Privacy Policy
Last updated: August 20, 2026
1. Information We Collect
This policy describes how Escalate (styled "escalate"), the product at escalate.me operated by Escalate Labs, handles your information. It covers the Escalate web app, the Escalate mobile apps, and the escalate command-line client, and it is the privacy policy referenced by our Google OAuth consent screen.
Escalate collects the minimum information necessary to operate the platform:
- Account information: Email address, name, and profile picture when you sign up via Google OAuth or email/password.
- Connector credentials: API keys, OAuth tokens, and session tokens you provide to connect third-party services. These are encrypted at rest using AES-256-GCM and sealed to each connector's attested identity, described under "Isolation and confidential compute" below.
- Usage data: Intents you create, actions proposed by agents, and your approval/denial decisions. This is used to show you your history, to maintain your audit trail, and to fix and improve the features you use in the product. It is never used to train generalized or non-personalized artificial intelligence or machine learning models.
- Device information: Browser type, IP address, and session identifiers for security and authentication purposes.
2. How We Use Your Information
We use your information only to provide and improve the features you see and use in Escalate:
- To authenticate you and maintain your session
- To execute approved actions on connected services on your behalf
- To display your intent history and audit trail
- To send notifications about pending approvals and completed actions
- To keep the service secure, and to diagnose and fix problems in the features you use
We do not use your information for advertising of any kind, we do not use it to build advertising or marketing profiles, and we do not use it to train generalized or non-personalized AI or machine learning models. Any other use is outside what this policy permits.
Where the information described in sections 1 and 2 is information received from Google APIs, section 5 governs: our use of it is limited to providing or improving user-facing features that are prominent in the Escalate interface, and where anything in sections 1 and 2 could be read more broadly than section 5, section 5 controls.
3. Credential Storage and Sealing
Your connector credentials (API keys, OAuth tokens, session tokens) are:
- Encrypted at rest using AES-256-GCM with per-credential keys
- Sealed to the connector's attested identity, so a credential can be released only to the exact connector code it belongs to, enforced by hardware attestation rather than by software policy alone
- Decrypted only inside the isolated runtime that uses them, at the moment of execution, never written to logs and never stored or transmitted in plaintext
- Not accessible to any other connector, and not exposed to Escalate's operators in plaintext
- Deletable at any time by disconnecting the connector
4. Isolation and Confidential Compute
Each connector runs in its own isolated runtime, and sensitive work, including the handling of your credentials, is designed to run inside confidential hardware enclaves (for example, AMD SEV-SNP or AWS Nitro Enclaves). Such an enclave produces a chip-signed attestation report that binds the exact code running to genuine hardware.
Because a secret is released to a connector only after it proves, through that attestation, that it is the expected code running on real hardware, a connector can only ever decrypt its own secrets, enforced by hardware and not by software alone. Credentials for one service are never accessible to another. The proxy layer enforces strict allowlists on which platform API calls are permitted, and no runtime has access to your host filesystem, network namespaces, or other runtimes' data.
A conceptual overview is available in our confidential compute documentation.
5. Google User Data
Escalate's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5.1 What Google user data we access
You choose which Google services to connect. Escalate requests only the OAuth scopes named below — the same scopes registered on our Google OAuth consent screen — and Google's own consent screen shows you exactly what you are granting before any access occurs. The scope names are given so you can check this list against that screen:
- Sign in with Google (openid, email, profile): your name, email address, and profile picture, to create and authenticate your Escalate account.
- Identifying the account you connect (userinfo.email): the email address of the Google account you just authorized, so Escalate can label that connection and match it when you reconnect.
- Gmail (gmail.readonly, gmail.send, gmail.modify, gmail.metadata): read and search your messages, threads, labels, and settings, so an agent can find and summarize the mail you ask about; send mail you have approved; and organize your mailbox (labels, drafts, archiving, marking read). The metadata scope is the narrow one: it returns labels, headers and message sizes and never the body of a message, so an inbox can be triaged without being read. We do not request the full mail.google.com scope, and Escalate cannot permanently delete your mail.
- Google Calendar (calendar.readonly, calendar.events, calendar): view your calendars and events; create, edit, RSVP to, and delete events; and manage the calendars themselves, including creating and deleting calendars, changing who they are shared with, and changing calendar settings.
- Google Drive (drive.readonly, drive): list, search, and download your files and folders; create, edit, organize, and delete them; and change sharing permissions when you ask us to.
- Google Docs (documents.readonly, documents, and drive.readonly to list and export them): read, create, and edit your documents.
- Google Sheets (spreadsheets.readonly, spreadsheets, and drive.readonly to list them): read, create, and edit your spreadsheets.
