Trust & data

Privacy notice

This notice explains the information Roundly processes to operate fundraising workspaces, connected inboxes, document workflows, funding records, cap tables, and the Roundly Guide.

Last updated August 31, 2026

Document version: privacy-2026-08-31-r2

Information Roundly processes

Account and workspace data: verified identity, name, email, company, role, session and device observations, and security events.

Fundraising data: investor contacts, communications, workflow status, meetings, documents, commitments, funding evidence, and cap-table records entered by authorized workspace users.

Connected services: OAuth account identifiers, encrypted access credentials, selected mailbox history, email headers and content needed for investor monitoring, calendar signals, and reviewed outbound messages.

Technical data: request logs, device and browser characteristics, diagnostics, and audit records used for reliability and security.

Why the information is used

Roundly uses this information to authenticate users, enforce company access, connect selected services, identify investor activity, prepare user-reviewed communications and documents, reconcile workflow records, provide support, investigate incidents, and comply with legal obligations.

Roundly does not sell connected-mailbox data or use it for advertising. Sensitive actions such as sending investor email, releasing protected materials, and changing financial records remain subject to the product's approval controls.

Mailbox and Google Workspace data

Mailbox access is optional and separate from sign-in. For Gmail, Roundly requests permission to read messages without modifying them and permission to send messages only after an administrator reviews them. Roundly does not request permission to modify or delete Gmail messages. Disconnecting a mailbox revokes future access; imported evidence and derived workspace records may remain until separately deleted or retained for a documented legal or audit reason.

Roundly's use and transfer of information received from Google Workspace APIs adheres to the Google Workspace API User Data and Developer Policy (https://developers.google.com/workspace/workspace-api-user-data-developer-policy), including its Limited Use requirements.

AI-assisted processing

If a workspace administrator enables managed AI, selected email excerpts and workspace context may be sent to the configured model provider to classify investor signals, explain evidence, and draft recommendations. Roundly stores the resulting evidence and suggestions so administrators can review them. AI suggestions do not automatically send email, execute documents, confirm funds, or change legal ownership records.

Before public Gmail processing is enabled, Roundly requires an explicit, versioned workspace consent describing the active provider and applicable retention terms.

Sharing, retention, and security

Information is shared only with infrastructure, identity, email, storage, and AI service providers needed to operate enabled features; with workspace users according to their role; or when required for security, legal compliance, or a business transfer. OAuth credentials and protected financial instructions are encrypted at rest, and company authorization is checked on server-side requests.

Retention depends on the data type, workspace configuration, legal obligations, and active contracts. Account deletion removes data that Roundly is not legally or operationally required to retain; regulated financial, legal-document, and audit records may be retained with access restricted.

Your choices

You can decline mailbox access, choose the history window, disconnect a provider, ask a workspace administrator to correct data, and request account deletion. Requests and privacy questions can be sent to support@getroundly.ai.