Cernos

Privacy Policy

Effective date: May 21, 2026

This Privacy Policy describes how Cernos ("Cernos", "we", "us") collects, uses, and protects information when you use Cernos, including the Cernos web application at app.cernos.app, Cernos for Outlook (the Office add-in for Outlook), Cernos for Gmail (the Chrome extension for Gmail), Cernos Desktop (the optional Windows overlay app), and any third-party services you choose to connect to your Cernos workspace (Microsoft 365, Google Workspace / Gmail / Google Calendar, HubSpot).

This Privacy Policy is separate from any Terms of Use that may apply to your use of Cernos. It is intended to give you a clear picture of what data Cernos handles, why, and what control you have over it.

1. Who this policy covers

This policy applies to all users of:

2. What data Cernos collects

2.1 Account and identity data

When you sign up for Cernos, sign in via Google through Clerk, or sign in via Microsoft 365 through the Cernos for Outlook add-in, we collect:

We do not store passwords. Authentication is delegated to Clerk, Microsoft Entra ID, and Google.

2.2 Microsoft Graph data

The Cernos for Outlook add-in requests one Microsoft Graph delegated permission:

PermissionWhat it grantsWhy Cernos uses it
User.Read (delegated)Read the signed-in user's basic profile (name, email, object ID)Identify which seller is opening the pane, so the Cernos backend can match them to their workspace

Cernos for Outlook does not request Mail.Read, Mail.ReadWrite, Files.Read, Calendars.Read, or any other Microsoft Graph scope beyond User.Read.

2.3 Outlook message data

When you open the Cernos pane on a message in Outlook, the Cernos for Outlook add-in reads, in memory only, the currently open message via Office.js APIs:

The add-in does not read your mailbox in bulk via Office.js, does not move or modify messages, does not write to your mailbox, and does not retain message content after the pane render completes. Message content is sent to the Cernos backend for matching and prose generation only for the message you have open.

2.4 Google API access (when you connect Google)

If you connect your Google account to your Cernos workspace, Cernos requests the following Google OAuth scopes:

ScopeWhat it grantsWhy Cernos uses it
gmail.readonlyRead messages and metadata in your Gmail mailboxSurface relevant prior email context against the prospects in your workspace
calendar.readonlyRead events on your Google CalendarDetect upcoming meetings with prospects so the pane can surface meeting-relevant context and prep

Cernos does not request gmail.modify, gmail.send, calendar.events (write), Google Drive, Google Contacts (people API), or any other Google OAuth scope beyond the read-only Gmail and Calendar scopes above. You can revoke Cernos's access to your Google account at any time from your Google Account permissions page, which cuts off any further Cernos access to your Gmail and Calendar data going forward.

2.5 Gmail message data

The Cernos for Gmail Chrome extension and the connected Google integration read Gmail content in two ways:

Cernos uses Gmail data only to deliver the user-facing features of the product. We do not use your Gmail data to train any general or third-party machine learning models. Cernos's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

2.6 Google Calendar data

If you grant the calendar.readonly scope, Cernos reads events on your primary Google Calendar to detect upcoming meetings with workspace prospects. We do not create, modify, or delete calendar events.

2.7 CRM and workspace data

If you connect a CRM (such as HubSpot or Salesforce) to your Cernos workspace, Cernos imports prospect, account, contact, and activity records on your behalf to populate your workspace. We store this data in your workspace and use it to render account intelligence in the Cernos web app, the Cernos for Outlook pane, and the Cernos for Gmail pane. You can revoke Cernos's ongoing access to a connected CRM from that provider's integration management page (for example, HubSpot's Connected Apps screen or Salesforce's connected app management screen), or by contacting support@cernossi.com to request that Cernos remove the integration and its synced data from your workspace.

2.8 Usage and operational data

We log limited operational data necessary to run the service: request timing, error events, and security-relevant authentication events. We do not currently use third-party analytics platforms (such as Google Analytics or Mixpanel) to track end-user behavior.

2.9 What Cernos remembers about your account conversations

Once you connect a supported service to your Cernos workspace, Cernos uses it to answer practical questions about your accounts — who is involved, what has been promised, what has changed, what objections recur, and what needs attention before your next meeting. What Cernos accesses and stores depends on which service is connected; the subsections below describe the current behavior for each.

