Privacy Policy
Effective date: July 10, 2026 · Last updated: July 10, 2026
driftlabHQ is a personal scheduling workspace operated by SLTR Digital, available at driftlabhq.com (collectively, with related services, the “Service”).
1. Introduction and scope
This Privacy Policy explains, in detail, what personal information SLTR Digital collects in connection with driftlabHQ (the “Service”), why we collect it, the legal bases on which we rely, how long we retain it, with whom it may be shared, and what choices and rights are available to you.
This Policy applies to the driftlabHQ web application at driftlabhq.com, to any associated mobile or desktop client we make available, and to all backend services that support them, including authentication, data storage, connector integrations, and transactional email.
By creating an account, signing in, or otherwise using the Service, you acknowledge that your personal information will be processed as described in this Policy. If you do not agree with this Policy, please do not create an account or use the Service.
2. Controller identity and contact
The data controller responsible for personal information processed in connection with the Service is SLTR Digital, the operator of driftlabHQ. For any question, request, or concern regarding this Policy or our handling of your personal information, you may contact us at kevin@sltrdigital.com. This is currently our single point of contact for privacy, security, legal, and support matters; we have not stood up separate departmental mailboxes at this time.
3. Definitions
| Term | Meaning |
|---|---|
| SLTR Digital / we / us / our | The operator of driftlabHQ and controller of personal information described in this Policy. |
| Service | The driftlabHQ web application at driftlabhq.com, its authentication system, database, connector features, and supporting infrastructure. |
| Personal Information / Personal Data | Information that identifies, relates to, describes, or could reasonably be linked, directly or indirectly, with you. |
| Account | Your registered driftlabHQ identity, associated with the email address you use to sign in. |
| User Content | Tasks, notes, dates, tags, and “Who” labels, and any other content you create or store within your workspace. |
| Connector | An optional, user-initiated integration with a third-party service, currently limited to Google (Gmail and Google Calendar). |
| Connector Tokens | OAuth access and refresh tokens issued by Google when you connect a Connector, stored server-side. |
| Connector Action Log | The audit trail we keep of actions taken through a connected Google service. |
4. Categories of data we collect
We collect only the categories of personal information described below. Categories that depend on optional features (such as connecting Google services) are only collected if you choose to use those features.
| Category | What it includes | When it is collected |
|---|---|---|
| Account information | Your email address, and internal account identifiers created by our authentication provider when your account is set up. | When you create an account |
| User content | Tasks, notes, dates, tags, and “Who” labels that you create, edit, or store in your workspace. | When you use the Service |
| Google connector tokens | OAuth access and refresh tokens for Gmail and Google Calendar scopes, held in a database table accessible only to our backend service role, never to end users or client-side code. | Only if you choose to connect Gmail and/or Google Calendar |
| Connector action audit log | A record of actions taken through a connected Google service (for example, that a calendar event was read or created), used for transparency, debugging, and security review. | Only when a connected Google service is used |
| Drift AI conversations | The messages you send to the Drift AI assistant and the replies it returns, together with a record of the actions it took. These are transmitted to a third-party model-inference provider for processing, as described in the Drift AI section. | Only when you use the Drift AI assistant |
| Analytics data | Site analytics: page visited, referrer, coarse device and browser type, with IP address processed transiently and not stored. Product analytics, where configured: product event names linked to your account identifier and email address, never to your content. | Automatically, whenever the Service is accessed |
| Standard hosting and server logs | Request metadata such as IP address, timestamps, user agent, and error information generated by our hosting infrastructure in the ordinary course of operating the Service. | Automatically, whenever the Service is accessed |
We do not collect any category of information beyond what is listed above. In particular, we do not collect payment or card information, advertising identifiers, precise location data, or biometric data. Our use of analytics is described in full in the Analytics, cookies, and local storage section, and our use of artificial intelligence is described in the Drift AI section.
5. Data we do not collect
We deliberately limit our collection of personal information. The Service does not collect, and we do not intend to collect:
- Payment card numbers, bank account numbers, or other financial account credentials; the Service does not process payments and holds no card data.
