Privacy Policy

Last updated September 14, 2026
Read this first: this is a starting template covering the standard terms a SaaS product like Productive needs - it is not legal advice, and it has not been reviewed by an attorney. Have a lawyer licensed in your jurisdiction review and customize it (entity name, governing law, liability caps, DPA sub-processor list) before treating it as binding.

This Privacy Policy describes how 33Labs ("we", "us") collects, uses, and shares information in connection with Productive (the "Service").

1. Information we collect

CategoryExamplesSource
Account infoName, email, profile picture (via social sign-in - Google/GitHub/Slack)You, or your identity provider
Workspace contentMessages, channels, files, agent configurations, connected-tool credentialsYou and your organization's members
Usage dataFeature usage, session activity, device/browser typeAutomatically, as you use the Service
Billing infoPlan, billing email; card details are held by Stripe, never by us directlyYou, via Stripe Checkout

2. How we use it

3. AI processing

When you use an AI agent, the relevant prompt and context is sent to the model provider your organization has configured (e.g. Anthropic, OpenAI, or another provider via OpenRouter) to generate a response. We do not use Customer Data to train our own foundation models. Model providers' own data-handling terms govern how they process what's sent to them - review the provider's terms for your configured model before sending sensitive data through it.

4. Sharing

We share information only with:

We do not sell personal information.

5. Data retention

We retain Customer Data for as long as the account is active, plus a reasonable period after termination to allow export and to meet legal/backup obligations (our operational backups are retained on a rolling basis, currently 14 days). You can request deletion of your account and associated data by contacting us; some information may be retained where required by law.

6. Your rights

Depending on your location, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. Contact us to exercise these rights; we'll respond within the timeframe required by applicable law (e.g. GDPR, CCPA).

7. Security

We use industry-standard measures to protect Customer Data, including encryption in transit, access controls, and regular backups. No method of transmission or storage is 100% secure, and we can't guarantee absolute security.

8. International transfers

Your information may be processed in countries other than your own. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for cross-border transfers.

9. Children

The Service is not directed to children under 16, and we don't knowingly collect personal information from them.

10. Changes

We'll post material changes to this policy here and, for significant changes, notify you via the Service or email.

11. Contact

Privacy questions or requests: joe@productive.team.