Gmail and Google Calendar

When you connect Gmail or Google Calendar, Cernos begins reviewing the account history on those services in the background so the rest of the product has context to work with.

What Cernos stores for each email conversation: the participants (names and email addresses), the date and direction of each message, the subject line, and the structure of the conversation. Cernos does not store the full bodies of your emails. Message body text is read in memory at the time of processing so Cernos can match the message to the right account and then discarded; the raw body is not written to the workspace database.

What Cernos stores for each calendar event: the title, the start time, and the participants. Cernos does not store the description, notes, or attachments of calendar events. If the event description is needed for matching, it is used in memory and discarded.

Microsoft 365 and Cernos for Outlook

The Cernos for Outlook add-in reads the currently open message in your Outlook reading pane, as described in Sections 2.2 and 2.3. The add-in does not read your Microsoft 365 mailbox in bulk, does not move or modify messages, and does not write to your mailbox.

When you open a specific message with the Cernos pane, Cernos can generate useful context (such as a one-paragraph read of the contact, the relationship state, and a recommended next step) from that message to render in the pane. The raw body of the message is not retained.

When you connect Microsoft 365, Cernos also begins reviewing the account history on that mailbox in the background so the rest of the product has context to work with — the same posture as Gmail described above.

What Cernos stores for each email conversation: the participants (names and email addresses), the date and direction of each message, the subject line, and the structure of the conversation. Cernos does not store the full bodies of your emails. The Microsoft Graph requests Cernos makes for this background review are restricted to header and identity fields only — message body text is not requested or stored. The background review covers the Inbox, Sent Items, and (when available) Archive folders; user-created custom folders and the Junk Email and Deleted Items folders are not reviewed.

HubSpot

When you connect HubSpot, Cernos imports and keeps the current state of deals and contacts associated with your accounts, plus metadata about engagements (emails, calls, meetings, notes, tasks) that HubSpot has logged for those records — specifically the type, date, direction, subject, and participants of each engagement. Cernos does not retain the raw body text of HubSpot-logged emails or notes. A broader backfill of historical engagement records predating workspace connection is on the product roadmap but is not part of the current HubSpot integration.

Salesforce

When you connect Salesforce, Cernos imports and keeps current CRM metadata for accounts, contacts, opportunities, tasks, and Salesforce Events (calendar items logged in Salesforce) that your Salesforce user can access. Cernos stores record names, dates, stage/status fields, and non-content identifiers needed to connect activity to workspace prospects. Cernos does not retain Salesforce note bodies, task descriptions, event descriptions, files, attachments, or raw CRM content.

Zoom (when connected)

When you connect Zoom, Cernos keeps the title, start time, and identifiers of each meeting or recording so it can connect them to the right accounts. For recorded meetings that have already happened, when Zoom makes participant data available, Cernos also keeps the list of participants — the name, the email address when Zoom provides one, and the times they joined and left — so it can recognize who was on the conversation. Cernos does not retain meeting agendas, recording content, transcripts, chat, attentiveness scores, or any other in-meeting content.

Where it lives, who can see it, and how long it is kept

Account history is stored inside your Cernos workspace on the application database described in Section 5 and is visible only to authorized members of that workspace. Useful context Cernos generates for messages you open is produced by the large language model providers listed in Section 5; the underlying provider terms prohibit using your data to train their models.

Account history is retained for the life of your Cernos workspace and is removed under the timeline described in Section 6 when you delete your workspace. If you disconnect an integration, Cernos stops reviewing new activity on that account; previously stored account history remains in your workspace until the workspace is deleted, or until you request earlier removal per Section 7.

2.10 Cernos Desktop overlay (Windows)

Cernos Desktop is an optional Windows application that displays your Cernos meeting prep on small, always-on-top notes you arrange over any meeting window. It shows the same seller-owned prep data described elsewhere in this policy. It introduces one additional, local-only signal: meeting detection.

