LEGAL · EFFECTIVE AUGUST 26, 2026

Privacy, without the fog.

Privacy, without the fog.

Privacy, without the fog.

How Sunny handles information across the authenticated Core App and the standalone Free Calendar Tool.

How Sunny handles information across the authenticated Core App and the standalone Free Calendar Tool.

Core App and Free Calendar Tool

Core App and Free Calendar Tool

CORE APP — Authenticated workspace for organization documents, chats, meetings, transcripts, Google integrations, search, and generated content.

FREE CALENDAR TOOL — Separate no-account utility. Schedules stay in the browser unless the user intentionally invokes AI. PDF-unlock email is not marketing consent and does not create a Sunny account.

Sunny (“Sunny,” “we,” “us,” or “our”) offers (1) the authenticated Sunny workspace, which helps organizations work with documents, meetings, calendars, and other connected business information (the “Core App”), and (2) a free, no-account production Calendar Tool offered as a standalone website feature (the “Free Calendar Tool”). Together, they are the “Service.” This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information across both products.

1. Scope and roles

This Policy applies to the Sunny website, application, APIs, and related support services. It does not apply to third-party services that you connect to Sunny, which are governed by their own terms and privacy policies.

For account, website, security, and business-administration information, Sunny generally acts as the business or controller. For documents, meeting content, calendar information, and other data submitted or connected by an organization, Sunny generally acts as a service provider or processor on that organization’s instructions. If your account is provided by an employer or other organization, that organization controls your workspace and may access, manage, export, or delete workspace data.

The Core App and Free Calendar Tool handle data differently

• Core App: requires an authorized Sunny account and may process organization-controlled documents, chats, meetings, transcripts, Google Drive files, Google or Microsoft calendar information, and generated content. Core App data may be stored and indexed on Sunny’s systems so authorized workspace users can search and use it.

• Free Calendar Tool: does not require a Sunny account and is separate from the Core App. Productions, tasks, stages, owners, notes, and other schedule content are stored in the user’s browser and are not added to a Sunny workspace. The browser creates a pseudonymous visitor identifier. Sunny receives Calendar Tool content only when the user deliberately submits it to the AI feature, plus limited operational telemetry. If the user requests a gated PDF download, Sunny also receives the work email submitted for that unlock. The Calendar Tool email is not marketing consent, is not automatically added to a mailing list, and is not used to create a Core App account.

2. Information we collect

We collect the following categories of information:

• Account and organization information: name, email address, authentication identifiers, organization and project membership, role, invitation records, and account settings.

• Content you provide: prompts, chats, uploaded files, documents, feedback, generated outputs, and metadata associated with that content.

• Connected-service data: information retrieved from services you choose to connect, including Google Drive files and folder metadata, Google or Microsoft calendar event information, meeting metadata, participant information, recordings, transcripts, and related artifacts.

• Usage and device information: IP address, browser and device type, operating system, timestamps, pages and features used, referring URLs, and diagnostic events.

• Support and communications: messages, attachments, and other information you send to support or provide in sales and service communications.

• Security and operational data: authentication events, audit records, request identifiers, error reports, performance telemetry, and information used to detect abuse or investigate incidents. Sunny’s application configuration disables default personally identifiable information in Sentry unless production configuration is deliberately changed.

• Free Calendar Tool information: a browser-generated visitor identifier; limited feature, outcome, duration, and abuse-prevention telemetry; Calendar Tool content intentionally sent in an AI request; and a work email if submitted to unlock PDF download. Calendar schedules otherwise remain in browser storage under the user’s control.

We do not intentionally collect payment-card details directly. If paid features are offered, payment information may be collected by the identified payment processor under its own privacy policy.

3. Google user data

Sunny accesses Google user data only after an authorized user connects a Google account and grants the requested permissions.

This section applies to integrations in the authenticated Core App. The Free Calendar Tool does not connect to or retrieve information from a user’s Google Drive or Google Calendar.

Google Calendar

Sunny requests read-only access to calendar events and access to the connected user’s email address. We use this information to display relevant calendar information, identify meetings, schedule an authorized meeting bot, associate meetings with the correct Sunny user or workspace, and produce searchable meeting transcripts, summaries, citations, and related user-requested features. Sunny does not use Calendar access to create, edit, or delete calendar events.

Google Drive

Sunny requests read-only Google Drive access. We use it to list folders, allow an authorized user to select folders, retrieve supported files and metadata from those selected locations, keep the connected content synchronized, and create searchable text, chunks, embeddings, citations, summaries, and answers for the user’s workspace. Sunny does not modify or delete source files in Google Drive.

Google Limited Use disclosure

Sunny’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

In particular, Google user data is not sold, used for advertising, transferred to data brokers, used to determine creditworthiness, or used to train or improve generalized artificial-intelligence or machine-learning models. We permit human access to Google user data only when the user gives specific consent, when needed for security or abuse investigation, when required by law, or when the data has been aggregated and de-identified for lawful internal operations. Automated processing and transfers to contracted service providers are limited to providing, securing, and improving Sunny’s user-facing features.

You can disconnect Google Calendar or Google Drive in Sunny’s integration settings. You can also revoke Sunny’s access through your Google Account permissions (https://myaccount.google.com/permissions). Disconnecting or revoking access stops new collection but does not automatically delete information previously imported into your Sunny workspace; use the deletion methods in Section 8 to request deletion of previously imported data and its derivatives.

