1. Introduction
Smooth (“we”, “our”, or “us”) provides an AI-powered automation platform that enables users to connect third-party services and create automated workflows operated by autonomous agents.
This Privacy Policy explains how we collect, use, and protect information when you use our services.
By using Smooth, you agree to the practices described in this policy.
2. Information We Collect
2.1 Account Information
When you create an account or sign in using a third-party identity provider, we may collect:
- Name
- Email address
- Basic profile information
- Authentication identifiers provided via OAuth or similar authorization mechanisms
This information is used solely for authentication, account management, and service delivery.
2.2 Connected Service Data
If you connect third-party services (such as Google Workspace, Microsoft 365, or other business tools), Smooth may request access to data necessary to execute the automation workflows you configure.
Depending on the connected service, this may include:
- Message content and metadata
- File contents and metadata
- Calendar events and attendees
- Sender and recipient information
- Timestamps
2.3 Agent Configuration and Execution History
We collect and retain:
- The agents, tools, triggers, and workflows you configure
- Records of every agent execution, including inputs, outputs, and data accessed
- Logs necessary to provide service reliability, debugging, and user-facing audit visibility
3. Google API Scopes Requested
Smooth requests the following Google OAuth scopes to provide its agent automation services:
gmail.readonly — to read emails the user wants the agent to processgmail.compose — to draft email responses on the user's behalf for user reviewgmail.send — to send emails on the user's behalf when explicitly authorized in agent configurationcalendar.readonly — to read calendar events for scheduling and coordination taskscalendar.events.owned — to create and manage calendar events owned by the userdrive — to read, create, and modify files in the user's Google Drive as part of automated workflowsspreadsheets — to read and update Google Sheets as part of automated workflowsdocuments — to read, create, and edit Google Docs as part of automated workflows
Users authorize each scope explicitly during the OAuth consent flow and may revoke access at any time via their Google Account settings or by contacting us at administracion@smooth.cl.
4. How We Use Information
We use collected information to:
- Authenticate users
- Execute user-defined automation workflows operated by agents
- Allow you to review, audit, and reuse past agent executions
- Provide agents with contextual continuity across executions, so they can perform recurring tasks correctly over time
- Maintain platform functionality and reliability
- Detect, prevent, and investigate fraud, abuse, and security incidents
- Provide customer support
We do not use personal data for advertising, behavioral profiling, or marketing analytics.
5. Third-Party API Data Usage & Compliance
When users connect third-party services, Smooth accesses data solely to provide user-facing automation functionality.
Connected service data:
- Is used exclusively to execute workflows configured by the user.
- Is not sold to third parties.
- Is not used for advertising.
- Is not used to train artificial intelligence or machine learning models.
- Is not accessed without explicit user authorization.
- Is not shared with third parties except as required to provide the service or comply with legal obligations.
Human access to connected service data is strictly limited and only occurs:
- With the user's affirmative agreement (including via acceptance of our Terms of Service, which authorize limited access by our personnel for service operation, support, and security purposes).
- When required for security, fraud prevention, or to investigate abuse.
- When required to comply with applicable law.
6. Google API Services Data Policy Compliance
Smooth's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We only use Google user data to provide or improve user-facing features that are prominent in Smooth's user interface.
- We do not transfer Google user data to third parties except as necessary to provide or improve user-facing features, or to comply with applicable law or as part of a merger, acquisition, or sale of assets.
- We do not use Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
- We do not allow humans to read Google user data unless we have obtained the user's affirmative agreement (including via acceptance of our Terms of Service, which authorize limited access by our personnel for service operation, support, and security purposes), it is necessary for security purposes (such as investigating abuse), or to comply with applicable law.
- We do not use Google user data, including data from Gmail, Drive, Calendar, Docs, or Sheets, to develop, improve, or train generalized AI and/or ML models.
Users may revoke Google access at any time via their Google Account permissions settings.
