Privacy Policy

Effective Date: 2 August, 2026

Contact: privacy@meetsquad.ai

1. Introduction

This privacy policy explains how Squad AI (“Squad,” “we,” “us,” or “our”) collects, uses, stores, and protects your personal data. It applies to:

  • The Squad website at meetsquad.ai

  • The Squad web application at app.meetsquad.ai

  • The Squad MCP (Model Context Protocol) server

  • The Squad CLI binary

  • Third-party AI platform integrations where Squad operates as a connected service, including OpenAI ChatGPT and Anthropic Claude

When you use Squad through a third-party AI platform (such as ChatGPT or Claude), that platform’s own privacy policy also applies to your use of that platform. This policy covers only the data that Squad receives and processes.

2. Who We Are

Squad AI is a decision intelligence and product strategy platform. We provide tools for managing product goals, data sources and signals, knowledge, and insights.

Our MCP server allows you to access Squad’s tools directly within AI assistants like ChatGPT and Claude, so you can research, plan, and manage product strategy without leaving your AI workflow.

Our Role in Handling Your Data

Squad handles personal data in two different capacities.

Where your organisation uses Squad under a business agreement, the content you and your colleagues create in your workspace is processed by us on your organisation’s instructions. Your organisation is the data controller for that content and Squad acts as its data processor, as set out in our Master Subscription Agreement. If you are an employee of a Squad customer and you want to exercise your rights over that content, contact your own organisation in the first instance.

This policy describes the data for which Squad itself determines the purpose and means: account and identity data, billing data, usage analytics, support correspondence, and marketing data.

Our Role in Handling Your Data

Squad handles personal data in two different capacities.

Where your organisation uses Squad under a business agreement, the content you and your colleagues create in your workspace is processed by us on your organisation’s instructions. Your organisation is the data controller for that content and Squad acts as its data processor, as set out in our Master Subscription Agreement. If you are an employee of a Squad customer and you want to exercise your rights over that content, contact your own organisation in the first instance.

This policy describes the data for which Squad itself determines the purpose and means: account and identity data, billing data, usage analytics, support correspondence, and marketing data.

3. Data We Collect

We collect and process the following categories of personal data:

3.1 Account and Identity Data
  • Email address

  • User ID (assigned by our authentication provider)

  • Organisation and workspace membership

3.2 Authentication Data
  • OAuth tokens (access tokens and refresh tokens) used to verify your identity

  • These tokens are issued by our authentication provider and are not stored permanently by Squad’s MCP server

3.3 Workspace Content Data
  • Goals, Signals, Insights, One-pagers, Actions, and knowledge items you create or modify through Squad

  • Relationships between these items

  • Workspace configuration and settings

3.4 MCP and AI Platform Interaction Data
  • When you use Squad through an AI platform (ChatGPT, Claude, or another MCP client), our server receives only the specific tool calls made by the AI assistant on your behalf. These tool calls contain structured parameters (such as “list my opportunities” or “create an opportunity with this title and description”).

  • We do not receive your full conversation history with the AI assistant.

  • We do not receive prompts or messages you send to the AI assistant that do not result in a Squad tool call.

  • Tool call parameters and responses are processed in real time to fulfill your request and are not separately logged or stored beyond standard server operation logs.

3.5 Usage and Technical Data
  • Server access logs, which may include IP addresses, timestamps, and request metadata

  • Error logs for diagnosing issues

  • Session identifiers used to maintain your connection during an MCP session

3.6 Website Data
  • Standard web analytics data if you visit meetsquad.ai (see Section 10 on cookies)


3.7 Voice Input


Where you use voice dictation in the Squad application, we process the audio of your speech and the transcript produced from it, in order to convert your speech to text. Audio is streamed to our speech-to-text provider for transcription and is not retained by Squad beyond producing the transcript.

3. Data We Collect

We collect and process the following categories of personal data:

3.1 Account and Identity Data
  • Email address

  • User ID (assigned by our authentication provider)

  • Organisation and workspace membership

3.2 Authentication Data
  • OAuth tokens (access tokens and refresh tokens) used to verify your identity

  • These tokens are issued by our authentication provider and are not stored permanently by Squad’s MCP server

3.3 Workspace Content Data
  • Goals, Signals, Insights, One-pagers, Actions, and knowledge items you create or modify through Squad

  • Relationships between these items

  • Workspace configuration and settings

3.4 MCP and AI Platform Interaction Data
  • When you use Squad through an AI platform (ChatGPT, Claude, or another MCP client), our server receives only the specific tool calls made by the AI assistant on your behalf. These tool calls contain structured parameters (such as “list my opportunities” or “create an opportunity with this title and description”).

