Back to Home

Privacy Policy

Last updated: February 13, 2026

1. Who We Are

ChiefofStaff is operated by:

Sonnet Advisors

Contact: craig@sonnetadvisors.com

Sonnet Advisors is the data controller responsible for decisions regarding the processing of Personal Data under this Privacy Policy.

The application is hosted on secure cloud infrastructure.

2. Scope

This Privacy Policy explains how we collect, use, disclose, store, and protect personal data when you use:

  • The ChiefofStaff mobile or web application
  • Associated services and integrations
  • Website and customer support communications

This Policy applies globally, including users in the United States, European Union (EU), European Economic Area (EEA), and United Kingdom (UK).

3. Data We Collect

We collect only the data necessary to provide the Service.

A. Account Information

  • First and last name
  • Email address
  • Organization name
  • Account credentials
  • Profile image (if uploaded)

B. Voice Data

  • Voice recordings (temporary, processed for transcription and immediately deleted after transcription)
  • Transcriptions of voice commands (retained up to 30 days or until account termination)

C. Task & Productivity Data

  • Tasks and reminders
  • Internal team assignments
  • Meeting notes
  • Email summaries
  • Calendar events

D. Internal Contacts

The App does not access or import device phone contacts.

Users may manually create internal contacts consisting of:

  • First name
  • Last name
  • Email address

Contacts are created only when:

  • The user manually enters them, or
  • The user gives a voice command and confirms creation in a permission popup.

Clear in-app disclosure explains how contact data is stored and used.

E. Integration Data (If Connected)

If you connect Google or Microsoft accounts, we may process:

  • Email content and metadata
  • Calendar events
  • Contact names and email addresses from integrated accounts

We access only the data necessary to provide core functionality (summarization, task creation, scheduling).

F. Technical Data

  • Device type
  • IP address
  • Log data
  • Usage analytics
  • Security event logs

4. How We Collect Data

We collect data through:

  • Direct user input
  • Voice microphone (with explicit permission)
  • Integration APIs (Google/Microsoft, if enabled)
  • Automated system logs

We do not scrape, purchase, or import phone contact lists.

5. Legal Bases for Processing (GDPR)

For EU/EEA/UK users, processing is based on:

Data TypeLegal Basis
Account dataContract performance
Voice transcriptionContract + Consent
Email/calendar integrationConsent + Contract
Internal contactsContract
Security logsLegitimate interest
Compliance recordsLegal obligation

Users may withdraw consent for integrations at any time by disconnecting accounts.

6. How We Use Personal Data

We use data solely to:

  • Provide AI executive assistant functionality
  • Transcribe and process voice commands
  • Summarize emails
  • Create and manage tasks
  • Manage calendars
  • Enable team collaboration
  • Provide customer support
  • Ensure security and fraud prevention
  • Comply with legal obligations

We do not:

  • Sell personal data
  • Use email or calendar content for advertising
  • Build marketing profiles from sensitive integrations
  • Use integration data for data mining

Sensitive data from email and calendar integrations (including email content, calendar events, and associated metadata) is used exclusively to provide the core Service functionality described above. This data is not used for marketing, advertising, or any form of use-based data mining, either by us or by any third-party service providers, subprocessors, or analytics partners.

7. Data Retention

Data TypeRetention PeriodDeletion Trigger
Voice recordingsImmediately deleted after transcriptionAutomatic
TranscriptionsUp to 30 daysAutomatic deletion or account termination
Account dataDuration of subscriptionAccount deletion
Task & productivity dataDuration of subscriptionAccount deletion
Integration dataWhile integration is activeDisconnection or account deletion
Security logsUp to 12 monthsSystem rotation

Upon account termination, personal data is deleted or anonymized within a commercially reasonable timeframe unless retention is legally required.

8. International Data Transfers

All data is hosted in the United States.

For EU/EEA/UK users, transfers are safeguarded by:

  • Standard Contractual Clauses (EU 2021/914)
  • UK International Data Transfer Addendum (where applicable)
  • Technical and organizational security measures
  • Contractual safeguards with subprocessors

9. Automated Decision-Making

The Service uses AI to process commands and summarize information.

The Service does not make decisions producing legal or similarly significant effects without human involvement.

Users retain full control over actions taken based on AI-generated outputs.

10. Your Rights

EU/EEA/UK Users

You have rights to:

  • Access
  • Rectification
  • Erasure
  • Restrict processing
  • Data portability
  • Object to processing
  • Lodge complaints with supervisory authorities

California Residents (CCPA/CPRA)

You have rights to:

  • Know what personal information is collected
  • Request deletion
  • Correct inaccurate data
  • Opt out of sale (we do not sell data)

Requests may be submitted to: privacy@chiefofstaff.pro

11. Security Measures

We implement:

  • Encryption in transit
  • Role-based access control
  • Limited internal access
  • Secure U.S. infrastructure
  • Contractual subprocessor safeguards

12. Subprocessors

We may use third-party service providers to host or support the Service.

A current list of subprocessors is available upon request at: privacy@chiefofstaff.pro

All subprocessors are contractually required to provide appropriate data protection safeguards.

Third-party service providers and subprocessors are contractually prohibited from using data accessed through Google and Microsoft integrations (including email content, calendar events, and contacts) for any purpose other than providing the Service. They may not use this data for marketing, advertising, targeted profiling, or use-based data mining.

13. Data Protection Officer

We have not appointed a Data Protection Officer as our processing activities do not require one under Article 37 GDPR.

14. EU and UK Representatives

Where required under Article 27 GDPR and UK GDPR, we will appoint a representative within the EU and United Kingdom and publish their contact details here.

15. Contact Us

For questions about this Privacy Policy or to exercise your rights, contact us at:

privacy@chiefofstaff.pro