TorqueX.ai torqueX.ai
// LEGAL · PRIVACY EFFECTIVE 2026-06-03

Privacy Policy

Effective date · 2026-06-03

torqueX Technologies Pvt. Ltd. ("Torquex", "we", "us") operates torquex.ai, Agent X and its agents (collectively, the "Service"). This policy describes what personal data we collect, how we use it, and the choices you have.

01 What we collect

1.1 You provide directly

1.2 You authorise us to collect via Google

When you use Google sign-in or Connect Gmail, we receive from Google (with your consent):

  • Your Google account ID (sub claim).
  • Your Google account email address.
  • Your Google account display name.
  • Your Google account profile picture URL.

When you connect a Google account, the Service requests the following permissions, each tied to a specific feature. It requests no others:

  • Know which account you connected - the userinfo.email scope. In plain English: the Service reads the email address of the Google account you just connected, and shows it to you in the product so you can tell which account is in use and disconnect the right one. It is not used for marketing and is not shared.
  • Send email on your behalf — the gmail.send scope. In plain English: the Service can send email from your Gmail account so it can deliver the outreach emails, replies, and follow-ups you approve to your customers and prospects, from your own address. The Service only sends a message after you review and approve it; it does not send mail without your action.
  • Create calendar events on your behalf — the calendar.events scope. In plain English: when a prospect accepts a meeting, or when you schedule a podcast recording, the Service creates that event on your calendar and invites the other party, including a Google Meet link. It creates and updates events it made for you at your direction; it does not delete events it did not create. To offer meeting slots, the Service may also check your calendar's free/busy availability (the Calendar free/busy query): this returns only which time blocks are busy or free — never the titles, attendees, locations, or any other contents of your events. You can revoke this at any time by disconnecting the account.
  • Create spreadsheets for you in Google Drive - the drive.file scope. In plain English: when you ask an agent to export something - a contact list, a group roster - it creates a NEW Google Sheet in your Drive and writes the rows, then gives you the link. This permission covers only files the Service itself created: it cannot open, read or list any file you already had, and it will tell you so rather than ask for broader access.
  • Upload videos to your YouTube channel - the youtube.upload scope. In plain English: the Marketing team can publish a video you reviewed and approved to the channel you connected. It uploads nothing you have not approved, and it does not read or change your existing videos.
  • Reply to comments on your videos - the youtube.force-ssl scope. In plain English: comments on your own videos appear in your unified inbox, and when you approve a reply the Service posts it. YouTube offers no narrower write permission for this. The Service does not delete or edit your videos, ratings, comments or captions.

Deliverability reporting (optional, Workspace administrators only). If you are a Google Workspace administrator, you may separately grant the Service the postmaster.readonly scope through domain-wide delegation. This returns Google’s aggregated reputation and spam-rate statistics for a domain you own, so the Service can warn you before your sending reputation harms your delivery. It contains no message content and identifies no individual recipient. It is never requested during the normal Connect Gmail flow, and the Service works without it.

A Google account connected by OAuth is send-only: the Service holds no permission to read your mailbox. Where you ask it to detect replies, that is done over IMAP using an app password you supply, and message bodies are handled in-memory during a single request - never stored beyond that request lifecycle (typically under 60 seconds). Only the structured outputs - reply and intent classifications, and any attached document files - are persisted, scoped to your tenant. Outbound messages you send through the Service are stored as part of the outreach record on your tenant.

With Gmail access, the Service does not:

  • Read mail unrelated to the feature you invoked (e.g., detecting replies to your outreach).
  • Send any email you have not reviewed and approved.
  • Sell or transfer Gmail content to third parties, or use it to train generalized or AI models.
  • Use Gmail data for advertising.

Disconnecting Gmail and deleting data. You can disconnect Gmail at any time from your account settings, or revoke access directly via your Google account permissions page. On disconnect we revoke the stored refresh token and stop sending on your behalf immediately. To delete the data the Service has already derived from Gmail (extracted line items, reply records, attachments, sent-message records), delete the associated records from the product or email enterprise@torquex.ai to request deletion of your account and all associated data.

1.3 We collect automatically

02 How we use it

We use the personal data described above only for the purposes listed below, each tied to a lawful basis under the EU / UK GDPR.

