Privacy Policy

Last updated: June 2026

1. Who we are

Binny is a voice assistant that helps you use digital services — including Gmail, Google Calendar, Google Contacts, Slack, and other integrations — from a regular phone call. We are committed to handling your data with transparency and care.

2. What data we collect

Depending on which services you connect, we may collect and store the following:

Account and phone

Google (Gmail, Calendar, and Contacts)

If you connect Google, we request OAuth access only to the scopes shown below. We store an encrypted OAuth refresh token, your linked Gmail address, and technical identifiers needed for Gmail push notifications (for example, history identifiers used with Google’s APIs). We do not store your full mailbox on our servers.

OAuth scopes we may request (exact URLs as shown on Google’s consent screen):

We also request OpenID Connect (`openid`) for secure sign-in.

Gmail: we use read access to list, search, and read messages so you can hear and manage mail by voice. We use send access only to compose and send messages you ask us to send (including replies and forwards). We do not use Gmail access to permanently delete messages, bulk-modify labels, or read your mail for unrelated advertising or data brokerage.

Google Calendar: we access calendar events you can access (create, read, update, delete events, RSVPs, and reminders you configure through Binny) to provide scheduling by voice and optional reminder calls.

Google Contacts: we access your contacts to search your address book, and to create, edit, and permanently delete contacts when you ask — by voice or from the Binny dashboard — including limited read-only access to “Other contacts” for suggestions and matching.

When you enable Gmail-related notifications, our systems process message metadata — the sender, subject, and a short snippet (preview) — to decide whether to place an outbound call you requested. We do not store your full email messages. When a notification matches, we save a delivery record containing the sender, subject, message ID, and that short snippet, so we can place the call and re-dial it if you don’t answer. Otherwise, message content is accessed only in real time to read it aloud when you ask, and is not retained.

Slack

We do not store the content of your Slack messages. When you enable Slack notifications, we retain only metadata about a triggering event — the sender, the channel or conversation, and the message timestamp — so we can place the call you requested and re-dial it if you don’t answer. The message text itself is read to you in real time during the notification call — it is never written to our database and is never used to train any AI or machine-learning models.

Other integrations and payments

If you use taxi booking, payments, or other features, we process the minimum data needed to operate those features (for example, ride or payment metadata). See the relevant product areas in your dashboard and notices shown at collection.

3. How we use your data

We never sell, rent, or share your personal information with third parties for their independent marketing purposes.

4. Limited use of Google user data

Binny’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we only use Google user data to provide or improve Binny’s user-facing features; we do not sell Google user data; we do not use Gmail content for serving advertisements; and we do not allow humans to read your Gmail content except as permitted under that policy (for example, with your consent for support, for security or legal compliance, or where aggregated and de-identified).

Binny complies with the Google Limited Use Policy. Google user data is processed in real time to provide voice-to-text features and is never cached, stored in our databases for reuse, or used to train machine learning or AI models. Separately, we retain only the encrypted account credentials and minimal technical metadata described in section 2 (for example, OAuth tokens and Gmail notification sync fields) solely to operate sign-in, API access, and optional notifications — not for model training.

5. How we protect your data

OAuth tokens (including Google refresh tokens and Slack access tokens) are encrypted at rest using AES-256-GCM authenticated encryption before being stored in our database. Traffic between Binny and third-party APIs uses HTTPS. Slack webhook payloads are verified using HMAC-SHA256 signatures where applicable.

6. Data retention

We retain connected-service tokens and preferences for as long as your Binny account is active and the connection remains enabled. You can disconnect Google or Slack from your dashboard at any time; disconnecting Google immediately deletes your stored Google OAuth tokens and related connection data (such as calendar watch channels and Gmail sync identifiers) from Binny, after which accessing your Google data again requires reconnecting.

7. Third-party services

Binny integrates with providers that process data on our behalf, including:

8. Your rights

9. AI features

Binny is an AI voice assistant. To understand your speech and generate responses, your requests are processed in real time by large language models, delivered through our voice infrastructure provider (Vapi). This processing is transient — the content serves your request in real time and is not retained by us or by that provider, nor used to train any models. Because responses are AI-generated, they may occasionally be inaccurate or incomplete. Please verify important information, and do not rely on Binny for legal, medical, financial, or other consequential decisions without independent human review; Binny does not make such decisions on your behalf.

10. Contact

For privacy-related questions or data requests, contact us at support@binny.io.