Privacy policy.
Effective September 21, 2026 · Papaya is operated by Papaya AI, Inc. This policy covers this website, contact messages and Business enquiries, the data Papaya receives from a Google account you connect, and the Papaya Desktop app for Mac.
What we collect on this website
The email address you give us when you message us or enquire about Business, and anything you choose to tell us about your team (name, company, size, tools, how you use agents, or what you need). We also collect information about how you use this website, as the next section describes.
Website analytics
We use analytics to understand how people use this website and to improve it. If you allow analytics cookies, we use them for this. If you don't, we measure your visit without cookies.
- What we collect: information about how you use the website, such as the pages you visit and how you interact with them, and technical information about your browser and device, including your IP address.
- Cookies: analytics cookies last up to a year. If you sign in to Papaya in the same browser, information collected with them may be linked to your account.
- Legal basis: your consent for analytics cookies, which you can withdraw at any time without affecting what was collected before, and our legitimate interest in understanding how the website is used for measurement without cookies. You can object to that measurement by turning on Global Privacy Control in your browser or by emailing hello@trypapaya.ai.
- Who receives it: an analytics service provider that processes it on our behalf and stores it in the United States. Transfers from the European Economic Area, the UK and Switzerland are protected by the European Commission's Standard Contractual Clauses.
- How long we keep it: only as long as we need it to understand how the website is used.
Change your choice at any time with Cookie settings at the bottom of every page.
How we use it
To reply to the message or Business enquiry you sent us, and to contact you about Papaya if you asked us to. And to understand how this website is used and improve it. That's it.
Where it lives
When the sales-enquiries service is configured, everything sent from the contact and Business forms is stored in its database. When a form cannot submit, you can send the same information to hello@trypapaya.ai instead. The providers of that service and our mail and workspace tools process and store the information on our behalf.
Messages, documents and other content inside a Papaya workspace are governed by our terms and by any separate agreement a team signs with us. Data Papaya receives from a connected Google account is covered by the section below.
Google user data
This section explains how Papaya accesses, uses, stores, shares and deletes data it receives from Google APIs when you connect a Google account. For Google user data, it applies in addition to the rest of this policy and takes precedence where they differ.
Limited Use
Papaya's use and transfer of information received from Google APIs, including raw or derived data received from Google Workspace APIs, adheres to the Google API Services User Data Policy, including the Limited Use requirements.
When Papaya receives Google user data
Only when you connect your own Google account to Papaya on the Connections page. Signing in to Papaya does not use Google. Each connection belongs to one person in one workspace, and only that person's requests, routines and briefings use it.
What we access, and why
- Your Google account (openid, email, profile): your Google account ID, email address, name and profile picture, so Papaya can show which account is connected.
- Gmail (gmail.readonly, gmail.compose): messages an agent searches for and reads when you, or a routine you set up, ask it to; message headers and Gmail's short preview snippet, at most 200 characters, for your daily Scout briefing (never message bodies); saving an email you have approved to your Gmail drafts, without sending it; and sending an email you have approved.
- Google Calendar (calendar): calendars and events an agent reads for you; event titles, times and attendee names for your daily briefing and your Radar (never event descriptions or meeting links in the briefing); and creating or updating an event you have approved.
How we use it
Only to provide the features you use in Papaya: answering and acting on your requests to agents, running routines you create, writing your daily Scout briefing, and showing work related to you on your Radar.
Agents act on your Google account only with your approval. Before Papaya sends an email, or creates or updates a calendar event, it shows you a consent card with the action, the account and the draft, and nothing happens until you approve it.
We do not sell Google user data, use it for advertising, or use it to determine creditworthiness or for lending.
AI and machine learning
Papaya's agents and briefings are powered by AI models. To answer a request or write a briefing, the Google user data involved is processed by Anthropic and OpenAI. Text in your workspace, which can include an agent's answer built from your Google data, is converted into search vectors by Voyage AI and may be read by a model we reach through OpenRouter (Z.ai) to understand conversation threads.
These providers process the data only to return results to Papaya, under terms that do not allow them to train their models on it. We do not use Google user data, or anything derived from it, to develop, improve or train generalized or non-personalized AI or machine learning models.
Who can see it
- Your daily briefing and your Radar are visible only to you.
- When you ask an agent something in a direct message, a channel or a routine, its answer, which may quote your Google data, is visible to the people who can see that conversation, channel or routine destination.
- For a calendar event that is linked to work in your workspace, its title, start time and attendee names can appear to other members of that workspace.
- A memory saved to the workspace, which can include a fact from your Google data, is visible to the members of that workspace.
Who we share it with
We share Google user data outside Papaya only:
- With service providers that process it on our behalf to run Papaya: Google Cloud (hosting, in the United States), the AI providers named above, Apple's push notification service (which delivers short message previews, including agent answers, to your devices), and our error-monitoring providers (Sentry and Pydantic Logfire), which can receive details of an error that occurs while handling it.
- When needed for security, such as investigating abuse or a bug.
- When required by law.
- As part of a merger, acquisition or sale of assets, and only after asking for your explicit consent.
We never transfer Google user data to advertising platforms, data brokers or information resellers.
Human access
People at Papaya do not read your Google user data unless you give us explicit permission to look at something specific (for example to resolve a support request), it is necessary for security (such as investigating abuse or a bug), it is required by law, or the data has been aggregated and anonymized for internal operations.
