HG InsightsHG Insights
  • HG Agents
  • Superagent
MCP ToolsPricingGTM MarketplaceSecurityDevelopers
Sign UpApp

HG Insights Privacy Policy

How HG Insights and HG SuperAgent access, use, store, share, and delete data they receive from Google, including data from Gmail and Google Calendar.

Scope and relationship to the HG Insights Privacy Policy

This policy covers HG Insights, the web application at phoenix.hginsights.com, and HG SuperAgent, the HG Insights agent for Slack and Microsoft Teams. It adds to the HG Insights Privacy Policy, which continues to apply to all personal data HG Insights processes.

Where the two policies conflict on how HG Insights or HG SuperAgent handles data received from Google APIs (“Google user data”), this policy controls.

Google user data we access

HG Insights receives Google user data in two ways: when you sign in with Google, and when you connect your own Gmail or Google Calendar account in HG Insights so HG SuperAgent can use it. Signing in and the connectors use separate Google authorizations, and each asks for your consent on Google’s own consent screen.

Used forGoogle scopeWhat it lets HG Insights read
Sign in with GoogleopenidYour Google account identifier, so HG Insights can recognize you when you sign in.
Sign in with GoogleemailYour Google account email address.
Sign in with GoogleprofileYour name and profile picture.
Gmail connectoropenidYour Google account identifier, so the connection is bound to you.
Gmail connectoremailYour Google account email address.
Gmail connectorhttps://www.googleapis.com/auth/gmail.readonlyRead-only access to search and read your email messages and their content. HG Insights cannot send, change, or delete email.
Google Calendar connectoropenidYour Google account identifier, so the connection is bound to you.
Google Calendar connectoremailYour Google account email address.
Google Calendar connectorhttps://www.googleapis.com/auth/calendar.events.owned.readonlyRead-only access to events on calendars you own, including invitations on your primary calendar. HG Insights cannot create, change, or delete events.

All access is read-only. HG Insights does not request any Google scope that can send, change, or delete email, or create, change, or delete calendar events. If HG Insights ever needs such a scope, we will update this policy first, and Google will ask for your consent again before it is granted.

How we use Google user data

HG SuperAgent uses your Gmail and Google Calendar data only to answer the questions you ask it as the connected user, for example “what did Acme’s CFO send me last week?” or “brief me on my 2pm meeting”.

Gmail and Google Calendar tools use only your own connection, and only to answer questions you ask. HG SuperAgent never uses your connected account to answer anyone else’s question: if someone else asks in the same thread, it uses their own connection or asks them to connect one.

You can ask in a direct message with HG SuperAgent or in a channel thread. In a channel, HG SuperAgent posts its answer in the thread, so everyone who can read that channel can read it, including anything it quotes or summarizes from your mail or calendar. Ask in a direct message to keep the answer between you and HG SuperAgent. HG SuperAgent does not use your connection in channels shared with another organization, and your organization can ask HG Insights to turn off connector use in channels.

Data from signing in with Google is used to create your HG Insights account, identify you, and keep your account secure.

We do not:

  • use Google user data to serve advertising, including personalized, retargeted, or interest-based ads;
  • sell Google user data;
  • use Google user data to train, develop, or improve generalized or non-personalized AI or machine-learning models;
  • use Google user data to determine creditworthiness or for lending purposes;
  • transfer Google user data to anyone else, except as needed to provide the features described in this policy, to comply with applicable law, or as part of a merger, acquisition, or sale of assets after obtaining your explicit prior consent. If you don’t give that consent, we delete the Google user data described in this policy, including your sign-in data, and disconnect Gmail and Google Calendar instead of transferring them.

No HG Insights employee reads your Gmail or Calendar data unless you have given us explicit permission for specific messages or events, it is necessary for security purposes such as investigating abuse, it is necessary to comply with applicable law, or the data has been aggregated and anonymized for internal operations.

Storage, retention, and deletion

Sign-in data. Your name, email address, profile picture, Google account identifier, and the sign-in tokens Google issues are stored in the HG Insights database for as long as your HG Insights account exists. You can ask us to delete this data by contacting us (see Contact below), and we delete it within 30 days of your request.

Gmail and Calendar connection tokens. The OAuth tokens for your Gmail or Calendar connection are stored only in the HG Insights database, encrypted at rest with AES-256-GCM. Your refresh token never leaves HG Insights. HG SuperAgent receives only a short-lived access token for the request it is answering, holds it in memory, and does not store it.

