights you have. Pilota is a calm, AI-assisted task cockpit that scores your tasks, plans your day against your calendar, and helps you triage messages from the tools you connect. Pilota is operated by Pilota ApS, CVR 46720776, Danneskiold-Samsøes Allé 41, 1434 Copenhagen K, Denmark. If you are in the EU/EEA or UK, we act as the data controller for the data described here.
Pilota is an early-stage product. Connected accounts, particularly Google accounts, may need to be reconnected periodically while we improve the service.
1. Information we collect
Information you give us
- Account details — your email address (used to sign in with a 6-digit code we email you) and your display name.
- Your content — the tasks, goals, notes/captures, tags, and preferences you create, the files you attach to tasks or assistant messages, files you ask Pilota to prepare, and your saved assistant conversations. This also includes agents you configure, their saved instructions and capabilities, schedules you save, run history, generated results, proposed task changes, and your approval or rejection records. Scheduled runs are temporarily paused. A chat you start from a task is kept with that task so you can pick it up later; conversations in the Ask Pilota panel and the focus copilot are kept too, and you can read them again under Archive. A chat you start from a specific email, meeting, or message is kept the same way, named generically (“Email conversation”, “Meeting”) rather than after the item. All of them store what you typed and what Pilota answered. Deleting a task also deletes the chat attached to it, and disconnecting an account deletes the chats started from its items.
- Voice dictation — when you select the microphone in Ask Pilota or Add Task, your browser records up to 90 seconds of audio and sends it for transcription. We do not save the recording to your Pilota account or file storage. The returned transcript remains editable and becomes stored content only if you submit it in a message or task.
- Billing and credit data — your selected plan, subscription and payment status, invoices, refunds, credit balance and usage, Stripe customer and payment identifiers, tax location evidence, and any company or tax identifier you provide. We also keep the consent, withdrawal, and refund records needed to handle consumer requests. Stripe collects payment-card details directly. Pilota does not receive or store your full card number or CVC.
Information from services you connect
When you connect Gmail, Google Calendar, Google Drive, Microsoft (Outlook mail, calendar, Teams and OneDrive), or Slack, Pilota reads a limited, read-only slice of your data to power the relevant screen. A crucial distinction:
- We display this content live and do not store it. Email headers (sender, subject, date), a short mail preview line, calendar events, Slack direct messages and messages that @-mention you, and your Teams chats are fetched from the provider each time you open the screen and are shown in your browser — their contents are not written to our database. We do keep an opaque reference to items you act on — an identifier, not the item — so that something you have handled does not resurface and the same item cannot become two tasks.
- OneNote uses a limited cache. If you connect OneNote, we store page titles, notebook and section names, provider timestamps, and stable links. Automatic sync does not request a text preview or page body. Expanding a page does not request its text. We fetch one page body only when you select Read page in Pilota or Ask Pilota about page. We do not store the page body.
- Google Drive and OneDrive use a metadata cache. We store file names, file types, sizes, provider links and identifiers, created and modified timestamps, the connected account label, and sync cursor or status data. We use this data to show your file library, recent changes, and sync progress. We do not download or store file bodies. Connected cloud files do not use your Pilota file-storage allowance.
- The one exception is what you choose to save. If you turn an email or message into a task, the task title and any details you keep are stored as your own task content — because you asked us to create it.
- Connection credentials. To fetch on your behalf we store the connected account’s address/label, the read-only permissions you granted, and the access/refresh tokens — which are encrypted at rest and only ever used on our servers (see “How we protect your data”).
Information we collect automatically
We keep minimal server and security logs (such as timestamps and error events) needed to run the service reliably and safely, and we use two privacy-preserving, first-party tools to keep Pilota running and improve it: Sentry for error monitoring (to find and fix crashes) and PostHog for product analytics (which features get used). Our analytics are cookieless — they store nothing on your device, are tied only to your account, and never follow you across other sites. We do not use third-party advertising or cross-site tracking.