7. Microsoft API (Microsoft Graph) Data Usage
When users connect Microsoft services, Smooth accesses Microsoft Graph API data solely to execute user-configured automation workflows.
Access is granted through delegated permissions and can be revoked at any time through Microsoft account settings.
The same Limited Use principles described in Section 6 apply to Microsoft data: no advertising, no sale, no training of generalized AI/ML models, and strictly limited human access.
8. User Control Over Agent Actions
Smooth provides granular controls so users remain in control of what each agent can do:
- Per-agent permissions: when configuring an agent, users explicitly assign which tools and scopes that agent can use. An agent designed for one task cannot access services that were not granted to it. Permissions are per-agent, not per-account.
- Human-in-the-loop for critical actions: users can configure any agent to require explicit user approval before performing sensitive operations (such as sending emails, deleting files, or sharing externally). When triggered, the agent pauses execution and requests authorization from the user before continuing.
- Pause and revoke: users can pause any agent instantly from the Smooth dashboard, and revoke Smooth's access to connected services at any time.
9. Data Storage & Security
We implement industry-standard security measures, including:
- Encrypted data transmission (HTTPS/TLS)
- Encryption of sensitive credentials and tokens at rest
- Role-based access controls
- Secure cloud infrastructure
Access tokens for connected services are securely stored and can be revoked by users at any time.
10. Data Retention & Deletion
Smooth retains user data, including data accessed from Google Workspace APIs and other connected services, for as long as the user maintains an active account. This retention is necessary for the continued operation of user-configured agents, which may run on recurring schedules over months or years and rely on historical context to perform their tasks correctly.
Specifically:
- Agent configurations, execution history, and outputs are retained for the lifetime of the account.
- OAuth credentials are retained while the user maintains the connection and are immediately invalidated upon revocation, either from the Smooth dashboard or the user's account settings on the connected service.
- Data accessed during agent execution (e.g. file contents, emails, calendar events read by the agent) is stored as part of the agent's execution history. This history is retained to allow the user to review, audit, and reuse past results, and to provide the agent with contextual continuity across executions.
10.1 User-initiated deletion
Users may request deletion of their data at any time by:
- Deleting specific items from the Smooth dashboard, or
- Emailing administracion@smooth.cl to request full account deletion.
Upon a deletion request:
- We delete the requested data from our active systems within 7 days.
- Backups containing the data are overwritten according to our backup rotation schedule (maximum 30 days).
- The user receives an email confirmation when deletion is complete.
10.2 Automatic deletion on account closure
When a user closes their Smooth account, all associated data is deleted within 30 days, except where retention is required by law (e.g. billing records for tax compliance).
10.3 Access revocation
When a user revokes Smooth's access from their connected service account settings (e.g. Google Account permissions), cached credentials are invalidated immediately. Data accessed prior to revocation that is stored in the agent's execution history remains until the user requests its deletion or closes their account.
11. User Rights
Users may:
- Request access to their stored personal data
- Request correction or deletion (see Section 10)
- Revoke third-party service access at any time
To exercise these rights, contact: administracion@smooth.cl
12. Subprocessors
We do not sell user data. We share data only with subprocessors that help us provide the service, under contractual obligations that restrict their use of the data:
- LLM providers (Anthropic, OpenAI) — for agent reasoning. We use enterprise API configurations that do not retain or train on customer data, where available.
- Cloud infrastructure providers (e.g. AWS, Google Cloud) — for hosting and data storage.
- Payment processors — for billing.
We may also disclose information when required by law, to comply with legal process, or to protect the rights, property, or safety of Smooth, our users, or others.
13. Third-Party Services
Smooth integrates with third-party services. These services operate under their own privacy policies, and we encourage users to review them.
We are not responsible for the privacy practices of third-party services.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Updates will be reflected on this page with a revised “Last updated” date.
Continued use of the service after updates constitutes acceptance of the revised policy.
15. Contact Information
If you have questions about this Privacy Policy, please contact: