Privacy Policy
This Privacy Policy describes how 33Labs ("we", "us") collects, uses, and shares information in connection with Productive (the "Service").
1. Information we collect
| Category | Examples | Source |
|---|---|---|
| Account info | Name, email, profile picture (via social sign-in - Google/GitHub/Slack) | You, or your identity provider |
| Workspace content | Messages, channels, files, agent configurations, connected-tool credentials | You and your organization's members |
| Usage data | Feature usage, session activity, device/browser type | Automatically, as you use the Service |
| Billing info | Plan, billing email; card details are held by Stripe, never by us directly | You, via Stripe Checkout |
2. How we use it
- To operate and improve the Service, including routing messages, running AI agents, and rendering the console.
- To process payments and manage your subscription.
- To send service communications (security notices, billing receipts, critical changes) - these are not optional; marketing email is opt-in.
- To detect and prevent abuse, fraud, and security incidents.
3. AI processing
When you use an AI agent, the relevant prompt and context is sent to the model provider your organization has configured (e.g. Anthropic, OpenAI, or another provider via OpenRouter) to generate a response. We do not use Customer Data to train our own foundation models. Model providers' own data-handling terms govern how they process what's sent to them - review the provider's terms for your configured model before sending sensitive data through it.
4. Sharing
We share information only with:
- Sub-processors that help operate the Service - hosting/infrastructure, the AI model provider(s) you configure, Stripe for payments, and email delivery. See our DPA for the current list.
- Legal requirements - if required by law, subpoena, or to protect the rights, property, or safety of Productive, our users, or the public.
- A successor in the event of a merger, acquisition, or asset sale, with notice to affected customers.
We do not sell personal information.
5. Data retention
We retain Customer Data for as long as the account is active, plus a reasonable period after termination to allow export and to meet legal/backup obligations (our operational backups are retained on a rolling basis, currently 14 days). You can request deletion of your account and associated data by contacting us; some information may be retained where required by law.
6. Your rights
Depending on your location, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. Contact us to exercise these rights; we'll respond within the timeframe required by applicable law (e.g. GDPR, CCPA).
7. Security
We use industry-standard measures to protect Customer Data, including encryption in transit, access controls, and regular backups. No method of transmission or storage is 100% secure, and we can't guarantee absolute security.
8. International transfers
Your information may be processed in countries other than your own. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for cross-border transfers.
9. Children
The Service is not directed to children under 16, and we don't knowingly collect personal information from them.
10. Changes
We'll post material changes to this policy here and, for significant changes, notify you via the Service or email.
11. Contact
Privacy questions or requests: joe@productive.team.