4. How we use information

We use personal information to:

• provide, operate, maintain, and personalize the Service;

• authenticate users and administer organizations, projects, permissions, and invitations;

• ingest, index, search, summarize, transcribe, and generate responses from authorized workspace content;

• connect and synchronize third-party integrations at the user’s direction;

• monitor reliability, debug errors, secure accounts, prevent abuse, and respond to incidents;

• provide support and send transactional or service communications;

• understand aggregate feature performance and improve the Service, without using Google Workspace API data to train generalized AI models;

• comply with law and enforce our agreements; and

• protect the rights, safety, and integrity of users, Sunny, and others.

Where applicable law requires a legal basis, we rely on performance of a contract, legitimate interests such as security and service improvement, consent, and compliance with legal obligations. An organization that controls workspace content determines the legal basis for Sunny’s processing of that content on its behalf.

5. How we disclose information

We may disclose information:

• To your organization and authorized users: according to workspace roles, sharing settings, and administrator controls.

• To service providers and subprocessors: solely to operate and secure the Service. Based on the current application architecture, these may include Supabase (authentication, database, and storage), Nango (connection and synchronization management), Recall.ai (calendar connection and meeting-bot/transcription workflows), OpenRouter and selected AI model providers (AI inference), Voyage AI or other configured retrieval providers (embeddings or reranking), Sentry (error and performance monitoring), Mailgun (transactional email), hosting and cache/queue providers, and document-processing providers. The production subprocessor list must identify the providers actually enabled.

• At your direction: when you connect a service, export content, share content, or otherwise instruct us to disclose it.

• For legal and safety reasons: if reasonably necessary to comply with law, legal process, or valid government requests; enforce agreements; or protect rights, safety, and security.

• In a business transaction: in connection with financing, merger, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality and, where required for Google user data, prior explicit user consent.

We do not sell personal information or share it for cross-context behavioral advertising. We do not use workspace content to serve targeted advertisements.

6. AI processing

Sunny uses commercial or enterprise API services—not consumer AI accounts—to process prompts and the minimum relevant workspace context needed to produce requested answers, summaries, classifications, embeddings, reranking results, and other features. Sunny does not use Customer Content, including prompts, documents, meeting content, connected-service data, or generated outputs, to train or improve Sunny’s or any third party’s generalized AI or machine-learning models. We require our AI and retrieval providers to process Customer Content only to provide the contracted API service and not to use it for model training. Outputs may be inaccurate or incomplete and should be reviewed before consequential use.

These commitments depend on Sunny using provider API plans, contractual terms, and account settings that prohibit training and enforce approved retention. We verify those controls before enabling a provider in production.

For the Free Calendar Tool, AI processing is proposal-only: relevant schedule content is sent to the configured enterprise API only when the user requests AI assistance. The response does not change the browser-local calendar until the user reviews and explicitly applies the proposal.

7. Security

We maintain administrative, technical, and physical safeguards designed to protect information, including access controls, tenant and project authorization, encryption in transit, protected credentials, logging and monitoring, vulnerability management, backup and recovery practices, and incident-response procedures. Access is limited according to job responsibilities and reviewed periodically. No system is completely secure, and we cannot guarantee absolute security.

If we discover a personal-data breach, we will investigate, mitigate, document, and notify affected customers, individuals, and authorities as required by applicable law and contractual commitments.

8. Retention, deletion, and export

We retain information only as long as reasonably necessary to provide the Service, meet contractual commitments, comply with law, resolve disputes, and protect the Service.

• Workspace content and its searchable derivatives are retained while the applicable customer account or workspace is active, unless the customer deletes them earlier.

• When content, an integration, workspace, or account is deleted, we delete or de-identify the associated active-system data within 30 days, unless law or a documented security need requires longer retention.

• Deleted information may remain in encrypted, access-restricted backups for up to 90 additional days and is removed through normal backup expiration. We do not restore deleted information to active use except for disaster recovery, and any restored data remains subject to the deletion request.

• Security, audit, and fraud-prevention records may be retained for up to 12 months, or longer when required by law or to investigate a specific incident.

• Transaction and legal records are retained for the period required by applicable law.

Authorized users may export available chats, documents, and generated artifacts through Service features. To request access, correction, export, or deletion, contact hello@loopsunny.com. Workspace users should ordinarily direct requests to their organization administrator; we will assist the organization as required.

9. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or obtain a portable copy of personal information, withdraw consent, and appeal a denied request. You may also have the right to complain to a data-protection authority. We may verify your identity and authority before completing a request. Authorized agents may submit requests where permitted by law.

Residents of U.S. states with applicable privacy laws may request confirmation, access, correction, deletion, or portability and may appeal our decision. Sunny does not sell personal information, use it for targeted advertising, or engage in profiling that produces legal or similarly significant effects, so we do not offer opt-outs for those activities.

10. International transfers

Sunny and its providers may process information in the United States and other countries. Where required, we use recognized transfer mechanisms and contractual safeguards. Enterprise customers may request relevant data-processing terms from hello@loopsunny.com.

11. Children

The Service is intended for business users and is not directed to children under 13. We do not knowingly collect personal information from children under 13. Users must be at least 18, or the age of legal majority where they live, unless an authorized organization has lawfully arranged their use of the Service. Contact us if you believe a child provided information improperly.

12. Cookies and similar technologies

We use cookies and local storage that are necessary for authentication, security, preferences, and core application functions. If we introduce non-essential analytics or advertising technologies, we will update this Policy and provide consent controls where required.

13. Changes to this Policy

We may update this Policy as the Service or law changes. We will post the updated version and change the date above. If a change materially expands our use of personal information, especially Google user data, we will provide prominent notice and obtain consent where required before applying the new use.

14. Contact

Sunny Address available upon valid legal request Email: hello@loopsunny.com