Meeting detection (local camera/microphone in-use status). To know when to surface your prep, Cernos Desktop may check your local Windows camera/microphone in-use status — the indicator the operating system maintains (Windows Capability Access Manager) for which applications are currently using those devices — to detect that a meeting is happening and surface seller prep. Specifically:

The overlay displays seller-owned Cernos prep locally and is designed to be excluded from screen sharing, so other meeting participants do not see it. Cernos Desktop runs in the background and starts with Windows by default; you can turn off start-with-Windows and meeting auto-open from its tray menu, and you can uninstall it like any other Windows application.

2.11 Billing and payment data

If you start a paid Cernos subscription or trial through Stripe, Stripe collects and processes payment information, billing details, and receipt information through its hosted checkout and customer portal. Cernos does not store full credit card numbers or bank account numbers.

Cernos stores subscription administration data needed to run the service, such as your Stripe customer ID, Stripe subscription ID, selected plan, subscription status, trial and billing-period dates, and the billing email address Stripe collected for receipts and payment administration.

The billing email address is used only for billing, receipts, support, and payment administration. It is not used as your Cernos account identity, is not used to decide which workspace data to sync, and is not used as evidence for account matching, recommendations, or seller identity.

3. How Cernos uses your data

Cernos does not sell your data and does not use your data to train third-party machine learning models on your behalf.

4. Legal basis for processing (where applicable)

Where the EU General Data Protection Regulation, the UK General Data Protection Regulation, or other comparable data protection laws apply, Cernos processes personal data on the legal bases of contract performance (delivering the service you signed up for), legitimate interest (operating, securing, and improving the service), and where required, your consent (for example, the Microsoft consent prompt when you first open the Outlook add-in).

5. Sub-processors and third parties

Cernos relies on the following sub-processors to deliver the service:

Sub-processorPurposeData handled
Microsoft (Entra ID, Microsoft Graph)Identity, Outlook add-in host, Microsoft 365 SSOIdentity claims, message metadata via Office.js
Google (when connected by you)Google sign-in (via Clerk), Gmail API, Google Calendar APIIdentity claims, Gmail message data (read-only), Google Calendar event data (read-only)
ClerkBrowser-side authenticationEmail, name, provider identity
Supabase (PostgreSQL)Application databaseWorkspace, prospect, account, and identity records
VercelWeb hosting and serverless runtimeRequest traffic, application logs
AnthropicLarge language model APIMatched-state context, prep, and synthesis content (prospect, account, and conversation excerpts)
OpenAILarge language model APIMatched-state context, prep, and synthesis content (prospect, account, and conversation excerpts)
HubSpot (when connected by you)CRM integrationProspect, account, contact, and activity records
StripeCheckout, subscription billing, invoices, and customer portalBilling email, payment method details, invoice and subscription records, customer and subscription identifiers

We update this list as our sub-processor set changes. We require sub-processors to maintain appropriate technical and organizational safeguards for the data they process on our behalf.

6. Data retention

We retain account and workspace data for as long as your account is active. If you delete your account, we delete or anonymize associated personal data within 30 days, except where retention is required by law or for legitimate business purposes (such as fraud prevention, accounting, or dispute resolution).

Message content read in-pane by the Cernos for Outlook add-in or the Cernos for Gmail extension is processed in memory at the time of the pane render and is not retained beyond the request. Gmail and Google Calendar data fetched via the Google APIs to populate prior-context records is stored in your workspace. Revoking Cernos's access from your Google Account permissions page stops further sync but does not by itself delete already-synced records; those records are removed when your Cernos account or workspace is deleted (see the retention timeline in this section). Match results and generated prose may be cached on a per-workspace basis for performance.

7. Your rights

Depending on where you live, you may have the following rights with respect to your personal data:

To exercise any of these rights, contact us at security@cernossi.com.

8. Security

9. International data transfers

Cernos and its sub-processors operate primarily from the United States. Where personal data is transferred from outside the United States, we rely on appropriate legal mechanisms (such as standard contractual clauses) where required.

10. Children's privacy

Cernos is a business product designed for use by sellers and organizations. The service is not directed to children under 16, and we do not knowingly collect personal data from children.

11. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Effective date" above and, where appropriate, notify you through the service or by email. Continued use of Cernos after a material change constitutes acceptance of the updated policy.

12. Contact

For privacy, security, or compliance questions: security@cernossi.com

For general support: support@cernossi.com