- Advertising identifiers, third-party advertising cookies, or any identifier used for cross-context behavioral advertising. We do use first-party product analytics, described in full in the Analytics and cookies section below.
- Precise device location data, such as GPS coordinates. Our analytics providers derive only a coarse country or region from your IP address.
- Biometric identifiers such as fingerprints or facial geometry.
- Government identification numbers, such as Social Security numbers or passport numbers.
We do not sell personal information, and we do not share personal information with third parties for cross-context behavioral advertising. We have no advertising business and no data broker relationships.
6. Purposes and legal bases for processing
We process personal information only for the following purposes, and we rely on the legal bases indicated for users in jurisdictions (such as the European Economic Area and the United Kingdom) where a legal basis is required:
| Purpose | Legal basis |
|---|---|
| Creating and authenticating your account, and delivering one-time sign-in codes by email | Performance of a contract with you (our Terms of Service) |
| Storing, displaying, and synchronizing your tasks, notes, dates, tags, and “Who” labels | Performance of a contract with you |
| Connecting and operating Gmail or Google Calendar features you request | Your consent, obtained at the time you connect the service, and revocable at any time |
| Maintaining server and connector action logs, detecting abuse, and securing the Service | Our legitimate interest in operating a secure and reliable service, balanced against your privacy interests |
| Responding to your support, privacy, or legal requests | Legitimate interest in providing customer support, and, where applicable, compliance with legal obligations |
Where we rely on consent, such as connecting a Google service, you may withdraw that consent at any time without affecting the lawfulness of processing before withdrawal.
7. Drift AI: artificial intelligence and automated processing
driftlabHQ includes an assistant, “Drift AI,” which interprets what you type and acts on your workspace on your behalf. Because this involves sending your information to a third party for processing, we describe it here in unusual detail.
What is sent, and to whom
When you send a message to Drift AI, we transmit the following to Amazon Bedrock, a hosted model-inference service operated by Amazon Web Services, for processing in the United States:
- The message you typed.
- Up to your twenty most recent messages in the same conversation, and the assistant's replies to them, so that the assistant understands context.
- A snapshot of your task list: titles, dates, times, statuses, tags, and priorities.
- The full content of any task the assistant reads while answering you, which includes the task's notes and any recipient email address stored on it.
- When the assistant checks your availability or briefs you on your day, the titles and times of events on your connected Google Calendar for the relevant dates.
- The current date and your time zone.
We do not transmit your Google OAuth tokens or your account password (we do not have one). We do not read your Gmail: the Google connection is send-only.
If you connect a mailbox from another provider (see Connected mailboxes below) and then ask the assistant to brief, triage, or read that mail, the content of those messages is sent to Amazon Bedrock to answer you, on the same terms as everything else in this section. If you never ask the assistant about your mail, no message content is sent to the model.
What the model provider may do with it
Amazon Bedrock processes this data to generate a response and returns it to us. AWS states that inputs to, and outputs from, Amazon Bedrock are not used to train any foundation model, whether Amazon's own or a third party's, and are not shared with any model provider. AWS further states that content processed by Bedrock is encrypted in transit and encrypted at rest within the AWS region in which it is processed, which for driftlabHQ is a region in the United States. We do not use your content, and we do not permit others to use your content, to train any generalized or third-party artificial intelligence or machine-learning model.
What we store, and for how long
We store your conversations with Drift AI, both your messages and the assistant's replies, in our database, so that the conversation persists between visits. They are protected by the same row-level security as the rest of your data: no other user can read them. They are deleted when you delete your account, as described in the Deletion section.
Actions the assistant takes on your behalf
Drift AI does not merely answer questions; it acts. It can create, edit, reschedule, and delete tasks, create and modify events on your connected Google Calendar, and send email from your connected account. These actions are performed with your authority, using the permissions you granted.
Two categories of action always require your explicit, affirmative confirmation before they occur: deleting a task and sending an email. The assistant cannot perform either without you clicking to confirm. In addition, the assistant will not schedule a task on top of an existing calendar commitment without telling you about the conflict first.
