Privacy

What Roster does with your data

Roster connects to your mailbox and your calendar, so this page has to be specific rather than reassuring. Where something is inconvenient to say, it is said here anyway — a policy you cannot check is a brochure.

Effective 4 September 2026. Wording last clarified 4 October 2026.

Who this covers

Roster Solo (“Roster”) is operated by an individual developer, not a company with a privacy department, and this policy covers the hosted service at rostersolo.com.

Two different sets of people appear in Roster: you, the owner of a workspace, and your contacts — the customers and prospects whose messages your agents read. You are our customer. Your contacts are yours, and we process their data on your instruction.

What we handle

Google user data

what we ask for, what it does, and what it cannot do

Roster requests the narrowest scopes that let the product work, and deliberately declines wider ones that would have been easier to get approved. Each scope below is requested only when you connect the matching account, and you can revoke any of them from your Google account at any time.

gmail.readonly

Read the threads your agents work on: triage what is a lead, draft a reply in context, follow up on a conversation that went quiet.

Read-only. It cannot alter, label, archive or delete anything.

gmail.send

Send the replies you approve, from your own Gmail account, so they sit in your Sent folder like any other message you wrote.

Send-only. It cannot read, draft, label, archive or delete your messages. Each reply is held in Roster for your approval first, and nothing is sent without it until you choose to give an agent more autonomy.

calendar.events.readonly

See external meetings so an agent can brief you beforehand and chase what was agreed after.

Read-only. Roster cannot create, move, accept or cancel an event. Agents may offer your booking link; they never commit your time.

Roster does not request gmail.modify, which most mail integrations ask for and which would also grant relabelling and trashing every message in your mailbox. Nothing in Roster alters your mail, so it does not ask for the ability to.

Limited Use. Roster’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace APIs, including Gmail, will also adhere to the Google Workspace API User Data and Developer Policy.

In plain terms, that commitment means all of the following.

How it is protected

Who else sees it

Roster is not sold, rented or shared for anyone else’s purposes. Data reaches the vendors below only to make the product work.

VendorWhyLocation
VercelApplication hosting and deliveryUnited States
SupabaseManaged Postgres — the database everything is stored inUnited States
AnthropicModel provider — receives the text an agent is reasoning overUnited States
OpenAIModel provider, when selected or brought as your own keyUnited States
GoogleGmail and Calendar, when you connect a Google accountUnited States
StripeSubscription billing, and payment links you send to your customersUnited States
ManyChatInstagram, Facebook, WhatsApp and TikTok messages, if connectedUnited States

We may also disclose data where required by law, and would tell you unless legally prevented from doing so.

Models, and what they retain

When an agent works, the text it is reasoning over — which can include the body of a customer’s email — is sent to a model provider. Nothing from your workspace trains a model, ours or a vendor’s.

What we do not have is a zero-retention agreement, and it would be easy to imply otherwise. The provider we route to deletes inputs and outputs within 30 days, and content its automated safety systems flag can be held for up to two years. Zero retention is negotiated per organisation with the provider; it is not a default anyone gets by asking. If your work requires it, bring your own key on an account that has it, and your customers’ mail travels under your contract instead of ours — or point Roster at a model running on your own hardware, in which case none of it leaves your machine.

How long we keep it

Your workspace data is kept for as long as your workspace exists, because a CRM whose records expire is not a CRM. There is no background job that deletes your contacts or your pipeline on a timer.

Deletion is something you do, and it happens immediately rather than on a queue:

One deliberate exception, stated because it would otherwise be a surprise: purging a mailbox does not delete your contacts. A contact is a CRM record you may have spent years building and may have entered by hand; it is not a by-product of the mail connection, and destroying it because a mailbox was disconnected would be the wrong default. Deleting the workspace does remove them.

Backups of the database are retained by our hosting provider on their own schedule and are purged on that cycle, so a deleted record can persist in a backup for a short period after it is gone from the live system.

What you can do

Children

Roster is a business tool and is not directed at anyone under 16. We do not knowingly collect data from children.

Changes

If this policy changes in a way that affects how your data is handled, the effective date above changes and we will tell you by email before it takes effect rather than after.

Roster Solo·How the trust works·Terms·privacy@rostersolo.com
Privacy · Roster Solo