Legal
Privacy Policy
Last updated: July 23, 2026
Cenizas Labs (“we”, “us”, “our”) operates SLX (“Salvatory Execution”) (the “Service”), a permission-aware AI workspace that lets teams chat with, analyze, draft from, and automate over the business data they connect. This Privacy Policy describes how we collect, use, and disclose your information when you use the Service, and the rights you have in relation to that information.
1. Information We Collect
We collect the following categories of information:
- Account information: name, email address, organization name, and authentication identifiers when you sign up.
- Integration data: with your authorization, we access content and metadata from the third-party services you connect — such as Gmail, Google Calendar, Microsoft 365, Salesforce, HubSpot, QuickBooks, Slack, DocuSign, and connected data platforms such as Snowflake, BigQuery, Looker, and Airtable — including data returned from live queries you or the Service run against those sources. We access only the scopes you grant. Data accessed from Google services is further described in Section 4.
- Usage data: logs, device identifiers, IP address, browser type, and interaction events (including action and billing events) used to operate, secure, and improve the Service.
- Content you provide: messages, documents, files, and other inputs you submit to the Service.
2. How We Use Your Information
- To provide, maintain, and improve the Service.
- To process, store, and generate AI-assisted outputs based on your inputs and connected data sources.
- To enforce access controls and evaluate permissions on the data you and your team can view (see Section 5, Permission-Aware Access).
- To authenticate users and secure accounts.
- To communicate with you about updates, security alerts, and support.
- To comply with legal obligations and enforce our Terms.
3. AI Processing
The Service routes requests to third-party AI providers (including Anthropic and OpenAI) to process your inputs and generate responses. We do not permit these providers to train their models on your content. Inputs are transmitted over encrypted connections and retained by providers only as required to deliver the Service.
4. Google User Data and Limited Use
When you connect a Google account, SLX accesses the following Google user data through Google APIs, subject to the scopes you grant:
- Gmail — the content, headers, and metadata of email messages, to let you search, summarize, draft, and automate over your mail within SLX.
- Google Calendar — event details and metadata, to let you view, analyze, and schedule around your calendar.
- Google Contacts (if granted) — names and email addresses, to resolve recipients and references.
We use Google user data solely to provide and improve these user-facing features. Specifically, we do not:
- use or transfer Google user data for advertising, lending, or any purpose unrelated to the features above;
- sell Google user data, or transfer it to data brokers or advertisers;
- allow humans to read Google user data, except (a) with your explicit consent, (b) where necessary for security or to comply with law, (c) where the data is aggregated and anonymized for internal operations, or (d) as required by applicable law; or
- use Google user data to develop, improve, or train generalized or non-personalized AI or machine-learning models. AI features process your Google data only to generate outputs for you, and our AI providers are contractually prohibited from training on your content.
You can revoke SLX’s access at any time at myaccount.google.com/permissions or from within SLX. On revocation or account deletion, we delete the Google user data we hold, except where retention is required by law.
SLX’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Permission-Aware Access
SLX is designed to respect the access controls of your connected systems. Our authorization layer, Engram, evaluates permissions on a per-field basis in real time, so that AI features and other users can only surface information they are authorized to see. Where access is partial, individual fields may be masked rather than disclosed. Access decisions are logged to support auditing, security review, and compliance.
6. Data Sharing and Disclosure
We do not sell your personal information. We share data only:
- With service providers who process data on our behalf (cloud hosting, email delivery, analytics, and the AI providers described above) under contractual confidentiality obligations.
- With third-party services you explicitly connect, limited to the scopes you authorize.
- When required by law, court order, or to protect the rights, safety, or property of Cenizas Labs, our users, or others.
- In connection with a merger, acquisition, or sale of assets, subject to confidentiality.
7. Data Security
We use industry-standard administrative, technical, and physical safeguards, including encryption in transit (TLS), encryption at rest, role- and permission-based access controls, per-field authorization (Engram), and audit logging. We also conduct periodic security testing (including third-party penetration testing) and maintain SOC 2–aligned controls. No method of transmission or storage is fully secure, and we cannot guarantee absolute security.
8. Data Retention
We retain your information for as long as your account is active or as needed to provide the Service. You may request deletion of your account and associated data at any time by contacting us. Data accessed from connected services is deleted on revocation or account deletion as described in Section 4 and the equivalent controls for other integrations. We may retain limited information — including access and audit logs — as required for legal, accounting, security, or audit purposes.
9. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal information; to object to or restrict certain processing; and to withdraw consent. Where SLX processes data on behalf of your organization, we act as a processor and will direct certain requests to that organization. To exercise these rights, contact us at the address below.
10. Cookies and Tracking
We use cookies and similar technologies to authenticate sessions, remember preferences, and analyze usage. You can control cookies through your browser settings; disabling cookies may affect Service functionality.
11. International Data Transfers
Your information may be processed in countries other than the one in which you reside. Where required, we use appropriate safeguards such as standard contractual clauses for cross-border transfers.
12. Children's Privacy
The Service is intended for business use and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, please contact us.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and update the “Last updated” date. Material changes will be notified via email or in-product notice.
14. Contact Us
Questions or requests regarding this Privacy Policy can be sent to privacy@cenizaslabs.com, or by mail to:
Cenizas Labs
13428 Burrough Farm Dr
Herndon, VA 20171
United States