How it is stored and protected
Papaya runs on Google Cloud in the United States. Traffic between you, Papaya and Google travels over encrypted connections (HTTPS), and Papaya's databases are encrypted at rest. The OAuth tokens that let Papaya reach your Google account are held by a separate credential service, encrypted, and are never stored by the main application.
How long we keep it
- Tokens are kept while your Google account is connected and deleted as soon as you disconnect it.
- What Papaya gathers for your daily briefing is stored with an expiry date, and the gathered details are deleted when you disconnect Google.
- Agent conversations, the Google data an agent read to answer them, agent answers, Radar items and related workspace knowledge are kept while your workspace uses Papaya, or until you ask us to delete them.
Your controls, revocation and deletion
- Disconnect Google at any time on the Connections page in Papaya. Papaya stops accessing your account and deletes its tokens immediately.
- Remove Papaya's access from your Google Account as well at myaccount.google.com/permissions. Disconnecting in Papaya does not remove the grant on Google's side.
- To delete Google user data we hold about you, email hello@trypapaya.ai. We will delete it within 30 days, and copies in backups are removed as those backups expire.
Changes to how we use Google user data
If we change how Papaya uses Google user data, we will tell you and ask for your consent before using it in the new way.
Read Google's API Services User Data Policy, including the Limited Use requirements.
Papaya Desktop
Papaya Desktop is the Papaya app for Mac. This section explains what the app keeps on your Mac, what it sends and to whom, and how to remove it. It applies in addition to the rest of this policy.
The app and your account
The app opens the same Papaya service you use in a web browser. Your account and your workspace are handled exactly as they are on the web.
Your sign-in
The app keeps your sign-in session in its data folder on your Mac, encrypted with a key held in your macOS Keychain. If that encryption is not available, the app keeps the session the way a web browser does.
Error reports
The app may send reports of errors in the app itself to our error-monitoring provider, Sentry. A report contains the error, where in the app it happened, recent app events such as a window opening, the app version, and technical details of your Mac, including its operating system and computer name. The app removes sign-in tokens and other secrets it recognizes before a report is sent. Reports do not include your messages, documents or runs, and the app never sends crash dumps of its memory.
Run on this Mac
You can choose Run on this Mac so an agent in your workspace can run its work on your Mac with your own AI coding tool, Claude Code or Codex. Nothing runs until you connect an agent, choose a folder for its runs and confirm.
- Downloads. Before it first runs the agent client, the app uses the uv tool that comes with it to download Python and Papaya's agent client (the papaya-agent-client package and the packages it needs) from third-party sources, including the Python Package Index (PyPI). These requests carry no Papaya account information, and the downloads are kept in the app's data folder.
- Connecting. Connecting an agent registers your Mac with Papaya as a connection named after your Mac's computer name. That connection has its own token, which is kept in the app's data folder.
- Other agents' setups. Before your Mac starts running an agent's work, and when you change its folder, the app looks in your AI tool's settings on this Mac for Papaya setups it did not make, and asks Papaya which agent and workspace each one belongs to, using that setup's own access key. If it finds one, it shows it to you and removes it from those settings only if you choose to. If the app edits a settings file itself, it keeps a copy of the file from before next to it.
- Your approval. Before each run, the app asks whether to run it, unless you chose to always run that agent's work. A run you don't allow goes back to Papaya.
- What a run can reach. Once you allow a run, your AI tool does the work with full access to your files and tools on this Mac, starting in the folder you chose.
- Your AI provider. Your AI tool sends the run's instructions, and whatever it reads to do the work, including content from your Papaya workspace, to its own provider, such as Anthropic for Claude Code or OpenAI for Codex. Your agreement with that provider, not this policy, governs how it handles that data.
- Results. What the agent posts back, such as a reply in a thread, goes to Papaya and is handled like any other agent message in your workspace.
- Logs. Each run's output and the app's own logs stay in the app's data folder on your Mac. The app does not upload them.
Updates
When automatic updates are on, the app checks our download server, downloads.trypapaya.ai, for a new version every few hours. The check includes the app's version and a random identifier the updater creates for this copy of the app, and no account information.
Stopping and removing the app
- Choose Stop running on this Mac in Papaya at any time. The app stops listening for work, and a run in progress stops.
- Choose Ask before every run in the same place or in the Workspace menu, and the app will ask before every run again.
- To remove the app and what it keeps on your Mac, quit it, move Papaya from your Applications folder to the Trash, and delete its data folder, ~/Library/Application Support/Papaya (or ~/Library/Application Support/Papaya Staging for the test build). That folder holds your encrypted sign-in, the agent client, the connection token and the logs.
What we never do
We don't sell your data, share it with advertisers, or add you to lists you didn't ask for. Every email we send includes a way to opt out, and one reply is enough to be removed.
Your choices
Ask us what we hold about you, ask us to correct it, or ask us to delete it: email hello@trypapaya.ai and we'll do it promptly, and for Google user data within 30 days.
If you are in the European Economic Area, the UK or Switzerland, Papaya AI, Inc. is the controller of your personal data. You also have the right to object to or ask us to restrict how we use your data, to receive it in a portable format, and to withdraw consent you have given at any time. You can complain to your local data protection authority.
Changes to this policy
If this policy changes in a way that matters, we'll note it here with a new effective date before it takes effect.
Questions? Email hello@trypapaya.ai.