Privacy Policy

This policy explains how 33io handles account, production, integration, and Google user data.

Last updated July 10, 2026

Who this policy covers

33io is a production operating system for film and television teams. This policy applies when you visit 33.io, create an account, join a production, connect a third-party service, or use 33io agents and workflows.

Information we collect

  • Account details such as name, email address, and authentication identifiers.
  • Production data you or your team add, including tasks, schedules, files, roles, and operational records.
  • Integration configuration and authorization tokens needed to maintain services you connect.
  • Technical, security, and audit events needed to operate and protect 33io.
  • Google user data only after you explicitly authorize a Google connection.

Google user data

When you connect Gmail, 33io requests read-only Gmail access and basic Google account identity. 33io reads message headers, labels, snippets, and message content only to provide features you request: inbox intelligence, evidence-backed role discovery, workflow suggestions, and draft-only assistant recommendations.

Raw Gmail message bodies are processed transiently and are not stored in 33io profile or role-discovery records. Stored outputs are limited to account metadata, aggregate signals, user-reviewed role claims, evidence identifiers and limited header metadata, decisions, and audit records. 33io does not send, delete, label, archive, or mark Gmail messages read through this connection.

33io's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How we use information

  • Provide, secure, support, and improve the user-facing 33io features you choose to use.
  • Keep access scoped to the user, production, department, or platform role that authorized it.
  • Generate private summaries, drafts, role profiles, and agent recommendations for your review.
  • Detect abuse, investigate failures, maintain audit trails, and comply with law.

33io does not sell Google user data, use it for advertising, use it to determine creditworthiness, or use it to train generalized AI models.

Service providers and data transfers

33io uses infrastructure, database, hosting, security, and AI processing providers to deliver features visible in the product. Providers receive only the data needed to perform those services and are required to protect it. Gmail excerpts may be transmitted to an AI processing provider only when needed to perform a user-requested role-discovery or drafting feature. They are not transferred for advertising, data brokerage, or generalized model training by 33io.

Security and retention

33io uses encrypted transport, access controls, row-level database policies, encrypted OAuth credentials, audit logging, and scoped service access. We retain account and production records while your account or production relationship is active and as needed for security, legal, and backup obligations. Gmail authorization tokens are removed when the connection is disconnected. Derived Gmail role profiles can be deleted with the connection or through a deletion request.

Your choices and deletion

  • You can decline Google authorization and continue using features that do not require Gmail.
  • You can disconnect Gmail in 33io, which revokes access and removes the stored authorization credentials.
  • You can also revoke 33io from your Google Account permissions.
  • You can request access, correction, export, or deletion of your personal data.

Contact

Privacy and data deletion requests: nick@33.io