Privacy policy
Last updated 19 September 2026
Rounds is a personal automation service. You connect your own accounts, you define routines that read from them, and the service writes you a brief. This page describes exactly what it reads, where that lands, how long it stays and who else can see it. It is written to be specific rather than broad, because a policy that reserves every right tells you nothing.
Who runs this
Rounds is operated by an individual, not a company, and is reachable at alex122287@gmail.com. It is offered to a small number of people and is not a consumer product.
What is collected
- Your account. Email address and name, handled by Clerk when you sign in. No password ever reaches Rounds.
- Data from accounts you connect. Only the services you grant, each asked for the first time a routine needs it rather than all at once. That can include Gmail messages and threads, Calendar events, Drive files and their extracted text, Meet transcripts and meeting notes, Google Tasks, and contact names and organisations. If you install the Mac agent, it uploads the text-message threads a keyword filter marks as related to the subject of your routines.
- Files you upload as reference material, and their text.
- What routines derive. The memory a routine keeps between rounds: people and companies, facts with their sources, conversation summaries, questions with their answers, and commitments. Also the briefs themselves, the record of what each round fetched, and delivery results.
- Operational records. Run timings, model token counts and costs, and errors.
What it is used for
Only to run your routines and produce your briefs. Your data is not sold, not rented, not used for advertising, and not used to train any model. Nobody browses it for product research.
Google user data
Rounds' use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Concretely: Google data is used only to provide the features you set up, is never transferred to anyone except as needed to provide those features or as required by law, is never used for advertising, and is never read by a human except where you explicitly ask for support, where it is needed for security, or where the law requires it.
You can see which Google permissions a connection holds in Settings, Connectors, remove any of them there, and revoke the whole connection at any time from your Google account permissions page.
Model processing
Writing a brief means sending the material a round gathered to Anthropic's API, using your own API key. That content is processed to produce the brief and is not used by Anthropic to train models. If you turn on web search, the search terms a routine uses are sent to the search provider you configure. No other content leaves for that.
Where it is stored
In a Postgres database hosted by Neon in the United States, and in private blob storage hosted by Vercel for larger items such as transcripts and generated files. Connection credentials and model keys are encrypted with AES-GCM before they are written, and are never displayed back to you or to anyone else. Everything travels over TLS.
How long it is kept
- Fetched source material (mail, meetings, messages, files): 180 days by default, adjustable per project between 7 and 365 days.
- Calendar snapshots: 30 days. Calendars are read live for each round rather than cached.
- Mac agent uploads: only the most recent 7 per device.
- Memory, briefs and run records: kept until you delete them, because they are the point of the product.
Expiry runs nightly and deletes the stored blob along with the row.
Who else is involved
These services process data on Rounds' behalf so that it can run at all:
- Vercel — hosting, and private file storage.
- Neon — the database.
- Clerk — sign-in.
- Anthropic — writing the briefs.
- Resend — sending briefs and receiving your replies, where email delivery is configured.
- Cloudflare — the timer that starts rounds on schedule. It carries no data of yours, only the signal to begin.
Beyond these, nothing is shared, except where the law compels it.
Your choices
- Disconnect any account in Settings, Connectors, which deletes its stored credential.
- Correct or retract anything in a routine's memory from the Memory tab, where every row shows where it came from.
- Ask for your data to be exported or deleted by writing to alex122287@gmail.com. Deletion removes the account, its projects, memory, briefs and stored source material.
Security, honestly stated
Credentials are encrypted at rest, pages require a signed-in session, each machine endpoint checks its own shared secret, and routines can only deliver to destinations you added rather than to an address a model chose. That said, this is a small service run by one person, and no system is immune. Do not connect an account whose exposure you could not tolerate.
Children
Rounds is not intended for anyone under 16, and is not knowingly provided to them.
Changes
If this policy changes in a way that affects what is collected or who sees it, the date above changes and connected users are told by email before it takes effect.
Questions about this page? Write to alex122287@gmail.com.