Tooling Studio Logo

Privacy Policy

Last Updated: 07/28/2026

Introduction

Tooling Studio ("Tooling Studio", "we", "us", or "our") provides Kanban, CRM, Google Workspace integrations, Chrome extension features, and related services (collectively, the "Services").

This Privacy Policy explains what personal data we collect, how we use and protect it, when it is shared, and the choices available to you. It applies to the Tooling Studio website, web application, Chrome extension, Google integrations, Model Context Protocol ("MCP") service, and support and marketing interactions.

Tooling Studio is the controller of personal data processed for its own business purposes. When a team uses Tooling Studio to manage information about its customers, contacts, employees, or other people, that team may be the controller and Tooling Studio may process that information on its behalf.

Information We Collect

Depending on how you use the Services, we may collect:

  • Account and identity information, such as your name, email address, Google account identifier, profile image, company, job title, city, and country.
  • Workspace information, such as team memberships, invitations, roles, settings, and subscription status.
  • Kanban and CRM content, such as boards, lists, tasks, comments, attachments, links, contacts, organizations, deals, notes, custom fields, owners, tags, and activity history.
  • Google Workspace information when you connect or use a Google integration, as described in the Google API Data section below.
  • Billing information, such as subscription, invoice, payment status, and Stripe customer or subscription references. Payment-card details are processed by our payment provider and are not stored directly by Tooling Studio.
  • Communications, including support requests, feedback, newsletter subscriptions, and information you submit through website forms or MCP issue reports.
  • Technical, security, and usage information, such as IP address, browser and device information, authentication and audit events, request metadata, error information, page visits, referral information, and interactions with the Services.

Some content entered into Kanban or CRM may be confidential or sensitive to you or your organization. You control what you and your team enter and are responsible for having an appropriate basis to process information about other people.

How We Use Information

We use personal data to:

  • provide, operate, synchronize, and maintain the Services;
  • authenticate users and administer accounts, teams, permissions, and subscriptions;
  • provide the Google Workspace features a user chooses to connect;
  • provide user-facing AI-assisted features requested through the Services;
  • enable user-authorized MCP clients to perform requested actions;
  • process payments and manage subscriptions;
  • respond to support requests and communicate service information;
  • protect the Services, prevent abuse, investigate incidents, and maintain audit records;
  • diagnose errors, measure performance, and improve product functionality;
  • understand website use and marketing attribution;
  • send product or marketing communications where permitted; and
  • comply with legal obligations and enforce our agreements.

Depending on the context and applicable law, we process personal data to perform our contract with you, with your consent, to comply with legal obligations, or for legitimate interests such as securing, operating, and improving the Services.

Google API Data

Google integrations are used only to provide or improve user-facing features that you choose to use. Optional integrations are requested in context and can be disconnected or disabled through Tooling Studio settings. Availability may also depend on a Tooling Studio feature flag.

Google identity

Tooling Studio uses the openid, email, and profile permissions to sign you in, identify your account, and display basic profile information.

Google Tasks

Tooling Studio may request Google Tasks read and management permissions. These permissions allow Tooling Studio to view, create, update, organize, complete, and delete tasks used by the Google Tasks synchronization feature. Tooling Studio stores the identifiers and mappings needed to synchronize Tooling Studio tasks with the dedicated Tooling Studio list in Google Tasks.

Turning task synchronization off stops the synchronization. Where the product offers removal of the dedicated Google Tasks list, removing it does not delete the original Tooling Studio tasks.

Google Contacts

Tooling Studio uses read-only Google Contacts access to import contact information into CRM. Depending on the information present in a Google contact, this may include names, email addresses, phone numbers, postal addresses, birthdays, organizations, job details, biographies or notes, photos, and user-defined fields.

Imported contact information becomes Tooling Studio CRM data and remains there until it is edited or deleted in Tooling Studio. Tooling Studio does not use this permission to edit or delete your Google contacts.

Google Calendar

If you separately enable the Google Calendar meetings feature for CRM, Tooling Studio requests read-only access to events on your Google Calendar. Tooling Studio reads event details and may match attendees to CRM contacts by email address.

For matched events, Tooling Studio may store the event identifier, calendar identifier, title, description, start and end time, all-day and status information, Calendar link, meeting link, location, organizer, attendees, and Google update time. This information is used to show meeting context for the matched CRM contact. Tooling Studio does not create, edit, or delete Google Calendar events through this feature.

Turning this setting off stops synchronization and removes the synchronized CRM calendar-event records associated with the feature.

Gmail

If the Gmail API feature is available and you separately connect it, Tooling Studio requests the gmail.readonly permission. Tooling Studio searches for messages involving email addresses associated with a CRM contact and retrieves a limited number of results. Those results may include the subject, sender, recipients, date, message snippet, and a link to the message in Gmail.

This feature does not send email, modify messages, read attachments, or retrieve raw message content. CRM Gmail results are fetched when requested and are not stored as a message cache in the Tooling Studio database.

The Chrome extension can separately store a relationship between a Gmail thread or message and a Tooling Studio task. That stored relationship may include a Gmail thread or message identifier and URL. It remains until it or the associated Tooling Studio data is deleted, even if the optional Gmail API connection is disconnected.

Gmail authorization credentials are stored separately from the base Google connection and can be removed by disconnecting Gmail. Disconnecting Gmail from Tooling Studio removes the dedicated Gmail connection in Tooling Studio but may not revoke the entire Tooling Studio application in your Google Account because that could also disconnect Google Tasks, Contacts, or Calendar. You can revoke Tooling Studio's Google access through your Google Account permissions.

Google Drive

If the Google Drive Picker feature is available and you choose "Find in Google Drive," Tooling Studio requests the drive.file permission in response to that action. This permission lets you use Google's Picker to select files that you choose to share with the feature.

The short-lived Drive access token is kept in browser memory for the Picker flow and is not stored in Tooling Studio's database or sent to the Tooling Studio API. Tooling Studio stores the selected file's display name, Google Drive or Google Docs URL, and, where available, its last-edited timestamp as a link attached to a task, contact, organization, or deal.

Tooling Studio does not download, copy, export, upload, or store the contents of the selected Drive file through this feature. Access to the linked file continues to be controlled by its Google Drive permissions. Removing the link from Tooling Studio does not delete the file from Google Drive.

Google authorization credentials

For integrations that require continued server-side access, Tooling Studio stores Google access and refresh credentials in encrypted form and uses them only for the connected feature. Drive Picker credentials are handled as described above and are not stored server-side.

Google Limited Use

Tooling Studio's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Tooling Studio does not sell Google user data, use it for advertising, or use it to train generalized artificial intelligence or machine-learning models. Google user data is not transferred except as needed to provide or improve a user-facing feature you request, for security or legal reasons permitted by Google's policies, or as part of a corporate transaction with the required safeguards and consent.

AI-Assisted Features and Google Gemini

Tooling Studio uses the Google Gemini API as the only external AI model provider for built-in product features that process Tooling Studio or Google Workspace-derived data. We use Gemini API as a paid service through a Google Cloud project with active Cloud Billing. Under the terms applicable to Gemini API paid services, Google does not use prompts or responses to improve its products or train generalized artificial-intelligence or machine-learning models.

When you use an AI-assisted feature, Tooling Studio may send Google Gemini the information needed to provide that visible feature. Depending on your request, this may include your prompt, relevant Kanban or CRM content, task titles and descriptions, CRM import field names or sample values, and information originally imported or synchronized from Google Workspace. Current built-in uses include generating assistant responses, suggesting task checklists, and helping map CRM import fields.

Tooling Studio limits this processing to providing the feature you request. Tooling Studio does not use Google Workspace data to train or improve generalized AI or machine-learning models and does not permit Google Gemini to do so. Tooling Studio does not currently use another external AI model provider for these built-in product features. Tooling Studio does not operate a self-hosted or offline AI model for these features.

Google may retain prompts and responses for a limited period for abuse monitoring, safety, security, and legal compliance as described in the terms for Gemini API paid services. The separate MCP functionality described below lets you choose and authorize your own external AI or MCP client; that client is not a built-in Tooling Studio AI provider and its own privacy and retention terms apply.

Model Context Protocol and AI Clients

Tooling Studio offers an MCP service that lets you connect a compatible third-party AI or MCP client. MCP access is controlled through Tooling Studio settings and requires your authorization.

When you approve a connection, the client can receive access to the Tooling Studio Kanban and CRM capabilities granted to that connection. Within your existing Tooling Studio permissions, a connected client may read and modify data such as teams, boards, lists, tasks, comments, task links, attachments, contacts, organizations, deals, owners, tags, and custom fields. Destructive tools require an additional confirmation parameter, but you should review the actions requested by your AI client.

Information returned through MCP is transferred to the client at your direction. Once received by a third-party client, that client's privacy policy, security, and retention practices also apply. Only connect clients you trust.

Tooling Studio stores MCP connection information such as the client name, identifier, redirect address, granted scopes, connection status, and last-used time. We also store limited activity and security telemetry such as protocol method, tool or operation name, result status, duration, and a sanitized argument summary. Routine MCP activity telemetry is designed not to store complete task, CRM, or tool payloads. If you submit an MCP issue report, we store the summary and details you provide together with relevant diagnostic context.

You can revoke an individual connection or disable MCP access in Tooling Studio. Revocation prevents future access and token refresh for that connection.