2. The permissions we request
We ask only for read-only access, and only for the tools you choose to connect:
- Google Calendar —
calendar.readonly(view your events). - Gmail —
gmail.metadata(message headers only: sender, subject, date and labels — never the body of your emails). - Google Drive —
drive.metadata.readonly(file metadata only, not file bodies). - Microsoft —
Mail.Read,Calendars.ReadandChat.Readfor Outlook and Teams. OneDrive uses a separate, read-onlyFiles.Readgrant. OneNote uses a separate, read-onlyNotes.Readgrant. You can connect either file service without granting Outlook or Teams access. Microsoft does not offer a metadata-only OneNote permission.Notes.Readcan read page bodies, but Pilota does not request them during automatic sync. - Slack — reading your direct messages and messages that mention you, so we can surface what needs your attention.
3. How we use your data
- To provide the service: store your tasks and preferences, score and prioritise your work, lay out your day, and surface messages that need you.
- To generate AI assistance (“Pilota’s read”, Ask Pilota, and agents you run) — see the next section.
- To secure the service, prevent abuse, debug problems, and communicate with you about your account.
- To provide paid plans, measure credit use, collect payment, issue invoices or credit notes, handle refunds and withdrawals, prevent payment fraud, and meet tax and accounting duties.
Our legal bases (EU/UK GDPR) are: performance of our contract with you (running the app you signed up for, including transcription that you request), your consent (each integration you connect, which you can withdraw at any time), our legal obligations for tax and accounting records, and our legitimate interests in keeping the service secure, reconciling payments, and preventing fraud.
4. AI processing
To power “Pilota’s read”, the Ask Pilota assistant, and an agent you run, we send the relevant details of your tasks and goals (such as title, description, steps, deadline and importance — including the names of files you attach to tasks or chats), the messages you type to the assistant, the instructions you saved for the selected agent, and the optional work profile you provide in Settings → About you (role, team, industry, organization name and size, country, and your goals for Pilota — your year of birth is stored for your own settings only and is never sent) to our AI providers, Anthropic (Claude) and OpenAI (GPT). Every feature runs on Anthropic by default. If Anthropic’s service is unavailable, the request is automatically retried once with OpenAI instead, so the feature still works; OpenAI does not otherwise see your data. “Pilota’s read” is generated automatically when you open your cockpit (and cached for the session); the assistant only runs when you message it. A chat you start from a task is sent with each new message in that conversation, so the assistant can follow the thread. When you start a new chat in the Ask Pilota panel, your first message and the assistant’s first reply are sent once more to name that conversation, so your saved chats are listed by subject rather than by the opening words you typed; this happens automatically, only on the first exchange, and you can rename any chat yourself. We do not send the raw contents of your email, calendar, Slack or Teams to AI providers. OneNote page text is sent only when you explicitly select Ask Pilota for that page. Other connected content reaches AI only where you choose to save an item as a task, in which case that task’s details are processed like any other task you create. We use these providers under their commercial API terms, which state that content submitted through the API is not used to train their models. AI output can be wrong — you stay in control, and Pilota asks you to confirm before it acts on your data.
A manual agent starts only when you select Run. It can read the board areas allowed by its capabilities. It stores a run record and its result. Proposed task changes are stored in a review queue and do not run until you approve them. Scheduled agents can start from a saved time without a new message from you. Scheduled runs are temporarily paused while we complete their legal and data-lifecycle controls. Future scheduled Workflow coordination will contain only opaque run identifiers and status values. Rich results stay in our owner-scoped EU database and are removed from temporary delivery storage after delivery or expiry.
