How Picrowd handles your data

A plain-language summary of what we store, how we use it, who can access it, and what control you have over your workspace data.

What we store

Picrowd stores the data you add to your workspace: records, custom fields, notes, files, comments, project structure, collaboration settings, shared links, and account details.

Files you upload are stored in Cloudflare R2. Authentication data is stored for any sign-in method you use: Google, GitHub, Apple, or magic links. We do not have access to your third-party account passwords.

How we use your data

Your data is used exclusively to operate the product you signed up for: running your workspace, keeping records and notes in sync between collaborators, generating shared links, sending notifications you have configured, and providing exports and API access.

  • Running the workspace and syncing data between collaborators
  • Supporting sharing, collaboration, reminders, and notifications you turn on
  • Providing CSV and JSON exports, API access, and billing
  • We do not sell, rent, or share your workspace data with third parties for their own purposes

Third-party services we rely on

To run the product, Picrowd uses a small set of infrastructure services. Your workspace data is stored in SQLite on Railway with persistent volumes. Uploaded files are stored in Cloudflare R2. Emails are sent through Resend. Authentication can involve Google, GitHub, or Apple depending on how you sign in.

Plugins like Drive, Dropbox, and Box access external services only when you explicitly connect them and grant permission. They operate under the access you provide.

How we protect your data

Picrowd encrypts data in transit using HTTPS and TLS. Stored OAuth tokens and connected-tool credentials are encrypted at rest with AES-256-GCM authenticated encryption. Encryption key material is kept in restricted server-side secret configuration and is never shipped to the browser.

Access to workspace and connected-tool data is enforced by authenticated user identity, project roles, and per-tool read and write controls. External tool calls are checked server-side and recorded in an audit log. Production infrastructure access is restricted to authorized operators, and credentials are removed when a connection is disconnected.

Google user data (Gmail, Google Calendar, Google Drive, Google Docs, Google Sheets)

Picrowd’s AI assistant can connect to Google services — Gmail, Google Calendar, Google Drive, Google Docs, and Google Sheets — but only after you explicitly connect each tool through Google’s OAuth consent screen. Nothing is accessed until you connect a tool yourself, and each tool receives only the permissions listed on that consent screen. You choose which tools to connect, and read and write access can be toggled per tool.

Google user data is accessed solely to provide the specific, user-facing features you invoke: searching or reading email to answer your request, drafting or sending messages you approve, managing calendar events you ask for, and creating, reading, or editing files and documents on your instruction. Tool results appear in your AI session history so you can review exactly what the assistant did; every tool call is also recorded in an audit log you can inspect. Google content is not copied into your workspace records unless you explicitly save it there.

When a request you make requires it, the minimum relevant Google content, such as the messages matching your search, is processed through Picrowd AI’s existing DeepSeek Open Platform API account strictly to provide the response or action you requested. Picrowd has disabled DeepSeek’s “Improve the model for everyone” control for this account. Google Workspace data is not used to develop or improve DeepSeek’s generalized models.

Picrowd’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

  • We do not use Google user data — including any data obtained through Google Workspace APIs — to develop, improve, or train generalized artificial intelligence or machine learning models.
  • No humans at Picrowd read your Google data, except with your explicit permission for support, where required for security investigations, or where the law requires it.
  • We do not sell Google user data, do not use it for advertising, and do not transfer it to third parties except as necessary to provide the feature you invoked or to comply with applicable law.
  • OAuth tokens and the connected account label/email are stored so the connection works. Google content is fetched on demand. Results can remain in the Picrowd AI conversation you asked us to create, in Picrowd Memory for your personalized experience, or in a workspace item only when the product feature or your instruction saves them. They are not placed in a generalized training dataset.
  • Disconnecting a tool in Picrowd AI immediately disables the connection and deletes its stored credentials. You can also revoke Picrowd’s access at any time at https://myaccount.google.com/permissions.
  • To request deletion of any retained data connected to your account, email hello@picrowd.com — we honor deletion requests for Google user data without undue delay.

AI features and your data

When you use Picrowd AI, the content needed to fulfill your request (your message, relevant workspace records, and, if you invoked a connected tool, the minimum relevant tool results) is processed by our AI model provider to generate the response. Sensitive external actions require your approval and are logged. Some external actions, such as sending an email, cannot be reversed after they complete.

We do not use your workspace content or Google user data to train our own or third-party generalized AI or machine learning models.

Picrowd AI uses DeepSeek Open Platform on Picrowd’s existing pay-as-you-go API account. The “Improve the model for everyone” control is disabled for that account. Picrowd does not operate a separate model for Google connectors and does not operate any self-hosted or offline AI model.

Picrowd Memory is a user-facing personalization feature. It may save useful context from an interaction for the relevant user, project, or record, subject to Picrowd’s access controls. Memory is not used to train or improve a generalized AI model and can be reviewed and managed inside Picrowd.

Optional generative media connectors include OpenAI Images and Speech, Google Gemini models for images and video, ElevenLabs, fal.ai, Replicate, Stability AI, Ideogram, and Higgsfield. These are separate tools connected by a user with that user’s own provider credentials and plan. Connecting a Google Workspace tool does not connect any optional media provider.

Your control

  • Export project data at any time from inside the product (CSV, JSON)
  • Delete records, projects, or your entire account
  • Revoke shared links, project tokens, and collaborator access
  • Disconnect any connected AI tool at any time — its stored credentials are deleted immediately
  • Contact us for account questions or data removal requests

Cookies and tracking

Picrowd uses an authentication cookie to keep you signed in. We do not use third-party tracking cookies, advertising pixels, or analytics scripts that follow you across the web.

Last updated August 11, 2026. Contact: hello@picrowd.com

Home · Terms · Security · Contact