Volver al inicio

Smooth Privacy Policy

Last updated: 12-05-2026

1. Introduction

Smooth (“we”, “our”, or “us”) provides an AI-powered automation platform that enables users to connect third-party services and create automated workflows operated by autonomous agents.

This Privacy Policy explains how we collect, use, and protect information when you use our services.

By using Smooth, you agree to the practices described in this policy.

2. Information We Collect

2.1 Account Information

When you create an account or sign in using a third-party identity provider, we may collect:

  • Name
  • Email address
  • Basic profile information
  • Authentication identifiers provided via OAuth or similar authorization mechanisms

This information is used solely for authentication, account management, and service delivery.

2.2 Connected Service Data

If you connect third-party services (such as Google Workspace, Microsoft 365, or other business tools), Smooth may request access to data necessary to execute the automation workflows you configure.

Depending on the connected service, this may include:

  • Message content and metadata
  • File contents and metadata
  • Calendar events and attendees
  • Sender and recipient information
  • Timestamps

2.3 Agent Configuration and Execution History

We collect and retain:

  • The agents, tools, triggers, and workflows you configure
  • Records of every agent execution, including inputs, outputs, and data accessed
  • Logs necessary to provide service reliability, debugging, and user-facing audit visibility

3. Google API Scopes Requested

Smooth requests the following Google OAuth scopes to provide its agent automation services:

  • gmail.readonly — to read emails the user wants the agent to process
  • gmail.compose — to draft email responses on the user's behalf for user review
  • gmail.send — to send emails on the user's behalf when explicitly authorized in agent configuration
  • calendar.readonly — to read calendar events for scheduling and coordination tasks
  • calendar.events.owned — to create and manage calendar events owned by the user
  • drive — to read, create, and modify files in the user's Google Drive as part of automated workflows
  • spreadsheets — to read and update Google Sheets as part of automated workflows
  • documents — to read, create, and edit Google Docs as part of automated workflows

Users authorize each scope explicitly during the OAuth consent flow and may revoke access at any time via their Google Account settings or by contacting us at administracion@smooth.cl.

4. How We Use Information

We use collected information to:

  • Authenticate users
  • Execute user-defined automation workflows operated by agents
  • Allow you to review, audit, and reuse past agent executions
  • Provide agents with contextual continuity across executions, so they can perform recurring tasks correctly over time
  • Maintain platform functionality and reliability
  • Detect, prevent, and investigate fraud, abuse, and security incidents
  • Provide customer support

We do not use personal data for advertising, behavioral profiling, or marketing analytics.

5. Third-Party API Data Usage & Compliance

When users connect third-party services, Smooth accesses data solely to provide user-facing automation functionality.

Connected service data:

  • Is used exclusively to execute workflows configured by the user.
  • Is not sold to third parties.
  • Is not used for advertising.
  • Is not used to train artificial intelligence or machine learning models.
  • Is not accessed without explicit user authorization.
  • Is not shared with third parties except as required to provide the service or comply with legal obligations.

Human access to connected service data is strictly limited and only occurs:

  • With the user's affirmative agreement (including via acceptance of our Terms of Service, which authorize limited access by our personnel for service operation, support, and security purposes).
  • When required for security, fraud prevention, or to investigate abuse.
  • When required to comply with applicable law.

6. Google API Services Data Policy Compliance

Smooth's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

  • We only use Google user data to provide or improve user-facing features that are prominent in Smooth's user interface.
  • We do not transfer Google user data to third parties except as necessary to provide or improve user-facing features, or to comply with applicable law or as part of a merger, acquisition, or sale of assets.
  • We do not use Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
  • We do not allow humans to read Google user data unless we have obtained the user's affirmative agreement (including via acceptance of our Terms of Service, which authorize limited access by our personnel for service operation, support, and security purposes), it is necessary for security purposes (such as investigating abuse), or to comply with applicable law.
  • We do not use Google user data, including data from Gmail, Drive, Calendar, Docs, or Sheets, to develop, improve, or train generalized AI and/or ML models.

Users may revoke Google access at any time via their Google Account permissions settings.

