Operator: Adaptive Agility LLC ("Sutradhar", "we",
"us", "our"). Contact: privacy@adaptiveagility.com
· https://app.sutradhar.io
1. Who we are and what this covers
Sutradhar is a sovereignty-first, consent-gated personal steward. It looks across
the accounts you choose to connect (such as email, calendar, and document storage) and surfaces what
matters to you (deadlines, renewals, documents to have ready, and the people you look after) without
taking actions on your behalf in those accounts.
This Privacy Policy explains what data Sutradhar accesses, how we use and protect it, and the
controls you have. It applies to the Sutradhar application at https://app.sutradhar.io and related
services.
2. Our core privacy commitments
These are the principles the product is built on, enforced in code, not just stated here:
- Read-only. We request read-only access to your connected
accounts. Sutradhar does not send email, modify or delete messages, change your
calendar, or alter your files.
- Metadata, not content, leaves your data at rest. We do not
store the full content of your documents. The Sutradhar "Vault" holds pointer records
only (a reference to a document that stays in your own storage), never the document
itself.
- No document content is sent to AI models. When Sutradhar uses an AI model to
reason, it works from metadata and extracted signals only, never the raw content
of your documents.
- No sensitive content is stored in our database. We do not retain PII, health, or
payment-card content in our database; what we keep are inferences and metadata
needed to serve you (e.g. "a renewal is due," "a document type is missing").
- You control the data flow. Connecting a service is not blanket
consent to collect everything; you control what Sutradhar looks at, you can pause the agent
globally at any time, and you can revoke any connection at any time.
- We do not sell your data or use it for advertising.
3. Information we access and process
a) Account information. When you create an account, we collect your name and email
address, and authentication information.
b) Connected services (only those you choose to connect, read-only). With your
explicit authorization, Sutradhar reads from providers such as:
- Google: Gmail (read-only), Google Calendar (read-only), Google Drive
(read-only).
- Microsoft: Outlook mail/calendar, OneDrive (read-only).
- Slack and other connectors you opt into.
From these, Sutradhar processes metadata and signals, for example: that a message
or event relates to a deadline, renewal, or a known contact; the type of a document
and its metadata (name, dates, source) rather than its contents. We use this to generate the
findings, reminders, and document-readiness the product provides.
c) Data Sutradhar derives for you. Goals and Projects you create, the people in
your Trusted Network and Circles, document pointer records in your Vault, and the
findings Sutradhar surfaces (which are inferences/metadata, not stored copies of
your content).
d) Technical and usage data. Logs, device/browser information, and an
immutable audit log of automated actions (used for transparency and security).
e) Public website analytics. On our public website (sutradhar.io) we count page
views, so we know which pages people find useful. We record only which page was viewed, the day it
was viewed, and the website that referred you. We set no cookies and store
no IP addresses, device identifiers, or profiles, so these counts cannot be linked
to you or to any account. This applies to the public website only, not to the product.
4. How we use information
- To provide the service: surface findings, watch for the things you asked us to watch, organize
the documents you need to have ready, and keep your Goals/Projects/Circles up to date.
- To secure the service, prevent abuse, and maintain the audit trail.
- To communicate with you about the service (e.g. notifications you have enabled).
- To comply with law.
We do not use your connected-account data for advertising, and we do
not sell it.
5. Service providers / sub-processors
We share the minimum necessary data with vetted providers that help us run Sutradhar:
- AI reasoning: Anthropic (Claude API). Sutradhar sends metadata and
extracted signals only (never document content) to generate findings. Under Anthropic's
commercial API terms, Anthropic does not train its models on data submitted
through the API.
- OAuth providers: Google, Microsoft, Slack. For the read-only access you
authorize.
- Hosting / infrastructure: Render (application hosting, managed PostgreSQL, and
Redis).
- Transactional email: Google Workspace, used only to deliver service emails such
as circle invitations (no connected-account content is sent).
We do not permit these providers to use your data for their own purposes.
6. Google user data and Limited Use
Sutradhar's use and transfer of information received from Google APIs adheres to the
Google
API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We request read-only Google scopes: Gmail (
gmail.readonly),
Calendar (calendar.readonly), and Drive (drive.readonly).
- We use Google user data only to provide and improve the user-facing features
described in this policy.
- We do not transfer Google user data except as necessary to provide or improve
those features, to comply with law, or as part of a merger/acquisition with appropriate notice.
- We do not use Google user data for advertising.
- We do not allow humans to read Google user data unless: (i) you give explicit
consent for specific data; (ii) it is necessary for security; (iii) to comply with law; or (iv) the
data is aggregated/de-identified.
- Per-scope use: Gmail (read-only) to detect deadlines, renewals, and relevant
contacts from message metadata/signals; Calendar (read-only) to surface upcoming commitments and
deadlines; Drive (read-only) to identify document types and gaps and create Vault
pointers (we do not copy or store document contents).
7. Security
- OAuth tokens are encrypted at rest.
- We follow the data-minimization principles in section 2 (no sensitive content in our database;
pointer-only Vault; no content to AI models).
- The audit log of automated actions is immutable.
- Data is encrypted in transit (TLS).
No system is perfectly secure; we cannot guarantee absolute security.
8. Data retention and deletion
- We retain the metadata described above for as long as your account is active or as needed to
provide the service.
- You can disconnect any service at any time, which stops further access;
you can delete your account, after which we immediately erase the
information Sutradhar holds about you — the findings, inferences, and signals we derived, your
Trusted Network, goals, projects, Vault pointers, and settings. We retain only the
immutable audit log (kept for security and legal reasons) and a
minimal account record — your email and name, which anchors that audit log and lets
us recognize you if you return, so we can tell you that your previous data is gone. No connected-account
content and no derived personal data are kept.
- Because the Vault stores pointers, deleting Sutradhar data does not touch the
documents that remain in your own storage.
9. Your rights and controls
- Sovereign controls: pause the agent globally, revoke any connection, and control
what Sutradhar looks at, at any time.
- Access / correction / deletion: you may request a copy of your data, correction,
or deletion at privacy@adaptiveagility.com.
- Depending on where you live, you may have additional rights (e.g. GDPR for the
EEA/UK, CCPA/CPRA for California).
- External sharing is consent-gated: Sutradhar requires your explicit consent
before any external share of your information, and such sharing is revocable.
10. Children
Sutradhar is not directed to children and is intended for users 18 and older. We do
not knowingly collect data from children under 18. (A minor-profile feature exists for a guardian
to manage a dependant within a family circle; that data is provided and controlled by the adult
guardian.)
11. International data transfers
If we process data across regions, we do so with appropriate safeguards for cross-border transfers.
12. Changes to this policy
We may update this policy; we will post the new effective date and, for material changes, notify you
in-app or by email. Continued use after changes means you accept them.
13. Contact
Questions or requests: privacy@adaptiveagility.com · Adaptive Agility LLC.