- Google Slides (presentations.readonly, presentations, and drive.readonly to list them): read, create, and edit your presentations.
- Google Photos (photoslibrary.readonly, photoslibrary.appendonly): browse and search your photo library and albums, and upload new photos or create albums. The append-only scope cannot modify or delete anything already in your library.
That is the complete list. Escalate does not request access to Google Contacts, Google Tasks, Google Meet, Google Home or Nest, Google Fit, YouTube, or Google Wallet. If we ever add one of those, we will register the scope with Google, update this policy, and show you a new consent screen before any access happens.
Every action that writes to a Google service — sending mail, editing a file, changing an event or a sharing permission — is proposed by the agent and executed only after you approve it, and each one is recorded in your audit trail.
5.2 How we use Google user data
Google user data is used solely to provide and improve the user-facing features you request: executing the specific actions you or your agents initiate (with your approval where required), showing you the results, and maintaining your intent history and audit trail. When an agent needs content from your Google account to fulfill a request (for example, summarizing an email thread or filling a spreadsheet), that content is processed by the AI model serving your request only as necessary to produce the result you asked for.
We use Google user data for no other purpose. It is not used for advertising, for building advertising or marketing profiles, for personalization outside the feature you are using, for market research, for product analytics or usage statistics, for credit or lending decisions, or to develop, improve, or train generalized or non-personalized AI or machine learning models. We do not use it to build any profile of you beyond the state the features you use require.
5.3 Limited Use commitments
Escalate's use of information received from Google APIs is limited to providing or improving user-facing features that are prominent in the Escalate interface. All other uses are prohibited. Specifically:
- We do not transfer Google user data to anyone, except in these four cases: where it is necessary to provide or improve the user-facing features you are using, and with your consent; for security purposes, such as investigating abuse; to comply with applicable law; or as part of a merger, acquisition, or sale of assets, after we give you prominent advance notice and obtain your explicit prior consent. Section 6 lists every recipient that the first case covers today. It never includes an advertiser, an ad network, a data broker, an information reseller, a marketing partner, or an analytics vendor.
- We do not use or transfer Google user data for advertising of any kind, including personalized, retargeted, or interest-based advertising, and we do not transfer it to advertising platforms.
- We do not sell or rent Google user data, and we do not transfer it to data brokers or information resellers.
- We do not use Google user data to determine creditworthiness or for lending purposes.
- We do not use Google user data, including Google Workspace and Google Photos data, to develop, improve, or train generalized or non-personalized artificial intelligence and/or machine learning models. Data retrieved through Google APIs is used only to serve your individual request.
- An agent cannot summarize a thread or draft a document without a model seeing that content, so the content your request needs is sent to the AI model serving that request, and only that content. We use it only to produce the result you asked for, and we do not send it to a model service that would use it to train generalized models. Section 5.5 sets out every kind of model endpoint a request can reach and what governs each one.
- No human reads your Google user data except where you have first affirmatively agreed to have specific messages, files, or other data viewed (for example, a support request you initiate), where it is necessary for security purposes such as investigating a bug or abuse, or where it is necessary to comply with applicable law. We do not aggregate or anonymize Google user data for internal analysis, statistics, or any other internal operation.
5.4 Storage, protection, retention, and deletion
- Your Google OAuth tokens are encrypted at rest with AES-256-GCM and sealed to attested connector identities, as described in sections 3 and 4. They are never stored or transmitted in plaintext.
- Content retrieved from Google services is processed transiently to fulfill your request. Portions that appear in your chat history, intent history, or audit logs are retained under the retention periods in section 7 and are visible only to you and members of your organization you have shared them with.
- Disconnecting a Google connector deletes its stored tokens immediately, and deleting your account removes all associated data. You can also revoke Escalate's access at any time from your Google Account security settings.
5.5 AI models that process Google user data
An agent cannot answer a question about your mail, files, or photos without a model reading that content, so this is the one place Google user data reaches a system that is not Escalate. What that system is depends on how your organization has configured Escalate, and in every case the content is sent only to answer the request in front of it:
- A model Escalate supplies. The request runs on the model provider's business or API tier, whose terms do not permit the provider to train its models on the content we send.
- Your organization's own model provider account. Where your organization connects its own account or API key, it selects that provider and directs those requests. Escalate sends only the content the request requires and uses the result only to answer that request.
- A model gateway your organization selects. A gateway or aggregator forwards the request to the downstream model chosen for it. Your organization selects the gateway and the model; the same limits apply to what Escalate sends and what Escalate does with the result.
- A confidential-computing endpoint. Some supported endpoints run the model inside a hardware-attested enclave and return a per-request proof of the code that served it, so what handled your content is verifiable rather than merely promised.
