Privacy Policy
Last updated: August 7, 2026
1. Information We Collect
Escalate collects the minimum information necessary to operate the platform:
- Account information: Email address, name, and profile picture when you sign up via Google OAuth or email/password.
- Connector credentials: API keys, OAuth tokens, and session tokens you provide to connect third-party services. These are encrypted at rest using AES-256-GCM and sealed to each connector's attested identity, described under "Isolation and confidential compute" below.
- Usage data: Intents you create, actions proposed by agents, and your approval/denial decisions. This is used to show you your history, to maintain your audit trail, and to fix and improve the features you use in the product. It is never used to train generalized or non-personalized artificial intelligence or machine learning models.
- Device information: Browser type, IP address, and session identifiers for security and authentication purposes.
2. How We Use Your Information
We use your information only to provide and improve the features you see and use in Escalate:
- To authenticate you and maintain your session
- To execute approved actions on connected services on your behalf
- To display your intent history and audit trail
- To send notifications about pending approvals and completed actions
- To keep the service secure, and to diagnose and fix problems in the features you use
We do not use your information for advertising of any kind, we do not use it to build advertising or marketing profiles, and we do not use it to train generalized or non-personalized AI or machine learning models. Any other use is outside what this policy permits.
3. Credential Storage and Sealing
Your connector credentials (API keys, OAuth tokens, session tokens) are:
- Encrypted at rest using AES-256-GCM with per-credential keys
- Sealed to the connector's attested identity, so a credential can be released only to the exact connector code it belongs to, enforced by hardware attestation rather than by software policy alone
- Decrypted only inside the isolated runtime that uses them, at the moment of execution, never written to logs and never stored or transmitted in plaintext
- Not accessible to any other connector, and not exposed to Escalate's operators in plaintext
- Deletable at any time by disconnecting the connector
4. Isolation and Confidential Compute
Each connector runs in its own isolated runtime, and sensitive work, including the handling of your credentials, is designed to run inside confidential hardware enclaves (for example, AMD SEV-SNP or AWS Nitro Enclaves). Such an enclave produces a chip-signed attestation report that binds the exact code running to genuine hardware.
Because a secret is released to a connector only after it proves, through that attestation, that it is the expected code running on real hardware, a connector can only ever decrypt its own secrets, enforced by hardware and not by software alone. Credentials for one service are never accessible to another. The proxy layer enforces strict allowlists on which platform API calls are permitted, and no runtime has access to your host filesystem, network namespaces, or other runtimes' data.
A conceptual overview is available in our confidential compute documentation.
5. Google User Data
Escalate's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5.1 What Google user data we access
You choose which Google services to connect. Escalate requests only the OAuth scopes needed for the connectors you enable, and Google's consent screen shows you exactly what you are granting before any access occurs:
- Sign in with Google: your basic profile information (name, email address, and profile picture) to create and authenticate your account.
- Gmail: read and search your email messages and settings, send email on your behalf, and organize your mailbox (labels, archiving, marking read). During guided setup, an optional inbox scan reads only message metadata such as labels and headers, never message bodies.
- Google Calendar: view your calendars, and view, create, edit, RSVP to, and manage events.
- Google Drive: list, search, download, create, edit, and manage your files, folders, and sharing permissions.
- Google Docs: read, create, and edit your documents.
- Google Sheets: read, create, and edit your spreadsheets.
- Google Slides: read, create, and edit your presentations.
- Google Contacts: search, view, create, and manage your contacts.
- Google Tasks: view, create, manage, and complete your tasks and task lists.
- Google Photos: browse and search your photo library, and upload new photos or create albums.
- Google Meet: create Meet spaces, and read information about your conferences, including participants, recordings, and transcripts.
- Google Home / Nest: view and control the smart home devices you explicitly select through Google's Smart Device Management partner flow.
5.2 How we use Google user data
Google user data is used solely to provide and improve the user-facing features you request: executing the specific actions you or your agents initiate (with your approval where required), showing you the results, and maintaining your intent history and audit trail. When an agent needs content from your Google account to fulfill a request (for example, summarizing an email thread or filling a spreadsheet), that content is processed by the AI model serving your request only as necessary to produce the result you asked for.
5.3 Limited Use commitments
Escalate's use of information received from Google APIs is limited to providing or improving user-facing features that are prominent in the Escalate interface. All other uses are prohibited. Specifically:
- We do not transfer Google user data to anyone, except in these four cases: where it is necessary to provide or improve the user-facing features you are using, and with your consent; for security purposes, such as investigating abuse; to comply with applicable law; or as part of a merger, acquisition, or sale of assets, after we give you prominent advance notice and obtain your explicit prior consent. Section 6 lists every recipient that the first case covers today. It never includes an advertiser, an ad network, a data broker, an information reseller, a marketing partner, or an analytics vendor.
