Legal
Privacy Policy
How Shepherd handles account data, connected-source data, product telemetry, support access, and customer-memory processing.
Last updated: June 28, 2026
Overview
This Privacy Policy explains how Shepherd collects, uses, stores, and shares information when you use Shepherd websites, apps, onboarding flows, dashboard, CLI and MCP tools, APIs, and related services.
Shepherd is a company-memory service. It can process messages, documents, meetings, code-session metadata, source metadata, summaries, embeddings, wiki artifacts, and related context that you or your organization authorize.
Information We Collect
- Account and organization information: Name, email address, organization, domain, role, authentication status, invite state, SSO metadata, and settings.
- Connected-source data: Content and metadata from sources you authorize, such as Google Workspace, Slack, Notion, Granola, GitHub, local Messages, coding-session collectors, office audio, Discord, Instagram, WhatsApp, Stripe, MCP clients, and similar sources enabled for your account or organization.
- Local app and setup data: Onboarding state, selected sources, selected Messages chats or handles, sync health, local permission state, and installation status for desktop or background sync components.
- Service usage data: Dashboard activity, chat and MCP requests, tool calls, support interactions, device and browser details, cookies, IP address, logs, error reports, and security events.
Connected Sources
For Google Workspace, Shepherd may process Gmail, Calendar, Drive, Docs, Sheets, Slides, Tasks, Contacts, directory, and Drive activity data depending on the scopes your administrator authorizes and the users or groups configured for syncing.
For local Messages on macOS, Shepherd asks for explicit setup and local permissions. It syncs selected chats unless you explicitly choose an all-current-and-future-chats option. Contact names may be read from the local macOS AddressBook database to make selected conversations understandable.
For coding-session sync, Shepherd's local collector reads Codex and Claude Code session records, redacts sensitive values locally, and uploads repo/title metadata plus structured user messages and agent responses. It does not upload raw JSONL lines, tool results, command output, or locally generated narrative summaries.
For office audio or room-memory features, Shepherd may process session-scoped audio-derived transcripts, speaker information, consent state, summaries, and related artifacts when those features are enabled.
How We Use Information
- Provide Shepherd: Authenticate users, connect sources, ingest authorized data, build memory and wiki artifacts, retrieve source context, answer questions, and operate dashboard, desktop, CLI, and MCP surfaces.
- Secure Shepherd: Detect abuse, debug service reliability, enforce organization and user scoping, audit access, protect accounts, and investigate security issues.
- Support customers: Respond to support requests, troubleshoot syncing, verify configuration, and maintain customer environments. Staff access to customer-confidential plaintext is governed by privacy gates, support grants, deployment posture, and audit requirements.
- Improve product quality: Analyze aggregated or de-identified usage patterns, fix bugs, improve onboarding, and measure performance. We do not sell personal information or share it for cross-context behavioral advertising.
Google API Data
Shepherd's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We use Google Workspace data to provide and improve user-facing Shepherd features that your organization enables. We do not use Google API data for advertising or to train generalized AI or ML models.
Human access to Google API data is limited to cases needed to provide or secure the service, comply with law, respond to an explicit support request, or perform permitted internal operations under appropriate privacy and security controls.
Sharing
We share information with service providers that help us operate Shepherd, including hosting, database, queue, observability, authentication, email, support, model-provider, and connected-service API providers. These providers are authorized to process information only as needed to provide services to Shepherd.
Information may be visible to other users in your organization according to organization settings, membership, source permissions, sharing rules, and the customer-facing surfaces you enable.
We may disclose information if required by law, to protect rights or safety, to investigate abuse, or in connection with a merger, financing, acquisition, or sale of assets, subject to appropriate protections.
Security
Shepherd uses administrative, technical, and organizational safeguards designed to protect information, including scoped authentication, signed sessions, access controls, audit paths, and internal customer-data boundaries.
No system is perfectly secure. Some deployments may include stricter customer-managed, dedicated, lockbox, or no-employee-plaintext controls, but those controls apply only when configured and verified for that customer deployment.
Retention
We retain information for as long as needed to provide Shepherd, comply with legal obligations, resolve disputes, maintain security, preserve audit records, and enforce agreements. Retention periods can vary by data type, source, customer configuration, backup state, and legal requirement.
You can disconnect sources or request deletion. Some information may remain in backups, logs, audit records, or legal records for a limited period where necessary.
Your Choices
- Sources: You or your administrator can choose which sources to connect and can disconnect sources through Shepherd or the connected service. Disconnecting a source stops or limits future access and may revoke tokens, but it does not automatically delete historical memory or wiki artifacts unless deletion is requested and completed.
- Local permissions: You can manage macOS permissions such as Full Disk Access and Contacts in System Settings, though disabling permissions may stop local syncing.
- Requests: Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to processing of personal information. Contact [email protected] to make a request.
- Marketing: If we send marketing email, you can unsubscribe using the link in the email or by contacting us.
International Use
Shepherd and its providers may process information in the United States and other countries where we or our providers operate. Those countries may have privacy laws different from where you live.
Children
Shepherd is intended for business use and is not directed to children under 13. Do not use Shepherd if you are under 13, and do not provide information about children unless your organization has the required rights and consents.
Changes
We may update this Privacy Policy as Shepherd changes. If we make material changes, we will provide notice through the service, by email, or by updating this page.
Contact
Questions or privacy requests can be sent to [email protected].