Cached Gmail and Calendar data. So that HG SuperAgent can answer follow-up questions without re-reading your mailbox or calendar every time, it keeps a cache of the messages and events it has retrieved for you, including their content. The cache also holds only these kinds of data derived from them: metadata (sender, recipients, subject, date, and attendees), summaries and excerpts, and search indexes (embeddings) that let it find relevant messages. HG SuperAgent builds these search indexes with an embedding model reached through OpenRouter, under the same no-storage, no-training rule described in “Sharing” below. The cache is encrypted, kept separately for each user, and used only to answer your own questions, apart from the limited exceptions for human access described in “How we use Google user data” above. Each cached item is deleted 30 days after it was last used or refreshed from Google.

Conversation history. HG SuperAgent keeps its own copy of your conversation, including content it retrieved to answer you, for 30 minutes after your last message so it can follow the thread, and then deletes it. The answers HG SuperAgent posted stay in the Slack or Teams conversation where you asked, a direct message or a channel thread, under your organization’s retention settings for that workspace.

Logs and monitoring. Gmail and Calendar content is not written to our logs, traces, monitoring tools, or AI-quality evaluation datasets. Those systems record only operational details, such as which tool ran and how long it took.

When you disconnect. If you disconnect Gmail or Google Calendar in HG Insights, we delete your stored tokens immediately and ask Google to revoke them. If you remove HG Insights’ access in your Google Account instead, Google notifies HG Insights and we delete your stored tokens as soon as we receive that notice. Either way, HG Insights and HG SuperAgent stop reading that account, and we delete your cached connector data within 24 hours.

Sharing, including AI model providers

We do not sell Google user data or share it for advertising. We share Gmail and Calendar data only with the service providers listed below, and only as needed to answer your request.

To answer a question, HG SuperAgent sends the relevant parts of your Gmail or Calendar data, together with your question, to the large language model (LLM) provider that generates the answer. By default that is a Claude model from Anthropic, reached directly or through OpenRouter, a routing service that may run the model on another host that meets the rule below, such as a major cloud provider. Your organization’s administrators can choose a different model for your organization’s HG SuperAgent agents: another model available through OpenRouter, or your organization’s own provider account, such as Amazon Bedrock.

Whichever model is used, Gmail and Calendar data is never used to train AI models. Every request that carries it through OpenRouter, on HG Insights’ account or your organization’s, including requests to build search indexes, instructs OpenRouter to use only providers that do not store the data or use it for training. Gmail and Calendar tools work with your organization’s own provider account only if that provider’s terms prohibit training on the data it receives; otherwise they are unavailable to your organization’s agents. Model providers process the data only to generate the answer or build the search index.

The service providers that receive Gmail and Calendar data are:

  • Amazon Web Services: hosting for HG Insights and HG SuperAgent, including the connector cache and conversation history
  • Neon: the HG Insights database, which holds your account data and encrypted connection tokens
  • Anthropic and OpenRouter: the default AI model providers, as described above
  • The model host OpenRouter forwards a request to: the company that runs the model for any request routed through OpenRouter (the default Claude models, the embedding model that builds search indexes, or a model your organization selects), limited to hosts that do not store the data or use it for training
  • The AI model provider your organization chooses: if your organization’s administrators select a different model or connect their own provider account, subject to the no-training rule above
  • Slack or Microsoft Teams: where HG SuperAgent delivers your answers, under your organization’s own agreement with them

Data from signing in with Google is shared with the service providers that operate HG Insights, such as hosting, database, email delivery, and monitoring providers, as described in the HG Insights Privacy Policy.

Limited Use

HG Insights' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How to revoke access

  • In HG Insights: open your organization’s Integrations page and choose Disconnect on your Gmail or Google Calendar connection.
  • In your Google Account: remove HG Insights’ access at any time at myaccount.google.com/permissions. This stops HG Insights from reading your Google data. See “Storage, retention, and deletion” above for data already stored.

Contact

Questions about this policy or about how HG Insights and HG SuperAgent handle Google user data: phoenix@hginsights.com. The HG Insights Privacy Policy lists other ways to contact HG Insights about privacy.

Effective date: October 6, 2026

HG InsightsHG Insights

Give your Enterprise agents the context they need to act intelligently

Product

  • Agents
  • Superagent
  • MCP Tools
  • Pricing
  • Calculator
  • Developers
  • Docs

HG Insights for...

  • Revenue teams
  • AI Transformation teams
  • ISVs
  • GTM Marketplace

Trust

  • Security Guardrails
  • AI Governance
  • Implementation
  • Privacy Policy

Compare

  • HG Insights vs Rox
  • HG Insights vs Clay
  • HG Insights vs ZoomInfo

Company

  • Team
  • Contact
  • HG Insights
  • LinkedIn
  • Blog

© 2026 HG Insights. All rights reserved.