- We do not use or transfer Google user data for advertising of any kind, including personalized, retargeted, or interest-based advertising, and we do not transfer it to advertising platforms.
- We do not sell or rent Google user data, and we do not transfer it to data brokers or information resellers.
- We do not use Google user data to determine creditworthiness or for lending purposes.
- We do not use Google user data, including Google Workspace data, to develop, improve, or train generalized or non-personalized artificial intelligence and/or machine learning models. Data retrieved through Google APIs is used only to serve your individual request. Where Escalate supplies the model, we use the model provider's business or API tier, whose terms do not permit the provider to train its models on the content we send. Where your organization connects its own model provider account or API key, requests run under that account and that provider's own terms apply to them.
- No human reads your Google user data except where you have first affirmatively agreed to have specific messages, files, or other data viewed (for example, a support request you initiate), where it is necessary for security purposes such as investigating a bug or abuse, where it is necessary to comply with applicable law, or where the data has been aggregated and anonymized and is used for internal operations.
5.4 Storage, protection, retention, and deletion
- Your Google OAuth tokens are encrypted at rest with AES-256-GCM and sealed to attested connector identities, as described in sections 3 and 4. They are never stored or transmitted in plaintext.
- Content retrieved from Google services is processed transiently to fulfill your request. Portions that appear in your chat history, intent history, or audit logs are retained under the retention periods in section 7 and are visible only to you and members of your organization you have shared them with.
- Disconnecting a Google connector deletes its stored tokens immediately, and deleting your account removes all associated data. You can also revoke Escalate's access at any time from your Google Account security settings.
If we change the way this application uses Google user data, we will update this policy and notify you before the change takes effect.
6. Data Sharing
Escalate does not sell or rent your personal information. We do not share it with advertisers, advertising platforms, data brokers, information resellers, marketing partners, or analytics vendors, and we have no such partners. We run no third-party advertising, ad-tech, or web-analytics code on our site.
The only recipients of your data are the ones needed to deliver the feature you asked for, and they receive only what that feature requires:
- The services you explicitly connect, and only to carry out the action you or your agent requested, for example sending an API call to Gmail on your behalf.
- The AI model provider serving your request, and only the content needed to produce the result you asked for. This is how the product works: an agent cannot summarize a thread or draft a document without the model seeing that content. Where Escalate supplies the model, we use the provider's business or API tier, whose terms do not permit training on the content we send. Where your organization connects its own model provider account or API key, that provider's terms apply to requests made under it.
- The infrastructure providers that run Escalate (cloud compute, database, and storage), who process data on our instructions under contract, solely to operate the service.
- The notification channel you choose (for example email, Telegram, WhatsApp, or a webhook URL you configure), and only the alert content you asked us to send there.
- Our payment processor, Stripe, for billing and payment fraud prevention. Stripe receives your billing details, and its card-entry script loads on our billing pages for that purpose. It never receives the content of your connected accounts.
- Law enforcement or other parties where required by law or legal process.
- Where necessary for security purposes, such as investigating abuse or a security incident.
- A successor entity in a merger, acquisition, or sale of assets, after we give you prominent advance notice. For Google user data, we will additionally obtain your explicit prior consent before any such transfer.
Each of these recipients is limited to providing the user-facing features you are using, to legal compliance, to security, or to the merger case above. We transfer your data to no one else and for no other purpose. For information received from Google APIs, the Limited Use commitments in section 5 control, and where anything in this section could be read more broadly than section 5, section 5 governs.
7. Data Retention
Account data is retained as long as your account is active. Intent history and audit logs are retained for 90 days. Connector credentials, including Google OAuth tokens, are deleted immediately when you disconnect a service. You can request full account deletion at any time by contacting support.
8. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and all associated data
- Export your intent history and audit logs
- Disconnect any connector at any time, immediately revoking Escalate's access
9. Cookies
Escalate uses a single session cookie for authentication. We do not use tracking cookies, analytics cookies, or third-party advertising cookies. The session cookie is HttpOnly, Secure, and set to SameSite=Strict.
10. Contact
For questions about this privacy policy or to exercise your data rights, contact us at privacy@escalate.me.
What escalate does
escalate is an AI agent workspace. You connect the accounts you already use, then ask agents to handle real tasks: summarize and triage your inbox, schedule meetings, organize files, draft documents, update spreadsheets, file tickets, or run multi-step workflows across several tools at once. Every agent runs under your account, with your permissions, and nothing irreversible happens without you.