  • We do not receive your full conversation history with the AI assistant.

  • We do not receive prompts or messages you send to the AI assistant that do not result in a Squad tool call.

  • Tool call parameters and responses are processed in real time to fulfill your request and are not separately logged or stored beyond standard server operation logs.

3.5 Usage and Technical Data
  • Server access logs, which may include IP addresses, timestamps, and request metadata

  • Error logs for diagnosing issues

  • Session identifiers used to maintain your connection during an MCP session

3.6 Website Data
  • Standard web analytics data if you visit meetsquad.ai (see Section 10 on cookies)

3.7 Voice Input

Where you use voice dictation in the Squad application, we process the audio of your speech and the transcript produced from it, in order to convert your speech to text. Audio is streamed to our speech-to-text provider for transcription and is not retained by Squad beyond producing the transcript.


4. Data We Do Not Collect

Squad does not ask for, and does not intentionally collect, the categories below. The platform is not designed for them and we ask that you do not enter them into your workspace. Because workspace content is created by you and your colleagues, you control what is submitted.

  • Payment card information. All payment processing is handled by our payment provider; we never receive or store card numbers.

  • Health data. Squad is not a healthcare service and is not intended for the processing of health information.

  • Government-issued identification numbers, such as national insurance, social security or passport numbers.

  • Passwords or third-party API keys. Authentication is handled through OAuth; we never see or store your password.

  • Biometric data. Where you use voice dictation, your audio is transcribed to text and is not used to identify you.

4. Data We Do Not Collect

Squad does not collect, process, or store:

  • Payment card information (PCI data): all payment processing is handled by third-party payment processors

  • Protected health information (PHI): Squad is not a healthcare service and does not process health data

  • Government-issued identification numbers: such as social security numbers, passport numbers, or national ID numbers

  • Passwords: authentication is handled entirely through OAuth; we never see or store your password

  • Biometric data

5. How We Use Your Data

We use your data for the following purposes:

Authenticating you and authorizing access to your workspaces. Lawful basis: Contractual necessity

Executing tool calls you initiate. Lawful basis: Contractual necessity

Maintaining MCP session state. Lawful basis: Legitimate interest

Diagnosing errors and maintaining service reliability. Lawful basis: Legitimate interest

Improving the Squad platform and MCP integration. Lawful basis: Legitimate interest

Responding to support requests. Lawful basis: Contractual necessity

Complying with legal obligations. Lawful basis: Legal obligation

Retrieving public reviews of your product from app stores and review sites. Lawful basis: Legitimate interest

Automated decision-making. Squad uses AI to generate insights, group related signals and score opportunities. These outputs support decisions that people make about your product. We do not make decisions about individuals by automated means that produce legal effects or similarly significant effects.

We do not use your workspace content or MCP interaction data for training AI models. We do not sell your personal data.

Marketing and Prospect Data

We contact people at businesses we believe may have a professional interest in Squad. Where we do, we hold your name, job title, business email address, employer, and engagement data such as whether a message was opened or replied to.

This information comes from publicly available professional sources and from third-party data providers. We did not obtain it from you.

Our lawful basis is legitimate interests: promoting a business product to business contacts. Every message we send includes a way to opt out, and we act on opt-outs and objections as soon as we receive them.

To find out what we hold about you, correct it, or be removed entirely, email privacy@meetsquad.ai.

6. Data Minimization

We follow a data minimization approach:

  • Our MCP server only receives the specific tool call parameters needed to fulfill each request. It does not receive or process your broader AI conversation context.

  • Session data is held in memory or Redis with a maximum time-to-live and is automatically evicted.

  • OAuth tokens are validated in real time and are not persisted beyond the active session.

  • Server logs are retained only as long as needed for operational purposes (see Section 8).

7. Who We Share Data With

We share data with the following service providers, only as necessary to provide the service. Each is bound by data processing terms and may only use the data to provide services to us.