7. Microsoft API (Microsoft Graph) Data Usage

When users connect Microsoft services, Smooth accesses Microsoft Graph API data solely to execute user-configured automation workflows.

Access is granted through delegated permissions and can be revoked at any time through Microsoft account settings.

The same Limited Use principles described in Section 6 apply to Microsoft data: no advertising, no sale, no training of generalized AI/ML models, and strictly limited human access.

8. User Control Over Agent Actions

Smooth provides granular controls so users remain in control of what each agent can do:

  • Per-agent permissions: when configuring an agent, users explicitly assign which tools and scopes that agent can use. An agent designed for one task cannot access services that were not granted to it. Permissions are per-agent, not per-account.
  • Human-in-the-loop for critical actions: users can configure any agent to require explicit user approval before performing sensitive operations (such as sending emails, deleting files, or sharing externally). When triggered, the agent pauses execution and requests authorization from the user before continuing.
  • Pause and revoke: users can pause any agent instantly from the Smooth dashboard, and revoke Smooth's access to connected services at any time.

9. Data Storage & Security

We implement industry-standard security measures, including:

  • Encrypted data transmission (HTTPS/TLS)
  • Encryption of sensitive credentials and tokens at rest
  • Role-based access controls
  • Secure cloud infrastructure

Access tokens for connected services are securely stored and can be revoked by users at any time.

10. Data Retention & Deletion

Smooth retains user data, including data accessed from Google Workspace APIs and other connected services, for as long as the user maintains an active account. This retention is necessary for the continued operation of user-configured agents, which may run on recurring schedules over months or years and rely on historical context to perform their tasks correctly.

Specifically:

  • Agent configurations, execution history, and outputs are retained for the lifetime of the account.
  • OAuth credentials are retained while the user maintains the connection and are immediately invalidated upon revocation, either from the Smooth dashboard or the user's account settings on the connected service.
  • Data accessed during agent execution (e.g. file contents, emails, calendar events read by the agent) is stored as part of the agent's execution history. This history is retained to allow the user to review, audit, and reuse past results, and to provide the agent with contextual continuity across executions.

10.1 User-initiated deletion

Users may request deletion of their data at any time by:

  • Deleting specific items from the Smooth dashboard, or
  • Emailing administracion@smooth.cl to request full account deletion.

Upon a deletion request:

  • We delete the requested data from our active systems within 7 days.
  • Backups containing the data are overwritten according to our backup rotation schedule (maximum 30 days).
  • The user receives an email confirmation when deletion is complete.

10.2 Automatic deletion on account closure

When a user closes their Smooth account, all associated data is deleted within 30 days, except where retention is required by law (e.g. billing records for tax compliance).

10.3 Access revocation

When a user revokes Smooth's access from their connected service account settings (e.g. Google Account permissions), cached credentials are invalidated immediately. Data accessed prior to revocation that is stored in the agent's execution history remains until the user requests its deletion or closes their account.

11. User Rights

Users may:

  • Request access to their stored personal data
  • Request correction or deletion (see Section 10)
  • Revoke third-party service access at any time

To exercise these rights, contact: administracion@smooth.cl

12. Subprocessors

We do not sell user data. We share data only with subprocessors that help us provide the service, under contractual obligations that restrict their use of the data:

  • LLM providers (Anthropic, OpenAI) — for agent reasoning. We use enterprise API configurations that do not retain or train on customer data, where available.
  • Cloud infrastructure providers (e.g. AWS, Google Cloud) — for hosting and data storage.
  • Payment processors — for billing.

We may also disclose information when required by law, to comply with legal process, or to protect the rights, property, or safety of Smooth, our users, or others.

13. Third-Party Services

Smooth integrates with third-party services. These services operate under their own privacy policies, and we encourage users to review them.

We are not responsible for the privacy practices of third-party services.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Updates will be reflected on this page with a revised “Last updated” date.

Continued use of the service after updates constitutes acceptance of the revised policy.

15. Contact Information

If you have questions about this Privacy Policy, please contact:

Smooth SpA

Email: administracion@smooth.cl

Address: Av. Las Condes 11380, Oficina 63, Santiago, 7650006, Chile

Website: https://smooth.cl