How escalate uses your Google account
When you connect Google, escalate requests only the scopes the connectors you enable actually need: Gmail (read, organize and send mail you have reviewed), Google Calendar (view and manage events), Google Drive, Docs, Sheets and Slides (find, read, create and update files), Contacts, Tasks, Meet, YouTube, Google Photos, Google Fit and Google Nest. Your data is fetched per request to fulfill the task you asked for, is never sold, is never used for advertising or to train models, and every write action (sending mail, editing files, changing events) requires your explicit in-product approval first.
escalate's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide or improve the user-facing features you use in escalate. It is not transferred to anyone except as needed to provide those features, for security purposes, to comply with applicable law, or in a merger or acquisition with your prior notice and consent. It is never transferred to advertisers, data brokers, or information resellers, never used for advertising, and never used to develop or train generalized or non-personalized AI or machine learning models. No human reads it except with your affirmative agreement, for security or legal reasons, or in aggregated anonymized form. The full policy is at escalate.me/privacy.
Agent proposes. You authorize. escalate executes.
Agents draft a plan you can inspect, each sensitive step waits for your approval, and everything the agent did is recorded in a full audit trail. Connections can be revoked at any time from your dashboard or from your Google account settings.
escalate is built by Escalate Labs. Privacy policy · Terms of service
Connect 200+ tools through one catalog
escalate ships a catalog of more than 200 connectors covering email, calendars, files and docs, team chat, project management, CRM, finance and payments, developer tools, e-commerce, smart home, and more: Gmail, Google Calendar, Google Drive, Docs, Sheets, Slack, GitHub, GitLab, Linear, Jira, Notion, Stripe, PayPal, Shopify, Square, Salesforce, HubSpot, Dropbox, Figma, Discord, Telegram, Spotify, Zoom, and the long tail of SaaS. Each connector is a typed, sandboxed service wrapping one external API, with a pinned network allowlist so it can only reach the hosts it declares. Browse the full catalog at escalate.me/explore.
A policy gate, not just a chatbot
Hosted chat products let a model act with your full credentials. escalate gates what an agent can actually do: a policy engine classifies every proposed action, read-only calls can flow automatically, and every write (sending mail, editing files, moving money, changing events) queues for explicit human approval with full context. Organizations can set per-agent quotas, per-tool budgets, and approval rules. Every tool call, approval, denial, and result lands in an audit trail you can review per agent, per connector, and per organization.
Security and confidential computing
Credentials live in an encrypted locker and are injected into the connector at call time only; the agent sees tool results, never tokens. Sensitive workloads run inside hardware-attested confidential computing environments (AMD SEV-SNP trusted execution), and escalate publishes cryptographic measurements so you can verify exactly what code handled your data. Connections are revocable at any time. Read more at escalate.me/security.
Where you use escalate
The web dashboard gives you agent chat, connector and credential management, an approval inbox, the audit log, and shareable dashboard apps that render live data from your connectors. iOS and Android apps handle chat and one-tap approvals via push notification. The open-source escalate CLI doubles as an MCP server, so local AI tools such as Claude, Claude Code, and Cursor can call escalate-gated tools while policy, approvals, and audit stay enforced server-side. Scheduled routines run agents on a cron without a human at the keyboard, still subject to the same gates.
Plans
escalate offers a Free tier, paid Pro and Team tiers with higher rate limits, write access, and more seats, and an Enterprise tier with dedicated or self-hosted workers, SSO, and custom SLAs. Current details at escalate.me/pricing.
Frequently asked questions
What is escalate?
escalate is an AI agent workspace by Escalate Labs. You connect the accounts you already use and AI agents do real work across them: triage email, schedule meetings, organize files, update spreadsheets, file tickets, and run multi-step workflows spanning several tools. Agents propose, you authorize, escalate executes with a full audit trail.
Is my data safe?
Every connector runs in an isolated container with a pinned egress allowlist; credentials are injected at call time and never enter the agent's context. Your data is fetched per request to fulfill the task you asked for, is never sold, is never used for advertising, and is never used to train models.
How is escalate different from using Claude or ChatGPT directly?
Chat products talk to you; escalate gates what your agent can actually do. It adds the connector catalog, a policy engine, human-approval flows, per-tool isolation, and an audit trail, and it works with your existing AI tools through MCP rather than replacing them.
Is there a mobile app?
Yes. iOS and Android apps cover chat, notifications, and the approval inbox, so a push notification and one tap approve an agent's pending action.
Can I self-host?
Enterprise customers can run escalate workers on their own Kubernetes cluster; the standard plans are fully managed SaaS.
Machine-readable overview for LLMs and crawlers: escalate.me/llms.txt · full connector directory: escalate.me/llms-full.txt