Plain English, no tricks
Privacy policy.
Last updated August 10, 2026. Short version: we collect what we need to run the course, we'll never sell your data, and you can ask us to delete everything at any time.
01Who we are
"Agents For Us" (agentsforus.ai) is an educational course operated by Aava. Deep Gill is your guide. This policy explains what personal information we collect when you visit the site or purchase the course, how we use it, and your choices.
Questions? Email hello@agentsforus.ai — a real person reads every message.
02What we collect
We collect only what we need to run the course and keep you updated:
- Name and email address — when you place a deposit or create a course account.
- Payment information — processed entirely by Stripe. We never see or store your card details.
- Course progress — which chapters and steps you've completed, so the course remembers where you left off.
- Survey responses — optional, collected if you fill out the access survey after joining.
- Basic usage data — page visits and errors, collected by Sentry and Vercel for debugging. No ad-targeting profiles.
03How we use it
We use your information to:
- Deliver the course and gate access to the right chapters.
- Send you a confirmation when your deposit goes through.
- Email you when the course opens, when new material drops, or when something important changes.
- Respond to support requests you send us.
- Detect and fix bugs or errors in the site.
We do not sell your data. We do not use it for advertising. We do not build profiles for third-party marketers.
04Third-party services
We use a small number of trusted services to run the site. Each one handles your data under their own privacy policies:
- Stripe — payment processing and deposit management.
- Clerk — account creation, sign-in, and session management.
- Supabase — course database (progress, cohort records).
- Vercel — web hosting and edge delivery.
- Sentry — error monitoring.
We do not share your personal information with any service beyond what is needed to operate the course.
05Google Workspace data (Gmail, Calendar, Drive, Sheets & Docs)
Part of the course teaches you to connect your own personal AI agent — software running on a private cloud server that you own and control — to your Google account. This connection is optional and initiated by you, through our Google OAuth application. Access is tiered: before connecting, you choose what your agent may do per service, and it requests only the scopes for the tier you picked. Depending on your choices, the app requests one or more of the following Google scopes:
- Gmail, read tier (gmail.readonly) — your agent reads your inbox to answer your questions and build briefings. It does not keep copies of your inbox.
- Gmail, drafting tier (gmail.compose) — your agent prepares draft replies. Drafts sit in your Drafts folder; you press send.
- Gmail, filing tier (gmail.modify) — your agent labels, archives, or files messages when you set up inbox triage. Filing never means deleting.
- Gmail, send (gmail.send) — only for full-access setups where you explicitly approve each outgoing message; the standing default across the course is draft-and-you-send.
- Calendar (calendar.readonly, or calendar for the read-and-write tier) — your agent reads your events and, if you allow it, creates, updates, or removes events for you.
- Drive (drive.readonly, or drive for the editor tier) — your agent finds and reads your files and, if you allow it, uploads or organizes them.
- Sheets & Docs (spreadsheets and documents, each with a .readonly reader tier) — your agent reads, and if you allow it edits, the specific spreadsheets and documents you point it at.
- Contacts (contacts.readonly) — your agent looks up the people you correspond with, to resolve names when you ask about email or scheduling.
The key architectural fact: we never see this data. The OAuth flow completes directly between Google and your own agent. Access and refresh tokens are issued to your agent and stored only on your private server — our systems never receive, store, or process your Google Workspace data or your tokens, and there is no shared backend that pools Workspace data across users. Your emails, events, spreadsheets, and documents move between Google's servers, your own server, and (when you ask a question about them) the AI model you connected — never through us.
Because we never receive your Google Workspace data, we retain none of it. Your agent reads data fresh when you ask and does not archive your inbox or calendar history. Anything it stores — notes and memory you asked it to keep — lives on your own server, under your control, and is deleted when you delete that server.