- A self-hosted or offline model your organization runs. Where your organization points Escalate at a model it hosts itself, the content is processed on infrastructure your organization controls. It is never transmitted to a model vendor, and so is never available to a vendor for training or for any secondary purpose.
Across all of them: we do not transfer Google user data, including Google Workspace and Google Photos data, whether raw, aggregated, or anonymized, to any service that uses it to develop, improve, or train generalized or non-personalized artificial intelligence or machine learning models. Content sent to a model is sent to produce the result you asked for and for nothing else, and the result is used only to answer that request.
If you need to know exactly which model providers your organization is routing to, an owner can see and change the configured provider in Escalate's settings at any time.
If we change the way this application uses Google user data, we will update this policy and notify you before the change takes effect.
6. Data Sharing
Escalate does not sell or rent your personal information. We do not share it with advertisers, advertising platforms, data brokers, information resellers, marketing partners, or analytics vendors, and we have no such partners. We run no third-party advertising, ad-tech, or web-analytics code on our site.
The only recipients of your data are the ones needed to deliver the feature you asked for, and they receive only what that feature requires:
- The services you explicitly connect, and only to carry out the action you or your agent requested, for example sending an API call to Gmail on your behalf.
- The AI model provider serving your request, and only the content needed to produce the result you asked for. This is how the product works: an agent cannot summarize a thread or draft a document without the model seeing that content. Where Escalate supplies the model, we use the provider's business or API tier, whose terms do not permit training on the content we send. Where your organization connects its own model provider account or API key, your organization chooses that provider and directs those requests; we send only what the request requires and use the result only to answer it.
- The infrastructure providers that run Escalate (cloud compute, database, and storage), who process data on our instructions under contract, solely to run the features you use. They may not use it for any purpose of their own.
- The notification channel you choose (for example email, Telegram, WhatsApp, or a webhook URL you configure), and only the alert content you asked us to send there.
- Our payment processor, Stripe, for billing and payment fraud prevention. Stripe receives your billing details, and its card-entry script loads on our billing pages for that purpose. It never receives Google user data or the content of any other connected account.
- Law enforcement or other parties where required by law or legal process.
- Where necessary for security purposes, such as investigating abuse or a security incident.
- A successor entity in a merger, acquisition, or sale of assets, after we give you prominent advance notice. For Google user data, we will additionally obtain your explicit prior consent before any such transfer.
Each of these recipients is limited to providing the user-facing features you are using, to legal compliance, to security, or to the merger case above. We transfer your data to no one else and for no other purpose. For information received from Google APIs, the Limited Use commitments in section 5 control, and where anything in this section could be read more broadly than section 5, section 5 governs.
7. Data Retention
Account data is retained as long as your account is active. Intent history and audit logs are retained for 90 days. Connector credentials, including Google OAuth tokens, are deleted immediately when you disconnect a service. You can request full account deletion at any time by contacting support.
Chat threads, including any content an agent retrieved from a connected service to answer you, are retained until you delete the thread or delete your account. Files saved into a chat workspace on hosted compute are removed after your organization's chat file retention window, seven days by default.
8. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and all associated data
- Export your intent history and audit logs
- Disconnect any connector at any time, immediately revoking Escalate's access
9. Cookies
Escalate uses a single session cookie for authentication. We do not use tracking cookies, analytics cookies, or third-party advertising cookies. The session cookie is HttpOnly, Secure, and set to SameSite=Strict.
10. Contact
For questions about this privacy policy or to exercise your data rights, contact us at privacy@escalate.me.
What escalate does
escalate is an AI agent workspace. You connect the accounts you already use, then ask agents to handle real tasks: summarize and triage your inbox, schedule meetings, organize files, draft documents, update spreadsheets, file tickets, or run multi-step workflows across several tools at once. Every agent runs under your account, with your permissions, and nothing irreversible happens without you.
How escalate uses your Google account
When you connect Google, escalate requests only the scopes the connectors you enable actually need, and no others: Gmail (read, search, organize and send mail you have reviewed, plus a metadata-only view of labels and headers), Google Calendar (view and manage events and calendars), Google Drive, Docs, Sheets and Slides (find, read, create and update files), and Google Photos (browse and search your library, upload new photos and create albums). It does not request Contacts, Tasks, Meet, Home/Nest, Fit, YouTube or Wallet. Your data is fetched per request to fulfill the task you asked for, is never sold, is never used for advertising or to train models, and every write action (sending mail, editing files, changing events) requires your explicit in-product approval first.