Accuracy, human oversight, and your rights
Large language models can produce output that is wrong, incomplete, or fabricated, including misreading a date or misunderstanding an instruction. Drift AI is a productivity tool. It must not be relied upon for legal, medical, financial, or other professional advice, and you remain responsible for reviewing what it does on your behalf.
Drift AI does not make decisions that produce legal effects concerning you, or similarly significantly affect you, within the meaning of Article 22 of the GDPR. It schedules and edits your own tasks at your direction. Every action it takes is recorded in the conversation and is subject to your review. Changes to your tasks can be reversed with the undo control. Sending an email cannot be undone once you have confirmed it, which is why your explicit confirmation is required first.
You can use driftlabHQ without using Drift AI. If you never open the assistant, no task content is transmitted to Amazon Bedrock.
8. Google API Services User Data Policy and Limited Use
driftlabHQ's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. This section describes our Google data practices explicitly and completely.
- Scopes and purpose. If you choose to connect Google, we request only the OAuth scopes necessary for the specific, user-initiated features you enable, and no others. Those scopes are, exhaustively:We do not request permission to read your Gmail. Through the Google connection, driftlabHQ cannot read your Gmail inbox, list your Gmail messages, or access your Gmail history. The gmail.send scope permits sending only. We use Google user data solely to provide these user-facing features within driftlabHQ. (Reading email is a separate, optional feature that works only with non-Google mailboxes you connect yourself; see Connected mailboxes.)
Scope What it permits Why we request it calendar.readonly Read events on your calendars To show your events in the Calendar view and to detect when a task you are scheduling conflicts with an existing commitment calendar.events Create and modify calendar events To mirror a scheduled task onto your calendar with a reminder, to move that event when you reschedule the task, and to remove it when you delete the task gmail.send Send mail as you To send an email that you have explicitly asked Drift AI to send, and confirmed - No human access, except in narrow circumstances. No SLTR Digital personnel read your Gmail or Calendar data in the ordinary course. We may access it only: (a) with your affirmative consent, for example when you contact support about a connector issue and ask us to look; (b) as necessary for security purposes, such as investigating suspected abuse or a security incident; or (c) to comply with applicable law or a valid legal process.
- Never for advertising. We do not use Google user data, or any information derived from it, to serve advertisements, including retargeted advertising, of any kind.
- Never sold, and not used to train generalized models. We do not sell Google user data to third parties. We do not use Google user data to train generalized or third-party artificial intelligence or machine learning models.
- Storage and isolation.Google OAuth tokens are stored in a database table restricted to our backend service role. No client-side code, and no other user, can read another user's connector tokens.
- Revocation. You may disconnect Gmail and Google Calendar access at any time from within the Service, or directly through Google at myaccount.google.com/permissions. Disconnecting removes our ability to access the connected service going forward and triggers deletion of the stored tokens.
9. Connected mailboxes (reading your email)
Separately from Google, you may connect a mailbox from another provider (currently Yahoo Mail, Zoho Mail, iCloud Mail, Fastmail, or a generic IMAP server) so that driftlabHQ can show your inbox inside the app, turn messages into tasks, and let Drift AI brief and triage your mail. Unlike the Google connection, this feature does read your email. This section describes exactly how.
How you connect, and what we store
You connect by generating an app-specific password in your mail provider's own security settings and pasting it into driftlabHQ. We never see or store your provider login password, and we cannot create the app-specific password for you; you do that yourself, inside your provider.
The app-specific password is a long-lived credential, so we protect it accordingly. It is encrypted the moment you submit it, using envelope encryption: a single-use data key encrypts the password with AES-256-GCM, and that data key is itself encrypted by AWS Key Management Service. Only the ciphertext and the KMS-wrapped key are stored, in a database table no end user can read. The plaintext password is never written to our database and never logged. It is decrypted only in memory, for the moment needed to open a single connection to your mailbox, and then discarded.
What we read, and what we keep
When you open the Mail view, or ask Drift AI about your mail, we connect to your mailbox over IMAP and read your inbox: the sender, subject, date, and body of your messages. We use this only to display your mail and to perform the actions you ask for.
We do not store the contents of your email. Your messages are fetched live from your provider each time and are not copied into our database. What we retain is limited to the encrypted app-specific password and basic account metadata (the provider and the mailbox address). If you turn a message into a task, the text you chose to bring over lives in that task, like any other task content.
