Privacy
What Roster does with your data
Roster connects to your mailbox and your calendar, so this page has to be specific rather than reassuring. Where something is inconvenient to say, it is said here anyway — a policy you cannot check is a brochure.
Who this covers
Roster Solo (“Roster”) is operated by an individual developer, not a company with a privacy department, and this policy covers the hosted service at rostersolo.com.
Two different sets of people appear in Roster: you, the owner of a workspace, and your contacts — the customers and prospects whose messages your agents read. You are our customer. Your contacts are yours, and we process their data on your instruction.
What we handle
- Account data — your name, email address, and the workspace you belong to, taken from the Google account you sign in with. If you were invited to sign in with an email address and password instead, we store only a salted, deliberately slow hash of the password (scrypt), never the password itself.
- Mail — the threads your agents work on, including sender, recipients, subject and body, once you connect a mailbox.
- Calendar — event times, titles and attendees, read-only, if you connect a calendar.
- CRM records — contacts, companies, deals, notes, quotes and rate-card items you or your agents create.
- Agent activity — every action an agent proposes or takes, the reasoning steps behind it, and what you approved or rejected.
- Social messages — Instagram, Facebook, WhatsApp or TikTok direct messages, only if you connect that channel.
- Billing — a Stripe customer and subscription identifier. Card numbers never reach Roster; checkout and the billing portal are Stripe’s own hosted pages.
Google user data
what we ask for, what it does, and what it cannot do
Roster requests the narrowest scopes that let the product work, and deliberately declines wider ones that would have been easier to get approved. Each scope below is requested only when you connect the matching account, and you can revoke any of them from your Google account at any time.
Read the threads your agents work on: triage what is a lead, draft a reply in context, follow up on a conversation that went quiet.
Read-only. It cannot alter, label, archive or delete anything.
Send the replies you approve, from your own Gmail account, so they sit in your Sent folder like any other message you wrote.
Send-only. It cannot read, draft, label, archive or delete your messages. Each reply is held in Roster for your approval first, and nothing is sent without it until you choose to give an agent more autonomy.
See external meetings so an agent can brief you beforehand and chase what was agreed after.
Read-only. Roster cannot create, move, accept or cancel an event. Agents may offer your booking link; they never commit your time.
Roster does not request gmail.modify, which most mail integrations ask for and which would also grant relabelling and trashing every message in your mailbox. Nothing in Roster alters your mail, so it does not ask for the ability to.
In plain terms, that commitment means all of the following.
- Google user data is used only to provide and improve the features you can see in Roster — reading a thread so an agent can draft a reply, and nothing else.
- It is never used for advertising, and never sold or transferred for advertising, credit assessment, or any other purpose unrelated to the product.
- It is never used to create, train, fine-tune or otherwise improve a machine-learning or artificial-intelligence model — ours or a vendor’s. That commitment is contractual with our model provider, not just a policy statement.
- It is transferred to a third party only to run the features you turned on: the text an agent is working on is sent to our model provider (Anthropic, or OpenAI where selected) to produce the reply or brief you see, and a reply you approve is sent through Gmail. It is also transferred where needed for security, to comply with the law, or, with your prior consent, as part of a merger or sale of the service. It is never transferred to advertising platforms, data brokers or information resellers.
- No human reads your Google user data, except where you have given explicit consent for specific messages, where it is necessary for security purposes such as investigating abuse, where it is required by law, or where the data has been aggregated and anonymised for internal operations.
How it is protected
- Encrypted in transit — every connection to Roster and every call to a provider is TLS. The database connection requires TLS.
- Credentials encrypted at rest — mail and calendar tokens are sealed with AES-256-GCM under a per-workspace key, and the ciphertext columns are not readable by the role that serves web requests.
- Workspaces are isolated in the database — row-level security is enforced on every tenant table, and the application connects as a role with no table privileges of its own.
- Everything is recorded — each agent action is written to an append-only, hash-chained audit log, where every entry commits to the one before it. The application role has no UPDATE or DELETE on that table at all, so tampering is detectable including by us.
Who else sees it
Roster is not sold, rented or shared for anyone else’s purposes. Data reaches the vendors below only to make the product work.
| Vendor | Why | Location |
|---|---|---|
| Vercel | Application hosting and delivery | United States |
| Supabase | Managed Postgres — the database everything is stored in | United States |
| Anthropic | Model provider — receives the text an agent is reasoning over | United States |
| OpenAI | Model provider, when selected or brought as your own key | United States |
| Gmail and Calendar, when you connect a Google account | United States | |
| Stripe | Subscription billing, and payment links you send to your customers | United States |
| ManyChat | Instagram, Facebook, WhatsApp and TikTok messages, if connected | United States |
We may also disclose data where required by law, and would tell you unless legally prevented from doing so.
Models, and what they retain
When an agent works, the text it is reasoning over — which can include the body of a customer’s email — is sent to a model provider. Nothing from your workspace trains a model, ours or a vendor’s.
What we do not have is a zero-retention agreement, and it would be easy to imply otherwise. The provider we route to deletes inputs and outputs within 30 days, and content its automated safety systems flag can be held for up to two years. Zero retention is negotiated per organisation with the provider; it is not a default anyone gets by asking. If your work requires it, bring your own key on an account that has it, and your customers’ mail travels under your contract instead of ours — or point Roster at a model running on your own hardware, in which case none of it leaves your machine.
How long we keep it
Your workspace data is kept for as long as your workspace exists, because a CRM whose records expire is not a CRM. There is no background job that deletes your contacts or your pipeline on a timer.
Deletion is something you do, and it happens immediately rather than on a queue:
- Disconnect a mailbox — Roster calls the provider’s revoke endpoint, overwrites the stored credential, and stops all syncing. For Google, the token is revoked with Google directly. For IMAP mail, the credential is destroyed here but must also be withdrawn at your own provider, and Roster tells you so at the time.
- Purge a mailbox — additionally deletes the mail threads and message activity ingested through that connection. Roster shows you the real row counts beforehand, queried from the rows a purge would actually remove.
- Delete your workspace — removes everything: contacts, companies, deals, quotes, agents, memory and connections. A final entry is written to the audit log recording that it happened, which is the one thing that survives, because a deletion nobody can evidence is not a deletion anybody should trust.
One deliberate exception, stated because it would otherwise be a surprise: purging a mailbox does not delete your contacts. A contact is a CRM record you may have spent years building and may have entered by hand; it is not a by-product of the mail connection, and destroying it because a mailbox was disconnected would be the wrong default. Deleting the workspace does remove them.
Backups of the database are retained by our hosting provider on their own schedule and are purged on that cycle, so a deleted record can persist in a backup for a short period after it is gone from the live system.
What you can do
- Take everything with you. Settings → “Download everything” exports your whole workspace — contacts, pipeline, quotes, your agents’ charters and the complete audit log — with the hash-chain verification recipe included, so you can confirm offline that nothing was rewritten. One click, not a support ticket.
- Revoke at the source. You can withdraw Roster’s access from your Google account permissions page at any time. Roster notices and stops.
- Ask us anything about your data, including access, correction and deletion, at privacy@rostersolo.com. Depending on where you live you may have rights under the GDPR, the UK GDPR, or US state privacy laws; we honour those requests regardless of whether a particular law applies to you.
Children
Roster is a business tool and is not directed at anyone under 16. We do not knowingly collect data from children.
Changes
If this policy changes in a way that affects how your data is handled, the effective date above changes and we will tell you by email before it takes effect rather than after.