Privacy Policy

Last updated: September 15, 2026

1. Introduction

Configure AI, Inc. ("Configure", "we", "us", "our") operates the Configure platform and profile services. Configure is personalization infrastructure for agents: a user-controlled system of record across agents. It recognizes the same user across agents and lets approved agents read and write shared user context through integrations such as API, MCP, and tool calls. Shared context can include identity information, preferences, memories, and connected tools.

This Privacy Policy applies to all users of the Configure platform, including:

By using Configure, you agree to the collection and use of information as described in this policy.

2. Information We Collect

Phone number

We collect your phone number for identity verification via SMS one-time passcode (OTP) through our verification provider, Prelude. Your phone number is stored as an irreversible cryptographic hash, together with its last four digits so that you can recognise your account. We cannot recover the full number from our database.

Profile data

When you use Configure through an integrated agent or application, we collect and store identity information (such as name, email, bio, occupation, interests, and location), preferences, and memories extracted from your conversations. This data forms your persistent Configure profile.

Each memory records which connected assistant or application saved it and the date it was saved. That attribution is part of the memory and is visible to the assistants and applications you authorize, so you can ask any of them what a particular source knows about you. When you ask an assistant what it knows about you, it receives your profile: your name, occupation, bio and interests, your preferences, the generated summary documents, the list of memory categories and sources with a one-line preview of each, the memories you chose to keep and, for integrations that include them, the connection status of your connected tools and applications. The memory integrations we publish in assistant directories never receive sign-in details (your phone number or any part of it, or how you signed in).

Imported memories. When you bring memories over from another AI assistant, or provide notes or documents for your profile, we store what you provided, split into individual memories where the material is a list of facts, together with a record of which assistant the material came from.

Generated profile documents. We generate short documents from your memories — a summary of who you are, your current focus, and how you like to be addressed — so that an assistant can use your profile without reading every memory. These documents are derived only from data already in your profile, are regenerated when your memories change, and are deleted with them.

Connected tool data

When you connect third-party services, we access metadata and content necessary to enrich your profile:

We only access data from services you explicitly connect and authorize.

Usage data

We collect standard server logs, including IP addresses, timestamps, and request paths, to operate and improve our services.

When you sign in, we also record your browser's user-agent string and a hashed form of it, together with a hashed form of your IP address. We use these records only to detect suspicious sign-in activity on your account. We do not use them for advertising or behavioral profiling.

Developer data

For developers using the Configure API or SDK, we collect API keys, agent configurations, and usage metrics.

3. How We Use Your Information

4. Profile Portability

Profile portability is a core feature of Configure. When you authorize an agent or application, it can access profile information allowed by your Configure permissions, including identity information, preferences, and memories. Profile information can include facts derived from connected tools such as Gmail.

This means your context follows you across agents — you do not need to re-introduce yourself or re-state your preferences each time you interact with a new application.

For end users: Your profile may contain personally identifiable information (PII), including your name, email, occupation, interests, and details extracted from conversations and connected tools. Review your profile and the access you grant to each application. An application's own privacy notice must describe its processing and additional service providers.

For developers: Profile data you receive through the Configure API may contain PII. Your handling of that data must comply with the Developer Terms, the user's permissions, and the Google API data restrictions in Section 5 where applicable. Being part of the Configure network does not by itself authorize a transfer.

Configure requires developers to use profile information only for disclosed, authorized purposes. These requirements do not reduce Configure's own obligations for data it collects or shares.

You can manage connected accounts, application access, and profile visibility in Configure. The available controls let you review and change what you share. Removing an application's access is separate from deleting information it has already received.

5. AI Processing

Configure uses AI inference to answer questions, extract facts and preferences, and maintain your profile. This processing can use conversations, selected Gmail content, and information derived from connected Gmail accounts. Connecting a readable Gmail account can start background analysis to build or update your profile. Analysis can also occur when you use email features or when Configure refreshes your profile. Configure does not use user data to train AI models.

Configure-operated services use Anthropic and Groq for email analysis, profile generation, memory processing, and agent responses. The provider used depends on the feature and its configuration. We use Composio to manage authorized Gmail connections and execute Gmail API requests. Relevant email content and derived profile information may be included in AI requests.

Configure stores profile facts and preferences, email-header records, selected email snippets, and summaries used by these features. Configure-operated chat applications also save user and assistant messages so you can return to conversations. Saved profile information and chat responses may contain Gmail-derived information.