Purpose Lawful basis (GDPR)
Provide the Service you signed up for Contract
Authenticate you on subsequent visits Contract
Run the outreach and agent pipelines you configure Contract
Send transactional emails (quote sent, password reset) Contract
Send product update emails Legitimate interest; opt-out via unsubscribe link
Fraud and abuse detection Legitimate interest
Comply with legal obligations (tax, requests from authorities) Legal obligation

We do not sell your personal data and do not share it with third parties for their own marketing.

03 Who we share it with

Recipient What they receive Why
Fly.io (US) All application data — the Service's compute and workers run here Hosting
Neon (US) The Service's database — accounts, contacts, campaigns, messages Managed Postgres
Cloudflare The web app and website; files and media you upload (R2 storage) Hosting and file storage
Dodo Payments Billing details and card data (we never hold your card number) Payment processing
SendGrid / Google Workspace Email address, subject, and body of transactional emails (verification, password reset, contact-form mail) Delivery
Maildoso; Inframail Managed sending mailboxes and their traffic, where you provision torqueX-managed email infrastructure Email infrastructure
Unipile The messaging accounts you connect (LinkedIn, WhatsApp, Instagram, and similar) and the conversations the Service handles on them Messaging-account connectivity
Hostinger; Namecheap Registrant contact details for domains you purchase through the Service Domain registration
Apify; People Data Labs The audience criteria you configure (role, industry, geography) used to source prospect contacts Contact sourcing
Cerebras / OpenRouter / Anthropic Content of the specific request you made (e.g., the context for an outreach draft, or text extracted from a document you uploaded) LLM inference for the agent
Google (when you use Google sign-in / Gmail connect) OAuth handshake metadata Authentication
Government authorities Only what a valid legal order compels us to disclose Compliance with applicable law

Each subprocessor is bound by a Data Processing Agreement enforcing the same privacy and security obligations we owe you. The current subprocessor list is also referenced in our Data Processing Addendum; we provide 30 days' notice of changes to Enterprise customers with a right to object.

04 Where we store it

Where: the Service runs on Fly.io and Neon in the United States, with web assets and uploaded files on Cloudflare's network. Your data is processed in the US regardless of where you sign up from

Enterprise customers who need a specific hosting region can contact us; regional deployment is available as a custom arrangement, not a default

05 How long we keep it

06 Your rights

You can:

  • Access the data we hold about you (export from account settings, or email enterprise@torquex.ai).
  • Correct inaccurate data (edit in-product or email us).
  • Delete your account and all associated data (account settings → Delete account; or email us).
  • Port your data — exports are JSON / CSV.
  • Object to legitimate-interest processing.
  • Withdraw consent at any time without affecting the lawfulness of prior processing.

EU / UK residents may also lodge a complaint with their local supervisory authority (for example, the Information Commissioner's Office in the UK, or your member-state Data Protection Authority in the EU).

07 Security

08 Children

The Service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact enterprise@torquex.ai and we will delete it.

09 Changes

We will email all account owners at least 30 days before any material change to this policy. Non-material changes (typos, clarifications, formatting) take effect on publication. Prior versions are preserved in our public git history.

10 Contact

11 Google API services — Limited Use Disclosure

The Service (torqueX) accesses Google user data through the Gmail API: it sends email on your behalf to deliver the quotes, outreach, replies, and follow-ups you approve. It also uses the Google Calendar API to create and update the meetings you or your prospects agree to — including their Google Meet links — on the calendar of the account you connected.

The Service also uses YouTube API Services when you connect a YouTube channel to the torqueX Marketing team: it uploads videos you have created and explicitly approved to your own channel (YouTube Data API), reads comments on your own videos and posts the replies you approve. The Service acts only on the authenticated channel you connected, only at your direction. By connecting YouTube you also agree to the YouTube Terms of Service; Google's handling of your data is described in the Google Privacy Policy. You can revoke the Service's access to your YouTube data at any time by disconnecting the channel in the product or via your Google security settings; on disconnect we revoke and delete the stored tokens, and you can request deletion of stored YouTube-derived data (video records, comment records) at enterprise@torquex.ai.

The Service's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular, the Service affirms that it does not:

  • Sell Google user data.
  • Use Google user data for advertising or any form of personalized advertising.
  • Use Google user data to train generalized or artificial-intelligence models.
  • Allow humans to read Google user data, except with your explicit consent (e.g., for support you request); where necessary for security, to investigate abuse, or to comply with applicable law; or where the data has been aggregated and anonymized.
  • Transfer Google user data except as necessary to provide or improve the feature you invoked, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to you.
// Effective 2026-06-03 · Counsel review pending · Material changes require 30 days notice to account owners. Prior versions in git history.