SMELT

Legal

Privacy Policy

Last updated 3 August 2026

1. Who we are

GIMZWARE is a company registered in England and Wales and is the data controller for personal data processed through SMELT Studio (the “Service”). You can contact us at [email protected].

2. Personal data we collect

Some of the categories below are data about you. Others are data you bring into the Service, which may describe other people. We hold both, and both are covered by this policy.

  • Account data - name, email address, and authentication identifiers provided by Google, GitHub, or Microsoft when you sign in through Firebase Authentication. A phone number if you give us one.
  • Workflow data - the workflows you build, including the prompts, addresses, and code you put in each block, the inputs you provide, and the outputs produced during execution. We keep a version history of each workflow so you can go back to an earlier draft.
  • Knowledge base contents - the files you upload and the text you paste into a knowledge base. We keep the original file, the text we extract from it, and the search index we build over that text. If a document contains personal data, we hold that personal data for as long as the knowledge base exists.
  • Agent memory - short notes an agent writes for itself so it can recall earlier work. The notes are drawn from your run content, so they can contain anything that ran through the agent.
  • Chat messages - the messages you send to a chat-triggered workflow, held briefly so the workflow can follow the conversation.
  • Trigger data - what a trigger needs to know what to act on. For an email trigger that is the search you configured and the identifiers of the messages it has already handled; once a run starts, the sender, subject, and body of the matched message become part of that run.
  • Integration credentials - OAuth access and refresh tokens for third-party services you connect (for example Gmail, Slack, GitHub), and any provider API key you choose to bring yourself. Both are stored through our integration provider Nango, not in our own database.
  • Team invitations - the email address of anyone you invite to a workspace, held so we can send the invitation and match it when they accept.
  • Usage data - logs describing which workflows you ran, when, how long they took, token counts, and cost.
  • Billing data - if you subscribe to a paid plan, billing and payment method details processed by Stripe on our behalf.
  • Technical data - your IP address, browser details, and the addresses you request. Our domains sit behind Cloudflare, so Cloudflare sees this on every request and keeps its own logs of it.

3. How we use your data

We process your data for the following purposes and lawful bases:

  • Providing the Service (performance of the contract) - authenticating you, executing workflows, and surfacing results.
  • Calling third-party APIs on your behalf (performance of the contract) - when a workflow connects to a provider you have authorised, we use your stored OAuth tokens to carry out the action you configured.
  • Improving reliability and performance (legitimate interest) - telemetry from the app and our servers covering which pages were opened, how long requests took, and what failed. It carries identifiers and timings, not the content of your workflows.
  • Billing (performance of the contract and legal obligation) - processing paid subscriptions and invoicing.
  • Screening content for harm and for prompt injection (legitimate interest) - text you add to a knowledge base is checked by an automated content-safety service before it is indexed, and the prompts your AI blocks send, together with what a connected tool returns to them, are checked for prompt injection before a model sees them.
  • Security (legitimate interest) - detecting and preventing abuse.

We do not use your workflows, run content, knowledge bases, or agent memory to train models, ours or anyone else’s.

4. Who we share data with

We share personal data only with sub-processors that help us run the Service:

  • Cloudflare - domain names and the traffic proxy in front of our site, app, and API. Every request passes through Cloudflare, which terminates the connection and therefore sees your IP address, the address you requested, and your browser details, and keeps its own request logs. It also serves a small analytics script from its edge.
  • Microsoft Azure - hosting, container orchestration, database, cache, and file storage (UK South region). Uploaded knowledge base files and generated report files are held in Azure Storage.
  • Google Firebase - user authentication.
  • Azure AI Foundry - inference for workflow AI blocks. Prompts, and whatever your workflow puts in them, are sent there to be answered.
  • OpenAI and Anthropic - inference, and only when you bring your own key for one of them. A workspace using its own provider key sends that workspace’s prompts straight to the provider the key belongs to, rather than through Azure AI Foundry. Workspaces on our managed AI never reach either.
  • Azure AI Content Safety - automated screening. Text you add to a knowledge base is checked before it is indexed, and the prompts your AI blocks send, together with what a connected tool returns to them, are checked for prompt injection before a model sees them.
  • DuckDuckGo - web search results for the Retrieve block. When you tick the web source on that block, the query it is configured with is sent to DuckDuckGo to be searched: the text you typed in the field, with any references resolved to the values earlier blocks in the run produced. Nothing else from the run is sent, and no other part of the Service reaches them.
  • Nango - OAuth flow management, secure storage of integration tokens and of any provider API key you bring yourself, and the proxying of calls your workflow makes to a connected provider.
  • Stripe - payment processing and subscription management.
  • Azure Communication Services - transactional email delivery.

We do not sell your personal data. We share workflow input and output with the third-party providers you have connected only to the extent required to execute the workflow you designed.

5. How Google user data is used

If you connect a Google service (Gmail, Calendar, Drive, Sheets), SMELT Studio uses the access granted only to perform the specific action configured in your workflow. We do not read your data for advertising, sell it, or use it to train generalised machine learning models. Use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements.

6. International transfers

Our primary infrastructure runs in Microsoft Azure UK South. Some sub-processors are based outside the UK (notably in the United States), and Cloudflare serves our traffic from whichever of its locations is nearest to the visitor. Transfers rely on the UK International Data Transfer Agreement and the European Commission’s Standard Contractual Clauses where applicable.

7. Data retention

We keep each category for as long as it serves the purpose we collected it for, and no longer.

  • Run history - 30 days. A daily sweep deletes runs older than that, along with their inputs, step outputs, and error messages. The monthly usage totals your bill is built from are held separately and are not affected, so your invoices and usage figures stay intact.
  • Knowledge bases and agent memory - until you delete the document, the collection, the agent, or your account.
  • Workflows and their version history - until you delete them or your account. We keep the 50 most recent versions of each workflow.
  • Live run state and chat - held in our cache and expired automatically: run events after 24 hours, chat history after one hour.
  • Team invitations - until accepted, revoked, or expired.
  • Integration credentials - when you disconnect an integration, the tokens are deleted and revoked with the upstream provider.
  • Account data - for as long as your account is active.

Backup copies are purged on a rolling 30-day cycle, so anything we delete can persist in a backup for up to 30 days after that.

When you ask us to delete your account, we keep it for 30 days so that you can change your mind, and we tell you the date it will be erased. You can cancel at any point in that window from your account settings. Nothing new runs during it, because we stop your subscription renewing as soon as you ask.

After the 30 days we permanently erase your personal details, workflows, run history, knowledge bases, and agent memory, and revoke your integration credentials with the upstream provider. We keep a record of what you were charged, without your personal details attached, for six years to meet UK tax obligations.

8. Your rights

Under the UK GDPR you have the right to access, correct, delete, restrict, or port your personal data, and to object to processing. To exercise any of these rights email [email protected]. You also have the right to complain to the Information Commissioner’s Office.

9. Storage on your device

We set no advertising or tracking cookies. Signing in stores your authentication tokens in your browser, and the app remembers which workspace you had open and whether the sidebar was collapsed. Clearing your browser storage signs you out and resets those two preferences.

Cloudflare may set a cookie of its own to tell automated traffic from real visitors. Our own product analytics runs without cookies.

10. Security

We encrypt data in transit with TLS and at rest using provider- managed keys. OAuth tokens are stored by Nango with AES-256 encryption. Access to production systems requires strong authentication and is logged.

11. Changes to this policy

We will update this page when our practices change and note the revision date above. Material changes will be notified by email to account holders.