The memory integrations we publish in assistant directories (ChatGPT, Claude) request no conversation content at all: they operate only on the facts you or the assistant explicitly send.

When you authorize another application to use your Configure profile, it may receive information allowed by your permissions. That application's privacy notice must identify its own processing and additional providers; the Google API data restrictions below apply to its use of Google-derived information.

Google API data and Limited Use

Configure adheres to the Google API Services User Data Policy, including its Limited Use requirements, when using or transferring information received from Google APIs.

We restrict Google API data to disclosed, authorized user-facing features and transfers permitted by Google's policies. We do not use it for advertising or sell it. Human access is limited to the circumstances allowed by those policies.

We do not use or permit service providers or integrated applications to use Google API data to create, train, fine-tune, or improve generalized or foundational AI or machine-learning models, including models used only internally. This prohibition covers raw content, metadata, and aggregated, anonymized, de-identified, or otherwise derived information. Inference for the disclosed features does not authorize model training.

We require recipients of Google API data to follow these restrictions, including when they engage further processors. These restrictions take precedence over any broader use, sharing, retention, or liability language elsewhere in this policy.

6. Third-Party Service Providers

We use third-party service providers for identity verification, AI model inference, application hosting, OAuth integration management, caching, and static site delivery. These providers process data only as necessary to operate the Configure platform and are subject to contractual obligations to protect your data.

When you connect third-party services (such as Gmail, Calendar, Drive, or Notion), we access those services through their official APIs using credentials you authorize.

Developers receiving profile information must disclose their own data practices and service providers, obtain required consent, and comply with the Developer Terms. Configure remains responsible for its own processing and for imposing the applicable restrictions on recipients of Google API data. Downstream processing must not bypass the protections in Section 5.

7. Data Storage and Security

While we implement industry-standard security measures, no system is completely secure. Configure cannot guarantee that personal information will never be accessed by unauthorized parties, and disclaims liability for any such unauthorized access to the maximum extent permitted by law. This applies equally to end user profile data and developer account data.

8. Data Breach Notification

In the event of a data breach that compromises the security of your personal information, we will:

9. Data Retention and Deletion

Aggregation, anonymization, or de-identification does not create an exception to the Google API data restrictions in Section 5. Those restrictions continue to apply to retained information derived from Google APIs.

10. Your Rights

Under applicable data protection laws, including the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA), you have the right to:

To exercise any of these rights, contact us at privacy@configure.dev. We will respond to your request within 30 days.

11. Legal Basis for Processing

For users in the European Economic Area (EEA), UK, and Switzerland, we process personal data on the following legal bases:

12. International Data Transfers

Configure AI, Inc. is based in the United States. Your data is processed and stored in the US.

For users in the European Economic Area (EEA), UK, or Switzerland, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to provide adequate safeguards for international data transfers.

By using our services, you acknowledge that your data will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction.

13. For Developers

When you integrate the Configure SDK or API into your application:

You are responsible for your application's handling of profile data and for ensuring that its service providers follow the applicable restrictions. Configure's own obligations continue to apply to data it collects or shares.

14. Limitation of Liability for Personal Information

For end users: You acknowledge that Configure is designed to share your profile — which may include PII — across agents and applications in the Configure network. Configure is not liable for any disclosure, exposure, or misuse of PII that results from this profile portability, including PII accessed by developers through the Configure API. You are responsible for reviewing and managing the content of your profile.

For developers: You acknowledge that profile data received through the Configure API may contain PII. Configure is not liable for any claims, damages, or regulatory penalties arising from your handling, storage, disclosure, or misuse of PII obtained through the Configure platform. You bear sole responsibility for complying with all applicable data protection laws in connection with your use of profile data.

To the maximum extent permitted by applicable law, Configure disclaims all liability for any unauthorized disclosure, exposure, breach, or leakage of personally identifiable information, whether caused by third-party developers, end user actions, security incidents, AI processing errors, or any other cause.

15. Children's Privacy

Our services are not directed at children under 16. We do not knowingly collect personal information from children under 16. If we learn that we have collected data from a child under 16, we will delete that information promptly. If you believe a child under 16 has provided us with personal data, please contact us at privacy@configure.dev.

16. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements.

We will provide at least 30 days' notice for material changes — through our website, through the service, or by email where possible. The "Last updated" date at the top of this page indicates when this policy was last revised.

Your continued use of Configure after changes take effect constitutes acceptance of the revised policy.

17. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data protection rights, contact us at:

privacy@configure.dev

Configure AI, Inc.