How We Share Information

We do not sell personal data. We may disclose information:

  • to members of your Tooling Studio team according to workspace permissions;
  • to Google when you use Google authentication or Google Workspace integrations;
  • to a third-party MCP or AI client that you authorize;
  • to infrastructure, database, storage, hosting, analytics, communications, customer-support, marketing, and payment providers that process information for us under appropriate contractual and confidentiality obligations;
  • when you ask us to make a transfer or integration available;
  • to professional advisers, auditors, insurers, or potential transaction parties where reasonably necessary and subject to safeguards; or
  • when required by law or necessary to protect rights, safety, and the integrity of the Services.

Providers used for relevant parts of the Services include Google and Google Cloud, Supabase, DigitalOcean, Cloudflare, Stripe, Google Analytics and Google Tag Manager, and Zoho Campaigns. The provider involved depends on the feature you use. Some website support and lead forms may notify our team through Google Chat.

Cookies, Local Storage, and Analytics

The website and application use cookies and similar technologies for authentication, security, load balancing, preferences, and other functionality necessary to provide the Services. Cloudflare and other infrastructure providers may set security cookies.

On the public website, Tooling Studio uses Google Tag Manager and Google Analytics to understand page visits and interactions. We may process page location, page title, referrer, campaign and attribution parameters, and interactions with links, calls to action, and forms. The website also uses browser sessionStorage and localStorage to remember landing pages, referrers, campaign attribution, and certain interface preferences.

You can use browser controls to delete or block cookies and local storage. Blocking technologies that are necessary for authentication or security may prevent parts of the Services from working. Where applicable law requires consent for non-essential analytics, we will handle those technologies in accordance with that requirement.

Data Security

We use technical and organizational measures designed to protect information against unauthorized access, loss, misuse, or alteration. These measures include, as appropriate:

  • encryption in transit and encryption of stored Google OAuth credentials;
  • access controls and tenant-level authorization checks;
  • OAuth state validation and Proof Key for Code Exchange (PKCE);
  • restricted and incremental authorization for optional Google integrations;
  • input validation, server-side request protections, and content sanitization;
  • security and audit logging with sensitive-value redaction;
  • dependency, secret, and security scanning in our development and deployment processes; and
  • connection revocation and account security controls.

No internet service can guarantee absolute security. You are responsible for keeping your account and connected-client credentials secure and for notifying us if you suspect unauthorized access.

Data Retention and Deletion

We retain account, workspace, Kanban, and CRM data while your account or workspace is active and as needed to provide the Services. Particular integration records are removed or disconnected as described in the Google API Data and MCP sections.

When an account is deleted, Tooling Studio deletes or anonymizes account and owned product data from active systems in accordance with the account's role, team ownership, and the data's relationship to other workspace members. Some records may be soft-deleted or retained in de-identified form to preserve shared-workspace integrity.

We may retain limited information after deletion where required for billing, fraud prevention, security, audit, dispute resolution, legal compliance, or enforcement. Residual copies may remain temporarily in backups and disaster-recovery systems until they are overwritten through normal retention cycles. Revoked connection records and security events may be retained for a limited period to demonstrate and protect account security.

You may also revoke Tooling Studio directly from your Google Account. Revoking access stops future Google API access but does not automatically delete information previously imported into Tooling Studio, such as CRM contacts or stored task mappings. Delete that information in Tooling Studio or request account deletion if you also want the Tooling Studio copy removed.

Marketing Communications

If you subscribe to a newsletter or receive optional marketing communications, we use your contact information to send those communications and measure their delivery. We may use Zoho Campaigns or another communications provider for this purpose. You can unsubscribe through the link in a marketing message or contact us.

Service and security communications that are necessary for your account are not marketing messages.

International Data Transfers

Tooling Studio and its service providers may process information in countries other than the country where you live. Where required, we use recognized safeguards for international transfers, such as adequacy decisions or contractual protections.

Your Rights and Choices

Depending on where you live, you may have rights to:

  • access or receive a copy of your personal data;
  • correct inaccurate information;
  • request deletion;
  • restrict or object to certain processing;
  • withdraw consent where processing is based on consent;
  • receive portable data;
  • opt out of marketing communications; or
  • complain to a data-protection authority.

You can update certain information and integration settings directly in Tooling Studio. You may disconnect Gmail, turn off Calendar synchronization, revoke MCP connections, revoke Tooling Studio through your Google Account, or delete your Tooling Studio account.

To exercise a right that is not available in the product, contact us at [email protected]. We may need to verify your identity before completing a request. Some rights are subject to legal exceptions.

Children's Privacy

The Services are intended for business and professional use and are not directed to children under 16. We do not knowingly collect personal data from children under 16 through the Services.

Contact Us

Questions, privacy requests, or complaints can be sent to [email protected].

Changes to This Policy

We may update this Privacy Policy when our Services, providers, or legal obligations change. We will publish the revised policy on this page and update the "Last Updated" date. If a change materially affects how we use information, we will provide additional notice where required.