Public policy
How picrm handles your data.
picrm stores the CRM data you add or choose to sync. External providers receive only the access a workspace administrator approves.
Effective 18 August 2026
Data we process
We process account identity, workspace membership, CRM records, tasks, interactions, audit history, and the configuration needed to run the service. Better Auth manages identity and sessions. Mailbox and integration tokens are encrypted before storage.
If a workspace administrator explicitly enables continuous sync for Google, Microsoft, or Zoho, picrm stores bounded email metadata and previews plus calendar titles, descriptions, organizers, participants, times, locations, meeting links, and status. Automatic CRM contact creation remains a separate opt-in. Slack content is posted only after a separate human approval.
Our self-hosted Rybbit analytics records page paths, referring origins, browser and device metadata, and session activity. It stores a persistent rybbit-visitor-id in local storage until you clear site data. Authentication, password-reset, invitation, and shared-agent routes are excluded from analytics.
Why we use it
We use this data to provide the CRM, authenticate users, connect approved providers, run requested workflows, prevent abuse, and keep tenant-scoped audit and reliability records. We do not sell personal data or use provider data for advertising.
Google user data is used only to provide user-facing Gmail and Calendar evidence features. It is not transferred for advertising, sold to data brokers, or used to train generalized AI models. Agent access remains limited to exact, reviewed evidence pins.
Service providers
The service runs on Cloudflare Workers, D1, Durable Objects, Workers AI, and Email Service. Site analytics are processed by an operator-controlled, self-hosted Rybbit instance and are not used for advertising. If you connect them, Google, Microsoft, Slack, Zoho, or AgentMail process requests under their own terms. picrm sends each provider only what is needed for the action you requested.
Control and retention
Workspace administrators choose each synced source, history window, and contact-creation setting; they can disable sync or revoke a provider grant at any time. Disabling stops new imports, while revocation immediately blocks both sync and new agent use. Operational logs exclude CRM payloads and use bounded route and error metadata.
Imported communication records remain in the workspace until the connection or workspace data is deleted, or a deletion request is completed. Rybbit session and event data remain until an administrator deletes them, while the local visitor identifier remains until you clear site data. For access, correction, deletion, or export requests, contact the operator through the support email displayed on the OAuth consent screen. We otherwise retain data while the workspace is active and as needed for security, legal obligations, and reliable service operation.
Security and changes
Every customer-owned database row is scoped to an authenticated organization. Outbound email and Slack messages retain a separate human approval boundary. We may update this notice as the product changes and will publish the effective date here.