Terms, privacy, and security.
Last updated: July 9, 2026
Terms of service
These terms govern your access to and use of the SmixAI platform and related professional services ("Services"). By using the Services, you agree to these terms.
1. The service
SmixAI connects to enterprise systems you authorize, analyzes configuration and metadata to produce grounded findings, and provides tooling to plan and operate AI-driven transformation.
2. Accounts & access
You are responsible for the accuracy of account information and for safeguarding credentials and connection authorizations. You must promptly notify us of any unauthorized use.
3. Acceptable use
You agree not to misuse the Services, including attempting to access another tenant's data, reverse-engineer the platform, or use outputs to violate applicable law or third-party rights.
4. Customer data & connected systems
You retain all rights to your data. You grant us a limited license to process connection metadata and findings solely to provide the Services. Record-level data remains in the source system and is accessed under the permissions you configure.
5. Fees
Paid plans and professional-services engagements are billed per the applicable order or statement of work. Fees are non-refundable except as required by law or expressly stated.
6. Intellectual property
The platform, including its software and methodology, is owned by SmixAI. These terms grant no rights other than the limited right to use the Services.
7. Disclaimers
Findings and ROI estimates are provided for informational purposes and depend on the data available in connected systems. The Services are provided "as is" without warranties of any kind to the extent permitted by law.
8. Limitation of liability
To the maximum extent permitted by law, SmixAI is not liable for indirect, incidental, or consequential damages, and total liability is limited to the amounts paid for the Services in the preceding twelve months.
9. Termination
Either party may terminate per the applicable order. On termination, we will disconnect integrations and delete or return access metadata in line with the privacy policy.
10. Governing law
These terms are governed by the laws of the jurisdiction stated in your order. Disputes are subject to the courts of that jurisdiction.
Privacy policy
Effective date: July 9, 2026 · Last updated: July 9, 2026
This Privacy Policy describes how SmixAI ("SmixAI," "we," "us," or "our") collects, uses, stores, and shares information in connection with the SmixAI platform, available at smixai.com (the "Service").
SmixAI is a multi-tenant B2B AI transformation platform that connects to a customer organization's enterprise systems to identify inefficiencies, generate recommendations, and deploy AI agents that act on those recommendations. This policy applies to visitors to our website, to authorized users of the Service acting on behalf of a customer organization ("Customer"), and to any third-party data (including Google user data) that SmixAI processes through connected systems.
If you are an end user of a Customer that uses SmixAI, your organization's own privacy policy and internal agreements also govern how your data is handled. Contact your organization's administrator with questions about your organization's specific configuration.
1. Information we collect
Account and authentication information. When you or your organization sign up for SmixAI, we collect information necessary to create and secure an account, including name, work email address, organization name, and authentication data processed through our identity provider (Clerk). If you sign in using a third-party account (such as Google), we receive basic profile information (name, email address) from that provider as authorized by you during sign-in.
Connected system data. With explicit authorization from a Customer administrator, SmixAI connects to a Customer's enterprise systems through OAuth or API credentials the Customer provides. Depending on which connectors a Customer enables, this may include data from: Salesforce, GitHub, Google Workspace (Gmail), MuleSoft Anypoint, Priority ERP, Monday.com, and Postman. This data may include metadata about system configuration, workflows, records, and usage patterns needed to generate findings and recommendations. SmixAI does not initiate connections to any system without a Customer's explicit configuration and consent. Record-level data remains in the source system; we minimize what we store to the access metadata and findings needed to operate the Service.
Usage and technical data. We automatically collect certain technical information when you use the Service, including IP address, browser type, device information, log data, and usage patterns, through tools such as Sentry (error tracking) and Axiom (logging).
2. Signing in with Google
SmixAI offers "Sign in with Google" as an authentication option, provided through our identity provider, Clerk. When you choose to sign in or sign up using Google, we receive only the following basic profile information from Google, limited to the openid, email, and profile scopes: your name, your email address, and your Google account profile picture (if available).
We use this information solely to create and authenticate your SmixAI account. We do not request or receive access to your Gmail messages, Google Drive files, calendar, or any other Google service through this sign-in method. SmixAI does not use this information for advertising, does not sell it, and does not share it with third parties except as described in Section 4 (service providers necessary to operate the Service).