When PDF reading is available and you attach a PDF stored in Pilota to an assistant message, the attachment notice tells you that sending the message lets Pilota read it. We extract text in an isolated, network-blocked Vercel processing environment. We keep a page-numbered text extraction with the file and send a limited part of that text through Vercel AI Gateway to an configured AI provider. The Gateway can route PDF text only to Anthropic or OpenAI. We request EU inference from Anthropic. The OpenAI fallback can process the request globally because its current fallback route does not support EU inference. Both routes require zero data retention and no prompt training. The request fails if no route can meet those rules. We keep the selected provider and broad route region with the usage record. That record does not contain PDF text. Do not include health data, financial account information, or government-issued identifiers. We do not read cloud-file bodies. We do not use OCR, so scanned PDFs may have no readable text.
When you request voice dictation in Ask Pilota or Add Task, Pilota sends the recording through Vercel AI Gateway to SpaceXAI for transcription with grok-stt. This route requires zero data retention and prohibits prompt training. It allows no other provider or model, so the request fails if the approved route is unavailable. The recording is processed temporarily in browser, application, Gateway, and provider memory. Pilota does not save it to its database or file storage. We keep only operational usage data, such as the model, provider, broad route region, duration, cost, and completion status. The transcript remains editable. Pilota does not send a message or create a task from it until you choose that action.
When you ask Pilota to prepare a PDF, Word document, PowerPoint presentation, or Excel workbook, the assistant selects exact Pilota source references for your approval. Pilota then assembles the file on our servers with a fixed template. The selected source text is not sent to an additional AI provider for this file-assembly step.
When you request an AI edit in Artifact Studio, Pilota sends the selected structured text, table values, formulas, chart data, and layout choice to the AI providers described above. The active section, slide, or sheet is the default scope. Pilota sends the whole structured file only when you select Whole file. Pilota does not send the original Office file, image data, private asset identifiers, brand settings, or database metadata. Pilota validates the result and shows a proposal. The proposal does not change your file until you select Apply, and you can undo it after you apply it.
5. Google user data — Limited Use
Pilota’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically: we only use your Google data to provide the calendar, mail, and Drive metadata features you connect; we do not sell it; we do not use it for advertising; and we do not use it to train generalised AI models. Gmail and Calendar content is fetched live and shown to you. Its contents are not stored on our servers. We store the limited Google Drive metadata described in section 1 while that connection is active. Beyond connection tokens and Drive metadata, we keep only an opaque reference to items you act on (for example, so an email you have already handled does not resurface, and turning the same one into a task twice does not create a duplicate). A reference identifies an item; it does not contain the item.
6. How we protect your data
- EU data residency — your account data is stored in the European Union (our database runs in Frankfurt, Germany).
- Isolation — row-level security scopes every record to your account, so one user can never read another’s data.
- Token encryption — the OAuth access and refresh tokens for your connected accounts are encrypted at rest (AES-256-GCM) with a key held only in our application environment, never in the database, and are used only on the server. Tokens never reach your browser. A small number of other connection values — such as a provider’s own sync-continuation cursor, which lets us fetch only what changed since your last sync — are not separately encrypted; they are protected the same way the rest of your account data is, by the isolation described above.
- Transport security — all traffic is served over HTTPS.
7. Who we share data with
We do not sell your personal data. We share it only with the service providers (“subprocessors”) that help us run Pilota, under contract and only as needed:
- Supabase — database, authentication and storage (EU region, Frankfurt).
- Vercel — application hosting, isolated PDF text extraction, AI request and voice-transcription routing, and opaque Workflow coordination for scheduled agents when that feature is enabled.
- Stripe — checkout, payment processing, subscription management, invoices, payment recovery, fraud prevention, and tax calculation. Stripe receives the billing and payment data needed for those services.
- Anthropic and OpenAI — AI processing (see section 4 for how each is used).
- SpaceXAI — zero-data-retention voice transcription through Vercel AI Gateway (see section 4).
- Sentry — error monitoring and crash reporting (EU region).
- PostHog — privacy-preserving, first-party product analytics (EU region).