Drift AI and your mail
If you ask the assistant to brief, triage, summarize, or act on your mail, the relevant message content is sent to Amazon Bedrock to generate the response, on the same terms described in the Drift AI section (not used to train any model, not shared with the model provider). If you never ask the assistant about your mail, no message content is sent to the model.
Sending, human access, and disconnecting
The same connection can send mail on your behalf over SMTP, only for messages you have explicitly confirmed. No SLTR Digital personnel read your mail in the ordinary course; access would occur only with your consent (for support), as needed for security, or where required by law.
You can disconnect a mailbox at any time, which deletes the encrypted credential from our systems. For completeness, revoke the app-specific password in your provider's settings as well, so it can no longer be used from anywhere.
10. Security measures
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. These measures include, specifically:
- Encryption of data at rest using AES-256, applied to our Supabase Postgres database.
- Encryption of data in transit using TLS for all connections between your device, our servers, and our database provider.
- Row-level security policies enforced at the database level, so that every row of user content is scoped to its owning account and cannot be read or modified by other users.
- Service-role isolation of connector tokens: Google OAuth tokens are stored in a database table that only our backend, using a privileged service-role credential, can read. No client application and no ordinary user session can access this table.
- No storage of your task, note, or connector content on your local device; the only information we persist on-device is a session authentication token and a one-time onboarding-completion flag, neither of which contains your workspace content.
- Passwordless authentication using one-time codes sent by email, which eliminates the risk of password reuse, credential stuffing against driftlabHQ, and password database compromise, because we do not store passwords at all.
No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. We continue to evaluate and improve our security practices as the Service evolves.
11. Subprocessors and disclosure limits
We use a limited set of subprocessors and service providers to operate the Service. We do not disclose personal information to any party beyond those listed here, except as required by law.
| Subprocessor | Function | Data involved |
|---|---|---|
| Supabase | Database (Postgres), authentication (one-time email codes), and row-level security enforcement | Account email, user content, connector tokens, connector action log |
| Amazon Web Services (AWS) | Application hosting, in the us-west-2 region | All Service data, as the underlying infrastructure host |
| Amazon Simple Email Service (SES) | Delivery of transactional email, including one-time sign-in codes | Account email address, and the content of the transactional message |
| Gmail and Google Calendar APIs, used only for accounts that choose to connect these services | OAuth tokens, and the specific email or calendar data requested by the feature you use | |
| Amazon Bedrock (AWS) | Hosted large-language-model inference, which powers the Drift AI assistant | The message you send to Drift AI, your recent conversation history, and your task data, including titles, notes, dates, times, statuses, tags, priorities, and any recipient address stored on a task. Calendar event titles and times are included when the assistant checks your availability. |
| Plausible Analytics | Cookieless site analytics on public and application pages | Page visited, referrer, coarse device and browser type. IP address processed transiently and not stored. No account identifiers, no user content. |
| PostHog | Product analytics within the signed-in application, where configured | Product event names, your account identifier, and your email address. No task content, no conversation content, no Google data, no tokens. |
Beyond the subprocessors above, we disclose personal information only where compelled by law, such as in response to a valid subpoena, court order, or other lawful legal process, or where necessary to protect the rights, property, or safety of SLTR Digital, our users, or the public. We do not otherwise share, rent, or sell personal information to third parties.
12. International data transfers
SLTR Digital hosts the Service on Amazon Web Services in the us-west-2 (Oregon, United States) region, and uses Supabase and Amazon SES as described above. If you access the Service from outside the United States, your personal information will be transferred to, stored in, and processed in the United States, where data protection laws may differ from those of your home jurisdiction.
Where such a transfer requires a safeguard under applicable law, such as the transfer of personal information from the European Economic Area, the United Kingdom, or Switzerland, we rely on the contractual and organizational safeguards made available by our subprocessors, and we will take reasonable steps to ensure your personal information continues to receive an adequate level of protection.