Provider

Purpose

Data shared

Processing location

Railway

Provider: Railway

Application hosting, database, file storage and server logs

Purpose: Application hosting, database, file storage and server logs

Account data, workspace content, uploaded files, server logs

Data shared: Account data, workspace content, uploaded files, server logs

Netherlands (EU)

Processing location: Netherlands (EU)

PropelAuth

Provider: PropelAuth

Authentication and OAuth token management

Purpose: Authentication and OAuth token management

User ID, email address, organisation and workspace membership, OAuth tokens

Data shared: User ID, email address, organisation and workspace membership, OAuth tokens

United States

Processing location: United States

PostHog

Provider: PostHog

Product and website analytics, error tracking

Purpose: Product and website analytics, error tracking

User identifiers, email address, usage events, device and browser metadata. Client IP addresses are discarded on receipt

Data shared: User identifiers, email address, usage events, device and browser metadata. Client IP addresses are discarded on receipt

European Union

Processing location: European Union

Stripe

Provider: Stripe

Billing and payment processing

Purpose: Billing and payment processing

Name, business email, billing address. We do not receive or store card numbers

Data shared: Name, business email, billing address. We do not receive or store card numbers

United States

Processing location: United States

Google Workspace

Provider: Google Workspace

Support correspondence and business documents

Purpose: Support correspondence and business documents

Name, email address, content of correspondence

Data shared: Name, email address, content of correspondence

United States

Processing location: United States

Google Cloud (Vertex AI)

Provider: Google Cloud (Vertex AI)

AI features: chat and research agents, signal and insight pipelines, retrieval embeddings

Purpose: AI features within Squad. Squad’s AI features are provided using Google’s Gemini models on Google Cloud Vertex AI. Workspace content is not used to train general-purpose AI models.

Workspace content submitted to the model as context

Data shared: Workspace content submitted to the model as context

United States

Processing location: United States

Deepgram

Provider: Deepgram

Live voice dictation

Purpose: Live voice dictation

Audio of your speech and its transcript

Data shared: Audio of your speech and its transcript

United States

Processing location: United States

Jina AI

Provider: Jina AI

Fetching and cleaning web pages you ask Squad to read

Purpose: Fetching and cleaning web pages you ask Squad to read

The URL and the content of the page retrieved

Data shared: The URL and the content of the page retrieved

United States

Processing location: United States

DataForSEO

Provider: DataForSEO

Retrieving public reviews from the App Store, Play Store, Google Reviews and Trustpilot for the sources your organisation configures

Purpose: Retrieving public reviews from the App Store, Play Store, Google Reviews and Trustpilot for the sources your organisation configures

Search parameters for the sources configured; reviews are returned to us

Data shared: Search parameters for the sources configured; reviews are returned to us

United States

Processing location: United States

Inngest

Provider: Inngest

Running background jobs in the signal and insight pipelines

Purpose: Running background jobs in the signal and insight pipelines

Workspace content and account identifiers passed through jobs

Data shared: Workspace content and account identifiers passed through jobs

United States

Processing location: United States

Novu

Provider: Novu

Notification delivery

Purpose: Notification delivery

Name and email address

Data shared: Name and email address

United States

Processing location: United States

AI platform providers. When you use Squad through ChatGPT, Claude or another AI assistant, that platform sends tool calls to our server on your behalf and receives our responses, which contain your workspace data. How that provider handles that data is governed by its own privacy policy, not ours.

AI platform providers. When you use Squad through ChatGPT, Claude or another AI assistant, that platform sends tool calls to our server on your behalf and receives our responses, which contain your workspace data. How that provider handles that data is governed by its own privacy policy, not ours.

AI features within Squad. Squad’s AI features are provided using Google’s Gemini models on Google Cloud Vertex AI. Workspace content is not used to train general-purpose AI models.

Review data. Where your organisation configures review sources, Squad retrieves publicly posted reviews of your product from the App Store, Play Store, Google Reviews and Trustpilot. Those reviews may include the display name the reviewer chose and the text they wrote. Squad processes this on your organisation’s instructions as part of your workspace content.

AI features within Squad. Squad’s AI features are provided using Google’s Gemini models on Google Cloud Vertex AI. Workspace content is not used to train general-purpose AI models.

Review data. Where your organisation configures review sources, Squad retrieves publicly posted reviews of your product from the App Store, Play Store, Google Reviews and Trustpilot. Those reviews may include the display name the reviewer chose and the text they wrote. Squad processes this on your organisation’s instructions as part of your workspace content.

We do not share your data with advertisers. We do not sell personal data to any third party.

We will give at least 30 days’ notice, by email or through the service, before a new provider begins processing personal data.

We do not share your data with advertisers. We do not sell personal data to any third party.

8. Data Retention

Account data (user ID, email, org membership). Retained while your account is active; deleted within 30 days of account deletion.