The Google, Microsoft and Slack services are the sources you connect, governed by their own privacy policies. We may also disclose data if required by law or to protect the rights and safety of our users.
8. International transfers
Your account data is stored in the EU, and our error-monitoring (Sentry) and product-analytics (PostHog) providers are configured to keep their data in the EU as well. Some of the other providers listed above — our AI providers, application host, and payment provider — operate in the United States, so the limited data described in sections 1 and 4 (your task details, assistant messages, agent instructions, temporary voice recordings, opaque scheduled-run identifiers, and billing data) is transferred outside the EEA. We rely on the data-protection terms and transfer safeguards those providers offer, including Standard Contractual Clauses. If you would like details of the safeguards that apply to a specific provider, contact us at privacy@usepilota.com.
9. Data retention
We keep your account data for as long as your account is active. Content fetched live from your connected tools is not retained, except for the limited OneNote, Google Drive, and OneDrive metadata caches described in section 1. We keep that metadata while its connection is active. OneNote page text and cloud-file bodies are not retained. A local PDF text extraction is kept while its source file is kept. A chat attached to a task is kept for as long as that task exists: delete the task and its chat is deleted with it. An uploaded file is kept while a task or chat still refers to it. Removing its final reference or deleting its final linked task or chat also deletes the stored file. A generated file is kept for 30 days unless you delete it sooner. A chat you start from a specific email, meeting, or message is kept until you delete it or disconnect the account it belongs to — it stores your conversation and a reference to the item, never the item’s contents. Agent instructions, run history, review records, and saved schedules are kept while your account is active. Temporary scheduled-result delivery rows expire after 24 hours and are removed after successful delivery. Vercel Workflow event state for future scheduled runs contains opaque run identifiers and status values only and follows Vercel’s service retention controls. When you delete your account, or disconnect an integration, the related data is removed as described below.
Raw voice recordings are not saved to your Pilota account, database, or file storage. They remain available in browser memory only long enough to transcribe or retry the request and are cleared when transcription succeeds, you cancel, the request times out, or you leave the feature. The application and provider process the recording temporarily to return the transcript. The separate usage record contains operational metadata but no recording or transcript.
We retain invoices, payment records, tax evidence, credit ledgers, and related accounting records for the period required by applicable tax, accounting, fraud-prevention, and legal rules. Stripe also retains payment data under its own retention obligations and privacy policy. Deleting your Pilota account does not remove records that we must keep by law. We restrict those records to the required purposes and delete or anonymise them when the retention period ends.
10. Your rights and choices
- Disconnect a tool — in Settings → Connections, at any time. We delete that account’s stored tokens, OneNote cache, cloud-file metadata, and sync state, and revoke Pilota’s access at the provider where the provider supports it (Google, Slack). If cleanup cannot finish, Settings shows a pending state and lets you retry. Microsoft does not offer a revocation endpoint, so although we delete our tokens and can no longer read anything, the authorisation remains listed in your Microsoft account until you remove Pilota there (Microsoft account → Privacy → App permissions).
- Delete your account — in Settings → Account. This permanently erases your product account and associated content (tasks, tags, notes, conversations, attached files, generated files and connections). We keep only billing, tax, accounting, fraud-prevention, and legal records that applicable law requires or permits us to retain.
- Export your data — email us and we will provide a copy of your Pilota data (data portability).
If you are in the EU/EEA or UK you also have the rights to access, correct, restrict or object to processing, and to withdraw consent — exercisable via the controls above or by contacting us. You may lodge a complaint with your local data protection authority.
11. Children
Pilota is not directed to children under 16 and we do not knowingly collect their data.
12. Changes to this policy
We may update this policy as Pilota evolves. We will change the “last updated” date above and, for material changes, notify you in the app or by email.
13. Contact
Questions or requests about your data: privacy@usepilota.com (data controller: Pilota ApS, CVR 46720776, Danneskiold-Samsøes Allé 41, 1434 Copenhagen K, Denmark).