Privacy Policy
This policy explains how Settra handles information when you use our website, managed service, or Google Drive connection.
Effective August 27, 2026
1. Scope and responsibility
This Privacy Policy applies to the Settra website and hosted Settra service. If you run Settra yourself, you or the organization operating that deployment controls the data processed there. This policy still describes the product's standard behavior, but the operator of that deployment is responsible for its own hosting, access, retention, and legal obligations.
2. Information Settra handles
- Account and workspace information. Name, email address, authentication identifiers, workspace membership, session information, and the settings needed to provide your account.
- Google account and authorization information. When you connect Google, Settra receives your basic Google profile, the permissions you granted, and an OAuth refresh token. Settra requests the narrow
drive.filepermission so it can access only files you select or open with Settra, rather than your entire Drive. - Selected file data. File identifiers, names, metadata, and tabular content from the Google Sheets, Excel, CSV, or other supported files you explicitly select. Settra copies this content into your configured data destination so it remains ready for your agents to query.
- Settra configuration and usage. Sources, collections, schedules, schemas, business definitions, MCP access grants, and privacy-safe service metrics. Settra does not store the contents of MCP requests or responses in request history.
- Technical information. We may process IP address, browser and device information, essential cookies, and service logs needed to authenticate users, secure the service, diagnose errors, and prevent abuse. The website stores your light or dark theme preference in your browser.
3. How we use information
We use information only to:
- authenticate you and operate your workspace;
- connect to and refresh files you explicitly choose;
- stage tabular data in your configured destination;
- let the agents and automations you authorize discover and query that staged data through MCP;
- secure, maintain, troubleshoot, and support the service; and
- comply with law and enforce our Terms.
4. Google user data and Limited Use
Settra's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, Google user data is used only to provide the user-facing file synchronization and agent-query features you choose. Settra does not sell Google user data, share it with data brokers, use it for advertising or credit decisions, use it for surveillance, or use it to train or improve generalized AI or machine-learning models.
Humans do not read Google user data except when you give explicit permission for support, when access is necessary to investigate a security issue or abuse, when the data is aggregated and anonymized for permitted internal operations, or when required by law.
Read the Google API Services User Data Policy.
5. When information is shared
- At your direction.Query results are sent to the Codex, ChatGPT, Claude, or custom agent you connect and invoke. That provider's privacy and retention terms apply after it receives the result.
- Service providers. Hosting, database, security, communications, and support providers may process information only on our behalf and under appropriate confidentiality and security obligations.
- Safety and law. We may disclose information when reasonably necessary to protect users or the service, investigate abuse, or comply with applicable law.
- Business changes.Google user data would be transferred as part of a merger, acquisition, or sale of assets only after obtaining the explicit prior consent required by Google's policies.
We do not sell or rent personal information or Google user data, and we do not share it with advertisers or information resellers.
6. Storage and security
Settra uses encrypted connections and reasonable administrative, technical, and organizational safeguards. Google OAuth refresh tokens are encrypted at rest per workspace and stored separately from the product database and source configuration. Workspaces isolate connections, staged data, access grants, and service metrics.
Staged file data is stored in Settra-managed PostgreSQL or the PostgreSQL destination selected by the deployment operator. No system can guarantee absolute security, so you should grant only the access needed and protect your account and MCP credentials.
7. Retention, disconnection, and deletion
- Disconnect Google from Settra's Connections page to delete the stored Google OAuth credential and stop future synchronization.
- You may also revoke Settra from your Google Account connections.
- Disconnecting Google or removing a source does not automatically delete previously staged copies. This preserves the last successful data until you choose to remove it.
- For a managed deployment, email support@outermeasure.com to request deletion of staged data, your account, or associated service data. For a self-hosted deployment, contact its operator or delete the data from the infrastructure you control.
We retain information only as long as needed to provide the service, meet legitimate security and recordkeeping needs, or comply with law. Residual copies may remain temporarily in protected backups until those backups cycle out in the ordinary course.
8. Your choices and rights
Depending on where you live, you may have rights to access, correct, export, restrict, object to, or delete personal information. Contact us to exercise a request. We may need to verify your identity before acting on it.
9. Children
Settra is built for business and developer use and is not directed to children under 18. We do not knowingly collect personal information from children.
10. Changes and contact
We may update this policy as Settra changes. If a change materially affects how previously authorized Google user data is used, we will provide notice and obtain consent when required before using that data for the new purpose.
Questions or privacy requests: support@outermeasure.com.