Workspace content. Retained while your workspace exists; deleted within 30 days of workspace deletion.

MCP organization and workspace selection. Maximum 30 days, automatically evicted.

OAuth tokens in session. Duration of active session only.

Server operation logs. 30 days.

Error/debug logs. 30 days.

Product and website analytics data (events and metadata). Retained by our analytics provider under its standard plan retention. Client IP addresses are not stored with analytics events.

Session recordings. Session recording is disabled. Where enabled, recordings are retained for a maximum of 30 days.

MCP session identifiers. Duration of the active session only.

Browser/console logs. 14 days.

Backups. Deleted data may persist in encrypted backups for a further six days, after which it ages out of the backup rotation.

9. Data Processing Locations

Our application, database and file storage are hosted in the Netherlands. Our analytics data is stored in the European Union. Some of the providers listed in Section 7 process data in the United States, including the AI models that power Squad’s features. Those transfers rely on the standard contractual clauses and the UK Addendum contained in each provider’s data processing terms.

10. Cookies and Tracking
10.1 Squad Website (meetsquad.ai)

When you visit our website we use:

  • Essential cookies: Required for site functionality, such as session management and authentication state. These cannot be disabled.

  • Analytics cookies: We use PostHog and Amplitude to understand how visitors use our site, including page views, referral sources and general geographic region.

  • Advertising and measurement cookies: We use Google Analytics, Google Ads, LinkedIn, Meta and X to measure how our marketing performs and to reach relevant business audiences.

You can accept or reject non-essential cookies when you first visit, and change your choice at any time from the cookie settings link in the footer. Rejecting them does not affect your ability to use the site.

10.2 MCP Server

The MCP server does not use cookies. Authentication is handled via OAuth bearer tokens transmitted in HTTP headers.

10.3 Third-Party AI Platforms

When you use Squad through ChatGPT, Claude, or another AI platform, any cookies or tracking are governed by that platform’s privacy policy, not ours. Our MCP server does not set cookies in these contexts.


11. Children’s Privacy

Squad is a business tool and is not intended for use by anyone under 18. We do not knowingly collect personal data from children. If we learn that we have, we will delete it promptly. If you believe a child has provided us with personal data, contact us at privacy@meetsquad.ai.

12. Your Data Rights

Depending on your location, you may have some or all of the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you

  • Correction: Request correction of inaccurate data

  • Deletion: Request deletion of your personal data

  • Portability: Request your data in a structured, machine-readable format

  • Restriction: Request that we limit how we process your data

  • Objection: Object to processing based on legitimate interest

  • Withdraw consent: Where processing is based on consent, withdraw it at any time

How to Exercise Your Rights

You can exercise your rights in any of the following ways:

  1. Email: Send a request to privacy@meetsquad.ai with the subject line “Privacy Rights Request”

  2. In-app: Delete your workspace content directly through the Squad application or MCP tools

  3. Account deletion: Request full account deletion by emailing privacy@meetsquad.ai

We will respond to verified requests within 30 days. If we need more time, we will notify you of the reason and extension period. We will verify your identity before processing any rights request to protect your data.

Complaints

If you are in the United Kingdom, you have the right to lodge a complaint with the Information Commissioner’s Office at ico.org.uk. If you are in the European Economic Area, you may complain to your local supervisory authority. We would ask that you contact us first at privacy@meetsquad.ai so that we have the opportunity to put things right.

13. Security

We protect your data through:

  • OAuth 2.0 authentication with token validation for every request

  • HTTPS/TLS encryption for all data in transit over public networks

  • Encryption at rest for stored data and backups

  • User-isolated data access. You can only access workspaces you are authorized for

  • Scoped access tokens with limited permissions

  • Automatic session expiration and cache eviction

  • No storage of passwords or credentials on our servers

14. Changes to This Policy

We may update this privacy policy from time to time. When we make material changes, we will:

  • Update the effective date at the top of this page

  • Post the revised policy on our website

  • Notify active users via email for significant changes

Your continued use of Squad after changes are posted constitutes acceptance of the updated policy.

15. Contact Us

Squad AI is a trading name of Basilisk Labs Ltd, a company registered in England and Wales under company number 15789841, with its registered office at 5 Beech Court, Hurst, Reading, England, RG10 0RQ. Basilisk Labs Ltd is the data controller for the personal data described in this policy.
Email: privacy@meetsquad.ai
Website: https://meetsquad.ai