Legal
Nysa is a company brain: it records the meetings you direct it to, reads the email and calendar data you authorize, and turns them into shared company knowledge that your team and the AI agents you connect can use. Doing that job requires access to sensitive information, so this policy is written to be read — it says plainly what we collect, why, where it lives, and what we will never do with it.
The facts, people, and company pages Nysa extracts are shared with your whole workspace and with the AI agents you connect. Your raw email and your own calendar events stay private to the account that connected them. Recorded meetings — including transcripts — are visible to teammates who attended and to anyone you explicitly share the meeting with; if your workspace turns on public share links (off by default), anyone holding one of those links can view the meeting without signing in, and the link expires after 90 days.
We do not sell your data. We do not use your data for advertising. We do not train general-purpose AI models on your content.
Nysa's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide or improve the user-facing features described above. We do not sell Google user data. We do not use it for advertising. We do not use it to train generalized AI or machine-learning models. We do not allow humans to read it, except with your explicit consent for specific messages, where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and anonymized.
We share Google user data only with the service providers below, only to deliver the features you have authorized, and only to the extent each provider needs. Every provider processes this data on our behalf under contract; none may use it for their own purposes.
These providers receive no Gmail, Calendar, or Workspace directory content: Sentry (error monitoring), PostHog (product analytics), Resend (account, invitation, and meeting-share emails — recipient addresses and the text of those emails, never Gmail or Calendar content), WorkOS (signs in the AI agents you connect over MCP; receives your account id, email, and workspace id), and Attio (our CRM; receives your waitlist email address and optional agent choices). Our analytics policy prohibits sending message content, transcript text, or the names and addresses of the people and companies in your workspace into product analytics events; PostHog does receive your own account name and email so we can identify you as a user.
AI agents you connect. When you connect an AI agent (for example Claude or ChatGPT) to Nysa over MCP, Nysa returns workspace data you ask for, including knowledge drawn from your Gmail and Calendar, to that agent, under your own sign-in and only within what you can already see in Nysa. Agents can also write to your workspace's Company Brain; what they write is content you add. From there, that data is handled by the agent's provider under your agreement with them.
Beyond the providers listed above, we transfer Google user data only where necessary to comply with applicable law or a valid legal process, or to detect and address security or abuse issues. We never sell it or transfer it for advertising. Outbound webhooks — a feature that would let your workspace send meeting or Brain content to an endpoint you configure, delivered through Svix — are still under internal review and not generally available.
Nysa runs on the infrastructure providers below, which process data on our behalf. For which of these receive data obtained from Google specifically, see How we share Google user data above.
Traffic to and from Nysa is encrypted in transit. Google OAuth tokens and other stored credentials are protected with envelope encryption (AES-256-GCM), not kept as plaintext. Every workspace's data is isolated at the database layer, primarily through row-level security, so one company's workspace can never read another's data or another member's private mailbox. In September 2026, Nysa passed an independent CASA Tier 2 security assessment conducted by TAC Security, an App Defense Alliance authorized lab.
We keep your data while your company's account is active, because a company memory is the product. A workspace created by a company belongs to that company: its workspace owners decide what is kept and when it is deleted, and we process the data on the company's behalf.
When a teammate leaves. Their access ends and Nysa stops reading their Gmail and Calendar. The knowledge they contributed stays in your company brain. Email and calendar data imported through their company Google Workspace account also stays with your company's workspace, so Nysa can keep your company brain accurate, including rebuilding people and company pages. It is processed only by Nysa's systems for your workspace, is not shown to anyone, and is never used to train AI models. It is deleted when your company asks us to delete it or closes its account. Requests from former employees about data held in a company workspace are handled with that company.
Personal Google accounts. If you connected a personal Gmail account rather than a company Google Workspace account, that data is yours: we delete it at your request, as described below.
Disconnecting Google. You can revoke Nysa's access at any time from your Google account permissions, from Settings → Connections in Nysa, or by asking us. Once access is revoked, Nysa stops reading any further Gmail or Calendar data. Data already collected remains in your workspace until it is deleted as described here, so that the knowledge your team has built does not disappear without warning.
Deleting your data. To delete your account, your workspace, or specifically the data Nysa obtained from Google, email hello@usenysa.com. We will complete the deletion — including stored Google credentials, Gmail message content, and calendar records — within 30 days of the request, except where we are required to retain something by law.
Closing your account. If your company closes its Nysa account, we keep its workspace for 90 days so you can come back or ask for an export, then delete it. Our backups are overwritten on a rolling basis within 90 days, so deleted data also leaves our backups within that time.
Nysa is in active development and this policy will evolve with the product. We will post updates here and note the effective date above; material changes will be announced to active users by email.
Questions, requests, or concerns: hello@usenysa.com.