You choose your agent's access level before you connect (for example, read-only email versus email with drafting), and you can revoke access at any time: from your Google Account's third-party access settings (myaccount.google.com, under Security), by disconnecting the integration through your agent, or by shutting down your server. Revoking stops all further access immediately.
Students who connect a Microsoft account instead go through an equivalent architecture: Microsoft's own OAuth consent, with tokens stored only on the student's own server.
06AI processing & Google Limited Use compliance
When you ask your agent about your email, calendar, or documents, your agent sends the relevant content — from your own server — to the AI model you connected during setup: Anthropic's Claude, accessed through your own OpenRouter account on the standard paid API tier. Under Anthropic's commercial API terms and OpenRouter's terms of service, content submitted through these APIs is not used to train their models. Your agent sends only the content needed to answer the request; it does not bulk-upload your inbox or files.
Agents For Us's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use, transfer, or sell Google Workspace user data — raw, aggregated, anonymized, or derived — to create, train, or improve any machine-learning or artificial-intelligence model, foundational or otherwise, and we do not transfer it to third-party AI services that would use it for training.
No human at Aava reads your Google Workspace data. It is never used for advertising, never sold, and never transferred to third parties except as required to provide the functionality you asked for (that is, to the AI model provider above, at your direction), to comply with applicable law, or as part of a merger or acquisition with prior notice to you.
07How we protect your data
Security mechanisms we use, in plain English:
- Encryption in transit — all traffic between your browser, our site, and our services is encrypted with TLS (HTTPS). Your agent's connections to Google and to its AI model are also TLS-encrypted.
- Encryption at rest — account and course data stored with our providers (Clerk, Supabase, Stripe) is encrypted at rest on their infrastructure.
- OAuth 2.0 for sensitive connections — we never see or store your Google or Microsoft password. You grant permissions on Google's or Microsoft's own consent screen, scoped to exactly what you approve, and can revoke them there at any time.
- No central store of sensitive data — Google Workspace data and OAuth tokens exist only on your own private server, not ours. A breach of our systems cannot expose your inbox, calendar, or documents, because we do not hold them.
- Payment isolation — card details are handled entirely by Stripe (PCI DSS Level 1 certified). They never touch our servers.
- Access control — access to our production systems and databases is limited to the course operator, protected by strong authentication.
If we ever discover a breach affecting your personal data, we will notify affected users promptly and describe what happened and what we are doing about it.
08Email communication
When you place a deposit or create an account, you'll receive transactional emails (confirmation, access, course updates). These are part of the service you signed up for.
If we ever send purely promotional email, we'll include an unsubscribe link. Transactional emails related to your account or access cannot be opted out of while your account is active — but they're infrequent and never spammy.
09Data retention
We keep your account information for as long as your course access is active. If you ask us to delete your account, we will remove your personal data within 30 days, except where we are required to retain it for legal or financial record-keeping (for example, payment records).
10Your rights
You have the right to access, correct, or delete the personal information we hold about you. You can:
- Email hello@agentsforus.ai to request a copy of your data or ask us to delete your account.
- Update your name or email from your account settings.
- Withdraw from the course and request a refund as described in the Terms of Use.
If you are in the EU or UK, you may also have rights under GDPR or UK GDPR — including the right to lodge a complaint with a supervisory authority. Email us and we will assist.
11Cookies
We use essential cookies only: session tokens set by Clerk to keep you logged in, and a small cookie to track whether you've accepted the course terms. We do not use advertising cookies or third-party tracking cookies.
12Children
This course is for adults. We do not knowingly collect information from anyone under 18. If you believe a minor has created an account, contact us and we will delete it.
13Changes to this policy
If we make material changes, the date at the top of this page will update and we'll note it in our next course communication. Continuing to use the site after a change is acceptance of the updated policy.
14Governing law
This policy is governed by the laws of Canada. For any privacy-related questions or concerns, email hello@agentsforus.ai.
Questions or requests: hello@agentsforus.ai. Also see our Terms of Use.