Separately, SmixAI offers an optional Google Workspace connector that, when a Customer administrator explicitly enables and authorizes it for their own organization's use, may access additional Google Workspace data (such as Gmail) for that Customer's specific business purposes. That connector requests its own distinct authorization and is covered by a separate disclosure at the time it is enabled; it is not part of, and is not required for, signing in to SmixAI.
Limited Use. SmixAI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never used for advertising, never sold, and never used to train generalized AI or machine-learning models.
3. How we use information
- Provide, maintain, and improve the Service.
- Authenticate users and secure accounts.
- Generate discovery findings, ROI-scored recommendations, and AI agent actions on behalf of an authorizing Customer.
- Route requests to our AI processing pipeline (including the model providers listed in Section 4) to analyze connected-system data and produce findings and recommendations.
- Monitor system health, detect and prevent abuse, and debug errors.
- Communicate with Customers about their account, the Service, and support requests.
- Comply with legal obligations.
4. How we share information
We do not sell personal information or Google user data. We share information only in the following circumstances.
Service providers (subprocessors). We use third-party infrastructure and service providers to operate SmixAI:
- Vercel — application hosting
- Railway — backend services, AI pipeline hosting, and job queue
- Supabase — database storage (PostgreSQL)
- Anthropic — AI model processing (Claude) for analysis and agent reasoning
- Clerk — authentication and identity management
- Cloudflare — DNS and content delivery
- Sentry — error tracking
- Axiom — logging and usage telemetry
These providers process data solely to provide their contracted service to SmixAI and are bound by confidentiality and data protection obligations.
Within a Customer's own organization. Data connected to SmixAI on behalf of a Customer is visible only to authorized users within that Customer's organization (enforced through per-tenant isolation and role-based access controls), unless the Customer configures otherwise.
Legal requirements. We may disclose information if required to do so by law, or in the good-faith belief that such action is necessary to comply with legal process, protect our rights, or protect the safety of users or the public.
Business transfers. If SmixAI is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to the confidentiality commitments in this policy and, for Google user data, subject to the user's affirmative consent where required.
5. Data storage, security, and residency
- Connector credentials are encrypted (AES-256-GCM) at rest and never stored in plaintext.
- Data is stored in Supabase-managed PostgreSQL hosted in the European Union (AWS eu-west-1), with per-tenant isolation enforced at the application and database layer.
- Where data is transferred across regions, we apply appropriate safeguards.
- Access to production systems is restricted to authorized personnel and logged.
No method of transmission or storage is 100% secure. While we implement industry-standard safeguards, we cannot guarantee absolute security.
6. Data retention
We retain information for as long as necessary to provide the Service to the Customer, or as required by contractual or legal obligations. Customers may request deletion of their organization's data by contacting us (Section 9). Google user data is retained only as long as necessary to provide the authorized feature, and is deleted or de-identified when no longer needed, or upon revocation of authorization, whichever comes first.
7. Your rights and choices
Depending on your location and applicable law (including GDPR for EU/EEA individuals), you may have rights to access, correct, delete, restrict, or port your personal information, and to withdraw consent at any time. To exercise any of these rights, contact us using the details in Section 9.
Revoking Google access. You can revoke SmixAI's access to your Google account at any time via your Google Account permissions page. Revoking access will stop SmixAI from accessing your Google data going forward but does not automatically delete data already processed; contact us to request deletion.
8. Children's privacy
The Service is intended for business use by adults acting on behalf of an organization. We do not knowingly collect personal information from children under 16.
9. Contact us
For privacy questions, data deletion requests, or to exercise your rights under this policy, contact us.
10. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify Customers via the Service or by email, and update the "Last updated" date above. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
This policy is intended to be read together with SmixAI's Terms of Service and any separate Data Processing Agreement (DPA) entered into with Enterprise Customers.
Cookie policy
We use a small number of cookies to operate the site and understand usage.
- Essential — sign-in and security; always on.
- Analytics — aggregate usage to improve the product; optional.
You can control non-essential cookies through your browser or our consent banner. Declining non-essential cookies will not affect core functionality.
Security overview
Security is built into the platform, not bolted on.
- Tenant isolation — every record carries a tenant boundary; no cross-tenant access, ever.
- Least privilege — connections use scoped credentials; record data is read under your permissions.
- Encryption — data encrypted in transit and at rest.
- Auditability — access decisions are logged with their reason for audit and chargeback.
- BYOK & residency — enterprise plans support bring-your-own keys and regional routing.
For a detailed security questionnaire or to report a vulnerability, contact us.