13. Retention
We retain personal information for as long as your account remains open, and for as long as necessary to provide the Service, unless a longer retention period is required or permitted by law.
| Data | Retention approach |
|---|---|
| Account and user content (tasks, notes, dates, tags, “Who” labels) | Retained until you delete individual items or delete your account |
| Google connector tokens | Retained until you disconnect the connector or delete your account |
| Connector action audit log | Follows the same lifecycle as your account; deleted upon account deletion, alongside all other account tables |
| Drift AI conversations (your messages and the assistant's replies) | Retained until you delete your account, so that conversations persist between visits; deleted upon account deletion alongside all other account tables |
| Analytics data | Site analytics are aggregate and carry no identifier tied to you. Product-analytics events are held by PostHog under its own retention schedule and are not automatically removed when you delete your account. Email us and we will delete your product-analytics profile. |
| Standard hosting and server logs | Retained by our hosting and infrastructure providers according to their operational logging practices |
| Provider backups | Supabase maintains database backups on its own rotation schedule; backup copies age out of that rotation independently of an individual account deletion |
When you delete your account through the in-app account deletion function, all associated tables, including your user content, connector tokens, and connector action log, are deleted immediately and in the same operation. The only data that may persist afterward is contained within provider backup snapshots taken before deletion, which age out according to Supabase's standard backup rotation schedule, not a schedule we control separately.
14. Your rights (GDPR and CCPA/CPRA)
If you are in the European Economic Area, the United Kingdom, or a similar jurisdiction
Subject to applicable law, you have the right to:
- Access the personal information we hold about you.
- Request rectification of inaccurate or incomplete personal information.
- Request erasure of your personal information, including through in-app account deletion.
- Request restriction of processing in certain circumstances.
- Receive your personal information in a portable, structured, commonly used format, including through in-app CSV export of your workspace data.
- Object to processing that is based on our legitimate interests.
- Lodge a complaint with your local data protection supervisory authority.
If you are a California resident (CCPA/CPRA)
Subject to applicable law, you have the right to:
- Know what personal information we collect, use, and disclose, as described in this Policy.
- Delete personal information we hold about you, including through in-app account deletion.
- Correct inaccurate personal information.
- Not be discriminated against for exercising any of these rights; we will not deny you the Service, charge different prices, or provide a different level of service because you exercised a privacy right.
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. Because we engage in neither practice, no opt-out of sale or sharing is required or offered, as there is nothing to opt out of.
How to exercise these rights
You can exercise access, export, correction, and deletion rights directly within the Service. For any other request, or if you need assistance, email kevin@sltrdigital.com from the email address associated with your account, describing the request. We will respond within the time required by applicable law.
15. Deletion mechanics
driftlabHQ provides an in-app account deletion function. When you initiate account deletion, the deletion cascades across all tables associated with your account immediately, including your account record, user content, Google connector tokens, and connector action log. There is no separate, delayed purge step within our own systems; deletion is immediate at the moment you confirm it in-app.
As described in the Retention section above, provider backups maintained by Supabase on its own rotation schedule may retain a copy of your data for a limited period after deletion, until that backup ages out of rotation. We do not use backup data for any purpose other than disaster recovery.
16. Children's privacy
The Service is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. driftlabHQ is a personal scheduling workspace intended for general adult use, consistent with the Children's Online Privacy Protection Act (COPPA).
If you believe a child under 13 has provided us with personal information, please contact kevin@sltrdigital.com, and we will investigate and delete such information promptly.
17. Breach notification commitment
If we become aware of a security incident involving unauthorized access to, or disclosure of, your personal information that creates a reasonable risk of harm, we will notify you and, where required, the relevant supervisory authorities or state regulators, without undue delay and in accordance with applicable law. Notification will describe, to the extent then known, the nature of the incident, the categories of information involved, and the steps we have taken or recommend you take in response.
19. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. When we make changes, we will revise the “Last updated” date at the top of this page. If a change is material, we will provide additional notice where appropriate, such as by email or an in-app notice. Your continued use of the Service after a revised Policy takes effect constitutes acceptance of the changes.
20. Contact
SLTR Digital
Operator of driftlabHQ
Email: kevin@sltrdigital.com
Web: https://driftlabhq.com/privacy