escalate's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide or improve the user-facing features that are prominent in the escalate interface. It is used for no other purpose: not for advertising, not for advertising or marketing profiles, not for market research, not for product analytics or usage statistics, not for credit or lending decisions, and never to develop, improve or train generalized or non-personalized AI or machine learning models. It is not transferred to anyone except as needed to provide those features, for security purposes, to comply with applicable law, or in a merger or acquisition with your prior notice and consent, and never to advertisers, data brokers, or information resellers. No human reads it except where you have affirmatively agreed to have specific messages or files viewed, for security purposes, or to comply with applicable law. An agent cannot answer a question about your mail, files or photos without a model reading that content, so the content a request needs is sent to the model serving it and to nothing else: an escalate-supplied model on the provider's business or API tier, your organization's own provider account, a gateway it selects, an attested confidential-computing endpoint, or a model your organization hosts itself — in which case the content stays on your organization's own infrastructure and never reaches a model vendor at all. No Workspace or Photos data, raw or aggregated, goes to any service that trains generalized models on it. The full policy is at escalate.me/privacy.
Agent proposes. You authorize. escalate executes.
Agents draft a plan you can inspect, each sensitive step waits for your approval, and everything the agent did is recorded in a full audit trail. Connections can be revoked at any time from your dashboard or from your Google account settings.
escalate is built by Escalate Labs. Privacy policy · Terms of service
Connect 200+ tools through one catalog
escalate ships a catalog of more than 200 connectors covering email, calendars, files and docs, team chat, project management, CRM, finance and payments, developer tools, e-commerce, smart home, and more: Gmail, Google Calendar, Google Drive, Docs, Sheets, Slack, GitHub, GitLab, Linear, Jira, Notion, Stripe, PayPal, Shopify, Square, Salesforce, HubSpot, Dropbox, Figma, Discord, Telegram, Spotify, Zoom, and the long tail of SaaS. Each connector is a typed, sandboxed service wrapping one external API, with a pinned network allowlist so it can only reach the hosts it declares. Browse the full catalog at escalate.me/explore.
A policy gate, not just a chatbot
Hosted chat products let a model act with your full credentials. escalate gates what an agent can actually do: a policy engine classifies every proposed action, read-only calls can flow automatically, and every write (sending mail, editing files, moving money, changing events) queues for explicit human approval with full context. Organizations can set per-agent quotas, per-tool budgets, and approval rules. Every tool call, approval, denial, and result lands in an audit trail you can review per agent, per connector, and per organization.
Security and confidential computing
Credentials live in an encrypted locker and are injected into the connector at call time only; the agent sees tool results, never tokens. Sensitive workloads run inside hardware-attested confidential computing environments (AMD SEV-SNP trusted execution), and escalate publishes cryptographic measurements so you can verify exactly what code handled your data. Connections are revocable at any time. Read more at escalate.me/security.
Where you use escalate
The web dashboard gives you agent chat, connector and credential management, an approval inbox, the audit log, and shareable dashboard apps that render live data from your connectors. iOS and Android apps handle chat and one-tap approvals via push notification. The open-source escalate CLI doubles as an MCP server, so local AI tools such as Claude, Claude Code, and Cursor can call escalate-gated tools while policy, approvals, and audit stay enforced server-side. Scheduled routines run agents on a cron without a human at the keyboard, still subject to the same gates.
Plans
escalate offers a Free tier, paid Pro and Team tiers with higher rate limits, write access, and more seats, and an Enterprise tier with dedicated or self-hosted workers, SSO, and custom SLAs. Current details at escalate.me/pricing.
Frequently asked questions
What is escalate?
escalate is an AI agent workspace by Escalate Labs. You connect the accounts you already use and AI agents do real work across them: triage email, schedule meetings, organize files, update spreadsheets, file tickets, and run multi-step workflows spanning several tools. Agents propose, you authorize, escalate executes with a full audit trail.
Is my data safe?
Every connector runs in an isolated container with a pinned egress allowlist; credentials are injected at call time and never enter the agent's context. Your data is fetched per request to fulfill the task you asked for, is never sold, is never used for advertising, and is never used to train models.
How is escalate different from using Claude or ChatGPT directly?
Chat products talk to you; escalate gates what your agent can actually do. It adds the connector catalog, a policy engine, human-approval flows, per-tool isolation, and an audit trail, and it works with your existing AI tools through MCP rather than replacing them.
Is there a mobile app?
Yes. iOS and Android apps cover chat, notifications, and the approval inbox, so a push notification and one tap approve an agent's pending action.
Can I self-host?
Enterprise customers can run escalate workers on their own Kubernetes cluster; the standard plans are fully managed SaaS.
Machine-readable overview for LLMs and crawlers: escalate.me/llms.txt · full connector directory: escalate.me/llms-full.txt